|
Plagegeister aller Art und deren Bekämpfung: Rechner mit MyStart by IncrediBar infiziert.Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
26.09.2012, 14:09 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Rechner mit MyStart by IncrediBar infiziert. Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ Logfiles bitte immer in CODE-Tags posten |
30.09.2012, 10:00 | #17 |
| Rechner mit MyStart by IncrediBar infiziert. Sry, ging wegen Schule und Arbeit nit eher ....
__________________Code:
ATTFilter OTL Extras logfile created on: 30.09.2012 09:44:07 - Run 1 OTL by OldTimer - Version 3.2.68.0 Folder = C:\Users\Teddy\Desktop Professional (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,08 Gb Available Physical Memory | 69,30% Memory free 6,00 Gb Paging File | 4,67 Gb Available in Paging File | 77,88% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 307,62 Gb Total Space | 68,54 Gb Free Space | 22,28% Space Free | Partition Type: NTFS Drive E: | 623,88 Gb Total Space | 535,91 Gb Free Space | 85,90% Space Free | Partition Type: NTFS Computer Name: TEDDY-PC | User Name: Teddy | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{042C7E2A-841E-45C1-A3D4-06EA70F430AB}" = lport=56316 | protocol=17 | dir=in | name=pando media booster | "{0A6AB701-DA6E-45D0-8B73-BA55BE034C80}" = rport=445 | protocol=6 | dir=out | app=system | "{178746BC-3AE8-4418-85D1-0EC7121C039F}" = lport=56961 | protocol=6 | dir=in | name=pando media booster | "{1C5F9690-D2DC-4B3F-8D90-4509D0115A93}" = lport=138 | protocol=17 | dir=in | app=system | "{21478779-9EEF-4500-8648-250FBA35C359}" = lport=56316 | protocol=6 | dir=in | name=pando media booster | "{2D3B327E-55AA-4923-84F1-B50F9F8E2EB0}" = lport=10243 | protocol=6 | dir=in | app=system | "{39AAC9C3-F834-4BD1-96C2-766CD1D9B5E5}" = lport=2869 | protocol=6 | dir=in | app=system | "{39DA9A05-F39A-4B13-A8DF-BDB8D86B1665}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{4DAD588E-8B8F-42F1-8B0D-D048E6A76B71}" = lport=2869 | protocol=6 | dir=in | app=system | "{52136536-26A9-485E-A366-E6D0F6E8F03F}" = lport=56316 | protocol=6 | dir=in | name=pando media booster | "{539A9354-B3F8-4823-8D81-E7D1B00636E0}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5D620BF4-3B7B-4B2D-8C79-712953F5FB0D}" = lport=445 | protocol=6 | dir=in | app=system | "{678D85D0-02F2-4C7A-934C-459221B87B08}" = lport=2869 | protocol=6 | dir=in | app=system | "{7617B37B-00ED-489C-8F14-8DFACF4D99B6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{76D7C153-1009-4E91-8866-0D38EAAA5E8E}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{773A5AA1-A81E-4C32-8C1D-D4802786A2C0}" = lport=56640 | protocol=17 | dir=in | name=pando media booster | "{847CA01F-AAD6-48A2-A2C5-ADFB7DB7E19D}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{885518BB-2620-4221-A537-8E6D488919CF}" = lport=56640 | protocol=6 | dir=in | name=pando media booster | "{905FF085-2F26-4CEC-B04B-FF6D521A358B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{939F9FD5-D88E-4433-A55C-C318ECB89733}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{99820895-7E31-4D2E-B173-9FD19C325F0D}" = rport=139 | protocol=6 | dir=out | app=system | "{99F9D15B-633A-4A8D-8C24-EBF2F330125E}" = rport=2869 | protocol=6 | dir=out | app=system | "{9B472875-5122-46AA-85B4-38CFD4327824}" = rport=138 | protocol=17 | dir=out | app=system | "{9EA523D1-4BF5-4954-A180-4FB5E6B4BECE}" = lport=58029 | protocol=6 | dir=in | name=pando media booster | "{AB745FBE-24C4-4A66-AA7E-8C9598F257B5}" = lport=56961 | protocol=17 | dir=in | name=pando media booster | "{B05BC583-8535-449B-BAA2-C7A1CC1FF7A4}" = lport=137 | protocol=17 | dir=in | app=system | "{B49061D0-A11B-41B8-A530-CC72A41D5ED2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B5AA2EC0-602D-4CD5-8573-21E7E77DC753}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B60080C3-7745-4E9E-814E-225E05C0BA3F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{B6455C3E-6792-4C33-9288-D6D75A2A83FE}" = lport=56961 | protocol=6 | dir=in | name=pando media booster | "{B8D59387-6BAC-4B49-9EDE-D7DD6273CBD9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{BC5B13A0-9231-4714-BFC3-13102D6D47B7}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BEC9E7C4-33E9-428D-88D6-4DBC7AD33922}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{C1E4DEB0-A57C-4E0F-B8AC-816EDC94299A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C2BC930A-7A2C-42EB-8E79-63EBF70753D1}" = rport=137 | protocol=17 | dir=out | app=system | "{C4349EB1-1267-41DF-B34D-49A5EBEB182F}" = lport=56961 | protocol=17 | dir=in | name=pando media booster | "{D5271AC5-F9F7-484A-9FC1-9F8BDFBF1B09}" = lport=56316 | protocol=17 | dir=in | name=pando media booster | "{DAC76632-FC0B-4A4E-9A7A-7B6AC5DA18F1}" = lport=58029 | protocol=6 | dir=in | name=pando media booster | "{DE9E9BE1-6272-4F73-8B39-9A5F6F12B8A8}" = rport=10243 | protocol=6 | dir=out | app=system | "{DFDD8C0A-DD63-4956-9337-6FF5F531CAC7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{E00AD9CA-C06D-47E6-8D6E-2C24745E172D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E291A67A-8910-4A21-B593-35156568AC6D}" = lport=58029 | protocol=17 | dir=in | name=pando media booster | "{E4D8F22C-53FC-4033-A8CA-52FFFF282188}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E6C58723-57C0-4A7E-8BE7-7FB1B3B1C11A}" = lport=56640 | protocol=6 | dir=in | name=pando media booster | "{E8109A89-A94C-44CE-B65D-235AEE2EF9F9}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{E989944F-0128-47AE-A695-FC43F1052E62}" = lport=58029 | protocol=17 | dir=in | name=pando media booster | "{EE2A06B7-7AEC-4C20-83BE-5751316F0A08}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{F586FD09-B8FE-4B51-A16F-8EE70A47BCD8}" = lport=139 | protocol=6 | dir=in | app=system | "{F949A64E-BBD7-4C6A-B724-4CCC51ADBF53}" = lport=56640 | protocol=17 | dir=in | name=pando media booster | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00CDB66E-5D70-46BF-90FD-E5D4C188B004}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{00DDED6A-1F9D-4240-8AC9-66868F7E2A39}" = protocol=17 | dir=in | app=e:\uo fl\client.exe | "{02625D39-75F7-4C1D-9B0A-E8C5757D65EF}" = protocol=6 | dir=in | app=c:\program files\xblades\xblades.exe | "{058B96FA-7F20-4082-90B5-A365E9A408CA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{0A979ED5-2F0E-4DDD-BDC6-293AACC95E54}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe | "{0B8E0B75-A01F-46BA-90B6-B97FE26D2D7B}" = protocol=6 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe | "{0EA2D3F7-365F-4AF6-ACCC-852EFCF400DF}" = protocol=17 | dir=in | app=c:\program files\raptr\raptr.exe | "{1334AB93-9D3F-49F8-A68F-0072176C6853}" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\alathair\rsync.exe | "{146128EC-D499-49C0-85B9-0597767FD0D5}" = dir=in | app=c:\program files\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe | "{19CA99BC-F985-4EB7-A668-A4ECB774BDEB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{2E092EC7-CA9B-42E4-99B0-4C0DD36B6F0D}" = protocol=6 | dir=in | app=c:\program files\pplive\pplite\pplite.exe | "{2FBBE5AB-2C2A-487E-BC40-5C3C832F8875}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{37B5F634-37F4-4212-89DD-536BE7E06DB9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{3B83BA8E-4ABE-476E-8F99-06E6F39D4A11}" = protocol=17 | dir=in | app=c:\program files\xblades\launcher.exe | "{3DAD6590-32F4-4796-8F7B-0E223CAA17B6}" = protocol=6 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe | "{3DF76B7E-FD00-4207-8DED-83EE9BC9183F}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{3E0C1EC0-7E20-45FB-8992-0AD3290ECDCE}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe | "{423C3723-BAB4-400C-A0B3-72D68E6F1FB9}" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\alathair\rsync.exe | "{4415A533-FDCA-47C5-BB02-0DA5CAABB536}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe | "{45F2749C-E01B-43A1-A71E-B1591831FC2D}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\update engine\sony ericsson update engine.exe | "{4B51D030-F7DE-48A8-88DD-FB4115778C17}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{4EB6680A-0DAC-4634-ABDF-FBBB74301839}" = protocol=6 | dir=in | app=c:\alathair\client.exe | "{5337969D-EA98-473F-8FFA-0F4C04A42B3E}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | "{53E21AA5-6423-4FDD-9FED-660B6D4692CB}" = protocol=17 | dir=in | app=c:\program files\pplive\pplite\pplite.exe | "{55CAD5D9-B56D-4AAD-8EDB-D184E424EB29}" = protocol=17 | dir=in | app=c:\koramgame\stonline\_launcher.exe | "{58C440F6-3D8B-4879-92ED-C32DE915D678}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | "{59915BD8-6733-4CEA-BD97-B2C78918FFB5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{5A471F4B-EA81-4C76-8DC8-382BD73C0A8E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{5A7CEFD2-7B89-4150-9A47-921748CDA2FE}" = protocol=17 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe | "{5C205E07-E92D-460A-A523-D2A4933BF5BE}" = protocol=6 | dir=out | app=c:\program files\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe | "{5D0A8849-23BF-453B-9E8D-E63CF71A24AB}" = protocol=17 | dir=in | app=e:\gpotato.eu\sevencore\sevencore.exe | "{615494AE-3943-4EEF-811E-4585AC8DF77B}" = protocol=6 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_launcher.exe | "{61F7CD10-6988-4776-BB6D-23A975D80112}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{62720D90-6C49-4122-8A21-82AA7A78DA8D}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | "{6A9787E0-26CA-4550-B96F-BCCE5C70FBAD}" = protocol=17 | dir=in | app=e:\gpotato.eu\sevencore\launcher.exe | "{6ABDA17B-3E91-4ED1-91F2-04162FC3B4E6}" = dir=in | app=c:\program files\wificonnector\nintendowfcreg.exe | "{6E3D13B6-EEDD-4068-9C54-C4CFC8B5C44B}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{75FCF4B6-AD97-4AAF-8362-60AE8C765E28}" = protocol=6 | dir=in | app=c:\alathair\rsync.exe | "{7CDB6F02-0BAC-41B1-A4CF-8ECB08427444}" = protocol=17 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_dx9.exe | "{7D379615-A772-44E1-8EB6-A39511CA9C2E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{7DDE379F-DC74-44CC-B9BF-BF46EA0E7E5E}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{7E8EF602-BEFA-4BDD-9F28-CE82531AE008}" = dir=in | app=c:\program files\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe | "{8073F3A0-46D6-4249-ABEA-F9258A11B7D9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{80A63A25-2250-4C6F-9875-37A9F54C3F04}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe | "{8114F343-3A9F-441F-9556-6B402827AFA0}" = protocol=6 | dir=in | app=c:\program files\xblades\launcher.exe | "{817E3EBC-857D-402B-A3F4-121503871714}" = protocol=17 | dir=in | app=c:\program files\xblades\xblades.exe | "{83C2438A-F650-4792-90B2-C7BAB91794B5}" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\client.exe | "{8426339A-C842-4BEC-9665-73D0BDDF1984}" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\uo.exe | "{88A598B2-86BF-4323-B8AD-A21853E4E899}" = protocol=6 | dir=in | app=e:\gpotato.eu\sevencore\sevencore.exe | "{8DD0FAE8-E968-415E-90BE-F1F3C8D2D5DA}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{8F55B8A9-4A44-45EE-89EE-F350C9E00442}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{90BF5CDF-7811-4ACC-B88E-19E1EC606709}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{950FB107-7C87-47A1-9DE5-666EED0E4319}" = dir=in | app=c:\program files\itunes\itunes.exe | "{9B7E5148-19CC-4D08-9F41-0B1B13A37641}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{9C8CD922-9606-4F41-803F-9031DDFCA4E6}" = protocol=6 | dir=in | app=c:\program files\raptr\raptr_im.exe | "{9E258B8F-CE8A-406D-A896-21725BC4E8D3}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | "{9E9CA593-42BB-46DF-BFF3-6DF10B578293}" = protocol=6 | dir=in | app=c:\program files\raptr\raptr.exe | "{A18F29DA-1E24-453E-92AB-83CE22A1477B}" = protocol=17 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe | "{A1E96149-BB72-4FCA-951C-6DB633F73869}" = protocol=6 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_dx10.exe | "{A2BDDD05-81FD-4190-88AC-98088D279C6E}" = protocol=6 | dir=out | app=c:\program files\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe | "{A66AEF93-99BC-42B5-ACB0-339F5959584B}" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\client.exe | "{A6C2595F-AA98-44F1-B5CB-B3BE19165499}" = protocol=17 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe | "{A8202EEF-0915-4ED6-88AB-2834A4B834B0}" = protocol=6 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_dx9.exe | "{A9BD0492-7188-4EB3-86E1-D26C9DC1A982}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{AB68E69F-47E0-47CA-84CA-646B61460163}" = protocol=17 | dir=in | app=c:\alathair\rsync.exe | "{AF5FEA63-B2CD-4C6B-9A7F-BDEC2E7E57CD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{B1A0663A-5B02-4564-832D-2FBC473C2E1B}" = dir=in | app=c:\gpotato.eu\allods online\bin\launcher.exe | "{B23E7BBD-F4D7-4A56-8B2B-C79481FDFAD7}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{B4974B62-3695-4C4E-9627-AACB3E2A24DB}" = protocol=6 | dir=in | app=c:\koramgame\stonline\_launcher.exe | "{B51DB17A-C6E6-488E-8E3B-2A51ECFA2870}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe | "{B61F6BB3-20B9-4EA2-A33C-AF3DEA5A0D84}" = protocol=6 | dir=in | app=c:\windows\system32\msiexec.exe | "{B96B6078-1CE5-4F48-B890-7434781519B6}" = protocol=17 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_dx10.exe | "{BEAE9E23-49BC-4DBE-A2BC-102DC04EAC87}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | "{BF311B7C-17C8-4F91-8535-A0BA5A0BAA0B}" = protocol=6 | dir=in | app=e:\gpotato.eu\sevencore\launcher.exe | "{BF8D3108-0C75-485B-9C19-A4EC87683751}" = protocol=17 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_launcher.exe | "{C05103F6-95B4-4B0A-AB8B-28DEAF06945A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{C087D857-1D33-4A7F-9591-4E104D106013}" = protocol=17 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe | "{C2A9D136-CC6B-4722-971F-BFA88DF23134}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | "{C35B1078-D012-4C35-88F2-4BDE014478DD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{C3DB37BB-A3CC-473B-9523-2AC2597E74A0}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | "{C4DB1259-34D8-4798-B36D-101070DD79AC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{C75581B5-3911-4898-BF2F-4786D729D5AF}" = protocol=6 | dir=in | app=c:\alathair\uo.exe | "{C842A4CB-AD59-41DA-BEC4-5F0C1E9306BB}" = protocol=17 | dir=in | app=c:\alathair\client.exe | "{D1E7058B-7345-4B5B-8619-16ED9ADB7A5F}" = protocol=6 | dir=out | app=system | "{D2204C16-DB8C-4058-9E35-BAB4419FD367}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{D33E86A6-E1D3-4AA0-99E8-1B2F8DA54F7F}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe | "{D54AF8D5-ED7E-4BF8-B391-5FCE764A95F5}" = protocol=17 | dir=in | app=c:\alathair\uo.exe | "{DA36953A-5F62-4D5B-9FE6-34583A75A582}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe | "{E14E95CE-D525-4723-AC5A-5CDB6D45190E}" = protocol=6 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe | "{E45157D2-4926-4C14-9322-C7A6E23D8DD5}" = protocol=17 | dir=in | app=c:\windows\system32\msiexec.exe | "{E869BE1E-E4AB-48D9-B4C8-471110DA7B68}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe | "{E89809AB-C733-4BFC-B966-3FE0FDA6C241}" = protocol=6 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe | "{EB49BA65-1FC4-4EB1-8956-59F83C07406E}" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\uo.exe | "{EEA2E0EA-BA0E-4710-B106-0418F601A36F}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "{F0B93396-24F0-4EFE-9918-5910C43C8AC8}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe | "{F198E940-E576-4CFC-AA98-6E8A22737402}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\update engine\sony ericsson update engine.exe | "{F6A2665A-284C-4047-A9D6-621815A758A7}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe | "{F7008223-0710-4C62-8581-B47DE7CA0DEA}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "{F76A36EB-0D10-464B-856D-2F075A149BD6}" = protocol=6 | dir=in | app=e:\uo fl\client.exe | "{F7FCF15F-079D-4861-8A6C-A60A4137A314}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{F9842304-E081-48F7-9659-A0B145C48E1F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{F9B34F76-BD92-4142-894C-0EA76C58BEF5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{FC3AE8DA-2F27-4E98-B418-A24863B5F313}" = protocol=17 | dir=in | app=c:\program files\raptr\raptr_im.exe | "{FD918D6C-9867-471F-A87A-2D03C0601321}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{FD9FCF52-0502-4DE5-901A-CF09DC583AC9}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | "TCP Query User{0E567B0E-B3AD-4533-9E32-6E7D4BABBA11}C:\program files\raptr\raptr.exe" = protocol=6 | dir=in | app=c:\program files\raptr\raptr.exe | "TCP Query User{352BFF5B-EEA2-4F83-8B7E-7076B645797A}C:\users\teddy\appdata\local\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\users\teddy\appdata\local\google\chrome\application\chrome.exe | "TCP Query User{355B8229-155A-43E7-BE89-00DC3D664F2D}C:\skariatain\client_5.0.4b.exe" = protocol=6 | dir=in | app=c:\skariatain\client_5.0.4b.exe | "TCP Query User{35B118EB-A398-4E55-A252-233B29153897}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "TCP Query User{38802DE5-A196-4086-B816-08FF631EB735}C:\alathair\uo.exe" = protocol=6 | dir=in | app=c:\alathair\uo.exe | "TCP Query User{3F614959-E8E9-4B2C-A86F-0048FE09B118}C:\spiele\uo\alathair spielserver\client.exe" = protocol=6 | dir=in | app=c:\spiele\uo\alathair spielserver\client.exe | "TCP Query User{40CCBEA8-7D5F-4769-BC58-A96B7F66BC09}C:\alathair\client.exe" = protocol=6 | dir=in | app=c:\alathair\client.exe | "TCP Query User{4B7FE0C6-F671-4B62-B22B-6AA4011A741A}C:\program files\common files\pplivenetwork\ppap.exe" = protocol=6 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe | "TCP Query User{50687EB0-6815-4064-8CCF-CDDF44830D65}C:\users\teddy\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\teddy\program files\dna\btdna.exe | "TCP Query User{52973A3E-01FC-4F5E-8767-20424E0DFA1C}E:\pro7\dc universe online live\unreal3\binaries\win32\dcgame.exe" = protocol=6 | dir=in | app=e:\pro7\dc universe online live\unreal3\binaries\win32\dcgame.exe | "TCP Query User{5612DD04-DB43-4501-9609-DB65F44E8A65}C:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_slim_eu.exe" = protocol=6 | dir=in | app=c:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_slim_eu.exe | "TCP Query User{5A74951A-0B6C-422C-886D-E3FE7A4C4EFD}H:\client.exe" = protocol=6 | dir=in | app=h:\client.exe | "TCP Query User{5C452A7E-0DC4-4A76-9039-551B7C05B1D9}E:\uo fl\client.exe" = protocol=6 | dir=in | app=e:\uo fl\client.exe | "TCP Query User{692C54E5-918D-4B2B-8552-23F301982990}C:\spiele\uo\alathair spielserver\uo.exe" = protocol=6 | dir=in | app=c:\spiele\uo\alathair spielserver\uo.exe | "TCP Query User{6DF8B29D-1398-4A54-AE73-FE8D9D339166}C:\users\teddy\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\teddy\appdata\local\akamai\netsession_win.exe | "TCP Query User{700310F3-B805-488A-B072-C8ACE09D8E3B}C:\spiele\uo\ultima online\client.exe" = protocol=6 | dir=in | app=c:\spiele\uo\ultima online\client.exe | "TCP Query User{72C8768A-7BC5-4908-81DC-A3A400F22394}C:\spiele\der herr der ringe online\lotroclient.exe" = protocol=6 | dir=in | app=c:\spiele\der herr der ringe online\lotroclient.exe | "TCP Query User{762488D3-B862-4C91-94AC-4595C2A171A4}C:\ultima online mondain's legacy\uo.exe" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\uo.exe | "TCP Query User{790C3487-610E-438B-9395-5988B497FF0B}C:\ultima online mondain's legacy\client.exe" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\client.exe | "TCP Query User{7C71D07D-CC73-407A-BB27-B5B00270D44F}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe | "TCP Query User{7F8E7AEE-D808-44DF-8A77-2D5A62606458}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe | "TCP Query User{93FCE622-545B-4296-927B-A7E57E2457B3}C:\program files\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe | "TCP Query User{98F065E6-F916-4B3F-88E3-3D967E9EE467}C:\program files\icq7.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "TCP Query User{A223E131-BFD8-4A21-A5D0-C85F5B6D8803}C:\users\public\games\cryptic studios\star trek online\live\gameclient.exe" = protocol=6 | dir=in | app=c:\users\public\games\cryptic studios\star trek online\live\gameclient.exe | "TCP Query User{A82B76F6-74DE-473E-862E-53DBFEAE4D16}C:\spiele\uo\alathair spielserver\uopatch.exe" = protocol=6 | dir=in | app=c:\spiele\uo\alathair spielserver\uopatch.exe | "TCP Query User{B346CD32-F7E7-4BBC-B5B4-F01753025B5C}C:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_full_eu_new.exe" = protocol=6 | dir=in | app=c:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_full_eu_new.exe | "TCP Query User{C4D38104-8650-4718-8558-EF3EA2369226}C:\spiele\uo\alathair spielserver\alathair\rsync.exe" = protocol=6 | dir=in | app=c:\spiele\uo\alathair spielserver\alathair\rsync.exe | "TCP Query User{C6B25E27-E003-4428-95FB-3785CE6BBCF5}C:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire\xfire.exe | "TCP Query User{CA43737F-A488-44DD-A47F-0E80404E2EBE}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe | "TCP Query User{CE8A6F57-8EC5-494E-9E19-A54322B7656A}C:\alathair\rsync.exe" = protocol=6 | dir=in | app=c:\alathair\rsync.exe | "TCP Query User{E7931745-2400-4953-80B3-B50C510FEA16}C:\program files\tmunitedforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmunitedforever\tmforever.exe | "TCP Query User{EBA1A418-C121-4318-9538-A030246F9F54}C:\program files\runes of magic\client.exe" = protocol=6 | dir=in | app=c:\program files\runes of magic\client.exe | "TCP Query User{F17BAF6F-E15B-4B3D-8254-1BD33EE8FB0E}C:\users\teddy\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\teddy\program files\dna\btdna.exe | "TCP Query User{F774567D-CDE4-401A-93DC-71E5E55DCC80}C:\users\teddy\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\teddy\appdata\local\akamai\netsession_win.exe | "TCP Query User{F82110CF-F27D-47D2-8B3F-4614CE62F732}C:\ultima online mondain's legacy\alathair\rsync.exe" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\alathair\rsync.exe | "UDP Query User{05EF0E08-C2B1-46BA-A82B-45A901AC61D2}E:\pro7\dc universe online live\unreal3\binaries\win32\dcgame.exe" = protocol=17 | dir=in | app=e:\pro7\dc universe online live\unreal3\binaries\win32\dcgame.exe | "UDP Query User{0625D1DB-866B-4DCC-B9F1-4A6D9442ACB4}C:\alathair\uo.exe" = protocol=17 | dir=in | app=c:\alathair\uo.exe | "UDP Query User{1A19E6DC-D5BE-4F4C-BDAE-D9190B64EDD8}C:\program files\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire\xfire.exe | "UDP Query User{1B44EDC6-C610-4A59-B2AC-9FE3316BB22B}C:\users\teddy\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\teddy\appdata\local\akamai\netsession_win.exe | "UDP Query User{2C1C555A-4742-4127-B8D3-2744252112BE}C:\program files\common files\pplivenetwork\ppap.exe" = protocol=17 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe | "UDP Query User{2E7A1319-3713-4F26-A0E5-CF782083D99F}E:\uo fl\client.exe" = protocol=17 | dir=in | app=e:\uo fl\client.exe | "UDP Query User{2F543649-A8E4-430D-9046-92B5AC8C493A}C:\skariatain\client_5.0.4b.exe" = protocol=17 | dir=in | app=c:\skariatain\client_5.0.4b.exe | "UDP Query User{375607A4-9817-46FC-A25D-BC2642FE2F80}C:\users\teddy\appdata\local\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\users\teddy\appdata\local\google\chrome\application\chrome.exe | "UDP Query User{3D8A6A01-F736-4A0A-87C1-C3183D7B10CB}C:\alathair\rsync.exe" = protocol=17 | dir=in | app=c:\alathair\rsync.exe | "UDP Query User{45A080B0-2EC8-4457-BC09-3458C4C43B2E}C:\alathair\client.exe" = protocol=17 | dir=in | app=c:\alathair\client.exe | "UDP Query User{46D6431F-D750-4296-AF11-44F719EE1D3A}C:\spiele\uo\alathair spielserver\uopatch.exe" = protocol=17 | dir=in | app=c:\spiele\uo\alathair spielserver\uopatch.exe | "UDP Query User{4CEBF930-5189-4760-B621-5E4DD1888579}C:\users\teddy\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\teddy\appdata\local\akamai\netsession_win.exe | "UDP Query User{4D802BAB-54BE-436C-97ED-4F43E59C00E0}C:\program files\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe | "UDP Query User{5723AA18-5D4F-4FF6-8BC3-203B6AC87203}C:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_full_eu_new.exe" = protocol=17 | dir=in | app=c:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_full_eu_new.exe | "UDP Query User{5CC30633-D87B-48E0-BBD2-F4D2BCCCA35E}C:\program files\icq7.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | "UDP Query User{613B514C-B52F-463A-816D-69C6914ACA69}C:\spiele\der herr der ringe online\lotroclient.exe" = protocol=17 | dir=in | app=c:\spiele\der herr der ringe online\lotroclient.exe | "UDP Query User{6720AC70-F825-4A43-96F8-6375EF166BE5}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe | "UDP Query User{6912B6FA-0F4C-4861-8EAE-80A5130F3F72}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "UDP Query User{6C054855-29BC-4F6E-8332-6027685F40E6}H:\client.exe" = protocol=17 | dir=in | app=h:\client.exe | "UDP Query User{70B9E9A7-C87B-4B5A-9DA9-D8A1AB81548E}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe | "UDP Query User{7148C411-2C7F-4454-9465-D623A60D3338}C:\spiele\uo\alathair spielserver\client.exe" = protocol=17 | dir=in | app=c:\spiele\uo\alathair spielserver\client.exe | "UDP Query User{7D0C9FF1-FACB-441E-B6AE-937F29B11200}C:\ultima online mondain's legacy\client.exe" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\client.exe | "UDP Query User{84102653-0AE3-4EF4-A61A-24C0B36D9F82}C:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_slim_eu.exe" = protocol=17 | dir=in | app=c:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_slim_eu.exe | "UDP Query User{84DB0956-F317-4D9E-8815-12CC2DCBC591}C:\ultima online mondain's legacy\alathair\rsync.exe" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\alathair\rsync.exe | "UDP Query User{8BC704C1-6A1D-410B-8427-E46D81746141}C:\users\public\games\cryptic studios\star trek online\live\gameclient.exe" = protocol=17 | dir=in | app=c:\users\public\games\cryptic studios\star trek online\live\gameclient.exe | "UDP Query User{911375C9-E7D8-439F-A134-AA755A7C0A87}C:\spiele\uo\ultima online\client.exe" = protocol=17 | dir=in | app=c:\spiele\uo\ultima online\client.exe | "UDP Query User{921E9140-06FD-4AB8-829C-0F4A970D0693}C:\spiele\uo\alathair spielserver\alathair\rsync.exe" = protocol=17 | dir=in | app=c:\spiele\uo\alathair spielserver\alathair\rsync.exe | "UDP Query User{97A18327-4DAB-4DD5-A747-A2ABC5A63334}C:\ultima online mondain's legacy\uo.exe" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\uo.exe | "UDP Query User{A2EF2046-E6BC-422A-93F9-B3B3CB289575}C:\program files\raptr\raptr.exe" = protocol=17 | dir=in | app=c:\program files\raptr\raptr.exe | "UDP Query User{CB681107-FAB4-4FD3-9FD9-0C12655EECCC}C:\spiele\uo\alathair spielserver\uo.exe" = protocol=17 | dir=in | app=c:\spiele\uo\alathair spielserver\uo.exe | "UDP Query User{E4902184-291A-4114-B524-8B0A88F451FD}C:\users\teddy\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\teddy\program files\dna\btdna.exe | "UDP Query User{EC4AC65F-99AB-4168-A453-9118A32EE6C0}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe | "UDP Query User{ED2A0A8C-3289-4C96-A6F9-5A7651AA7BC0}C:\program files\runes of magic\client.exe" = protocol=17 | dir=in | app=c:\program files\runes of magic\client.exe | "UDP Query User{EF92AE53-AC7B-4E09-83E1-275B77F980B0}C:\program files\tmunitedforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmunitedforever\tmforever.exe | "UDP Query User{F43ED939-7BAB-4177-9868-514009DFD01B}C:\users\teddy\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\teddy\program files\dna\btdna.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation(R)Store "{0F25F02B-854E-49B3-8F68-6D27CE4D477E}" = Ultima Online 2D Client "{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode "{14DC74E9-F248-47DF-B43F-9C6633F7438D}" = Holiday World "{14FE48DA-E172-4CC5-B397-92ECA4B0E088}" = STOnline "{167A1F6A-9BF2-4B24-83DB-C6D659F680EA}" = Media Go "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 29 "{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22 "{27018D57-D152-44EF-BCE0-5E3B3445EABE}" = X-Blades "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{28CBE511-A28E-4010-BE83-1623FC3F1D3A}" = RUNAWAY - A road adventure "{2ABCB142-9439-4FB5-A957-3D6C72D20C0C}" = Luvinia "{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}" = Free Ride Games Player "{2BE97610-5E4E-434F-9E84-01B0AB49EC92}" = Gilbert Goodmate "{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0 "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{36F4AF22-A159-4E0F-AABE-67638D2B939D}" = Super Webcam "{37491A3D-B2A6-402D-898E-5C4EF3984C29}" = Adobe Flash Media Live Encoder 3.1 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3 "{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = Die Sims™ 3 Late Night "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4B2B78EC-5111-4C0E-A955-0D84BBA49740}" = Animation Shop 3 Try And Buy "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{556F2137-B772-43BB-9A45-E0275234DD16}" = Free Notes & Office Ink "{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{5F624839-947D-46EA-BD63-FD847C1AC6F1}" = BearShare "{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = NCsoft Launcher "{65761BAE-11E8-48FE-B30F-1F01011AB906}" = Die Sims™ 3 "Erstelle eine Welt"-Tool - Beta "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6C26A305-4549-4A8A-9F03-25719C03B0FB}" = FreeRide Games "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = Die Sims™ 3 Luxus-Accessoires "{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World "{7FA856CB-5544-449D-84C5-07A18CD51467}" = Loong "{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}" = Rosetta Stone Version 3 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie "{8537166B-40F4-4FAE-BAC5-454A4DD773B7}" = Power Presenter RE II "{8B92D97D-DB3D-4926-A8F7-718FE7C5EE18}" = iTunes "{8CFA9151-6404-409A-AF22-4632D04582FD}" = Assassin's Creed "{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage "{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = Die Sims™ 3 Traumkarrieren "{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{95140000-00AF-0407-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{99A37AC7-E724-4621-B167-500B5A52B69C}" = LastChaosGER "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175 "{A1C659AF-C761-47A8-BAFD-5FD2BE1ED419}" = Wildlife Park 2 "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch "{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 301.42 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 301.42 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 301.42 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 301.42 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.0213 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.8.15 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{B3D74F2B-82A3-4A94-90C4-2037CC590350}" = DBO_CT_TW "{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation(R)Network Downloader "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player "{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = Die Sims™ 3 Reiseabenteuer "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die Sims™ 3 "{C12631C6-804D-4B32-B0DD-8A496462F106}" = Die Sims™ 3 Einfach tierisch "{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CD95F661-A5C4-44F5-A6AA-ECDD91C240CC}" = WinZip 16.0 "{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call "{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX "{DF7B213D-2065-41ED-BB51-7A3EED31EA7B}" = Ultima Online: Mondain's Legacy "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E820F6CD-75FD-4DCA-A293-A76F4D2C56EC}" = Luvinia "{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support "{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support "{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony PC Companion 2.10.094 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "4f6dcc3b-179d-4b1b-80f0-b6083a0b3ce6_is1" = DER HERR DER RINGE ONLINE: Die Minen Von Moria v02.01.03.4020 "827bc50d929d3142db3db7d83e32ee38" = Farm Frenzy - Viking Heroes "8461-7759-5462-8226" = Vuze "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "AhnLab Online Security" = AhnLab Online Security "Akamai" = Akamai NetSession Interface Service "AstrumNival Allods" = Allods Online 3.0.02.33 "At the Cutting Edge_is1" = At the Cutting Edge "Atlantica_GER" = Atlantica_GER "Avira AntiVir Desktop" = Avira Free Antivirus "BearShare" = BearShare "CCleaner" = CCleaner "Die Verlassenen Inseln" = Die Verlassenen Inseln "DMO" = GDMO "DSGPlayer" = DEUTSCHLAND SPIELT GAME CENTER "ESET Online Scanner" = ESET Online Scanner v3 "exent_466552" = The Treasures of Montezuma "Fiesta Online(EU_German)" = Fiesta Online(EU_German) 1.04.000 "Free Download Manager_is1" = Free Download Manager 3.9 "Guild Wars" = GUILD WARS "Haushaltsbuch_is1" = Haushaltsbuch 1.1.0 "Kanji Gold_is1" = Kanji Gold 2.10 "KaraKEYoke Karaoke 3_is1" = KaraKEYoke Karaoke 3.2.3 "KLiteCodecPack_is1" = K-Lite Codec Pack 5.8.0 (Basic) "LingoPad_is1" = LingoPad 2.6 (Build 360) "MabinogiEU" = MabinogiEU "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.0.1400 "McAfee Security Scan" = McAfee Security Scan Plus "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Mozilla Firefox 12.0 (x86 de)" = Mozilla Firefox 12.0 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Neffy" = Neffy 1,3,29,0 "NSS" = Norton Security Scan "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "OpenAL" = OpenAL "Opera 11.11.2109" = Opera 11.11 "Origin" = Origin "PPLite" = PPLite 1.0.0.106 "ProtectDisc Driver 11" = ProtectDisc Driver, Version 11 "QuickTime" = QuickTime "Raptr" = Raptr "RE: Alistair++" = RE: Alistair++ 1 "RealPlayer 15.0" = RealPlayer "Regnum Online" = Regnum Online 1.6.2 "Reise zum Zentrum des Mondes" = Reise zum Zentrum des Mondes "RmTablet" = Tablet Driver With Macrokey Manager "SiS163u" = 802.11 USB Wireless LAN Adapter "Star Trek Online" = Star Trek Online "Synthesia" = Synthesia (remove only) "TeamViewer 5" = TeamViewer 5 "The I of the Dragon" = The I of the Dragon "The Rosetta Stone" = The Rosetta Stone "TmUnitedForever_is1" = TmUnitedForever Update 2010-03-15 "Update Engine" = Sony Ericsson Update Engine "Wakan" = Wakan 1.67 "WiFiConnector" = Registrierungsprogramm für den Nintendo Wi-Fi USB Connector "WinGimp-2.0_is1" = GIMP 2.6.10 "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR "Xfire" = Xfire (remove only) "Youtube Saved" = Youtube Saved "Zylom Games Player Plugin" = Zylom Games Player Plugin ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface "Analog Clock" = Analog Clock "BitTorrent DNA" = DNA "Google Chrome" = Google Chrome "IGG Web3D Player_is1" = IGG Web3D Player version 1.0.0.37 "IMVU Avatar chat client software BETA" = IMVU Avatar Chat Software "MAESTIA" = MAESTIA "PlanetWerks" = PlanetWerks "SimAquarium" = SimAquarium "SOE-DC Universe Online Live" = DC Universe Online Live "SOE-DC Universe Online Live PSG" = DC Universe Online Live "Uncompressor" = Uncompressor "UnityWebPlayer" = Unity Web Player ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 20.02.2012 15:35:50 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842785 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\sony ericsson\sony ericsson pc companion\Drivers\DPInst64.exe". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error - 22.02.2012 15:36:23 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842815 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error - 22.02.2012 15:39:30 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842785 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\sony ericsson\sony ericsson pc companion\Drivers\DPInst64.exe". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error - 23.02.2012 10:09:29 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842815 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error - 23.02.2012 10:13:04 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842785 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\sony ericsson\sony ericsson pc companion\Drivers\DPInst64.exe". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error - 25.02.2012 08:26:44 | Computer Name = Teddy-PC | Source = Application Hang | ID = 1002 Description = Programm chrome.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: f48 Startzeit: 01ccf3b65abadd8a Endzeit: 10 Anwendungspfad: C:\Users\Teddy\AppData\Local\Google\Chrome\Application\chrome.exe Berichts-ID: e9a8bb4f-5fab-11e1-921b-925eefeb732f Error - 25.02.2012 14:44:45 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842815 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error - 25.02.2012 14:48:17 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842785 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\sony ericsson\sony ericsson pc companion\Drivers\DPInst64.exe". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error - 26.02.2012 07:48:47 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842815 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error - 26.02.2012 07:51:48 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842785 Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\sony ericsson\sony ericsson pc companion\Drivers\DPInst64.exe". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". [ System Events ] Error - 24.09.2012 16:45:41 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004 Description = Error - 24.09.2012 17:59:50 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004 Description = Error - 24.09.2012 17:59:50 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004 Description = Error - 24.09.2012 18:35:02 | Computer Name = Teddy-PC | Source = DCOM | ID = 10010 Description = Error - 25.09.2012 14:44:18 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004 Description = Error - 26.09.2012 04:11:41 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004 Description = Error - 27.09.2012 16:28:14 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004 Description = Error - 27.09.2012 16:28:23 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004 Description = Error - 28.09.2012 15:56:57 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004 Description = Error - 30.09.2012 03:32:33 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004 Description = < End of report > |
01.10.2012, 12:16 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Rechner mit MyStart by IncrediBar infiziert. Ich hab doch extra drauf hingewiesen, dass du OTL vorher neu runterladen sollst - außerdem hast du nur das Extras-Log gepostet
__________________
__________________ |
01.10.2012, 22:10 | #19 |
| Rechner mit MyStart by IncrediBar infiziert. Ich hab es neu herunter geladen gehabt. Kannte das Programm vorher ja nicht mal. Hoffe ich hab diesmal den richtigen Log eingefügt. Code:
ATTFilter OTL logfile created on: 01.10.2012 22:22:08 - Run 2 OTL by OldTimer - Version 3.2.68.0 Folder = C:\Users\Teddy\Desktop Professional (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,04 Gb Available Physical Memory | 67,90% Memory free 6,00 Gb Paging File | 4,74 Gb Available in Paging File | 79,09% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 307,62 Gb Total Space | 68,00 Gb Free Space | 22,11% Space Free | Partition Type: NTFS Drive E: | 623,88 Gb Total Space | 535,91 Gb Free Space | 85,90% Space Free | Partition Type: NTFS Computer Name: TEDDY-PC | User Name: Teddy | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.09.26 23:47:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Teddy\Desktop\OTL.exe PRC - [2012.08.10 18:59:52 | 004,440,896 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Teddy\AppData\Local\Akamai\netsession_win.exe PRC - [2012.08.08 22:55:44 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.06.11 11:48:51 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Programme\Real\RealPlayer\Update\realsched.exe PRC - [2012.05.31 15:00:22 | 000,445,624 | ---- | M] (Sony) -- C:\Programme\Sony\Sony PC Companion\PCCompanion.exe PRC - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe PRC - [2012.05.15 11:28:16 | 001,820,480 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe PRC - [2012.05.15 11:27:34 | 000,857,920 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe PRC - [2012.05.15 05:21:28 | 000,461,176 | ---- | M] (PPLive Corporation) -- C:\Programme\Common Files\PPLiveNetwork\PPAP.exe PRC - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2012.05.08 22:52:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2012.05.08 22:52:24 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2012.05.08 22:52:24 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2012.04.30 11:57:42 | 000,067,072 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe PRC - [2012.04.29 09:31:36 | 004,901,744 | ---- | M] (Exent Technologies Ltd.) -- C:\Programme\FreeRide Games\GPlayer.exe PRC - [2012.04.16 20:51:46 | 000,066,992 | ---- | M] (Raptr, Inc) -- C:\Programme\Raptr\raptr.exe PRC - [2012.04.16 20:51:46 | 000,043,952 | ---- | M] (Raptr, Inc) -- C:\Programme\Raptr\raptr_im.exe PRC - [2011.09.01 19:18:54 | 004,862,384 | ---- | M] (Exent Technologies Ltd.) -- C:\Programme\Free Ride Games\GPlayer.exe PRC - [2011.07.16 06:31:12 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2011.06.17 19:33:04 | 000,272,528 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee Security Scan\3.0.207\SSScheduler.exe PRC - [2011.06.09 14:06:06 | 000,507,624 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Common Files\Java\Java Update\jucheck.exe PRC - [2011.02.26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2011.01.26 08:45:58 | 000,870,120 | ---- | M] () -- C:\Windows\System32\atwtusb.exe PRC - [2011.01.17 18:37:40 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe PRC - [2011.01.17 18:37:40 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin PRC - [2010.12.24 09:31:08 | 007,134,952 | ---- | M] () -- C:\Windows\System32\WTMKM.exe PRC - [2010.05.13 21:55:53 | 000,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Users\Teddy\Program Files\DNA\btdna.exe PRC - [2010.03.18 11:26:08 | 000,172,328 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version5\TeamViewer_Service.exe PRC - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2009.07.14 03:14:42 | 000,181,760 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\TabTip.exe PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2009.07.14 03:14:38 | 001,173,504 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.07.14 03:14:21 | 000,294,400 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\InputPersonalization.exe ========== Modules (No Company Name) ========== MOD - [2012.05.24 11:50:32 | 000,203,776 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\MExplorer.dll MOD - [2012.05.23 11:38:36 | 000,583,680 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PhoneUpdate.dll MOD - [2012.05.15 05:21:14 | 000,522,600 | ---- | M] () -- C:\Programme\Common Files\PPLiveNetwork\1.0.0.53\MngModule.dll MOD - [2012.04.30 11:57:42 | 000,067,072 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe MOD - [2012.04.30 11:57:42 | 000,039,936 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\TMonitorAPI.dll MOD - [2012.03.25 13:51:43 | 000,985,088 | ---- | M] () -- C:\Programme\OpenOffice.org 3\program\libxml2.dll MOD - [2012.02.20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012.02.20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2012.02.17 19:53:28 | 000,494,592 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtNetwork.pyd MOD - [2012.02.17 19:53:24 | 001,661,952 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtCore.pyd MOD - [2012.02.17 19:53:20 | 000,313,856 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtWebKit.pyd MOD - [2012.02.17 19:53:06 | 005,809,664 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtGui.pyd MOD - [2012.02.17 19:52:26 | 000,067,584 | ---- | M] () -- C:\Programme\Raptr\sip.pyd MOD - [2011.11.21 04:20:46 | 001,949,696 | ---- | M] () -- C:\Programme\Raptr\libtorrent.pyd MOD - [2011.10.24 20:49:56 | 002,717,595 | ---- | M] () -- C:\Programme\Raptr\heliotrope._purple.pyd MOD - [2011.09.09 01:47:40 | 001,183,699 | ---- | M] () -- C:\Programme\Raptr\liboscar.dll MOD - [2011.09.09 01:47:36 | 001,640,221 | ---- | M] () -- C:\Programme\Raptr\libjabber.dll MOD - [2011.09.09 01:47:32 | 001,052,194 | ---- | M] () -- C:\Programme\Raptr\libymsg.dll MOD - [2011.09.09 01:47:22 | 000,495,680 | ---- | M] () -- C:\Programme\Raptr\plugins\libaim.dll MOD - [2011.09.09 01:47:22 | 000,483,306 | ---- | M] () -- C:\Programme\Raptr\plugins\libicq.dll MOD - [2011.09.09 01:47:16 | 000,655,356 | ---- | M] () -- C:\Programme\Raptr\plugins\libirc.dll MOD - [2011.09.09 01:47:16 | 000,603,326 | ---- | M] () -- C:\Programme\Raptr\plugins\ssl-nss.dll MOD - [2011.09.09 01:47:14 | 000,497,782 | ---- | M] () -- C:\Programme\Raptr\plugins\libyahoojp.dll MOD - [2011.09.09 01:47:14 | 000,474,199 | ---- | M] () -- C:\Programme\Raptr\plugins\ssl.dll MOD - [2011.09.09 01:47:10 | 001,306,387 | ---- | M] () -- C:\Programme\Raptr\plugins\libmsn.dll MOD - [2011.09.09 01:47:04 | 000,565,461 | ---- | M] () -- C:\Programme\Raptr\plugins\libxmpp.dll MOD - [2011.09.09 01:46:56 | 000,506,276 | ---- | M] () -- C:\Programme\Raptr\plugins\libyahoo.dll MOD - [2011.07.07 14:54:36 | 000,233,984 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\Report.dll MOD - [2011.02.15 20:17:28 | 001,213,633 | ---- | M] () -- C:\Programme\Raptr\libxml2-2.dll MOD - [2011.02.15 20:17:28 | 000,417,501 | ---- | M] () -- C:\Programme\Raptr\sqlite3.dll MOD - [2010.12.24 09:31:08 | 007,134,952 | ---- | M] () -- C:\Windows\System32\WTMKM.exe MOD - [2010.11.23 01:06:22 | 000,055,808 | ---- | M] () -- C:\Programme\Raptr\zlib1.dll MOD - [2010.11.23 00:57:34 | 000,167,936 | ---- | M] () -- C:\Programme\Raptr\win32gui.pyd MOD - [2010.11.23 00:57:34 | 000,111,104 | ---- | M] () -- C:\Programme\Raptr\win32file.pyd MOD - [2010.11.23 00:57:34 | 000,096,256 | ---- | M] () -- C:\Programme\Raptr\win32api.pyd MOD - [2010.11.23 00:57:34 | 000,036,352 | ---- | M] () -- C:\Programme\Raptr\win32process.pyd MOD - [2010.11.23 00:57:18 | 000,141,312 | ---- | M] () -- C:\Programme\Raptr\gobject._gobject.pyd MOD - [2010.11.23 00:57:06 | 000,263,168 | ---- | M] () -- C:\Programme\Raptr\win32com.shell.shell.pyd MOD - [2010.11.23 00:56:56 | 000,354,304 | ---- | M] () -- C:\Programme\Raptr\pythoncom26.dll MOD - [2010.11.23 00:56:56 | 000,110,592 | ---- | M] () -- C:\Programme\Raptr\pywintypes26.dll MOD - [2010.11.23 00:56:26 | 000,324,608 | ---- | M] () -- C:\Programme\Raptr\PIL._imaging.pyd MOD - [2010.11.23 00:56:02 | 000,805,376 | ---- | M] () -- C:\Programme\Raptr\_ssl.pyd MOD - [2010.11.23 00:56:02 | 000,583,680 | ---- | M] () -- C:\Programme\Raptr\unicodedata.pyd MOD - [2010.11.23 00:56:02 | 000,356,864 | ---- | M] () -- C:\Programme\Raptr\_hashlib.pyd MOD - [2010.11.23 00:56:02 | 000,127,488 | ---- | M] () -- C:\Programme\Raptr\pyexpat.pyd MOD - [2010.11.23 00:56:02 | 000,087,040 | ---- | M] () -- C:\Programme\Raptr\_ctypes.pyd MOD - [2010.11.23 00:56:02 | 000,044,544 | ---- | M] () -- C:\Programme\Raptr\_sqlite3.pyd MOD - [2010.11.23 00:56:02 | 000,043,008 | ---- | M] () -- C:\Programme\Raptr\_socket.pyd MOD - [2010.11.23 00:56:02 | 000,009,216 | ---- | M] () -- C:\Programme\Raptr\winsound.pyd MOD - [2010.01.11 16:44:54 | 000,053,248 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\VObject.dll MOD - [2008.09.16 21:18:06 | 000,132,608 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll ========== Services (SafeList) ========== SRV - [2012.09.22 20:50:22 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.09.20 22:42:33 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.09.06 20:37:25 | 004,537,664 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_5891ae0.dll -- (Akamai) SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012.05.08 22:52:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.05.08 22:52:24 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.04.29 09:26:24 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2012.01.18 14:38:28 | 000,155,320 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Programme\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion) SRV - [2011.06.17 19:33:04 | 000,237,008 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Programme\McAfee Security Scan\3.0.207\McCHSvc.exe -- (McComponentHostService) SRV - [2011.01.26 08:45:58 | 000,870,120 | ---- | M] () [Auto | Running] -- C:\Windows\System32\atwtusb.exe -- (WTService) SRV - [2010.03.28 10:50:19 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2010.03.18 11:26:08 | 000,172,328 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5) SRV - [2009.12.16 19:26:00 | 003,453,712 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc) SRV - [2009.07.14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva380.sys -- (XDva380) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (awfj5kor) DRV - [2012.09.17 21:31:15 | 000,076,800 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\SSHDRV84.sys -- (SSHDRV84) DRV - [2012.07.07 11:07:44 | 000,025,200 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc) DRV - [2012.07.07 11:07:44 | 000,012,400 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt) DRV - [2012.05.15 12:26:00 | 011,354,944 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2012.05.12 17:59:30 | 000,013,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\apf003.sys -- (apf003) DRV - [2012.05.08 22:52:24 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.05.08 22:52:24 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.12.15 16:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2010.11.22 10:25:22 | 000,046,184 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto | Running] -- C:\Programme\FreeRide Games\X6XSEx.sys -- (X6XSEx_Pr148) DRV - [2010.11.22 09:25:22 | 000,046,184 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto | Running] -- C:\Programme\Free Ride Games\X6XSEx.sys -- (X6XSEx) DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010.05.23 13:25:15 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd) DRV - [2009.09.23 03:19:31 | 000,294,912 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcvmm.sys -- (vpcvmm) DRV - [2009.09.23 03:19:31 | 000,055,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcnfltr.sys -- (vpcnfltr) DRV - [2009.09.23 03:18:08 | 000,078,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpcusb.sys -- (vpcusb) DRV - [2009.09.23 03:18:07 | 000,165,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpchbus.sys -- (vpcbus) DRV - [2009.08.20 12:38:24 | 000,006,144 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\walvhid.sys -- (vhidmini) DRV - [2009.07.14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2009.07.14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2009.07.14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2009.07.14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2009.07.14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2009.07.14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2009.03.08 13:15:14 | 000,006,144 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\moufiltr.sys -- (moufiltr) DRV - [2009.01.19 20:31:56 | 000,277,544 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11) DRV - [2007.07.03 15:05:00 | 000,162,944 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RT25USBAP.SYS -- (RT25USBAP) DRV - [2006.06.27 09:56:50 | 000,031,872 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\superwebcam.sys -- (SUPERWEBCAM) DRV - [2005.06.20 10:12:00 | 000,215,040 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\sis163u.sys -- (SIS163u) DRV - [2005.02.26 09:25:52 | 000,091,527 | ---- | M] (VM) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbVM31b.sys -- (ZSMC301b) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\URLSearchHook: - No CLSID value found IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms} IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://zynga.com/ IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 78 5E 77 19 B3 CA 01 [binary data] IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {90b49673-5506-483e-b92b-ca0265bd9ca8} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://search.bearshare.net" FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1 FF - prefs.js..extensions.enabledItems: {ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}:1.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26 FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0 FF - prefs.js..extensions.enabledItems: {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}:4.6.1.02 FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.5.7.4 FF - prefs.js..extensions.enabledItems: ocr@babylon.com:1.1 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll () FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@exent.com/npExentControl,version=7.1.0.1: C:\Program Files\FreeRide Games\npExentControl.dll (Exent Technologies Ltd.) FF - HKLM\Software\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0: C:\Program Files\Free Ride Games\npExentCtl.dll (Exent Technologies Ltd.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF - HKLM\Software\MozillaPlugins\@pptv.com/plugin: C:\Program Files\Internet Explorer\PPLite\plugin\1.0.0.53\npplugin2.dll (PPLive Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) FF - HKLM\Software\MozillaPlugins\@zylom.com/ZylomGamesPlayer: C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.) FF - HKCU\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Users\Teddy\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.) FF - HKCU\Software\MozillaPlugins\@g2.com/iggweb3dupdater: C:\Users\Teddy\AppData\Roaming\IGG\Web3D\1.0.0.37\NPIGGWeb3DUpdater.dll (IGG) FF - HKCU\Software\MozillaPlugins\@g2.com/joyconnectshell: C:\Users\Teddy\AppData\Roaming\IGG\Web3D\1.0.0.37\NPJoyConnectShell.dll (IGG) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Teddy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.08.03 16:04:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.22 20:50:23 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.09.22 22:07:34 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}: C:\Users\Teddy\Program Files\DNA [2012.10.01 21:51:02 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}: C:\Users\Teddy\AppData\Roaming\5008 [2010.11.09 17:44:47 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Teddy\AppData\Roaming\IDM\idmmzcc5 [2012.03.25 13:37:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Teddy\AppData\Roaming\mozilla\Extensions [2012.09.22 20:50:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions [2011.08.04 17:38:17 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2012.03.25 13:37:02 | 000,000,000 | ---D | M] (Wincore Mediabar) -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} [2012.09.22 00:21:33 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-1.xml [2012.03.25 20:28:36 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-2.xml [2012.09.22 00:11:34 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-3.xml [2012.03.11 00:30:33 | 000,001,056 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin.xml [2012.09.22 20:50:26 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.09.15 23:30:05 | 000,000,000 | ---D | M] (Babylon Translation Activation) -- C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com [2012.09.22 20:50:22 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.10.03 06:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2012.06.11 11:48:58 | 000,129,144 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll [2009.03.24 12:10:44 | 000,114,688 | ---- | M] (Zylom) -- C:\Program Files\mozilla firefox\plugins\npzylomgamesplayer.dll [2012.09.22 20:50:20 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.22 20:50:20 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.09.22 20:50:20 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.09.22 20:50:20 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.09.22 20:50:20 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.09.22 20:50:20 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Ecosia (Enabled) CHR - default_search_provider: search_url = hxxp://ecosia.org/search.php?q={searchTerms}&addon=opensearch CHR - default_search_provider: suggest_url = hxxp://ecosia.org/ajax/searchsuggestions.php?q={searchTerms}&addon=opensearch CHR - homepage: hxxp://www.google.com/ CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Teddy\AppData\Local\Google\Chrome\Application\12.0.742.100\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: Chrome NaCl (Disabled) = C:\Users\Teddy\AppData\Local\Google\Chrome\Application\12.0.742.100\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Teddy\AppData\Local\Google\Chrome\Application\12.0.742.100\pdf.dll CHR - plugin: Perion plugin (Enabled) = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll CHR - plugin: Zylom Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll CHR - plugin: AhnLab MyKeyDefense 2.5 (Enabled) = C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll CHR - plugin: Exent\u00AE AOD Gecko Plugin (Enabled) = C:\Program Files\Free Ride Games\npExentCtl.dll CHR - plugin: Exent\u00AE AOD Gecko Plugin (Enabled) = C:\Program Files\FreeRide Games\npExentControl.dll CHR - plugin: PPLive PPTV Plugin (Enabled) = C:\Program Files\Internet Explorer\PPLite\plugin\1.0.0.53\npplugin2.dll CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll CHR - plugin: Media Go Detector (Enabled) = C:\Program Files\Sony\Media Go\npmediago.dll CHR - plugin: PlayStation(R)Network Downloader Check Plug-in (Enabled) = C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll CHR - plugin: Unity Player (Enabled) = C:\Users\Teddy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll CHR - plugin: IGG Web3D Updater NP Plugin for Mozilla (Enabled) = C:\Users\Teddy\AppData\Roaming\IGG\Web3D\1.0.0.37\NPIGGWeb3DUpdater.dll CHR - plugin: JoyConnect NP Plugin for Mozilla (Enabled) = C:\Users\Teddy\AppData\Roaming\IGG\Web3D\1.0.0.37\NPJoyConnectShell.dll CHR - plugin: DNA Plug-in (Enabled) = C:\Users\Teddy\Program Files\DNA\plugins\npbtdna.dll CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\ CHR - Extension: New tab for Chrome\u2122 = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\ CHR - Extension: Click to activate/deactivate ProxTube = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkdbaehcjcomcnnjhlmnfddpgoafpcko\1.0.6_0\ CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\ CHR - Extension: New tab for Chrome\u2122 = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\ CHR - Extension: Click to activate/deactivate ProxTube = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkdbaehcjcomcnnjhlmnfddpgoafpcko\1.0.6_0\ O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (DataMngr) - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Programme\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll (MusicLab, LLC) O2 - BHO: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll () O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programme\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll () O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No CLSID value found. O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found. O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {90B49673-5506-483E-B92B-CA0265BD9CA8} - No CLSID value found. O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [MacrokeyManager] C:\Windows\System32\WTMKM.exe () O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.) O4 - HKU\.DEFAULT..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-18..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-19..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-20..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Akamai NetSession Interface] C:\Users\Teddy\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [BitTorrent DNA] C:\Users\Teddy\Program Files\DNA\btdna.exe (BitTorrent, Inc.) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Exetender_148] C:\Program Files\FreeRide Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [PlayNC Launcher] File not found O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [PPAP] C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe (PPLive Corporation) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Raptr] C:\Programme\Raptr\raptrstub.exe (Raptr, Inc) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Sony PC Companion] C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Sony) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - Startup: C:\Users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files\Free Download Manager\dlall.htm () O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files\Free Download Manager\dlselected.htm () O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files\Free Download Manager\dllink.htm () O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files\Free Download Manager\dlfvideo.htm () O8 - Extra context menu item: Web-Suche - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in ) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: sony.com ([]* in ) O16 - DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} (ExentInf1 Class) O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{14B43710-DFCA-4ADB-8A04-DFA39535C9DF}: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1537B177-72F8-4837-A69C-4491A1A46E4D}: DhcpNameServer = 192.168.3.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B1D98BB-9065-4F58-B709-0608A62BE7C8}: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{769B5C26-4B44-47FB-B41A-27AC47E2AB05}: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Programme\Common Files\microsoft shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell - "" = AutoRun O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell\AutoRun\command - "" = H:\Startme.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare Software.lnk - - File not found MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Registrierungsprogramm ausführen.lnk - C:\Programme\WiFiConnector\NintendoWFCReg.exe - () MsConfig - StartUpFolder: C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk - C:\Programme\OpenOffice.org 3\program\quickstart.exe - () MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - File not found MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) MsConfig - StartUpReg: TkBellExe - hkey= - key= - c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.) MsConfig - State: "startup" - 0 SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: NTDS - File not found SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vmms - Service SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: NTDS - File not found SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vmms - Service SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D} - Microsoft .NET Framework 1.1 Security Update (KB953297) ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com) Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com) Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll () CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.09.26 23:47:27 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Teddy\Desktop\OTL.exe [2012.09.22 22:49:29 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012.09.22 22:40:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus [2012.09.22 22:09:47 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee Security Scan [2012.09.22 22:09:42 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan [2012.09.22 22:09:42 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee [2012.09.22 20:50:26 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service [2012.09.22 20:50:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2012.09.22 14:46:51 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2012.09.22 09:25:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared [2012.09.21 23:52:20 | 000,000,000 | ---D | C] -- C:\Users\Teddy\AppData\Roaming\Malwarebytes [2012.09.21 23:52:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.09.21 23:52:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.09.21 23:52:05 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.09.21 23:52:05 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012.09.21 23:47:14 | 000,000,000 | ---D | C] -- C:\Users\Teddy\Start Menu [2012.09.21 13:56:14 | 000,000,000 | ---D | C] -- C:\Program Files\Perion [2012.09.17 21:26:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gathering [2012.09.16 14:10:02 | 000,000,000 | ---D | C] -- C:\Users\Teddy\Desktop\Neuer Ordner [2012.09.15 22:56:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SWF Studio [2012.09.15 22:55:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prelusion [2012.09.06 21:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cornelsen [2012.09.06 21:48:24 | 000,000,000 | ---D | C] -- C:\Program Files\Cornelsen [5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\Teddy\AppData\Roaming\*.tmp files -> C:\Users\Teddy\AppData\Roaming\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.10.01 21:58:36 | 000,020,720 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.10.01 21:58:36 | 000,020,720 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.10.01 21:51:24 | 000,000,376 | ---- | M] () -- C:\Windows\tasks\RNUpgradeHelperLogonPrompt_Teddy.job [2012.10.01 21:50:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.10.01 21:50:40 | 2415,255,552 | -HS- | M] () -- C:\hiberfil.sys [2012.10.01 14:42:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.10.01 12:28:17 | 000,164,648 | ---- | M] () -- C:\Users\Teddy\Desktop\buntesleben.jpg [2012.10.01 00:12:02 | 000,000,366 | ---- | M] () -- C:\Windows\tasks\ReclaimerUpdateXML_Teddy.job [2012.09.30 23:12:03 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\ReclaimerUpdateFiles_Teddy.job [2012.09.26 23:47:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Teddy\Desktop\OTL.exe [2012.09.24 15:26:33 | 000,513,501 | ---- | M] () -- C:\Users\Teddy\Desktop\adwcleaner.exe [2012.09.23 10:27:49 | 000,000,436 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Teddy.job [2012.09.22 22:40:55 | 000,002,040 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk [2012.09.22 22:40:55 | 000,002,040 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2012.09.22 22:07:34 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2012.09.22 11:38:23 | 000,000,298 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat [2012.09.21 23:52:07 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.09.21 22:57:03 | 000,003,405 | ---- | M] () -- C:\Users\Teddy\.recently-used.xbel [2012.09.17 21:31:15 | 000,076,800 | ---- | M] () -- C:\Windows\System32\drivers\SSHDRV84.sys [2012.09.17 21:30:33 | 000,000,000 | ---- | M] () -- C:\Users\Public\Documents\PCD549.L!C [2012.09.17 21:26:18 | 000,000,616 | ---- | M] () -- C:\Users\Public\Desktop\Holiday World.lnk [2012.09.15 22:55:51 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Gilbert Goodmate.lnk [2012.09.07 20:55:14 | 000,315,280 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.09.06 21:49:47 | 000,001,101 | ---- | M] () -- C:\Users\Public\Desktop\At the Cutting Edge.lnk [2012.09.04 23:55:56 | 000,666,270 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.09.04 23:55:56 | 000,625,116 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.09.04 23:55:56 | 000,135,198 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.09.04 23:55:56 | 000,110,754 | ---- | M] () -- C:\Windows\System32\perfc009.dat [5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\Teddy\AppData\Roaming\*.tmp files -> C:\Users\Teddy\AppData\Roaming\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.10.01 12:28:28 | 000,164,648 | ---- | C] () -- C:\Users\Teddy\Desktop\buntesleben.jpg [2012.09.27 00:10:02 | 000,000,376 | ---- | C] () -- C:\Windows\tasks\RNUpgradeHelperLogonPrompt_Teddy.job [2012.09.27 00:10:01 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\ReclaimerUpdateFiles_Teddy.job [2012.09.27 00:10:00 | 000,000,366 | ---- | C] () -- C:\Windows\tasks\ReclaimerUpdateXML_Teddy.job [2012.09.26 12:50:47 | 000,602,972 | ---- | C] () -- C:\Users\Teddy\Desktop\DSC_0151.JPG [2012.09.24 15:26:32 | 000,513,501 | ---- | C] () -- C:\Users\Teddy\Desktop\adwcleaner.exe [2012.09.22 22:09:42 | 000,002,040 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk [2012.09.22 22:09:42 | 000,002,040 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2012.09.22 22:07:34 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2012.09.22 22:07:34 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2012.09.22 20:50:24 | 000,001,100 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2012.09.22 11:11:09 | 000,000,298 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat [2012.09.21 23:52:07 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.09.21 22:57:03 | 000,003,405 | ---- | C] () -- C:\Users\Teddy\.recently-used.xbel [2012.09.17 21:31:15 | 000,076,800 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV84.sys [2012.09.17 21:30:33 | 000,000,000 | ---- | C] () -- C:\Users\Public\Documents\PCD549.L!C [2012.09.17 21:26:18 | 000,000,616 | ---- | C] () -- C:\Users\Public\Desktop\Holiday World.lnk [2012.09.15 22:55:51 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Gilbert Goodmate.lnk [2012.09.06 21:49:47 | 000,001,101 | ---- | C] () -- C:\Users\Public\Desktop\At the Cutting Edge.lnk [2012.08.22 22:48:13 | 000,000,232 | ---- | C] () -- C:\Users\Teddy\.KanjiGymLight [2012.08.13 17:53:37 | 000,000,059 | ---- | C] () -- C:\Windows\RUNAWAY.INI [2012.05.18 17:40:39 | 000,010,525 | ---- | C] () -- C:\Windows\System32\Default_3.ini [2012.05.18 17:40:39 | 000,010,283 | ---- | C] () -- C:\Windows\System32\Default_2.ini [2012.05.18 17:40:39 | 000,009,917 | ---- | C] () -- C:\Windows\System32\Default_1.ini [2012.05.18 17:40:39 | 000,000,738 | ---- | C] () -- C:\Windows\System32\MKProfile.ini [2012.05.18 17:40:36 | 000,000,105 | R--- | C] () -- C:\ProgramData\Ppster.ini [2012.05.18 17:40:30 | 000,870,120 | ---- | C] () -- C:\Windows\System32\atwtusb.exe [2012.05.18 17:40:28 | 007,134,952 | ---- | C] () -- C:\Windows\System32\WTMKM.exe [2012.05.18 17:40:23 | 000,045,056 | ---- | C] () -- C:\Windows\System32\InstallService.exe [2012.05.18 17:40:22 | 003,683,560 | ---- | C] () -- C:\Windows\System32\Control Panel_Betteryless.exe [2012.05.18 17:40:20 | 000,148,200 | ---- | C] () -- C:\Windows\System32\Calibration.exe [2012.05.18 17:40:12 | 000,835,072 | ---- | C] () -- C:\Windows\RmTablet.exe [2012.05.18 17:40:11 | 000,010,708 | ---- | C] () -- C:\Windows\System32\aiptbl.ini [2012.05.15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe [2012.05.12 17:59:30 | 000,016,304 | ---- | C] () -- C:\Windows\System32\apl003.sys [2012.05.12 17:59:30 | 000,013,232 | ---- | C] () -- C:\Windows\System32\apf003.sys [2012.04.16 23:36:22 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2012.04.14 22:56:32 | 000,000,000 | ---- | C] () -- C:\Users\Teddy\__ng3d.lock [2012.03.25 12:13:13 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat [2012.03.04 01:19:48 | 000,000,410 | ---- | C] () -- C:\Windows\{27018D57-D152-44EF-BCE0-5E3B3445EABE}_WiseFW.ini [2011.12.23 03:43:56 | 000,230,752 | ---- | C] () -- C:\Windows\patchw32.dll [2011.12.23 03:43:56 | 000,118,176 | ---- | C] () -- C:\Windows\patchw.dll [2010.11.17 17:57:56 | 000,006,936 | ---- | C] () -- C:\Windows\Go Screensaver.ini [2010.09.15 21:26:32 | 000,000,148 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\urhtps.dat [2010.05.28 15:06:46 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_3 [2010.05.28 00:08:52 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_1 [2010.05.28 00:06:06 | 000,000,169 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\D2Info0 [2010.05.28 00:06:06 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_2 [2010.04.18 18:08:31 | 000,032,256 | ---- | C] () -- C:\Users\Teddy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.02.21 20:31:04 | 000,000,093 | ---- | C] () -- C:\Users\Teddy\AppData\Local\fusioncache.dat ========== ZeroAccess Check ========== [2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2010.07.27 16:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2011.10.16 18:35:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\.minecraft [2010.09.15 01:00:21 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5005 [2010.10.04 18:09:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5006 [2010.11.09 17:44:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5008 [2010.03.08 21:06:30 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Anabel [2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\app [2012.08.03 16:04:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Azureus [2012.03.25 22:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Cat's Eye Games [2010.09.15 01:00:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\cock [2012.05.04 23:05:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DAEMON Tools Lite [2010.03.08 22:51:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dekovir [2011.08.10 22:18:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DMCache [2012.10.01 22:51:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DNA [2010.05.28 23:56:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus 2 [2010.05.28 00:06:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2010.05.28 15:06:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2010.05.28 00:08:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2012.09.22 14:47:14 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoft [2012.07.09 13:22:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoftIEHelpers [2012.04.28 23:46:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EnchantedCavern [2010.03.09 06:52:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EscapeTheMuseum2 [2012.03.25 16:46:15 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Exent Technologies [2012.03.25 23:36:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Finstere Liebschaft [2011.01.04 17:40:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\FOG Downloader [2012.09.24 15:26:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Free Download Manager [2012.04.05 00:38:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Friday's games [2012.04.28 22:10:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gamers Digital [2010.03.08 19:35:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Games [2012.04.17 00:12:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\GetRightToGo [2010.03.08 21:42:43 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gogii [2012.09.08 13:21:19 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\gtk-2.0 [2011.08.07 18:08:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Haushaltsbuch [2012.03.25 00:45:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ICQ [2012.04.05 21:08:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IGG [2011.12.26 14:48:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVU [2011.12.14 22:23:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVUClient [2012.07.08 01:14:28 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Jasc [2012.05.12 17:07:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\KlLauncherST [2011.11.05 23:06:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Lingo4u [2011.11.16 00:26:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\LolClient [2012.03.25 13:36:37 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\MusicNet [2010.05.28 19:36:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\OpenOffice.org [2010.06.11 23:59:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Opera [2011.10.22 16:51:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Origin [2012.04.09 01:13:44 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayFirst [2011.06.30 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayPond [2010.03.07 01:16:25 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Playrix Entertainment [2010.03.08 21:23:32 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PoBros [2012.08.08 13:54:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PPlive [2010.03.09 05:48:03 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Princess Isabella [2010.04.01 01:41:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ProtectDisc [2012.10.01 21:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Raptr [2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2012.04.14 16:06:17 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RenPy [2010.03.28 15:47:09 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RobinsonCrusoe [2012.01.10 23:36:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Sony [2012.07.30 13:39:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Synthesia [2011.10.16 18:32:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TeamViewer [2010.03.08 18:55:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TitanicMystery [2008.06.27 00:59:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TuneUp Software [2010.02.22 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Turbine [2010.09.16 13:25:07 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\UAs [2010.05.25 01:37:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Ubisoft [2011.07.07 16:58:36 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Unity [2010.03.08 07:46:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Virtual City [2010.09.16 13:25:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\xmldm ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2011.10.16 18:35:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\.minecraft [2010.09.15 01:00:21 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5005 [2010.10.04 18:09:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5006 [2010.11.09 17:44:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5008 [2012.09.23 11:30:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Adobe [2010.03.08 21:06:30 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Anabel [2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\app [2012.03.28 22:37:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Apple Computer [2012.02.14 22:09:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Avira [2012.08.03 16:04:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Azureus [2012.03.25 22:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Cat's Eye Games [2010.09.15 01:00:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\cock [2012.05.04 23:05:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DAEMON Tools Lite [2010.03.08 22:51:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dekovir [2011.08.10 22:18:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DMCache [2012.10.01 22:51:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DNA [2010.05.28 23:56:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus 2 [2010.05.28 00:06:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2010.05.28 15:06:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2010.05.28 00:08:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2012.09.22 14:47:14 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoft [2012.07.09 13:22:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoftIEHelpers [2012.04.28 23:46:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EnchantedCavern [2010.03.09 06:52:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EscapeTheMuseum2 [2012.03.25 16:46:15 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Exent Technologies [2012.03.25 23:36:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Finstere Liebschaft [2011.01.04 17:40:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\FOG Downloader [2012.09.24 15:26:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Free Download Manager [2012.04.05 00:38:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Friday's games [2012.04.28 22:10:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gamers Digital [2010.03.08 19:35:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Games [2012.04.17 00:12:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\GetRightToGo [2010.03.08 21:42:43 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gogii [2012.09.08 13:21:19 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\gtk-2.0 [2011.08.07 18:08:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Haushaltsbuch [2012.03.25 00:45:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ICQ [2010.02.21 18:51:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Identities [2012.04.05 21:08:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IGG [2011.12.26 14:48:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVU [2011.12.14 22:23:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVUClient [2010.03.09 20:56:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\InstallShield [2012.07.08 01:14:28 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Jasc [2012.05.12 17:07:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\KlLauncherST [2011.11.05 23:06:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Lingo4u [2011.11.16 00:26:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\LolClient [2010.02.21 20:31:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Macromedia [2012.09.21 23:52:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Malwarebytes [2009.07.14 10:56:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Media Center Programs [2012.08.18 20:31:05 | 000,000,000 | --SD | M] -- C:\Users\Teddy\AppData\Roaming\Microsoft [2010.09.15 21:23:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Mozilla [2012.03.25 13:36:37 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\MusicNet [2012.06.18 15:22:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\NVIDIA [2010.05.28 19:36:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\OpenOffice.org [2010.06.11 23:59:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Opera [2011.10.22 16:51:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Origin [2012.04.09 01:13:44 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayFirst [2011.06.30 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayPond [2010.03.07 01:16:25 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Playrix Entertainment [2010.03.08 21:23:32 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PoBros [2012.08.08 13:54:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PPlive [2010.03.09 05:48:03 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Princess Isabella [2010.04.01 01:41:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ProtectDisc [2012.10.01 21:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Raptr [2012.05.06 22:21:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Real [2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2012.04.14 16:06:17 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RenPy [2010.03.28 15:47:09 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RobinsonCrusoe [2012.01.10 23:36:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Sony [2012.07.30 13:39:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Synthesia [2011.10.16 18:32:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TeamViewer [2010.03.08 18:55:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TitanicMystery [2008.06.27 00:59:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TuneUp Software [2010.02.22 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Turbine [2010.09.16 13:25:07 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\UAs [2010.05.25 01:37:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Ubisoft [2011.07.07 16:58:36 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Unity [2010.03.08 07:46:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Virtual City [2010.02.21 19:06:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\WinRAR [2012.05.12 20:30:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Xfire [2010.09.16 13:25:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\xmldm < %APPDATA%\*.exe /s > [2012.04.29 01:03:37 | 000,310,208 | ---- | M] (Georgia Institute of Technology) -- C:\Users\Teddy\AppData\Roaming\Azureus\plugins\mlab\ShaperProbeC.exe [2012.04.05 21:08:12 | 000,726,814 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IGG\Web3D\1.0.0.37\unins000.exe [2011.11.01 18:34:52 | 000,013,312 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\devicefingerprint.exe [2011.11.03 21:04:14 | 000,158,208 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\devicefingerprint_old.exe [2011.11.21 21:03:22 | 000,053,504 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUClient.exe [2011.11.21 21:03:22 | 000,022,784 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe [2011.11.21 21:03:24 | 000,097,200 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUupdater.exe [2011.07.30 01:55:56 | 000,009,728 | ---- | M] (Mozilla Corporation) -- C:\Users\Teddy\AppData\Roaming\IMVUClient\plugin-container.exe [2011.12.14 22:23:04 | 000,077,973 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\Uninstall.exe [2011.04.28 20:51:30 | 000,049,664 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\w9xpopen.exe [2011.11.01 19:00:38 | 000,134,144 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\WriteMiniDump.exe [2011.12.14 22:20:05 | 023,223,800 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\installer\SetupImvu_update.exe [2010.03.24 14:19:14 | 000,038,784 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe [2010.03.21 18:27:59 | 000,010,134 | R--- | M] () -- C:\Users\Teddy\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe [2012.08.07 21:44:21 | 005,527,872 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLite\Update\PPLite_Update.exe [2012.06.13 05:10:04 | 000,464,288 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\PPLive.exe [2012.08.07 22:32:29 | 000,328,985 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\uninst.exe [2012.06.13 05:09:32 | 000,236,448 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\crashreporter.exe [2012.06.13 05:09:34 | 000,130,976 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\hwcheck.exe [2012.06.13 05:09:48 | 000,464,288 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\PPLiveU.exe [2012.06.13 05:09:52 | 000,099,744 | ---- | M] (PPTV) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\PPTVIconBubble.exe [2012.06.13 04:55:04 | 000,202,112 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\PPTVLauncher.exe [2012.06.13 04:55:04 | 000,046,456 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\RepairSetup.exe [2012.06.13 04:55:02 | 000,032,120 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\SkinConverter.exe [2010.04.24 22:07:25 | 000,443,912 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\setup3.11\setup.exe [2011.01.26 17:59:11 | 000,510,120 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\setup3.13\setup.exe [2012.09.25 21:09:07 | 000,449,176 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\temp\~Upg0\rnupgagent.exe [2012.09.25 21:09:07 | 000,449,176 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe [2012.09.27 00:11:56 | 027,433,440 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\stub_data\RealPlayer.exe [2012.09.27 00:10:07 | 000,760,128 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\stub_exe\RealPlayer.exe < %SYSTEMDRIVE%\*.exe > [2011.12.23 03:39:35 | 2059,036,792 | ---- | M] (Acresso Software Inc.) -- C:\LuviniaInstaller_1010040.exe < MD5 for: AGP440.SYS > [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys < MD5 for: ATAPI.SYS > [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll < MD5 for: IASTORV.SYS > [2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys [2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\drivers\iaStorV.sys [2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0033117673c16921\iaStorV.sys [2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys [2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys [2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys [2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys [2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys [2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys < MD5 for: NETLOGON.DLL > [2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll < MD5 for: NVSTOR.SYS > [2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys [2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\drivers\nvstor.sys [2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_38e464dbe521cc7f\nvstor.sys [2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys [2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys [2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys [2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys [2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys [2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys < MD5 for: SCECLI.DLL > [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll [2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll < MD5 for: USER32.DLL > [2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\System32\user32.dll [2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll [2004.08.03 17:53:30 | 000,574,464 | ---- | M] (Microsoft Corporation) MD5=F18CDF551E5223255CF7F0D124B829EF -- C:\Joymax\DMO\user32.dll [2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll < MD5 for: USERINIT.EXE > [2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe [2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe [2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe [2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe [2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe [2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > [2010.05.23 13:25:15 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\Windows\system32\drivers\sptd.sys < %systemroot%\System32\config\*.sav > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < > [2009.07.14 06:53:46 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2009.07.14 06:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT [2012.06.11 13:48:17 | 000,000,436 | -H-- | C] () -- C:\Windows\Tasks\Norton Security Scan for Teddy.job [2012.07.21 19:33:49 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job [2012.09.27 00:10:00 | 000,000,366 | ---- | C] () -- C:\Windows\Tasks\ReclaimerUpdateXML_Teddy.job [2012.09.27 00:10:01 | 000,000,370 | ---- | C] () -- C:\Windows\Tasks\ReclaimerUpdateFiles_Teddy.job [2012.09.27 00:10:02 | 000,000,376 | ---- | C] () -- C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Teddy.job < End of report > |
02.10.2012, 14:56 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Rechner mit MyStart by IncrediBar infiziert. Du hast es dann aber nicht von meinem extra angebenen Downloadlink runtergeladen In diesem Log steht immer noch eine alte Version drin
__________________ Logfiles bitte immer in CODE-Tags posten |
02.10.2012, 22:07 | #21 |
| Rechner mit MyStart by IncrediBar infiziert. Ich bin ein braver Teddy, ich hab auf das OTL in deinem Post geklickt. |
03.10.2012, 18:11 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Rechner mit MyStart by IncrediBar infiziert. Wirklich? Kann ich mir kaum vorstellen. Mach es bitte nochmal, da müsste nun Version 3.2.70.1 oder höher sein
__________________ Logfiles bitte immer in CODE-Tags posten |
05.10.2012, 22:07 | #23 |
| Rechner mit MyStart by IncrediBar infiziert. Püh .. anzuzweifeln, dass ich brav bin ... du bist kein Charmeur. Code:
ATTFilter OTL logfile created on: 05.10.2012 22:11:14 - Run 3 OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\Teddy\Downloads Professional (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,86 Gb Available Physical Memory | 62,11% Memory free 6,00 Gb Paging File | 4,61 Gb Available in Paging File | 76,88% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 307,62 Gb Total Space | 67,44 Gb Free Space | 21,92% Space Free | Partition Type: NTFS Drive E: | 623,88 Gb Total Space | 535,91 Gb Free Space | 85,90% Space Free | Partition Type: NTFS Drive I: | 1,87 Gb Total Space | 0,28 Gb Free Space | 15,21% Space Free | Partition Type: FAT32 Computer Name: TEDDY-PC | User Name: Teddy | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.10.05 22:10:25 | 000,601,088 | ---- | M] (OldTimer Tools) -- C:\Users\Teddy\Downloads\OTL.exe PRC - [2012.10.03 11:51:37 | 000,296,096 | ---- | M] (RealNetworks, Inc.) -- C:\Programme\Real\RealPlayer\Update\realsched.exe PRC - [2012.08.10 18:59:52 | 004,440,896 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Teddy\AppData\Local\Akamai\netsession_win.exe PRC - [2012.08.08 22:55:44 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.05.31 15:00:22 | 000,445,624 | ---- | M] (Sony) -- C:\Programme\Sony\Sony PC Companion\PCCompanion.exe PRC - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe PRC - [2012.05.15 11:28:16 | 001,820,480 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe PRC - [2012.05.15 11:27:34 | 000,857,920 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe PRC - [2012.05.15 05:21:28 | 000,461,176 | ---- | M] (PPLive Corporation) -- C:\Programme\Common Files\PPLiveNetwork\PPAP.exe PRC - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2012.05.08 22:52:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2012.05.08 22:52:24 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2012.05.08 22:52:24 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2012.04.30 11:57:42 | 000,067,072 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe PRC - [2012.04.29 09:31:36 | 004,901,744 | ---- | M] (Exent Technologies Ltd.) -- C:\Programme\FreeRide Games\GPlayer.exe PRC - [2012.04.16 20:51:46 | 000,066,992 | ---- | M] (Raptr, Inc) -- C:\Programme\Raptr\raptr.exe PRC - [2012.04.16 20:51:46 | 000,043,952 | ---- | M] (Raptr, Inc) -- C:\Programme\Raptr\raptr_im.exe PRC - [2011.09.01 19:18:54 | 004,862,384 | ---- | M] (Exent Technologies Ltd.) -- C:\Programme\Free Ride Games\GPlayer.exe PRC - [2011.07.16 06:31:12 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2011.06.17 19:33:04 | 000,272,528 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee Security Scan\3.0.207\SSScheduler.exe PRC - [2011.06.09 14:06:06 | 000,507,624 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Common Files\Java\Java Update\jucheck.exe PRC - [2011.02.26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2011.01.26 08:45:58 | 000,870,120 | ---- | M] () -- C:\Windows\System32\atwtusb.exe PRC - [2011.01.17 18:37:40 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe PRC - [2011.01.17 18:37:40 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin PRC - [2010.12.24 09:31:08 | 007,134,952 | ---- | M] () -- C:\Windows\System32\WTMKM.exe PRC - [2010.05.13 21:55:53 | 000,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Users\Teddy\Program Files\DNA\btdna.exe PRC - [2010.03.18 11:26:08 | 000,172,328 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version5\TeamViewer_Service.exe PRC - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2009.07.14 03:14:42 | 000,181,760 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\TabTip.exe PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2009.07.14 03:14:38 | 001,173,504 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.07.14 03:14:21 | 000,294,400 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\InputPersonalization.exe ========== Modules (No Company Name) ========== MOD - [2012.05.24 11:50:32 | 000,203,776 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\MExplorer.dll MOD - [2012.05.23 11:38:36 | 000,583,680 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PhoneUpdate.dll MOD - [2012.05.15 05:21:14 | 000,522,600 | ---- | M] () -- C:\Programme\Common Files\PPLiveNetwork\1.0.0.53\MngModule.dll MOD - [2012.04.30 11:57:42 | 000,067,072 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe MOD - [2012.04.30 11:57:42 | 000,039,936 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\TMonitorAPI.dll MOD - [2012.03.25 13:51:43 | 000,985,088 | ---- | M] () -- C:\Programme\OpenOffice.org 3\program\libxml2.dll MOD - [2012.02.20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012.02.20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2012.02.17 19:53:28 | 000,494,592 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtNetwork.pyd MOD - [2012.02.17 19:53:24 | 001,661,952 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtCore.pyd MOD - [2012.02.17 19:53:20 | 000,313,856 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtWebKit.pyd MOD - [2012.02.17 19:53:06 | 005,809,664 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtGui.pyd MOD - [2012.02.17 19:52:26 | 000,067,584 | ---- | M] () -- C:\Programme\Raptr\sip.pyd MOD - [2011.11.21 04:20:46 | 001,949,696 | ---- | M] () -- C:\Programme\Raptr\libtorrent.pyd MOD - [2011.10.24 20:49:56 | 002,717,595 | ---- | M] () -- C:\Programme\Raptr\heliotrope._purple.pyd MOD - [2011.09.09 01:47:40 | 001,183,699 | ---- | M] () -- C:\Programme\Raptr\liboscar.dll MOD - [2011.09.09 01:47:36 | 001,640,221 | ---- | M] () -- C:\Programme\Raptr\libjabber.dll MOD - [2011.09.09 01:47:32 | 001,052,194 | ---- | M] () -- C:\Programme\Raptr\libymsg.dll MOD - [2011.09.09 01:47:22 | 000,495,680 | ---- | M] () -- C:\Programme\Raptr\plugins\libaim.dll MOD - [2011.09.09 01:47:22 | 000,483,306 | ---- | M] () -- C:\Programme\Raptr\plugins\libicq.dll MOD - [2011.09.09 01:47:16 | 000,655,356 | ---- | M] () -- C:\Programme\Raptr\plugins\libirc.dll MOD - [2011.09.09 01:47:16 | 000,603,326 | ---- | M] () -- C:\Programme\Raptr\plugins\ssl-nss.dll MOD - [2011.09.09 01:47:14 | 000,497,782 | ---- | M] () -- C:\Programme\Raptr\plugins\libyahoojp.dll MOD - [2011.09.09 01:47:14 | 000,474,199 | ---- | M] () -- C:\Programme\Raptr\plugins\ssl.dll MOD - [2011.09.09 01:47:10 | 001,306,387 | ---- | M] () -- C:\Programme\Raptr\plugins\libmsn.dll MOD - [2011.09.09 01:47:04 | 000,565,461 | ---- | M] () -- C:\Programme\Raptr\plugins\libxmpp.dll MOD - [2011.09.09 01:46:56 | 000,506,276 | ---- | M] () -- C:\Programme\Raptr\plugins\libyahoo.dll MOD - [2011.07.07 14:54:36 | 000,233,984 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\Report.dll MOD - [2011.02.15 20:17:28 | 001,213,633 | ---- | M] () -- C:\Programme\Raptr\libxml2-2.dll MOD - [2011.02.15 20:17:28 | 000,417,501 | ---- | M] () -- C:\Programme\Raptr\sqlite3.dll MOD - [2010.12.24 09:31:08 | 007,134,952 | ---- | M] () -- C:\Windows\System32\WTMKM.exe MOD - [2010.11.23 01:06:22 | 000,055,808 | ---- | M] () -- C:\Programme\Raptr\zlib1.dll MOD - [2010.11.23 00:57:34 | 000,167,936 | ---- | M] () -- C:\Programme\Raptr\win32gui.pyd MOD - [2010.11.23 00:57:34 | 000,111,104 | ---- | M] () -- C:\Programme\Raptr\win32file.pyd MOD - [2010.11.23 00:57:34 | 000,096,256 | ---- | M] () -- C:\Programme\Raptr\win32api.pyd MOD - [2010.11.23 00:57:34 | 000,036,352 | ---- | M] () -- C:\Programme\Raptr\win32process.pyd MOD - [2010.11.23 00:57:18 | 000,141,312 | ---- | M] () -- C:\Programme\Raptr\gobject._gobject.pyd MOD - [2010.11.23 00:57:06 | 000,263,168 | ---- | M] () -- C:\Programme\Raptr\win32com.shell.shell.pyd MOD - [2010.11.23 00:56:56 | 000,354,304 | ---- | M] () -- C:\Programme\Raptr\pythoncom26.dll MOD - [2010.11.23 00:56:56 | 000,110,592 | ---- | M] () -- C:\Programme\Raptr\pywintypes26.dll MOD - [2010.11.23 00:56:26 | 000,324,608 | ---- | M] () -- C:\Programme\Raptr\PIL._imaging.pyd MOD - [2010.11.23 00:56:02 | 000,805,376 | ---- | M] () -- C:\Programme\Raptr\_ssl.pyd MOD - [2010.11.23 00:56:02 | 000,583,680 | ---- | M] () -- C:\Programme\Raptr\unicodedata.pyd MOD - [2010.11.23 00:56:02 | 000,356,864 | ---- | M] () -- C:\Programme\Raptr\_hashlib.pyd MOD - [2010.11.23 00:56:02 | 000,127,488 | ---- | M] () -- C:\Programme\Raptr\pyexpat.pyd MOD - [2010.11.23 00:56:02 | 000,087,040 | ---- | M] () -- C:\Programme\Raptr\_ctypes.pyd MOD - [2010.11.23 00:56:02 | 000,044,544 | ---- | M] () -- C:\Programme\Raptr\_sqlite3.pyd MOD - [2010.11.23 00:56:02 | 000,043,008 | ---- | M] () -- C:\Programme\Raptr\_socket.pyd MOD - [2010.11.23 00:56:02 | 000,009,216 | ---- | M] () -- C:\Programme\Raptr\winsound.pyd MOD - [2010.01.11 16:44:54 | 000,053,248 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\VObject.dll MOD - [2008.09.16 21:18:06 | 000,132,608 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll ========== Services (SafeList) ========== SRV - [2012.09.22 20:50:22 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.09.20 22:42:33 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.09.06 20:37:25 | 004,537,664 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_5891ae0.dll -- (Akamai) SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012.05.08 22:52:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.05.08 22:52:24 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.04.29 09:26:24 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2012.01.18 14:38:28 | 000,155,320 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Programme\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion) SRV - [2011.06.17 19:33:04 | 000,237,008 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Programme\McAfee Security Scan\3.0.207\McCHSvc.exe -- (McComponentHostService) SRV - [2011.01.26 08:45:58 | 000,870,120 | ---- | M] () [Auto | Running] -- C:\Windows\System32\atwtusb.exe -- (WTService) SRV - [2010.03.28 10:50:19 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2010.03.18 11:26:08 | 000,172,328 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5) SRV - [2009.12.16 19:26:00 | 003,453,712 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc) SRV - [2009.07.14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva380.sys -- (XDva380) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (aoc6lxmn) DRV - [2012.09.17 21:31:15 | 000,076,800 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\SSHDRV84.sys -- (SSHDRV84) DRV - [2012.07.07 11:07:44 | 000,025,200 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc) DRV - [2012.07.07 11:07:44 | 000,012,400 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt) DRV - [2012.05.15 12:26:00 | 011,354,944 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2012.05.12 17:59:30 | 000,013,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\apf003.sys -- (apf003) DRV - [2012.05.08 22:52:24 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.05.08 22:52:24 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.12.15 16:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2010.11.22 10:25:22 | 000,046,184 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto | Running] -- C:\Programme\FreeRide Games\X6XSEx.sys -- (X6XSEx_Pr148) DRV - [2010.11.22 09:25:22 | 000,046,184 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto | Running] -- C:\Programme\Free Ride Games\X6XSEx.sys -- (X6XSEx) DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010.05.23 13:25:15 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd) DRV - [2009.09.23 03:19:31 | 000,294,912 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcvmm.sys -- (vpcvmm) DRV - [2009.09.23 03:19:31 | 000,055,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcnfltr.sys -- (vpcnfltr) DRV - [2009.09.23 03:18:08 | 000,078,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpcusb.sys -- (vpcusb) DRV - [2009.09.23 03:18:07 | 000,165,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpchbus.sys -- (vpcbus) DRV - [2009.08.20 12:38:24 | 000,006,144 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\walvhid.sys -- (vhidmini) DRV - [2009.07.14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2009.07.14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2009.07.14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2009.07.14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2009.07.14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2009.07.14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2009.03.08 13:15:14 | 000,006,144 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\moufiltr.sys -- (moufiltr) DRV - [2009.01.19 20:31:56 | 000,277,544 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11) DRV - [2007.07.03 15:05:00 | 000,162,944 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RT25USBAP.SYS -- (RT25USBAP) DRV - [2006.06.27 09:56:50 | 000,031,872 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\superwebcam.sys -- (SUPERWEBCAM) DRV - [2005.06.20 10:12:00 | 000,215,040 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\sis163u.sys -- (SIS163u) DRV - [2005.02.26 09:25:52 | 000,091,527 | ---- | M] (VM) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbVM31b.sys -- (ZSMC301b) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\URLSearchHook: - No CLSID value found IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms} IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://zynga.com/ IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 78 5E 77 19 B3 CA 01 [binary data] IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {90b49673-5506-483e-b92b-ca0265bd9ca8} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://search.bearshare.net" FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1 FF - prefs.js..extensions.enabledItems: {ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}:1.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26 FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0 FF - prefs.js..extensions.enabledItems: {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}:4.6.1.02 FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.5.7.4 FF - prefs.js..extensions.enabledItems: ocr@babylon.com:1.1 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll () FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@exent.com/npExentControl,version=7.1.0.1: C:\Program Files\FreeRide Games\npExentControl.dll (Exent Technologies Ltd.) FF - HKLM\Software\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0: C:\Program Files\Free Ride Games\npExentCtl.dll (Exent Technologies Ltd.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF - HKLM\Software\MozillaPlugins\@pptv.com/plugin: C:\Program Files\Internet Explorer\PPLite\plugin\1.0.0.53\npplugin2.dll (PPLive Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@zylom.com/ZylomGamesPlayer: C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.) FF - HKCU\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Users\Teddy\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.) FF - HKCU\Software\MozillaPlugins\@g2.com/iggweb3dupdater: C:\Users\Teddy\AppData\Roaming\IGG\Web3D\1.0.0.37\NPIGGWeb3DUpdater.dll (IGG) FF - HKCU\Software\MozillaPlugins\@g2.com/joyconnectshell: C:\Users\Teddy\AppData\Roaming\IGG\Web3D\1.0.0.37\NPJoyConnectShell.dll (IGG) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Teddy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.10.03 11:51:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.10.03 11:51:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.03 11:51:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.03 11:52:15 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}: C:\Users\Teddy\Program Files\DNA [2012.10.05 20:04:34 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}: C:\Users\Teddy\AppData\Roaming\5008 [2010.11.09 17:44:47 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Teddy\AppData\Roaming\IDM\idmmzcc5 [2012.03.25 13:37:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Teddy\AppData\Roaming\mozilla\Extensions [2012.09.22 20:50:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions [2011.08.04 17:38:17 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2012.03.25 13:37:02 | 000,000,000 | ---D | M] (Wincore Mediabar) -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} [2012.09.22 00:21:33 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-1.xml [2012.03.25 20:28:36 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-2.xml [2012.09.22 00:11:34 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-3.xml [2012.03.11 00:30:33 | 000,001,056 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin.xml [2012.09.22 20:50:26 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.09.15 23:30:05 | 000,000,000 | ---D | M] (Babylon Translation Activation) -- C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com [2012.09.22 20:50:22 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.10.03 06:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2012.10.03 11:51:42 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll [2009.03.24 12:10:44 | 000,114,688 | ---- | M] (Zylom) -- C:\Program Files\mozilla firefox\plugins\npzylomgamesplayer.dll [2012.09.22 20:50:20 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.22 20:50:20 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.09.22 20:50:20 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.09.22 20:50:20 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.09.22 20:50:20 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.09.22 20:50:20 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - homepage: CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR - homepage: CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\pdf.dll CHR - plugin: Perion plugin (Enabled) = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll CHR - plugin: Zylom Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll CHR - plugin: AhnLab MyKeyDefense 2.5 (Enabled) = C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll CHR - plugin: Exent\u00AE AOD Gecko Plugin (Enabled) = C:\Program Files\Free Ride Games\npExentCtl.dll CHR - plugin: Exent\u00AE AOD Gecko Plugin (Enabled) = C:\Program Files\FreeRide Games\npExentControl.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll CHR - plugin: PPLive PPTV Plugin (Enabled) = C:\Program Files\Internet Explorer\PPLite\plugin\1.0.0.53\npplugin2.dll CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll CHR - plugin: Media Go Detector (Enabled) = C:\Program Files\Sony\Media Go\npmediago.dll CHR - plugin: PlayStation(R)Network Downloader Check Plug-in (Enabled) = C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll CHR - plugin: Unity Player (Enabled) = C:\Users\Teddy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll CHR - plugin: IGG Web3D Updater NP Plugin for Mozilla (Enabled) = C:\Users\Teddy\AppData\Roaming\IGG\Web3D\1.0.0.37\NPIGGWeb3DUpdater.dll CHR - plugin: JoyConnect NP Plugin for Mozilla (Enabled) = C:\Users\Teddy\AppData\Roaming\IGG\Web3D\1.0.0.37\NPJoyConnectShell.dll CHR - plugin: DNA Plug-in (Enabled) = C:\Users\Teddy\Program Files\DNA\plugins\npbtdna.dll CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll CHR - Extension: YouTube = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Google-Suche = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: Teddy Bear = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gocdpcbhljdnfjpoknadapdpjokmfoif\1_0\ CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\ CHR - Extension: New tab for Chrome\u2122 = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\ CHR - Extension: FastestChrome \u2013 Schneller browsen = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmffncokckfccddfenhkhnllmlobdahm\6.8.6_0\ CHR - Extension: Vuze Remote = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\2.3.4.2_0\ CHR - Extension: Google Mail = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (DataMngr) - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Programme\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll (MusicLab, LLC) O2 - BHO: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll () O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programme\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll () O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No CLSID value found. O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found. O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {90B49673-5506-483E-B92B-CA0265BD9CA8} - No CLSID value found. O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [MacrokeyManager] C:\Windows\System32\WTMKM.exe () O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.) O4 - HKU\.DEFAULT..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-18..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-19..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-20..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Akamai NetSession Interface] C:\Users\Teddy\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [BitTorrent DNA] C:\Users\Teddy\Program Files\DNA\btdna.exe (BitTorrent, Inc.) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Exetender_148] C:\Program Files\FreeRide Games\GPlayer.exe (Exent Technologies Ltd.) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [PlayNC Launcher] File not found O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [PPAP] C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe (PPLive Corporation) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Raptr] C:\Programme\Raptr\raptrstub.exe (Raptr, Inc) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Sony PC Companion] C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Sony) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - Startup: C:\Users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files\Free Download Manager\dlall.htm () O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files\Free Download Manager\dlselected.htm () O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files\Free Download Manager\dllink.htm () O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files\Free Download Manager\dlfvideo.htm () O8 - Extra context menu item: Web-Suche - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in ) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: sony.com ([]* in ) O16 - DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} (ExentInf1 Class) O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{14B43710-DFCA-4ADB-8A04-DFA39535C9DF}: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1537B177-72F8-4837-A69C-4491A1A46E4D}: DhcpNameServer = 192.168.3.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B1D98BB-9065-4F58-B709-0608A62BE7C8}: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{769B5C26-4B44-47FB-B41A-27AC47E2AB05}: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Programme\Common Files\microsoft shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell - "" = AutoRun O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell\AutoRun\command - "" = H:\Startme.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare Software.lnk - - File not found MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Registrierungsprogramm ausführen.lnk - C:\Programme\WiFiConnector\NintendoWFCReg.exe - () MsConfig - StartUpFolder: C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk - C:\Programme\OpenOffice.org 3\program\quickstart.exe - () MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - File not found MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) MsConfig - StartUpReg: TkBellExe - hkey= - key= - c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.) MsConfig - State: "startup" - 0 SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: NTDS - File not found SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vmms - Service SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: NTDS - File not found SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vmms - Service SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D} - Microsoft .NET Framework 1.1 Security Update (KB953297) ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com) Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com) Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll () CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.10.05 21:33:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome [2012.10.05 21:31:49 | 000,000,000 | ---D | C] -- C:\Program Files\Google [2012.10.05 21:31:46 | 000,000,000 | ---D | C] -- C:\Users\Teddy\AppData\Local\Google [2012.10.03 11:52:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared [2012.09.22 22:49:29 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012.09.22 22:40:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus [2012.09.22 22:09:47 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee Security Scan [2012.09.22 22:09:42 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan [2012.09.22 22:09:42 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee [2012.09.22 20:50:26 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service [2012.09.22 20:50:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2012.09.22 09:25:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared [2012.09.21 23:52:20 | 000,000,000 | ---D | C] -- C:\Users\Teddy\AppData\Roaming\Malwarebytes [2012.09.21 23:52:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.09.21 23:52:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.09.21 23:52:05 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.09.21 23:52:05 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012.09.21 23:47:14 | 000,000,000 | ---D | C] -- C:\Users\Teddy\Start Menu [2012.09.21 13:56:14 | 000,000,000 | ---D | C] -- C:\Program Files\Perion [2012.09.17 21:26:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gathering [2012.09.16 14:10:02 | 000,000,000 | ---D | C] -- C:\Users\Teddy\Desktop\Neuer Ordner [2012.09.15 22:56:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SWF Studio [2012.09.15 22:55:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prelusion [2012.09.06 21:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cornelsen [2012.09.06 21:48:24 | 000,000,000 | ---D | C] -- C:\Program Files\Cornelsen [1 C:\Users\Teddy\AppData\Roaming\*.tmp files -> C:\Users\Teddy\AppData\Roaming\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.10.05 21:42:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.10.05 21:36:03 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.10.05 21:36:00 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.10.05 21:33:05 | 000,002,193 | ---- | M] () -- C:\Users\Teddy\Desktop\Google Chrome.lnk [2012.10.05 20:11:51 | 000,020,720 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.10.05 20:11:51 | 000,020,720 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.10.05 20:04:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.10.05 20:04:13 | 2415,255,552 | -HS- | M] () -- C:\hiberfil.sys [2012.10.05 15:43:49 | 000,627,443 | ---- | M] () -- C:\Users\Teddy\Desktop\Komplexarbeit Handke.pdf [2012.10.03 23:35:34 | 000,666,270 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.10.03 23:35:34 | 000,625,116 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.10.03 23:35:34 | 000,135,198 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.10.03 23:35:34 | 000,110,754 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.10.03 11:52:11 | 000,001,012 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk [2012.10.03 11:51:39 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll [2012.10.02 23:19:04 | 000,414,198 | ---- | M] () -- C:\Users\Teddy\Desktop\bookmarks_02.10.12.html [2012.10.02 23:15:55 | 000,001,775 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk [2012.10.01 12:28:17 | 000,164,648 | ---- | M] () -- C:\Users\Teddy\Desktop\buntesleben.jpg [2012.09.24 15:26:33 | 000,513,501 | ---- | M] () -- C:\Users\Teddy\Desktop\adwcleaner.exe [2012.09.23 10:27:49 | 000,000,436 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Teddy.job [2012.09.22 22:40:55 | 000,002,040 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk [2012.09.22 22:40:55 | 000,002,040 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2012.09.22 22:07:34 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2012.09.22 11:38:23 | 000,000,298 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat [2012.09.21 23:52:07 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.09.21 22:57:03 | 000,003,405 | ---- | M] () -- C:\Users\Teddy\.recently-used.xbel [2012.09.17 21:31:15 | 000,076,800 | ---- | M] () -- C:\Windows\System32\drivers\SSHDRV84.sys [2012.09.17 21:30:33 | 000,000,000 | ---- | M] () -- C:\Users\Public\Documents\PCD549.L!C [2012.09.17 21:26:18 | 000,000,616 | ---- | M] () -- C:\Users\Public\Desktop\Holiday World.lnk [2012.09.15 22:55:51 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Gilbert Goodmate.lnk [2012.09.07 20:55:14 | 000,315,280 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.09.06 21:49:47 | 000,001,101 | ---- | M] () -- C:\Users\Public\Desktop\At the Cutting Edge.lnk [1 C:\Users\Teddy\AppData\Roaming\*.tmp files -> C:\Users\Teddy\AppData\Roaming\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.10.05 21:33:05 | 000,002,193 | ---- | C] () -- C:\Users\Teddy\Desktop\Google Chrome.lnk [2012.10.05 21:31:52 | 000,001,096 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.10.05 21:31:51 | 000,001,092 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.10.05 15:43:46 | 000,627,443 | ---- | C] () -- C:\Users\Teddy\Desktop\Komplexarbeit Handke.pdf [2012.10.03 11:52:11 | 000,001,012 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk [2012.10.02 23:15:55 | 000,001,787 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk [2012.10.02 23:15:55 | 000,001,775 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk [2012.10.02 23:08:54 | 000,414,198 | ---- | C] () -- C:\Users\Teddy\Desktop\bookmarks_02.10.12.html [2012.10.01 12:28:28 | 000,164,648 | ---- | C] () -- C:\Users\Teddy\Desktop\buntesleben.jpg [2012.09.26 12:50:47 | 000,602,972 | ---- | C] () -- C:\Users\Teddy\Desktop\DSC_0151.JPG [2012.09.24 15:26:32 | 000,513,501 | ---- | C] () -- C:\Users\Teddy\Desktop\adwcleaner.exe [2012.09.22 22:09:42 | 000,002,040 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk [2012.09.22 22:09:42 | 000,002,040 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2012.09.22 22:07:34 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2012.09.22 22:07:34 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2012.09.22 20:50:24 | 000,001,100 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2012.09.22 11:11:09 | 000,000,298 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat [2012.09.21 23:52:07 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.09.21 22:57:03 | 000,003,405 | ---- | C] () -- C:\Users\Teddy\.recently-used.xbel [2012.09.17 21:31:15 | 000,076,800 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV84.sys [2012.09.17 21:30:33 | 000,000,000 | ---- | C] () -- C:\Users\Public\Documents\PCD549.L!C [2012.09.17 21:26:18 | 000,000,616 | ---- | C] () -- C:\Users\Public\Desktop\Holiday World.lnk [2012.09.15 22:55:51 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Gilbert Goodmate.lnk [2012.09.06 21:49:47 | 000,001,101 | ---- | C] () -- C:\Users\Public\Desktop\At the Cutting Edge.lnk [2012.08.22 22:48:13 | 000,000,232 | ---- | C] () -- C:\Users\Teddy\.KanjiGymLight [2012.08.13 17:53:37 | 000,000,059 | ---- | C] () -- C:\Windows\RUNAWAY.INI [2012.05.18 17:40:39 | 000,010,525 | ---- | C] () -- C:\Windows\System32\Default_3.ini [2012.05.18 17:40:39 | 000,010,283 | ---- | C] () -- C:\Windows\System32\Default_2.ini [2012.05.18 17:40:39 | 000,009,917 | ---- | C] () -- C:\Windows\System32\Default_1.ini [2012.05.18 17:40:39 | 000,000,738 | ---- | C] () -- C:\Windows\System32\MKProfile.ini [2012.05.18 17:40:36 | 000,000,105 | R--- | C] () -- C:\ProgramData\Ppster.ini [2012.05.18 17:40:30 | 000,870,120 | ---- | C] () -- C:\Windows\System32\atwtusb.exe [2012.05.18 17:40:28 | 007,134,952 | ---- | C] () -- C:\Windows\System32\WTMKM.exe [2012.05.18 17:40:23 | 000,045,056 | ---- | C] () -- C:\Windows\System32\InstallService.exe [2012.05.18 17:40:22 | 003,683,560 | ---- | C] () -- C:\Windows\System32\Control Panel_Betteryless.exe [2012.05.18 17:40:20 | 000,148,200 | ---- | C] () -- C:\Windows\System32\Calibration.exe [2012.05.18 17:40:12 | 000,835,072 | ---- | C] () -- C:\Windows\RmTablet.exe [2012.05.18 17:40:11 | 000,010,708 | ---- | C] () -- C:\Windows\System32\aiptbl.ini [2012.05.15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe [2012.05.12 17:59:30 | 000,016,304 | ---- | C] () -- C:\Windows\System32\apl003.sys [2012.05.12 17:59:30 | 000,013,232 | ---- | C] () -- C:\Windows\System32\apf003.sys [2012.04.16 23:36:22 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2012.04.14 22:56:32 | 000,000,000 | ---- | C] () -- C:\Users\Teddy\__ng3d.lock [2012.03.25 12:13:13 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat [2012.03.04 01:19:48 | 000,000,410 | ---- | C] () -- C:\Windows\{27018D57-D152-44EF-BCE0-5E3B3445EABE}_WiseFW.ini [2011.12.23 03:43:56 | 000,230,752 | ---- | C] () -- C:\Windows\patchw32.dll [2011.12.23 03:43:56 | 000,118,176 | ---- | C] () -- C:\Windows\patchw.dll [2010.11.17 17:57:56 | 000,006,936 | ---- | C] () -- C:\Windows\Go Screensaver.ini [2010.09.15 21:26:32 | 000,000,148 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\urhtps.dat [2010.05.28 15:06:46 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_3 [2010.05.28 00:08:52 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_1 [2010.05.28 00:06:06 | 000,000,169 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\D2Info0 [2010.05.28 00:06:06 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_2 [2010.04.18 18:08:31 | 000,032,256 | ---- | C] () -- C:\Users\Teddy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.02.21 20:31:04 | 000,000,093 | ---- | C] () -- C:\Users\Teddy\AppData\Local\fusioncache.dat ========== ZeroAccess Check ========== [2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2010.07.27 16:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2011.10.16 18:35:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\.minecraft [2010.09.15 01:00:21 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5005 [2010.10.04 18:09:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5006 [2010.11.09 17:44:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5008 [2010.03.08 21:06:30 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Anabel [2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\app [2012.08.03 16:04:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Azureus [2012.03.25 22:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Cat's Eye Games [2010.09.15 01:00:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\cock [2012.05.04 23:05:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DAEMON Tools Lite [2010.03.08 22:51:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dekovir [2011.08.10 22:18:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DMCache [2012.10.05 22:34:49 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DNA [2010.05.28 23:56:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus 2 [2010.05.28 00:06:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2010.05.28 15:06:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2010.05.28 00:08:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2012.09.22 14:47:14 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoft [2012.07.09 13:22:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoftIEHelpers [2012.04.28 23:46:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EnchantedCavern [2010.03.09 06:52:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EscapeTheMuseum2 [2012.03.25 16:46:15 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Exent Technologies [2012.03.25 23:36:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Finstere Liebschaft [2011.01.04 17:40:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\FOG Downloader [2012.10.03 08:42:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Free Download Manager [2012.04.05 00:38:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Friday's games [2012.04.28 22:10:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gamers Digital [2010.03.08 19:35:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Games [2012.04.17 00:12:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\GetRightToGo [2010.03.08 21:42:43 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gogii [2012.09.08 13:21:19 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\gtk-2.0 [2011.08.07 18:08:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Haushaltsbuch [2012.03.25 00:45:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ICQ [2012.04.05 21:08:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IGG [2011.12.26 14:48:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVU [2011.12.14 22:23:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVUClient [2012.07.08 01:14:28 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Jasc [2012.05.12 17:07:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\KlLauncherST [2011.11.05 23:06:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Lingo4u [2011.11.16 00:26:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\LolClient [2012.03.25 13:36:37 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\MusicNet [2010.05.28 19:36:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\OpenOffice.org [2010.06.11 23:59:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Opera [2011.10.22 16:51:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Origin [2012.04.09 01:13:44 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayFirst [2011.06.30 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayPond [2010.03.07 01:16:25 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Playrix Entertainment [2010.03.08 21:23:32 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PoBros [2012.08.08 13:54:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PPlive [2010.03.09 05:48:03 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Princess Isabella [2010.04.01 01:41:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ProtectDisc [2012.10.05 20:04:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Raptr [2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2012.04.14 16:06:17 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RenPy [2010.03.28 15:47:09 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RobinsonCrusoe [2012.01.10 23:36:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Sony [2012.07.30 13:39:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Synthesia [2011.10.16 18:32:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TeamViewer [2010.03.08 18:55:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TitanicMystery [2008.06.27 00:59:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TuneUp Software [2010.02.22 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Turbine [2010.09.16 13:25:07 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\UAs [2010.05.25 01:37:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Ubisoft [2011.07.07 16:58:36 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Unity [2010.03.08 07:46:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Virtual City [2010.09.16 13:25:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\xmldm ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2011.10.16 18:35:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\.minecraft [2010.09.15 01:00:21 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5005 [2010.10.04 18:09:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5006 [2010.11.09 17:44:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5008 [2012.09.23 11:30:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Adobe [2010.03.08 21:06:30 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Anabel [2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\app [2012.03.28 22:37:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Apple Computer [2012.02.14 22:09:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Avira [2012.08.03 16:04:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Azureus [2012.03.25 22:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Cat's Eye Games [2010.09.15 01:00:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\cock [2012.05.04 23:05:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DAEMON Tools Lite [2010.03.08 22:51:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dekovir [2011.08.10 22:18:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DMCache [2012.10.05 22:34:49 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DNA [2010.05.28 23:56:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus 2 [2010.05.28 00:06:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2010.05.28 15:06:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2010.05.28 00:08:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2012.09.22 14:47:14 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoft [2012.07.09 13:22:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoftIEHelpers [2012.04.28 23:46:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EnchantedCavern [2010.03.09 06:52:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EscapeTheMuseum2 [2012.03.25 16:46:15 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Exent Technologies [2012.03.25 23:36:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Finstere Liebschaft [2011.01.04 17:40:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\FOG Downloader [2012.10.03 08:42:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Free Download Manager [2012.04.05 00:38:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Friday's games [2012.04.28 22:10:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gamers Digital [2010.03.08 19:35:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Games [2012.04.17 00:12:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\GetRightToGo [2010.03.08 21:42:43 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gogii [2012.09.08 13:21:19 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\gtk-2.0 [2011.08.07 18:08:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Haushaltsbuch [2012.03.25 00:45:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ICQ [2010.02.21 18:51:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Identities [2012.04.05 21:08:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IGG [2011.12.26 14:48:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVU [2011.12.14 22:23:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVUClient [2010.03.09 20:56:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\InstallShield [2012.07.08 01:14:28 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Jasc [2012.05.12 17:07:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\KlLauncherST [2011.11.05 23:06:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Lingo4u [2011.11.16 00:26:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\LolClient [2010.02.21 20:31:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Macromedia [2012.09.21 23:52:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Malwarebytes [2009.07.14 10:56:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Media Center Programs [2012.08.18 20:31:05 | 000,000,000 | --SD | M] -- C:\Users\Teddy\AppData\Roaming\Microsoft [2010.09.15 21:23:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Mozilla [2012.03.25 13:36:37 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\MusicNet [2012.06.18 15:22:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\NVIDIA [2010.05.28 19:36:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\OpenOffice.org [2010.06.11 23:59:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Opera [2011.10.22 16:51:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Origin [2012.04.09 01:13:44 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayFirst [2011.06.30 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayPond [2010.03.07 01:16:25 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Playrix Entertainment [2010.03.08 21:23:32 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PoBros [2012.08.08 13:54:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PPlive [2010.03.09 05:48:03 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Princess Isabella [2010.04.01 01:41:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ProtectDisc [2012.10.05 20:04:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Raptr [2012.05.06 22:21:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Real [2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 [2012.04.14 16:06:17 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RenPy [2010.03.28 15:47:09 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RobinsonCrusoe [2012.01.10 23:36:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Sony [2012.07.30 13:39:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Synthesia [2011.10.16 18:32:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TeamViewer [2010.03.08 18:55:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TitanicMystery [2008.06.27 00:59:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TuneUp Software [2010.02.22 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Turbine [2010.09.16 13:25:07 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\UAs [2010.05.25 01:37:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Ubisoft [2011.07.07 16:58:36 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Unity [2010.03.08 07:46:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Virtual City [2010.02.21 19:06:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\WinRAR [2012.05.12 20:30:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Xfire [2010.09.16 13:25:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\xmldm < %APPDATA%\*.exe /s > [2012.04.29 01:03:37 | 000,310,208 | ---- | M] (Georgia Institute of Technology) -- C:\Users\Teddy\AppData\Roaming\Azureus\plugins\mlab\ShaperProbeC.exe [2012.04.05 21:08:12 | 000,726,814 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IGG\Web3D\1.0.0.37\unins000.exe [2011.11.01 18:34:52 | 000,013,312 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\devicefingerprint.exe [2011.11.03 21:04:14 | 000,158,208 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\devicefingerprint_old.exe [2011.11.21 21:03:22 | 000,053,504 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUClient.exe [2011.11.21 21:03:22 | 000,022,784 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe [2011.11.21 21:03:24 | 000,097,200 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUupdater.exe [2011.07.30 01:55:56 | 000,009,728 | ---- | M] (Mozilla Corporation) -- C:\Users\Teddy\AppData\Roaming\IMVUClient\plugin-container.exe [2011.12.14 22:23:04 | 000,077,973 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\Uninstall.exe [2011.04.28 20:51:30 | 000,049,664 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\w9xpopen.exe [2011.11.01 19:00:38 | 000,134,144 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\WriteMiniDump.exe [2011.12.14 22:20:05 | 023,223,800 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\installer\SetupImvu_update.exe [2010.03.24 14:19:14 | 000,038,784 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe [2010.03.21 18:27:59 | 000,010,134 | R--- | M] () -- C:\Users\Teddy\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe [2012.08.07 21:44:21 | 005,527,872 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLite\Update\PPLite_Update.exe [2012.06.13 05:10:04 | 000,464,288 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\PPLive.exe [2012.08.07 22:32:29 | 000,328,985 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\uninst.exe [2012.06.13 05:09:32 | 000,236,448 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\crashreporter.exe [2012.06.13 05:09:34 | 000,130,976 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\hwcheck.exe [2012.06.13 05:09:48 | 000,464,288 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\PPLiveU.exe [2012.06.13 05:09:52 | 000,099,744 | ---- | M] (PPTV) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\PPTVIconBubble.exe [2012.06.13 04:55:04 | 000,202,112 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\PPTVLauncher.exe [2012.06.13 04:55:04 | 000,046,456 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\RepairSetup.exe [2012.06.13 04:55:02 | 000,032,120 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\3.1.6.0056\SkinConverter.exe [2010.04.24 22:07:25 | 000,443,912 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\setup3.11\setup.exe [2011.01.26 17:59:11 | 000,510,120 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\setup3.13\setup.exe [2012.09.25 21:09:07 | 000,449,176 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\temp\~Upg0\rnupgagent.exe [2012.09.25 21:09:07 | 000,449,176 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe [2012.09.27 00:11:56 | 027,433,440 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\stub_data\RealPlayer.exe [2012.09.27 00:10:07 | 000,760,128 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\stub_exe\RealPlayer.exe < %SYSTEMDRIVE%\*.exe > [2011.12.23 03:39:35 | 2059,036,792 | ---- | M] (Acresso Software Inc.) -- C:\LuviniaInstaller_1010040.exe < MD5 for: AGP440.SYS > [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys < MD5 for: ATAPI.SYS > [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll < MD5 for: IASTORV.SYS > [2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys [2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\drivers\iaStorV.sys [2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0033117673c16921\iaStorV.sys [2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys [2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys [2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys [2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys [2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys [2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys < MD5 for: NETLOGON.DLL > [2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll < MD5 for: NVSTOR.SYS > [2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys [2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\drivers\nvstor.sys [2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_38e464dbe521cc7f\nvstor.sys [2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys [2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys [2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys [2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys [2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys [2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys < MD5 for: SCECLI.DLL > [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll [2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll < MD5 for: USER32.DLL > [2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\System32\user32.dll [2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll [2004.08.03 17:53:30 | 000,574,464 | ---- | M] (Microsoft Corporation) MD5=F18CDF551E5223255CF7F0D124B829EF -- C:\Joymax\DMO\user32.dll [2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll < MD5 for: USERINIT.EXE > [2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe [2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe [2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe [2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe [2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe [2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > [2010.05.23 13:25:15 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\Windows\system32\drivers\sptd.sys < %systemroot%\System32\config\*.sav > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < > [2009.07.14 06:53:46 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2009.07.14 06:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT [2012.06.11 13:48:17 | 000,000,436 | -H-- | C] () -- C:\Windows\Tasks\Norton Security Scan for Teddy.job [2012.07.21 19:33:49 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job [2012.10.05 21:31:51 | 000,001,092 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [2012.10.05 21:31:52 | 000,001,096 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job < End of report > |
07.10.2012, 05:19 | #24 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Rechner mit MyStart by IncrediBar infiziert. Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL IE - HKLM\..\URLSearchHook: - No CLSID value found IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://zynga.com/ IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 78 5E 77 19 B3 CA 01 [binary data] IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {90b49673-5506-483e-b92b-ca0265bd9ca8} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - No CLSID value found IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms} IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local FF - prefs.js..browser.startup.homepage: "http://search.bearshare.net" FF - prefs.js..extensions.enabledItems: ocr@babylon.com:1.1 FF - user.js - File not found [2011.08.04 17:38:17 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2012.03.25 13:37:02 | 000,000,000 | ---D | M] (Wincore Mediabar) -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} [2012.09.22 00:21:33 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-1.xml [2012.03.25 20:28:36 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-2.xml [2012.09.22 00:11:34 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-3.xml [2012.03.11 00:30:33 | 000,001,056 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin.xml [2012.09.15 23:30:05 | 000,000,000 | ---D | M] (Babylon Translation Activation) -- C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (DataMngr) - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Programme\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll (MusicLab, LLC) O2 - BHO: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll () O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll () O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No CLSID value found. O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found. O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {90B49673-5506-483E-B92B-CA0265BD9CA8} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell - "" = AutoRun O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell\AutoRun\command - "" = H:\Startme.exe :Files C:\Users\Teddy\__ng3d.lock C:\Users\Teddy\AppData\Roaming\50?? C:\Users\Teddy\AppData\Roaming\cock C:\Users\Teddy\AppData\Roaming\xmldm C:\Users\Teddy\AppData\Roaming\kock C:\Users\Teddy\AppData\Roaming\UAs C:\Program Files\BearShare Applications C:\Users\Teddy\Downloads\cnet2_realistair_installer_exe.exe C:\Users\Teddy\Downloads\PageRage (1).exe C:\Users\Teddy\Downloads\PageRage (2).exe C:\Users\Teddy\Downloads\PageRage.exe C:\Users\Teddy\Downloads\SoftonicDownloader_fuer_animation-shop.exe ipconfig /flushdns /c :Commands [purity] [emptytemp] [resethosts] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ Logfiles bitte immer in CODE-Tags posten |
07.10.2012, 11:24 | #25 |
| Rechner mit MyStart by IncrediBar infiziert. Danke, dass du dir so viel Mühe machst. Code:
ATTFilter All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}\ not found. HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully! HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully! HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\ not found. Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found. Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{90b49673-5506-483e-b92b-ca0265bd9ca8} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90b49673-5506-483e-b92b-ca0265bd9ca8}\ not found. Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found. Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{f92a9fe4-2850-4198-b9d5-279880e49b16} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f92a9fe4-2850-4198-b9d5-279880e49b16}\ not found. HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found. Registry key HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}\ not found. HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! Prefs.js: "hxxp://search.bearshare.net" removed from browser.startup.homepage Prefs.js: ocr@babylon.com:1.1 removed from extensions.enabledItems C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img folder moved successfully. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} scheduled to be moved on reboot. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\components folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\searchbar folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\options folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\icons folder moved successfully. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\uwa folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio\images folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio\css folder moved successfully. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\images folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default\scripts folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default\images folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default\css folder moved successfully. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\css folder moved successfully. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin scheduled to be moved on reboot. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox\thumbs folder moved successfully. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets scheduled to be moved on reboot. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\modules folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\lib folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\data\search folder moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\data folder moved successfully. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} scheduled to be moved on reboot. C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-1.xml moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-2.xml moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-3.xml moved successfully. C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin.xml moved successfully. C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com\chrome\skin folder moved successfully. C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com\chrome\content folder moved successfully. C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com\chrome folder moved successfully. Folder move failed. C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com scheduled to be moved on reboot. Registry delete failed. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B939CF93-F2CB-443d-956C-DC523D85C9DB}\ deleted successfully. Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B939CF93-F2CB-443d-956C-DC523D85C9DB}\ . C:\Programme\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\ not found. C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\ not found. File C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3}\ not found. Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}\ not found. Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{90B49673-5506-483E-B92B-CA0265BD9CA8} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90B49673-5506-483E-B92B-CA0265BD9CA8}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\ not found. File H:\Startme.exe not found. ========== FILES ========== C:\Users\Teddy\__ng3d.lock moved successfully. C:\Users\Teddy\AppData\Roaming\5005\components folder moved successfully. Folder move failed. C:\Users\Teddy\AppData\Roaming\5005 scheduled to be moved on reboot. C:\Users\Teddy\AppData\Roaming\5006\components folder moved successfully. Folder move failed. C:\Users\Teddy\AppData\Roaming\5006 scheduled to be moved on reboot. C:\Users\Teddy\AppData\Roaming\5008\components folder moved successfully. Folder move failed. C:\Users\Teddy\AppData\Roaming\5008 scheduled to be moved on reboot. C:\Users\Teddy\AppData\Roaming\cock folder moved successfully. C:\Users\Teddy\AppData\Roaming\xmldm folder moved successfully. File\Folder C:\Users\Teddy\AppData\Roaming\kock not found. C:\Users\Teddy\AppData\Roaming\UAs folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\components folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\searchbar folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\options folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\icons folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\uwa folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio\images folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio\css folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\images folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default\scripts folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default\css folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\css folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox\thumbs folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\modules folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\lib folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\data\search folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\data folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar scheduled to be moved on reboot. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension\content folder moved successfully. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension\components folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar scheduled to be moved on reboot. C:\Program Files\BearShare Applications\BearShare\Skins\Images folder moved successfully. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview\images folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot. C:\Program Files\BearShare Applications\BearShare\Skins\html\images folder moved successfully. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble\images folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot. C:\Program Files\BearShare Applications\BearShare\Skins\html\cdripview folder moved successfully. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview\images folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview\images folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins scheduled to be moved on reboot. C:\Program Files\BearShare Applications\BearShare\HTML\Images folder moved successfully. Folder move failed. C:\Program Files\BearShare Applications\BearShare\HTML scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications scheduled to be moved on reboot. C:\Users\Teddy\Downloads\cnet2_realistair_installer_exe.exe moved successfully. C:\Users\Teddy\Downloads\PageRage (1).exe moved successfully. C:\Users\Teddy\Downloads\PageRage (2).exe moved successfully. C:\Users\Teddy\Downloads\PageRage.exe moved successfully. File\Folder C:\Users\Teddy\Downloads\SoftonicDownloader_fuer_animation-shop.exe not found. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Teddy\Downloads\cmd.bat deleted successfully. C:\Users\Teddy\Downloads\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 41620 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: Teddy ->Temp folder emptied: 840799 bytes ->Temporary Internet Files folder emptied: 7666723 bytes ->Java cache emptied: 2954041 bytes ->FireFox cache emptied: 66617881 bytes ->Google Chrome cache emptied: 309407136 bytes ->Opera cache emptied: 0 bytes ->Flash cache emptied: 45507 bytes User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 41620 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 6854 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 370,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.70.2 log created on 10072012_121509 Files\Folders moved on Reboot... Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} scheduled to be moved on reboot. Folder move failed. C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\5005 scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\5006 scheduled to be moved on reboot. Folder move failed. C:\Users\Teddy\AppData\Roaming\5008 scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\HTML scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\HTML scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\MediaBar scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare\HTML scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications\BearShare scheduled to be moved on reboot. Folder move failed. C:\Program Files\BearShare Applications scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Edit: Beim Neustart kommt eine Nachricht, dass "der Player" nicht richtig installiert wurde. Weißt du vielleicht welcher Player gemeint ist? Und noch schlimmer ... wenn ich bei eigenen Datein oder Systemsteuerung und so gehen will, dann kommt da nur die Meldung "Schnittstelle wird nicht unterstützt". Geändert von TDBear (07.10.2012 um 12:14 Uhr) |
07.10.2012, 19:05 | #26 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Rechner mit MyStart by IncrediBar infiziert. Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm! Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet, Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs. Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Rechner mit MyStart by IncrediBar infiziert. |
administrator, adware.hotbar.rb, anti-malware, appdata, autostart, browser, dateien, explorer, gelöscht, gen, google, helper, hängt, infiziert, infiziert., install.exe, löschen, lösung, malwarebytes, microsoft, problem, pup.bundleinstaller.bi, quarantäne, rechner, recycle.bin, roaming, software, speicher, this, trojan.spyeyes.wc, trojan.toggle, uninstall.exe |