Rechner mit MyStart by IncrediBar infiziert.

Rechner mit MyStart by IncrediBar infiziert.

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

 hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
  • Starte bitte die OTL.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Kopiere nun den kompletten Inhalt aus der untenstehenden Codebox in die Textbox von OTL - wenn OTL auf deutsch ist wird sie mit beschriftet
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.exe /s
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Klick auf .
  • Kopiere nun den Inhalt aus OTL.txt hier in Deinen Thread
Logfiles bitte immer in CODE-Tags posten

Rechner mit MyStart by IncrediBar infiziert.

Sry, ging wegen Schule und Arbeit nit eher ....

OTL Extras logfile created on: 30.09.2012 09:44:07 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\Teddy\Desktop
 Professional  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,08 Gb Available Physical Memory | 69,30% Memory free
6,00 Gb Paging File | 4,67 Gb Available in Paging File | 77,88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 307,62 Gb Total Space | 68,54 Gb Free Space | 22,28% Space Free | Partition Type: NTFS
Drive E: | 623,88 Gb Total Space | 535,91 Gb Free Space | 85,90% Space Free | Partition Type: NTFS
Computer Name: TEDDY-PC | User Name: Teddy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
"{042C7E2A-841E-45C1-A3D4-06EA70F430AB}" = lport=56316 | protocol=17 | dir=in | name=pando media booster | 
"{0A6AB701-DA6E-45D0-8B73-BA55BE034C80}" = rport=445 | protocol=6 | dir=out | app=system | 
"{178746BC-3AE8-4418-85D1-0EC7121C039F}" = lport=56961 | protocol=6 | dir=in | name=pando media booster | 
"{1C5F9690-D2DC-4B3F-8D90-4509D0115A93}" = lport=138 | protocol=17 | dir=in | app=system | 
"{21478779-9EEF-4500-8648-250FBA35C359}" = lport=56316 | protocol=6 | dir=in | name=pando media booster | 
"{2D3B327E-55AA-4923-84F1-B50F9F8E2EB0}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{39AAC9C3-F834-4BD1-96C2-766CD1D9B5E5}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{39DA9A05-F39A-4B13-A8DF-BDB8D86B1665}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{4DAD588E-8B8F-42F1-8B0D-D048E6A76B71}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{52136536-26A9-485E-A366-E6D0F6E8F03F}" = lport=56316 | protocol=6 | dir=in | name=pando media booster | 
"{539A9354-B3F8-4823-8D81-E7D1B00636E0}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{5D620BF4-3B7B-4B2D-8C79-712953F5FB0D}" = lport=445 | protocol=6 | dir=in | app=system | 
"{678D85D0-02F2-4C7A-934C-459221B87B08}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{7617B37B-00ED-489C-8F14-8DFACF4D99B6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{76D7C153-1009-4E91-8866-0D38EAAA5E8E}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{773A5AA1-A81E-4C32-8C1D-D4802786A2C0}" = lport=56640 | protocol=17 | dir=in | name=pando media booster | 
"{847CA01F-AAD6-48A2-A2C5-ADFB7DB7E19D}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{885518BB-2620-4221-A537-8E6D488919CF}" = lport=56640 | protocol=6 | dir=in | name=pando media booster | 
"{905FF085-2F26-4CEC-B04B-FF6D521A358B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{939F9FD5-D88E-4433-A55C-C318ECB89733}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{99820895-7E31-4D2E-B173-9FD19C325F0D}" = rport=139 | protocol=6 | dir=out | app=system | 
"{99F9D15B-633A-4A8D-8C24-EBF2F330125E}" = rport=2869 | protocol=6 | dir=out | app=system | 
"{9B472875-5122-46AA-85B4-38CFD4327824}" = rport=138 | protocol=17 | dir=out | app=system | 
"{9EA523D1-4BF5-4954-A180-4FB5E6B4BECE}" = lport=58029 | protocol=6 | dir=in | name=pando media booster | 
"{AB745FBE-24C4-4A66-AA7E-8C9598F257B5}" = lport=56961 | protocol=17 | dir=in | name=pando media booster | 
"{B05BC583-8535-449B-BAA2-C7A1CC1FF7A4}" = lport=137 | protocol=17 | dir=in | app=system | 
"{B49061D0-A11B-41B8-A530-CC72A41D5ED2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{B5AA2EC0-602D-4CD5-8573-21E7E77DC753}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{B60080C3-7745-4E9E-814E-225E05C0BA3F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{B6455C3E-6792-4C33-9288-D6D75A2A83FE}" = lport=56961 | protocol=6 | dir=in | name=pando media booster | 
"{B8D59387-6BAC-4B49-9EDE-D7DD6273CBD9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{BC5B13A0-9231-4714-BFC3-13102D6D47B7}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{BEC9E7C4-33E9-428D-88D6-4DBC7AD33922}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{C1E4DEB0-A57C-4E0F-B8AC-816EDC94299A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{C2BC930A-7A2C-42EB-8E79-63EBF70753D1}" = rport=137 | protocol=17 | dir=out | app=system | 
"{C4349EB1-1267-41DF-B34D-49A5EBEB182F}" = lport=56961 | protocol=17 | dir=in | name=pando media booster | 
"{D5271AC5-F9F7-484A-9FC1-9F8BDFBF1B09}" = lport=56316 | protocol=17 | dir=in | name=pando media booster | 
"{DAC76632-FC0B-4A4E-9A7A-7B6AC5DA18F1}" = lport=58029 | protocol=6 | dir=in | name=pando media booster | 
"{DE9E9BE1-6272-4F73-8B39-9A5F6F12B8A8}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{DFDD8C0A-DD63-4956-9337-6FF5F531CAC7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{E00AD9CA-C06D-47E6-8D6E-2C24745E172D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{E291A67A-8910-4A21-B593-35156568AC6D}" = lport=58029 | protocol=17 | dir=in | name=pando media booster | 
"{E4D8F22C-53FC-4033-A8CA-52FFFF282188}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{E6C58723-57C0-4A7E-8BE7-7FB1B3B1C11A}" = lport=56640 | protocol=6 | dir=in | name=pando media booster | 
"{E8109A89-A94C-44CE-B65D-235AEE2EF9F9}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{E989944F-0128-47AE-A695-FC43F1052E62}" = lport=58029 | protocol=17 | dir=in | name=pando media booster | 
"{EE2A06B7-7AEC-4C20-83BE-5751316F0A08}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{F586FD09-B8FE-4B51-A16F-8EE70A47BCD8}" = lport=139 | protocol=6 | dir=in | app=system | 
"{F949A64E-BBD7-4C6A-B724-4CCC51ADBF53}" = lport=56640 | protocol=17 | dir=in | name=pando media booster | 
========== Vista Active Application Exception List ==========
"{00CDB66E-5D70-46BF-90FD-E5D4C188B004}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{00DDED6A-1F9D-4240-8AC9-66868F7E2A39}" = protocol=17 | dir=in | app=e:\uo fl\client.exe | 
"{02625D39-75F7-4C1D-9B0A-E8C5757D65EF}" = protocol=6 | dir=in | app=c:\program files\xblades\xblades.exe | 
"{058B96FA-7F20-4082-90B5-A365E9A408CA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{0A979ED5-2F0E-4DDD-BDC6-293AACC95E54}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe | 
"{0B8E0B75-A01F-46BA-90B6-B97FE26D2D7B}" = protocol=6 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe | 
"{0EA2D3F7-365F-4AF6-ACCC-852EFCF400DF}" = protocol=17 | dir=in | app=c:\program files\raptr\raptr.exe | 
"{1334AB93-9D3F-49F8-A68F-0072176C6853}" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\alathair\rsync.exe | 
"{146128EC-D499-49C0-85B9-0597767FD0D5}" = dir=in | app=c:\program files\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe | 
"{19CA99BC-F985-4EB7-A668-A4ECB774BDEB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{2E092EC7-CA9B-42E4-99B0-4C0DD36B6F0D}" = protocol=6 | dir=in | app=c:\program files\pplive\pplite\pplite.exe | 
"{2FBBE5AB-2C2A-487E-BC40-5C3C832F8875}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{37B5F634-37F4-4212-89DD-536BE7E06DB9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{3B83BA8E-4ABE-476E-8F99-06E6F39D4A11}" = protocol=17 | dir=in | app=c:\program files\xblades\launcher.exe | 
"{3DAD6590-32F4-4796-8F7B-0E223CAA17B6}" = protocol=6 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe | 
"{3DF76B7E-FD00-4207-8DED-83EE9BC9183F}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | 
"{3E0C1EC0-7E20-45FB-8992-0AD3290ECDCE}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe | 
"{423C3723-BAB4-400C-A0B3-72D68E6F1FB9}" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\alathair\rsync.exe | 
"{4415A533-FDCA-47C5-BB02-0DA5CAABB536}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe | 
"{45F2749C-E01B-43A1-A71E-B1591831FC2D}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\update engine\sony ericsson update engine.exe | 
"{4B51D030-F7DE-48A8-88DD-FB4115778C17}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | 
"{4EB6680A-0DAC-4634-ABDF-FBBB74301839}" = protocol=6 | dir=in | app=c:\alathair\client.exe | 
"{5337969D-EA98-473F-8FFA-0F4C04A42B3E}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | 
"{53E21AA5-6423-4FDD-9FED-660B6D4692CB}" = protocol=17 | dir=in | app=c:\program files\pplive\pplite\pplite.exe | 
"{55CAD5D9-B56D-4AAD-8EDB-D184E424EB29}" = protocol=17 | dir=in | app=c:\koramgame\stonline\_launcher.exe | 
"{58C440F6-3D8B-4879-92ED-C32DE915D678}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | 
"{59915BD8-6733-4CEA-BD97-B2C78918FFB5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{5A471F4B-EA81-4C76-8DC8-382BD73C0A8E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{5A7CEFD2-7B89-4150-9A47-921748CDA2FE}" = protocol=17 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe | 
"{5C205E07-E92D-460A-A523-D2A4933BF5BE}" = protocol=6 | dir=out | app=c:\program files\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe | 
"{5D0A8849-23BF-453B-9E8D-E63CF71A24AB}" = protocol=17 | dir=in | app=e:\gpotato.eu\sevencore\sevencore.exe | 
"{615494AE-3943-4EEF-811E-4585AC8DF77B}" = protocol=6 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_launcher.exe | 
"{61F7CD10-6988-4776-BB6D-23A975D80112}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | 
"{62720D90-6C49-4122-8A21-82AA7A78DA8D}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | 
"{6A9787E0-26CA-4550-B96F-BCCE5C70FBAD}" = protocol=17 | dir=in | app=e:\gpotato.eu\sevencore\launcher.exe | 
"{6ABDA17B-3E91-4ED1-91F2-04162FC3B4E6}" = dir=in | app=c:\program files\wificonnector\nintendowfcreg.exe | 
"{6E3D13B6-EEDD-4068-9C54-C4CFC8B5C44B}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | 
"{75FCF4B6-AD97-4AAF-8362-60AE8C765E28}" = protocol=6 | dir=in | app=c:\alathair\rsync.exe | 
"{7CDB6F02-0BAC-41B1-A4CF-8ECB08427444}" = protocol=17 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_dx9.exe | 
"{7D379615-A772-44E1-8EB6-A39511CA9C2E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{7DDE379F-DC74-44CC-B9BF-BF46EA0E7E5E}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | 
"{7E8EF602-BEFA-4BDD-9F28-CE82531AE008}" = dir=in | app=c:\program files\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe | 
"{8073F3A0-46D6-4249-ABEA-F9258A11B7D9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{80A63A25-2250-4C6F-9875-37A9F54C3F04}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe | 
"{8114F343-3A9F-441F-9556-6B402827AFA0}" = protocol=6 | dir=in | app=c:\program files\xblades\launcher.exe | 
"{817E3EBC-857D-402B-A3F4-121503871714}" = protocol=17 | dir=in | app=c:\program files\xblades\xblades.exe | 
"{83C2438A-F650-4792-90B2-C7BAB91794B5}" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\client.exe | 
"{8426339A-C842-4BEC-9665-73D0BDDF1984}" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\uo.exe | 
"{88A598B2-86BF-4323-B8AD-A21853E4E899}" = protocol=6 | dir=in | app=e:\gpotato.eu\sevencore\sevencore.exe | 
"{8DD0FAE8-E968-415E-90BE-F1F3C8D2D5DA}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | 
"{8F55B8A9-4A44-45EE-89EE-F350C9E00442}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{90BF5CDF-7811-4ACC-B88E-19E1EC606709}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{950FB107-7C87-47A1-9DE5-666EED0E4319}" = dir=in | app=c:\program files\itunes\itunes.exe | 
"{9B7E5148-19CC-4D08-9F41-0B1B13A37641}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | 
"{9C8CD922-9606-4F41-803F-9031DDFCA4E6}" = protocol=6 | dir=in | app=c:\program files\raptr\raptr_im.exe | 
"{9E258B8F-CE8A-406D-A896-21725BC4E8D3}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | 
"{9E9CA593-42BB-46DF-BFF3-6DF10B578293}" = protocol=6 | dir=in | app=c:\program files\raptr\raptr.exe | 
"{A18F29DA-1E24-453E-92AB-83CE22A1477B}" = protocol=17 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe | 
"{A1E96149-BB72-4FCA-951C-6DB633F73869}" = protocol=6 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_dx10.exe | 
"{A2BDDD05-81FD-4190-88AC-98088D279C6E}" = protocol=6 | dir=out | app=c:\program files\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe | 
"{A66AEF93-99BC-42B5-ACB0-339F5959584B}" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\client.exe | 
"{A6C2595F-AA98-44F1-B5CB-B3BE19165499}" = protocol=17 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe | 
"{A8202EEF-0915-4ED6-88AB-2834A4B834B0}" = protocol=6 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_dx9.exe | 
"{A9BD0492-7188-4EB3-86E1-D26C9DC1A982}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{AB68E69F-47E0-47CA-84CA-646B61460163}" = protocol=17 | dir=in | app=c:\alathair\rsync.exe | 
"{AF5FEA63-B2CD-4C6B-9A7F-BDEC2E7E57CD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{B1A0663A-5B02-4564-832D-2FBC473C2E1B}" = dir=in | app=c:\gpotato.eu\allods online\bin\launcher.exe | 
"{B23E7BBD-F4D7-4A56-8B2B-C79481FDFAD7}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | 
"{B4974B62-3695-4C4E-9627-AACB3E2A24DB}" = protocol=6 | dir=in | app=c:\koramgame\stonline\_launcher.exe | 
"{B51DB17A-C6E6-488E-8E3B-2A51ECFA2870}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe | 
"{B61F6BB3-20B9-4EA2-A33C-AF3DEA5A0D84}" = protocol=6 | dir=in | app=c:\windows\system32\msiexec.exe | 
"{B96B6078-1CE5-4F48-B890-7434781519B6}" = protocol=17 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_dx10.exe | 
"{BEAE9E23-49BC-4DBE-A2BC-102DC04EAC87}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | 
"{BF311B7C-17C8-4F91-8535-A0BA5A0BAA0B}" = protocol=6 | dir=in | app=e:\gpotato.eu\sevencore\launcher.exe | 
"{BF8D3108-0C75-485B-9C19-A4EC87683751}" = protocol=17 | dir=in | app=c:\ubisoft\assassin's creed\assassinscreed_launcher.exe | 
"{C05103F6-95B4-4B0A-AB8B-28DEAF06945A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{C087D857-1D33-4A7F-9591-4E104D106013}" = protocol=17 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe | 
"{C2A9D136-CC6B-4722-971F-BFA88DF23134}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | 
"{C35B1078-D012-4C35-88F2-4BDE014478DD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{C3DB37BB-A3CC-473B-9523-2AC2597E74A0}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | 
"{C4DB1259-34D8-4798-B36D-101070DD79AC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{C75581B5-3911-4898-BF2F-4786D729D5AF}" = protocol=6 | dir=in | app=c:\alathair\uo.exe | 
"{C842A4CB-AD59-41DA-BEC4-5F0C1E9306BB}" = protocol=17 | dir=in | app=c:\alathair\client.exe | 
"{D1E7058B-7345-4B5B-8619-16ED9ADB7A5F}" = protocol=6 | dir=out | app=system | 
"{D2204C16-DB8C-4058-9E35-BAB4419FD367}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{D33E86A6-E1D3-4AA0-99E8-1B2F8DA54F7F}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe | 
"{D54AF8D5-ED7E-4BF8-B391-5FCE764A95F5}" = protocol=17 | dir=in | app=c:\alathair\uo.exe | 
"{DA36953A-5F62-4D5B-9FE6-34583A75A582}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe | 
"{E14E95CE-D525-4723-AC5A-5CDB6D45190E}" = protocol=6 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe | 
"{E45157D2-4926-4C14-9322-C7A6E23D8DD5}" = protocol=17 | dir=in | app=c:\windows\system32\msiexec.exe | 
"{E869BE1E-E4AB-48D9-B4C8-471110DA7B68}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe | 
"{E89809AB-C733-4BFC-B966-3FE0FDA6C241}" = protocol=6 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe | 
"{EB49BA65-1FC4-4EB1-8956-59F83C07406E}" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\uo.exe | 
"{EEA2E0EA-BA0E-4710-B106-0418F601A36F}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | 
"{F0B93396-24F0-4EFE-9918-5910C43C8AC8}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe | 
"{F198E940-E576-4CFC-AA98-6E8A22737402}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\update engine\sony ericsson update engine.exe | 
"{F6A2665A-284C-4047-A9D6-621815A758A7}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe | 
"{F7008223-0710-4C62-8581-B47DE7CA0DEA}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | 
"{F76A36EB-0D10-464B-856D-2F075A149BD6}" = protocol=6 | dir=in | app=e:\uo fl\client.exe | 
"{F7FCF15F-079D-4861-8A6C-A60A4137A314}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{F9842304-E081-48F7-9659-A0B145C48E1F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{F9B34F76-BD92-4142-894C-0EA76C58BEF5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | 
"{FC3AE8DA-2F27-4E98-B418-A24863B5F313}" = protocol=17 | dir=in | app=c:\program files\raptr\raptr_im.exe | 
"{FD918D6C-9867-471F-A87A-2D03C0601321}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | 
"{FD9FCF52-0502-4DE5-901A-CF09DC583AC9}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | 
"TCP Query User{0E567B0E-B3AD-4533-9E32-6E7D4BABBA11}C:\program files\raptr\raptr.exe" = protocol=6 | dir=in | app=c:\program files\raptr\raptr.exe | 
"TCP Query User{352BFF5B-EEA2-4F83-8B7E-7076B645797A}C:\users\teddy\appdata\local\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\users\teddy\appdata\local\google\chrome\application\chrome.exe | 
"TCP Query User{355B8229-155A-43E7-BE89-00DC3D664F2D}C:\skariatain\client_5.0.4b.exe" = protocol=6 | dir=in | app=c:\skariatain\client_5.0.4b.exe | 
"TCP Query User{35B118EB-A398-4E55-A252-233B29153897}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | 
"TCP Query User{38802DE5-A196-4086-B816-08FF631EB735}C:\alathair\uo.exe" = protocol=6 | dir=in | app=c:\alathair\uo.exe | 
"TCP Query User{3F614959-E8E9-4B2C-A86F-0048FE09B118}C:\spiele\uo\alathair spielserver\client.exe" = protocol=6 | dir=in | app=c:\spiele\uo\alathair spielserver\client.exe | 
"TCP Query User{40CCBEA8-7D5F-4769-BC58-A96B7F66BC09}C:\alathair\client.exe" = protocol=6 | dir=in | app=c:\alathair\client.exe | 
"TCP Query User{4B7FE0C6-F671-4B62-B22B-6AA4011A741A}C:\program files\common files\pplivenetwork\ppap.exe" = protocol=6 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe | 
"TCP Query User{50687EB0-6815-4064-8CCF-CDDF44830D65}C:\users\teddy\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\teddy\program files\dna\btdna.exe | 
"TCP Query User{52973A3E-01FC-4F5E-8767-20424E0DFA1C}E:\pro7\dc universe online live\unreal3\binaries\win32\dcgame.exe" = protocol=6 | dir=in | app=e:\pro7\dc universe online live\unreal3\binaries\win32\dcgame.exe | 
"TCP Query User{5612DD04-DB43-4501-9609-DB65F44E8A65}C:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_slim_eu.exe" = protocol=6 | dir=in | app=c:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_slim_eu.exe | 
"TCP Query User{5A74951A-0B6C-422C-886D-E3FE7A4C4EFD}H:\client.exe" = protocol=6 | dir=in | app=h:\client.exe | 
"TCP Query User{5C452A7E-0DC4-4A76-9039-551B7C05B1D9}E:\uo fl\client.exe" = protocol=6 | dir=in | app=e:\uo fl\client.exe | 
"TCP Query User{692C54E5-918D-4B2B-8552-23F301982990}C:\spiele\uo\alathair spielserver\uo.exe" = protocol=6 | dir=in | app=c:\spiele\uo\alathair spielserver\uo.exe | 
"TCP Query User{6DF8B29D-1398-4A54-AE73-FE8D9D339166}C:\users\teddy\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\teddy\appdata\local\akamai\netsession_win.exe | 
"TCP Query User{700310F3-B805-488A-B072-C8ACE09D8E3B}C:\spiele\uo\ultima online\client.exe" = protocol=6 | dir=in | app=c:\spiele\uo\ultima online\client.exe | 
"TCP Query User{72C8768A-7BC5-4908-81DC-A3A400F22394}C:\spiele\der herr der ringe online\lotroclient.exe" = protocol=6 | dir=in | app=c:\spiele\der herr der ringe online\lotroclient.exe | 
"TCP Query User{762488D3-B862-4C91-94AC-4595C2A171A4}C:\ultima online mondain's legacy\uo.exe" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\uo.exe | 
"TCP Query User{790C3487-610E-438B-9395-5988B497FF0B}C:\ultima online mondain's legacy\client.exe" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\client.exe | 
"TCP Query User{7C71D07D-CC73-407A-BB27-B5B00270D44F}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe | 
"TCP Query User{7F8E7AEE-D808-44DF-8A77-2D5A62606458}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe | 
"TCP Query User{93FCE622-545B-4296-927B-A7E57E2457B3}C:\program files\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe | 
"TCP Query User{98F065E6-F916-4B3F-88E3-3D967E9EE467}C:\program files\icq7.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | 
"TCP Query User{A223E131-BFD8-4A21-A5D0-C85F5B6D8803}C:\users\public\games\cryptic studios\star trek online\live\gameclient.exe" = protocol=6 | dir=in | app=c:\users\public\games\cryptic studios\star trek online\live\gameclient.exe | 
"TCP Query User{A82B76F6-74DE-473E-862E-53DBFEAE4D16}C:\spiele\uo\alathair spielserver\uopatch.exe" = protocol=6 | dir=in | app=c:\spiele\uo\alathair spielserver\uopatch.exe | 
"TCP Query User{B346CD32-F7E7-4BBC-B5B4-F01753025B5C}C:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_full_eu_new.exe" = protocol=6 | dir=in | app=c:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_full_eu_new.exe | 
"TCP Query User{C4D38104-8650-4718-8558-EF3EA2369226}C:\spiele\uo\alathair spielserver\alathair\rsync.exe" = protocol=6 | dir=in | app=c:\spiele\uo\alathair spielserver\alathair\rsync.exe | 
"TCP Query User{C6B25E27-E003-4428-95FB-3785CE6BBCF5}C:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire\xfire.exe | 
"TCP Query User{CA43737F-A488-44DD-A47F-0E80404E2EBE}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe | 
"TCP Query User{CE8A6F57-8EC5-494E-9E19-A54322B7656A}C:\alathair\rsync.exe" = protocol=6 | dir=in | app=c:\alathair\rsync.exe | 
"TCP Query User{E7931745-2400-4953-80B3-B50C510FEA16}C:\program files\tmunitedforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmunitedforever\tmforever.exe | 
"TCP Query User{EBA1A418-C121-4318-9538-A030246F9F54}C:\program files\runes of magic\client.exe" = protocol=6 | dir=in | app=c:\program files\runes of magic\client.exe | 
"TCP Query User{F17BAF6F-E15B-4B3D-8254-1BD33EE8FB0E}C:\users\teddy\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\teddy\program files\dna\btdna.exe | 
"TCP Query User{F774567D-CDE4-401A-93DC-71E5E55DCC80}C:\users\teddy\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\teddy\appdata\local\akamai\netsession_win.exe | 
"TCP Query User{F82110CF-F27D-47D2-8B3F-4614CE62F732}C:\ultima online mondain's legacy\alathair\rsync.exe" = protocol=6 | dir=in | app=c:\ultima online mondain's legacy\alathair\rsync.exe | 
"UDP Query User{05EF0E08-C2B1-46BA-A82B-45A901AC61D2}E:\pro7\dc universe online live\unreal3\binaries\win32\dcgame.exe" = protocol=17 | dir=in | app=e:\pro7\dc universe online live\unreal3\binaries\win32\dcgame.exe | 
"UDP Query User{0625D1DB-866B-4DCC-B9F1-4A6D9442ACB4}C:\alathair\uo.exe" = protocol=17 | dir=in | app=c:\alathair\uo.exe | 
"UDP Query User{1A19E6DC-D5BE-4F4C-BDAE-D9190B64EDD8}C:\program files\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire\xfire.exe | 
"UDP Query User{1B44EDC6-C610-4A59-B2AC-9FE3316BB22B}C:\users\teddy\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\teddy\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{2C1C555A-4742-4127-B8D3-2744252112BE}C:\program files\common files\pplivenetwork\ppap.exe" = protocol=17 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe | 
"UDP Query User{2E7A1319-3713-4F26-A0E5-CF782083D99F}E:\uo fl\client.exe" = protocol=17 | dir=in | app=e:\uo fl\client.exe | 
"UDP Query User{2F543649-A8E4-430D-9046-92B5AC8C493A}C:\skariatain\client_5.0.4b.exe" = protocol=17 | dir=in | app=c:\skariatain\client_5.0.4b.exe | 
"UDP Query User{375607A4-9817-46FC-A25D-BC2642FE2F80}C:\users\teddy\appdata\local\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\users\teddy\appdata\local\google\chrome\application\chrome.exe | 
"UDP Query User{3D8A6A01-F736-4A0A-87C1-C3183D7B10CB}C:\alathair\rsync.exe" = protocol=17 | dir=in | app=c:\alathair\rsync.exe | 
"UDP Query User{45A080B0-2EC8-4457-BC09-3458C4C43B2E}C:\alathair\client.exe" = protocol=17 | dir=in | app=c:\alathair\client.exe | 
"UDP Query User{46D6431F-D750-4296-AF11-44F719EE1D3A}C:\spiele\uo\alathair spielserver\uopatch.exe" = protocol=17 | dir=in | app=c:\spiele\uo\alathair spielserver\uopatch.exe | 
"UDP Query User{4CEBF930-5189-4760-B621-5E4DD1888579}C:\users\teddy\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\teddy\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{4D802BAB-54BE-436C-97ED-4F43E59C00E0}C:\program files\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe | 
"UDP Query User{5723AA18-5D4F-4FF6-8BC3-203B6AC87203}C:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_full_eu_new.exe" = protocol=17 | dir=in | app=c:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_full_eu_new.exe | 
"UDP Query User{5CC30633-D87B-48E0-BBD2-F4D2BCCCA35E}C:\program files\icq7.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | 
"UDP Query User{613B514C-B52F-463A-816D-69C6914ACA69}C:\spiele\der herr der ringe online\lotroclient.exe" = protocol=17 | dir=in | app=c:\spiele\der herr der ringe online\lotroclient.exe | 
"UDP Query User{6720AC70-F825-4A43-96F8-6375EF166BE5}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe | 
"UDP Query User{6912B6FA-0F4C-4861-8EAE-80A5130F3F72}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | 
"UDP Query User{6C054855-29BC-4F6E-8332-6027685F40E6}H:\client.exe" = protocol=17 | dir=in | app=h:\client.exe | 
"UDP Query User{70B9E9A7-C87B-4B5A-9DA9-D8A1AB81548E}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe | 
"UDP Query User{7148C411-2C7F-4454-9465-D623A60D3338}C:\spiele\uo\alathair spielserver\client.exe" = protocol=17 | dir=in | app=c:\spiele\uo\alathair spielserver\client.exe | 
"UDP Query User{7D0C9FF1-FACB-441E-B6AE-937F29B11200}C:\ultima online mondain's legacy\client.exe" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\client.exe | 
"UDP Query User{84102653-0AE3-4EF4-A61A-24C0B36D9F82}C:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_slim_eu.exe" = protocol=17 | dir=in | app=c:\users\teddy\downloads\yuleech-runes_of_magic_4_0_0_2360_slim_eu.exe | 
"UDP Query User{84DB0956-F317-4D9E-8815-12CC2DCBC591}C:\ultima online mondain's legacy\alathair\rsync.exe" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\alathair\rsync.exe | 
"UDP Query User{8BC704C1-6A1D-410B-8427-E46D81746141}C:\users\public\games\cryptic studios\star trek online\live\gameclient.exe" = protocol=17 | dir=in | app=c:\users\public\games\cryptic studios\star trek online\live\gameclient.exe | 
"UDP Query User{911375C9-E7D8-439F-A134-AA755A7C0A87}C:\spiele\uo\ultima online\client.exe" = protocol=17 | dir=in | app=c:\spiele\uo\ultima online\client.exe | 
"UDP Query User{921E9140-06FD-4AB8-829C-0F4A970D0693}C:\spiele\uo\alathair spielserver\alathair\rsync.exe" = protocol=17 | dir=in | app=c:\spiele\uo\alathair spielserver\alathair\rsync.exe | 
"UDP Query User{97A18327-4DAB-4DD5-A747-A2ABC5A63334}C:\ultima online mondain's legacy\uo.exe" = protocol=17 | dir=in | app=c:\ultima online mondain's legacy\uo.exe | 
"UDP Query User{A2EF2046-E6BC-422A-93F9-B3B3CB289575}C:\program files\raptr\raptr.exe" = protocol=17 | dir=in | app=c:\program files\raptr\raptr.exe | 
"UDP Query User{CB681107-FAB4-4FD3-9FD9-0C12655EECCC}C:\spiele\uo\alathair spielserver\uo.exe" = protocol=17 | dir=in | app=c:\spiele\uo\alathair spielserver\uo.exe | 
"UDP Query User{E4902184-291A-4114-B524-8B0A88F451FD}C:\users\teddy\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\teddy\program files\dna\btdna.exe | 
"UDP Query User{EC4AC65F-99AB-4168-A453-9118A32EE6C0}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe | 
"UDP Query User{ED2A0A8C-3289-4C96-A6F9-5A7651AA7BC0}C:\program files\runes of magic\client.exe" = protocol=17 | dir=in | app=c:\program files\runes of magic\client.exe | 
"UDP Query User{EF92AE53-AC7B-4E09-83E1-275B77F980B0}C:\program files\tmunitedforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmunitedforever\tmforever.exe | 
"UDP Query User{F43ED939-7BAB-4177-9868-514009DFD01B}C:\users\teddy\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\teddy\program files\dna\btdna.exe | 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation(R)Store
"{0F25F02B-854E-49B3-8F68-6D27CE4D477E}" = Ultima Online 2D Client
"{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode
"{14DC74E9-F248-47DF-B43F-9C6633F7438D}" = Holiday World
"{14FE48DA-E172-4CC5-B397-92ECA4B0E088}" = STOnline
"{167A1F6A-9BF2-4B24-83DB-C6D659F680EA}" = Media Go
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 29
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
"{27018D57-D152-44EF-BCE0-5E3B3445EABE}" = X-Blades
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{28CBE511-A28E-4010-BE83-1623FC3F1D3A}" = RUNAWAY - A road adventure
"{2ABCB142-9439-4FB5-A957-3D6C72D20C0C}" = Luvinia
"{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}" = Free Ride Games Player
"{2BE97610-5E4E-434F-9E84-01B0AB49EC92}" = Gilbert Goodmate
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{36F4AF22-A159-4E0F-AABE-67638D2B939D}" = Super Webcam
"{37491A3D-B2A6-402D-898E-5C4EF3984C29}" = Adobe Flash Media Live Encoder 3.1
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = Die Sims™ 3 Late Night
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B2B78EC-5111-4C0E-A955-0D84BBA49740}" = Animation Shop 3 Try And Buy
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{556F2137-B772-43BB-9A45-E0275234DD16}" = Free Notes & Office Ink
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5F624839-947D-46EA-BD63-FD847C1AC6F1}" = BearShare
"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = NCsoft Launcher
"{65761BAE-11E8-48FE-B30F-1F01011AB906}" = Die Sims™ 3 "Erstelle eine Welt"-Tool - Beta
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C26A305-4549-4A8A-9F03-25719C03B0FB}" = FreeRide Games
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = Die Sims™ 3 Luxus-Accessoires
"{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{7FA856CB-5544-449D-84C5-07A18CD51467}" = Loong
"{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}" = Rosetta Stone Version 3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie
"{8537166B-40F4-4FAE-BAC5-454A4DD773B7}" = Power Presenter RE II
"{8B92D97D-DB3D-4926-A8F7-718FE7C5EE18}" = iTunes
"{8CFA9151-6404-409A-AF22-4632D04582FD}" = Assassin's Creed
"{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = Die Sims™ 3 Traumkarrieren
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-00AF-0407-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{99A37AC7-E724-4621-B167-500B5A52B69C}" = LastChaosGER
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1C659AF-C761-47A8-BAFD-5FD2BE1ED419}" = Wildlife Park 2
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.0213
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.8.15
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B3D74F2B-82A3-4A94-90C4-2037CC590350}" = DBO_CT_TW
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation(R)Network Downloader
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = Die Sims™ 3 Reiseabenteuer
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die Sims™ 3
"{C12631C6-804D-4B32-B0DD-8A496462F106}" = Die Sims™ 3 Einfach tierisch
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240CC}" = WinZip 16.0
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{DF7B213D-2065-41ED-BB51-7A3EED31EA7B}" = Ultima Online: Mondain's Legacy
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E820F6CD-75FD-4DCA-A293-A76F4D2C56EC}" = Luvinia
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony PC Companion 2.10.094
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"4f6dcc3b-179d-4b1b-80f0-b6083a0b3ce6_is1" = DER HERR DER RINGE ONLINE: Die Minen Von Moria v02.01.03.4020
"827bc50d929d3142db3db7d83e32ee38" = Farm Frenzy - Viking Heroes
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AhnLab Online Security" = AhnLab Online Security
"Akamai" = Akamai NetSession Interface Service
"AstrumNival Allods" = Allods Online
"At the Cutting Edge_is1" = At the Cutting Edge
"Atlantica_GER" = Atlantica_GER
"Avira AntiVir Desktop" = Avira Free Antivirus
"BearShare" = BearShare
"CCleaner" = CCleaner
"Die Verlassenen Inseln" = Die Verlassenen Inseln
"ESET Online Scanner" = ESET Online Scanner v3
"exent_466552" = The Treasures of Montezuma
"Fiesta Online(EU_German)" = Fiesta Online(EU_German) 1.04.000
"Free Download Manager_is1" = Free Download Manager 3.9
"Guild Wars" = GUILD WARS
"Haushaltsbuch_is1" = Haushaltsbuch 1.1.0
"Kanji Gold_is1" = Kanji Gold 2.10
"KaraKEYoke Karaoke 3_is1" = KaraKEYoke Karaoke 3.2.3
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.8.0 (Basic)
"LingoPad_is1" = LingoPad 2.6 (Build 360)
"MabinogiEU" = MabinogiEU
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 12.0 (x86 de)" = Mozilla Firefox 12.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Neffy" = Neffy 1,3,29,0
"NSS" = Norton Security Scan
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"Opera 11.11.2109" = Opera 11.11
"Origin" = Origin
"PPLite" = PPLite
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"QuickTime" = QuickTime
"Raptr" = Raptr
"RE: Alistair++" = RE: Alistair++ 1
"RealPlayer 15.0" = RealPlayer
"Regnum Online" = Regnum Online 1.6.2
"Reise zum Zentrum des Mondes" = Reise zum Zentrum des Mondes
"RmTablet" = Tablet Driver With Macrokey Manager
"SiS163u" = 802.11 USB Wireless LAN Adapter
"Star Trek Online" = Star Trek Online
"Synthesia" = Synthesia (remove only)
"TeamViewer 5" = TeamViewer 5
"The I of the Dragon" = The I of the Dragon
"The Rosetta Stone" = The Rosetta Stone
"TmUnitedForever_is1" = TmUnitedForever Update 2010-03-15
"Update Engine" = Sony Ericsson Update Engine
"Wakan" = Wakan 1.67
"WiFiConnector" = Registrierungsprogramm für den Nintendo Wi-Fi USB Connector
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"Xfire" = Xfire (remove only)
"Youtube Saved" = Youtube Saved
"Zylom Games Player Plugin" = Zylom Games Player Plugin
========== HKEY_USERS Uninstall List ==========
"Akamai" = Akamai NetSession Interface
"Analog Clock" = Analog Clock
"BitTorrent DNA" = DNA
"Google Chrome" = Google Chrome
"IGG Web3D Player_is1" = IGG Web3D Player version
"IMVU Avatar chat client software BETA" = IMVU Avatar Chat Software
"PlanetWerks" = PlanetWerks
"SimAquarium" = SimAquarium
"SOE-DC Universe Online Live" = DC Universe Online Live
"SOE-DC Universe Online Live PSG" = DC Universe Online Live
"Uncompressor" = Uncompressor
"UnityWebPlayer" = Unity Web Player
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 20.02.2012 15:35:50 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\sony
 ericsson\sony ericsson pc companion\Drivers\DPInst64.exe".  Die abhängige Assemblierung
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
Error - 22.02.2012 15:36:23 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files\Common
 Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei
 "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3.
 im assemblyIdentity-Element ist ungültig.
Error - 22.02.2012 15:39:30 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\sony
 ericsson\sony ericsson pc companion\Drivers\DPInst64.exe".  Die abhängige Assemblierung
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
Error - 23.02.2012 10:09:29 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files\Common
 Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei
 "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3.
 im assemblyIdentity-Element ist ungültig.
Error - 23.02.2012 10:13:04 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\sony
 ericsson\sony ericsson pc companion\Drivers\DPInst64.exe".  Die abhängige Assemblierung
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
Error - 25.02.2012 08:26:44 | Computer Name = Teddy-PC | Source = Application Hang | ID = 1002
Description = Programm chrome.exe, Version kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: f48    Startzeit: 
01ccf3b65abadd8a    Endzeit: 10    Anwendungspfad: C:\Users\Teddy\AppData\Local\Google\Chrome\Application\chrome.exe

Error - 25.02.2012 14:44:45 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files\Common
 Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei
 "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3.
 im assemblyIdentity-Element ist ungültig.
Error - 25.02.2012 14:48:17 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\sony
 ericsson\sony ericsson pc companion\Drivers\DPInst64.exe".  Die abhängige Assemblierung
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
Error - 26.02.2012 07:48:47 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files\Common
 Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei
 "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3.
 im assemblyIdentity-Element ist ungültig.
Error - 26.02.2012 07:51:48 | Computer Name = Teddy-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\sony
 ericsson\sony ericsson pc companion\Drivers\DPInst64.exe".  Die abhängige Assemblierung
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
[ System Events ]
Error - 24.09.2012 16:45:41 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 24.09.2012 17:59:50 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 24.09.2012 17:59:50 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 24.09.2012 18:35:02 | Computer Name = Teddy-PC | Source = DCOM | ID = 10010
Description = 
Error - 25.09.2012 14:44:18 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 26.09.2012 04:11:41 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 27.09.2012 16:28:14 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 27.09.2012 16:28:23 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 28.09.2012 15:56:57 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 30.09.2012 03:32:33 | Computer Name = Teddy-PC | Source = ipnathlp | ID = 31004
Description = 
< End of report >

Rechner mit MyStart by IncrediBar infiziert.

Rechner mit MyStart by IncrediBar infiziert.

Ich hab doch extra drauf hingewiesen, dass du OTL vorher neu runterladen sollst - außerdem hast du nur das Extras-Log gepostet

Alt 01.10.2012, 22:10   #19
Rechner mit MyStart by IncrediBar infiziert.

Rechner mit MyStart by IncrediBar infiziert.

Ich hab es neu herunter geladen gehabt. Kannte das Programm vorher ja nicht mal. Hoffe ich hab diesmal den richtigen Log eingefügt.

OTL logfile created on: 01.10.2012 22:22:08 - Run 2
OTL by OldTimer - Version     Folder = C:\Users\Teddy\Desktop
 Professional  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,04 Gb Available Physical Memory | 67,90% Memory free
6,00 Gb Paging File | 4,74 Gb Available in Paging File | 79,09% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 307,62 Gb Total Space | 68,00 Gb Free Space | 22,11% Space Free | Partition Type: NTFS
Drive E: | 623,88 Gb Total Space | 535,91 Gb Free Space | 85,90% Space Free | Partition Type: NTFS
Computer Name: TEDDY-PC | User Name: Teddy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.09.26 23:47:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Teddy\Desktop\OTL.exe
PRC - [2012.08.10 18:59:52 | 004,440,896 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Teddy\AppData\Local\Akamai\netsession_win.exe
PRC - [2012.08.08 22:55:44 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.06.11 11:48:51 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Programme\Real\RealPlayer\Update\realsched.exe
PRC - [2012.05.31 15:00:22 | 000,445,624 | ---- | M] (Sony) -- C:\Programme\Sony\Sony PC Companion\PCCompanion.exe
PRC - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012.05.15 11:28:16 | 001,820,480 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe
PRC - [2012.05.15 11:27:34 | 000,857,920 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2012.05.15 05:21:28 | 000,461,176 | ---- | M] (PPLive Corporation) -- C:\Programme\Common Files\PPLiveNetwork\PPAP.exe
PRC - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.05.08 22:52:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.08 22:52:24 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.08 22:52:24 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.04.30 11:57:42 | 000,067,072 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe
PRC - [2012.04.29 09:31:36 | 004,901,744 | ---- | M] (Exent Technologies Ltd.) -- C:\Programme\FreeRide Games\GPlayer.exe
PRC - [2012.04.16 20:51:46 | 000,066,992 | ---- | M] (Raptr, Inc) -- C:\Programme\Raptr\raptr.exe
PRC - [2012.04.16 20:51:46 | 000,043,952 | ---- | M] (Raptr, Inc) -- C:\Programme\Raptr\raptr_im.exe
PRC - [2011.09.01 19:18:54 | 004,862,384 | ---- | M] (Exent Technologies Ltd.) -- C:\Programme\Free Ride Games\GPlayer.exe
PRC - [2011.07.16 06:31:12 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.06.17 19:33:04 | 000,272,528 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee Security Scan\3.0.207\SSScheduler.exe
PRC - [2011.06.09 14:06:06 | 000,507,624 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Common Files\Java\Java Update\jucheck.exe
PRC - [2011.02.26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.01.26 08:45:58 | 000,870,120 | ---- | M] () -- C:\Windows\System32\atwtusb.exe
PRC - [2011.01.17 18:37:40 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe
PRC - [2011.01.17 18:37:40 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin
PRC - [2010.12.24 09:31:08 | 007,134,952 | ---- | M] () -- C:\Windows\System32\WTMKM.exe
PRC - [2010.05.13 21:55:53 | 000,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Users\Teddy\Program Files\DNA\btdna.exe
PRC - [2010.03.18 11:26:08 | 000,172,328 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version5\TeamViewer_Service.exe
PRC - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.07.14 03:14:42 | 000,181,760 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\TabTip.exe
PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.07.14 03:14:38 | 001,173,504 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.07.14 03:14:21 | 000,294,400 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\InputPersonalization.exe
========== Modules (No Company Name) ==========
MOD - [2012.05.24 11:50:32 | 000,203,776 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\MExplorer.dll
MOD - [2012.05.23 11:38:36 | 000,583,680 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PhoneUpdate.dll
MOD - [2012.05.15 05:21:14 | 000,522,600 | ---- | M] () -- C:\Programme\Common Files\PPLiveNetwork\\MngModule.dll
MOD - [2012.04.30 11:57:42 | 000,067,072 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe
MOD - [2012.04.30 11:57:42 | 000,039,936 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\TMonitorAPI.dll
MOD - [2012.03.25 13:51:43 | 000,985,088 | ---- | M] () -- C:\Programme\OpenOffice.org 3\program\libxml2.dll
MOD - [2012.02.20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012.02.20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2012.02.17 19:53:28 | 000,494,592 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtNetwork.pyd
MOD - [2012.02.17 19:53:24 | 001,661,952 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtCore.pyd
MOD - [2012.02.17 19:53:20 | 000,313,856 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtWebKit.pyd
MOD - [2012.02.17 19:53:06 | 005,809,664 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtGui.pyd
MOD - [2012.02.17 19:52:26 | 000,067,584 | ---- | M] () -- C:\Programme\Raptr\sip.pyd
MOD - [2011.11.21 04:20:46 | 001,949,696 | ---- | M] () -- C:\Programme\Raptr\libtorrent.pyd
MOD - [2011.10.24 20:49:56 | 002,717,595 | ---- | M] () -- C:\Programme\Raptr\heliotrope._purple.pyd
MOD - [2011.09.09 01:47:40 | 001,183,699 | ---- | M] () -- C:\Programme\Raptr\liboscar.dll
MOD - [2011.09.09 01:47:36 | 001,640,221 | ---- | M] () -- C:\Programme\Raptr\libjabber.dll
MOD - [2011.09.09 01:47:32 | 001,052,194 | ---- | M] () -- C:\Programme\Raptr\libymsg.dll
MOD - [2011.09.09 01:47:22 | 000,495,680 | ---- | M] () -- C:\Programme\Raptr\plugins\libaim.dll
MOD - [2011.09.09 01:47:22 | 000,483,306 | ---- | M] () -- C:\Programme\Raptr\plugins\libicq.dll
MOD - [2011.09.09 01:47:16 | 000,655,356 | ---- | M] () -- C:\Programme\Raptr\plugins\libirc.dll
MOD - [2011.09.09 01:47:16 | 000,603,326 | ---- | M] () -- C:\Programme\Raptr\plugins\ssl-nss.dll
MOD - [2011.09.09 01:47:14 | 000,497,782 | ---- | M] () -- C:\Programme\Raptr\plugins\libyahoojp.dll
MOD - [2011.09.09 01:47:14 | 000,474,199 | ---- | M] () -- C:\Programme\Raptr\plugins\ssl.dll
MOD - [2011.09.09 01:47:10 | 001,306,387 | ---- | M] () -- C:\Programme\Raptr\plugins\libmsn.dll
MOD - [2011.09.09 01:47:04 | 000,565,461 | ---- | M] () -- C:\Programme\Raptr\plugins\libxmpp.dll
MOD - [2011.09.09 01:46:56 | 000,506,276 | ---- | M] () -- C:\Programme\Raptr\plugins\libyahoo.dll
MOD - [2011.07.07 14:54:36 | 000,233,984 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\Report.dll
MOD - [2011.02.15 20:17:28 | 001,213,633 | ---- | M] () -- C:\Programme\Raptr\libxml2-2.dll
MOD - [2011.02.15 20:17:28 | 000,417,501 | ---- | M] () -- C:\Programme\Raptr\sqlite3.dll
MOD - [2010.12.24 09:31:08 | 007,134,952 | ---- | M] () -- C:\Windows\System32\WTMKM.exe
MOD - [2010.11.23 01:06:22 | 000,055,808 | ---- | M] () -- C:\Programme\Raptr\zlib1.dll
MOD - [2010.11.23 00:57:34 | 000,167,936 | ---- | M] () -- C:\Programme\Raptr\win32gui.pyd
MOD - [2010.11.23 00:57:34 | 000,111,104 | ---- | M] () -- C:\Programme\Raptr\win32file.pyd
MOD - [2010.11.23 00:57:34 | 000,096,256 | ---- | M] () -- C:\Programme\Raptr\win32api.pyd
MOD - [2010.11.23 00:57:34 | 000,036,352 | ---- | M] () -- C:\Programme\Raptr\win32process.pyd
MOD - [2010.11.23 00:57:18 | 000,141,312 | ---- | M] () -- C:\Programme\Raptr\gobject._gobject.pyd
MOD - [2010.11.23 00:57:06 | 000,263,168 | ---- | M] () -- C:\Programme\Raptr\win32com.shell.shell.pyd
MOD - [2010.11.23 00:56:56 | 000,354,304 | ---- | M] () -- C:\Programme\Raptr\pythoncom26.dll
MOD - [2010.11.23 00:56:56 | 000,110,592 | ---- | M] () -- C:\Programme\Raptr\pywintypes26.dll
MOD - [2010.11.23 00:56:26 | 000,324,608 | ---- | M] () -- C:\Programme\Raptr\PIL._imaging.pyd
MOD - [2010.11.23 00:56:02 | 000,805,376 | ---- | M] () -- C:\Programme\Raptr\_ssl.pyd
MOD - [2010.11.23 00:56:02 | 000,583,680 | ---- | M] () -- C:\Programme\Raptr\unicodedata.pyd
MOD - [2010.11.23 00:56:02 | 000,356,864 | ---- | M] () -- C:\Programme\Raptr\_hashlib.pyd
MOD - [2010.11.23 00:56:02 | 000,127,488 | ---- | M] () -- C:\Programme\Raptr\pyexpat.pyd
MOD - [2010.11.23 00:56:02 | 000,087,040 | ---- | M] () -- C:\Programme\Raptr\_ctypes.pyd
MOD - [2010.11.23 00:56:02 | 000,044,544 | ---- | M] () -- C:\Programme\Raptr\_sqlite3.pyd
MOD - [2010.11.23 00:56:02 | 000,043,008 | ---- | M] () -- C:\Programme\Raptr\_socket.pyd
MOD - [2010.11.23 00:56:02 | 000,009,216 | ---- | M] () -- C:\Programme\Raptr\winsound.pyd
MOD - [2010.01.11 16:44:54 | 000,053,248 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\VObject.dll
MOD - [2008.09.16 21:18:06 | 000,132,608 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
========== Services (SafeList) ==========
SRV - [2012.09.22 20:50:22 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.09.20 22:42:33 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.09.06 20:37:25 | 004,537,664 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_5891ae0.dll -- (Akamai)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.05.08 22:52:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.05.08 22:52:24 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.04.29 09:26:24 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012.01.18 14:38:28 | 000,155,320 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Programme\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
SRV - [2011.06.17 19:33:04 | 000,237,008 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Programme\McAfee Security Scan\3.0.207\McCHSvc.exe -- (McComponentHostService)
SRV - [2011.01.26 08:45:58 | 000,870,120 | ---- | M] () [Auto | Running] -- C:\Windows\System32\atwtusb.exe -- (WTService)
SRV - [2010.03.28 10:50:19 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010.03.18 11:26:08 | 000,172,328 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5)
SRV - [2009.12.16 19:26:00 | 003,453,712 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2009.07.14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva380.sys -- (XDva380)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (awfj5kor)
DRV - [2012.09.17 21:31:15 | 000,076,800 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\SSHDRV84.sys -- (SSHDRV84)
DRV - [2012.07.07 11:07:44 | 000,025,200 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2012.07.07 11:07:44 | 000,012,400 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt)
DRV - [2012.05.15 12:26:00 | 011,354,944 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012.05.12 17:59:30 | 000,013,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\apf003.sys -- (apf003)
DRV - [2012.05.08 22:52:24 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.08 22:52:24 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.12.15 16:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.11.22 10:25:22 | 000,046,184 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto | Running] -- C:\Programme\FreeRide Games\X6XSEx.sys -- (X6XSEx_Pr148)
DRV - [2010.11.22 09:25:22 | 000,046,184 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto | Running] -- C:\Programme\Free Ride Games\X6XSEx.sys -- (X6XSEx)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.05.23 13:25:15 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2009.09.23 03:19:31 | 000,294,912 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcvmm.sys -- (vpcvmm)
DRV - [2009.09.23 03:19:31 | 000,055,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV - [2009.09.23 03:18:08 | 000,078,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpcusb.sys -- (vpcusb)
DRV - [2009.09.23 03:18:07 | 000,165,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpchbus.sys -- (vpcbus)
DRV - [2009.08.20 12:38:24 | 000,006,144 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\walvhid.sys -- (vhidmini)
DRV - [2009.07.14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009.07.14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009.07.14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009.07.14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009.07.14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009.07.14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2009.03.08 13:15:14 | 000,006,144 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\moufiltr.sys -- (moufiltr)
DRV - [2009.01.19 20:31:56 | 000,277,544 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2007.07.03 15:05:00 | 000,162,944 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RT25USBAP.SYS -- (RT25USBAP)
DRV - [2006.06.27 09:56:50 | 000,031,872 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\superwebcam.sys -- (SUPERWEBCAM)
DRV - [2005.06.20 10:12:00 | 000,215,040 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\sis163u.sys -- (SIS163u)
DRV - [2005.02.26 09:25:52 | 000,091,527 | ---- | M] (VM) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbVM31b.sys -- (ZSMC301b)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://zynga.com/
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 78 5E 77 19 B3 CA 01  [binary data]
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {90b49673-5506-483e-b92b-ca0265bd9ca8} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =;<local>;*.local
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://search.bearshare.net"
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:
FF - prefs.js..extensions.enabledItems: {ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}:
FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:
FF - prefs.js..extensions.enabledItems: ocr@babylon.com:1.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@exent.com/npExentControl,version= C:\Program Files\FreeRide Games\npExentControl.dll (Exent Technologies Ltd.)
FF - HKLM\Software\MozillaPlugins\@exent.com/npExentCtl,version= C:\Program Files\Free Ride Games\npExentCtl.dll (Exent Technologies Ltd.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF - HKLM\Software\MozillaPlugins\@pptv.com/plugin: C:\Program Files\Internet Explorer\PPLite\plugin\\npplugin2.dll (PPLive Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version= c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version= c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version= C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version= C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version= c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@zylom.com/ZylomGamesPlayer: C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKCU\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Users\Teddy\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKCU\Software\MozillaPlugins\@g2.com/iggweb3dupdater: C:\Users\Teddy\AppData\Roaming\IGG\Web3D\\NPIGGWeb3DUpdater.dll (IGG)
FF - HKCU\Software\MozillaPlugins\@g2.com/joyconnectshell: C:\Users\Teddy\AppData\Roaming\IGG\Web3D\\NPJoyConnectShell.dll (IGG)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Teddy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.08.03 16:04:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.22 20:50:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.09.22 22:07:34 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}: C:\Users\Teddy\Program Files\DNA [2012.10.01 21:51:02 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}: C:\Users\Teddy\AppData\Roaming\5008 [2010.11.09 17:44:47 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Teddy\AppData\Roaming\IDM\idmmzcc5
[2012.03.25 13:37:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Teddy\AppData\Roaming\mozilla\Extensions
[2012.09.22 20:50:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions
[2011.08.04 17:38:17 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.03.25 13:37:02 | 000,000,000 | ---D | M] (Wincore Mediabar) -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}
[2012.09.22 00:21:33 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-1.xml
[2012.03.25 20:28:36 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-2.xml
[2012.09.22 00:11:34 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-3.xml
[2012.03.11 00:30:33 | 000,001,056 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin.xml
[2012.09.22 20:50:26 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.09.15 23:30:05 | 000,000,000 | ---D | M] (Babylon Translation Activation) -- C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com
[2012.09.22 20:50:22 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 06:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012.06.11 11:48:58 | 000,129,144 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2009.03.24 12:10:44 | 000,114,688 | ---- | M] (Zylom) -- C:\Program Files\mozilla firefox\plugins\npzylomgamesplayer.dll
[2012.09.22 20:50:20 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.22 20:50:20 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.09.22 20:50:20 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.09.22 20:50:20 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.09.22 20:50:20 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.09.22 20:50:20 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome  ==========
CHR - default_search_provider: Ecosia (Enabled)
CHR - default_search_provider: search_url = hxxp://ecosia.org/search.php?q={searchTerms}&addon=opensearch
CHR - default_search_provider: suggest_url = hxxp://ecosia.org/ajax/searchsuggestions.php?q={searchTerms}&addon=opensearch
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Teddy\AppData\Local\Google\Chrome\Application\12.0.742.100\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Java Deployment Toolkit (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Chrome NaCl (Disabled) = C:\Users\Teddy\AppData\Local\Google\Chrome\Application\12.0.742.100\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Teddy\AppData\Local\Google\Chrome\Application\12.0.742.100\pdf.dll
CHR - plugin: Perion plugin (Enabled) = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Zylom Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
CHR - plugin: AhnLab MyKeyDefense 2.5 (Enabled) = C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll
CHR - plugin: Exent\u00AE AOD Gecko Plugin (Enabled) = C:\Program Files\Free Ride Games\npExentCtl.dll
CHR - plugin: Exent\u00AE AOD Gecko Plugin (Enabled) = C:\Program Files\FreeRide Games\npExentControl.dll
CHR - plugin: PPLive PPTV Plugin (Enabled) = C:\Program Files\Internet Explorer\PPLite\plugin\\npplugin2.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Media Go Detector (Enabled) = C:\Program Files\Sony\Media Go\npmediago.dll
CHR - plugin: PlayStation(R)Network Downloader Check Plug-in (Enabled) = C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Teddy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: IGG Web3D Updater NP Plugin for Mozilla (Enabled) = C:\Users\Teddy\AppData\Roaming\IGG\Web3D\\NPIGGWeb3DUpdater.dll
CHR - plugin: JoyConnect NP Plugin for Mozilla (Enabled) = C:\Users\Teddy\AppData\Roaming\IGG\Web3D\\NPJoyConnectShell.dll
CHR - plugin: DNA Plug-in (Enabled) = C:\Users\Teddy\Program Files\DNA\plugins\npbtdna.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: New tab for Chrome\u2122 = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\
CHR - Extension: Click to activate/deactivate ProxTube = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkdbaehcjcomcnnjhlmnfddpgoafpcko\1.0.6_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: New tab for Chrome\u2122 = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\
CHR - Extension: Click to activate/deactivate ProxTube = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkdbaehcjcomcnnjhlmnfddpgoafpcko\1.0.6_0\
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (DataMngr) - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Programme\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll (MusicLab, LLC)
O2 - BHO: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programme\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No CLSID value found.
O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found.
O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {90B49673-5506-483E-B92B-CA0265BD9CA8} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [MacrokeyManager] C:\Windows\System32\WTMKM.exe ()
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\.DEFAULT..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-18..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-19..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-20..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Akamai NetSession Interface] C:\Users\Teddy\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [BitTorrent DNA] C:\Users\Teddy\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Exetender_148] C:\Program Files\FreeRide Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [PlayNC Launcher]  File not found
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [PPAP] C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe (PPLive Corporation)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Raptr] C:\Programme\Raptr\raptrstub.exe (Raptr, Inc)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Sony PC Companion] C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Sony)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Web-Suche - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: sony.com ([]* in )
O16 - DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095}  (ExentInf1 Class)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}  (ExentInf Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{14B43710-DFCA-4ADB-8A04-DFA39535C9DF}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1537B177-72F8-4837-A69C-4491A1A46E4D}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B1D98BB-9065-4F58-B709-0608A62BE7C8}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{769B5C26-4B44-47FB-B41A-27AC47E2AB05}: DhcpNameServer =
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Programme\Common Files\microsoft shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell - "" = AutoRun
O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell\AutoRun\command - "" = H:\Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare Software.lnk -  - File not found
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Registrierungsprogramm ausführen.lnk - C:\Programme\WiFiConnector\NintendoWFCReg.exe - ()
MsConfig - StartUpFolder: C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk - C:\Programme\OpenOffice.org 3\program\quickstart.exe - ()
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= -  File not found
MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
MsConfig - StartUpReg: TkBellExe - hkey= - key= - c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
MsConfig - State: "startup" - 0
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D} - Microsoft .NET Framework 1.1 Security Update (KB953297)
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012.09.26 23:47:27 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Teddy\Desktop\OTL.exe
[2012.09.22 22:49:29 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.09.22 22:40:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
[2012.09.22 22:09:47 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee Security Scan
[2012.09.22 22:09:42 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan
[2012.09.22 22:09:42 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2012.09.22 20:50:26 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012.09.22 20:50:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.09.22 14:46:51 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012.09.22 09:25:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2012.09.21 23:52:20 | 000,000,000 | ---D | C] -- C:\Users\Teddy\AppData\Roaming\Malwarebytes
[2012.09.21 23:52:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.21 23:52:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.21 23:52:05 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.21 23:52:05 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.09.21 23:47:14 | 000,000,000 | ---D | C] -- C:\Users\Teddy\Start Menu
[2012.09.21 13:56:14 | 000,000,000 | ---D | C] -- C:\Program Files\Perion
[2012.09.17 21:26:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gathering
[2012.09.16 14:10:02 | 000,000,000 | ---D | C] -- C:\Users\Teddy\Desktop\Neuer Ordner
[2012.09.15 22:56:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SWF Studio
[2012.09.15 22:55:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prelusion
[2012.09.06 21:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cornelsen
[2012.09.06 21:48:24 | 000,000,000 | ---D | C] -- C:\Program Files\Cornelsen
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Teddy\AppData\Roaming\*.tmp files -> C:\Users\Teddy\AppData\Roaming\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.10.01 21:58:36 | 000,020,720 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.01 21:58:36 | 000,020,720 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.01 21:51:24 | 000,000,376 | ---- | M] () -- C:\Windows\tasks\RNUpgradeHelperLogonPrompt_Teddy.job
[2012.10.01 21:50:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.01 21:50:40 | 2415,255,552 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.01 14:42:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.01 12:28:17 | 000,164,648 | ---- | M] () -- C:\Users\Teddy\Desktop\buntesleben.jpg
[2012.10.01 00:12:02 | 000,000,366 | ---- | M] () -- C:\Windows\tasks\ReclaimerUpdateXML_Teddy.job
[2012.09.30 23:12:03 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\ReclaimerUpdateFiles_Teddy.job
[2012.09.26 23:47:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Teddy\Desktop\OTL.exe
[2012.09.24 15:26:33 | 000,513,501 | ---- | M] () -- C:\Users\Teddy\Desktop\adwcleaner.exe
[2012.09.23 10:27:49 | 000,000,436 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Teddy.job
[2012.09.22 22:40:55 | 000,002,040 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2012.09.22 22:40:55 | 000,002,040 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2012.09.22 22:07:34 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012.09.22 11:38:23 | 000,000,298 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2012.09.21 23:52:07 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.09.21 22:57:03 | 000,003,405 | ---- | M] () -- C:\Users\Teddy\.recently-used.xbel
[2012.09.17 21:31:15 | 000,076,800 | ---- | M] () -- C:\Windows\System32\drivers\SSHDRV84.sys
[2012.09.17 21:30:33 | 000,000,000 | ---- | M] () -- C:\Users\Public\Documents\PCD549.L!C
[2012.09.17 21:26:18 | 000,000,616 | ---- | M] () -- C:\Users\Public\Desktop\Holiday World.lnk
[2012.09.15 22:55:51 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Gilbert Goodmate.lnk
[2012.09.07 20:55:14 | 000,315,280 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.06 21:49:47 | 000,001,101 | ---- | M] () -- C:\Users\Public\Desktop\At the Cutting Edge.lnk
[2012.09.04 23:55:56 | 000,666,270 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.09.04 23:55:56 | 000,625,116 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.09.04 23:55:56 | 000,135,198 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.09.04 23:55:56 | 000,110,754 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Teddy\AppData\Roaming\*.tmp files -> C:\Users\Teddy\AppData\Roaming\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.10.01 12:28:28 | 000,164,648 | ---- | C] () -- C:\Users\Teddy\Desktop\buntesleben.jpg
[2012.09.27 00:10:02 | 000,000,376 | ---- | C] () -- C:\Windows\tasks\RNUpgradeHelperLogonPrompt_Teddy.job
[2012.09.27 00:10:01 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\ReclaimerUpdateFiles_Teddy.job
[2012.09.27 00:10:00 | 000,000,366 | ---- | C] () -- C:\Windows\tasks\ReclaimerUpdateXML_Teddy.job
[2012.09.26 12:50:47 | 000,602,972 | ---- | C] () -- C:\Users\Teddy\Desktop\DSC_0151.JPG
[2012.09.24 15:26:32 | 000,513,501 | ---- | C] () -- C:\Users\Teddy\Desktop\adwcleaner.exe
[2012.09.22 22:09:42 | 000,002,040 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2012.09.22 22:09:42 | 000,002,040 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2012.09.22 22:07:34 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012.09.22 22:07:34 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012.09.22 20:50:24 | 000,001,100 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.09.22 11:11:09 | 000,000,298 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2012.09.21 23:52:07 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.09.21 22:57:03 | 000,003,405 | ---- | C] () -- C:\Users\Teddy\.recently-used.xbel
[2012.09.17 21:31:15 | 000,076,800 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV84.sys
[2012.09.17 21:30:33 | 000,000,000 | ---- | C] () -- C:\Users\Public\Documents\PCD549.L!C
[2012.09.17 21:26:18 | 000,000,616 | ---- | C] () -- C:\Users\Public\Desktop\Holiday World.lnk
[2012.09.15 22:55:51 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Gilbert Goodmate.lnk
[2012.09.06 21:49:47 | 000,001,101 | ---- | C] () -- C:\Users\Public\Desktop\At the Cutting Edge.lnk
[2012.08.22 22:48:13 | 000,000,232 | ---- | C] () -- C:\Users\Teddy\.KanjiGymLight
[2012.08.13 17:53:37 | 000,000,059 | ---- | C] () -- C:\Windows\RUNAWAY.INI
[2012.05.18 17:40:39 | 000,010,525 | ---- | C] () -- C:\Windows\System32\Default_3.ini
[2012.05.18 17:40:39 | 000,010,283 | ---- | C] () -- C:\Windows\System32\Default_2.ini
[2012.05.18 17:40:39 | 000,009,917 | ---- | C] () -- C:\Windows\System32\Default_1.ini
[2012.05.18 17:40:39 | 000,000,738 | ---- | C] () -- C:\Windows\System32\MKProfile.ini
[2012.05.18 17:40:36 | 000,000,105 | R--- | C] () -- C:\ProgramData\Ppster.ini
[2012.05.18 17:40:30 | 000,870,120 | ---- | C] () -- C:\Windows\System32\atwtusb.exe
[2012.05.18 17:40:28 | 007,134,952 | ---- | C] () -- C:\Windows\System32\WTMKM.exe
[2012.05.18 17:40:23 | 000,045,056 | ---- | C] () -- C:\Windows\System32\InstallService.exe
[2012.05.18 17:40:22 | 003,683,560 | ---- | C] () -- C:\Windows\System32\Control Panel_Betteryless.exe
[2012.05.18 17:40:20 | 000,148,200 | ---- | C] () -- C:\Windows\System32\Calibration.exe
[2012.05.18 17:40:12 | 000,835,072 | ---- | C] () -- C:\Windows\RmTablet.exe
[2012.05.18 17:40:11 | 000,010,708 | ---- | C] () -- C:\Windows\System32\aiptbl.ini
[2012.05.15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
[2012.05.12 17:59:30 | 000,016,304 | ---- | C] () -- C:\Windows\System32\apl003.sys
[2012.05.12 17:59:30 | 000,013,232 | ---- | C] () -- C:\Windows\System32\apf003.sys
[2012.04.16 23:36:22 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2012.04.14 22:56:32 | 000,000,000 | ---- | C] () -- C:\Users\Teddy\__ng3d.lock
[2012.03.25 12:13:13 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2012.03.04 01:19:48 | 000,000,410 | ---- | C] () -- C:\Windows\{27018D57-D152-44EF-BCE0-5E3B3445EABE}_WiseFW.ini
[2011.12.23 03:43:56 | 000,230,752 | ---- | C] () -- C:\Windows\patchw32.dll
[2011.12.23 03:43:56 | 000,118,176 | ---- | C] () -- C:\Windows\patchw.dll
[2010.11.17 17:57:56 | 000,006,936 | ---- | C] () -- C:\Windows\Go Screensaver.ini
[2010.09.15 21:26:32 | 000,000,148 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\urhtps.dat
[2010.05.28 15:06:46 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_3
[2010.05.28 00:08:52 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_1
[2010.05.28 00:06:06 | 000,000,169 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\D2Info0
[2010.05.28 00:06:06 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_2
[2010.04.18 18:08:31 | 000,032,256 | ---- | C] () -- C:\Users\Teddy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.02.21 20:31:04 | 000,000,093 | ---- | C] () -- C:\Users\Teddy\AppData\Local\fusioncache.dat
========== ZeroAccess Check ==========
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
"" = %SystemRoot%\system32\shell32.dll -- [2010.07.27 16:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011.10.16 18:35:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\.minecraft
[2010.09.15 01:00:21 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5005
[2010.10.04 18:09:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5006
[2010.11.09 17:44:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5008
[2010.03.08 21:06:30 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Anabel
[2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\app
[2012.08.03 16:04:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Azureus
[2012.03.25 22:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Cat's Eye Games
[2010.09.15 01:00:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\cock
[2012.05.04 23:05:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DAEMON Tools Lite
[2010.03.08 22:51:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dekovir
[2011.08.10 22:18:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DMCache
[2012.10.01 22:51:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DNA
[2010.05.28 23:56:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus 2
[2010.05.28 00:06:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010.05.28 15:06:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010.05.28 00:08:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2012.09.22 14:47:14 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoft
[2012.07.09 13:22:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.04.28 23:46:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EnchantedCavern
[2010.03.09 06:52:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EscapeTheMuseum2
[2012.03.25 16:46:15 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Exent Technologies
[2012.03.25 23:36:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Finstere Liebschaft
[2011.01.04 17:40:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\FOG Downloader
[2012.09.24 15:26:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Free Download Manager
[2012.04.05 00:38:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Friday's games
[2012.04.28 22:10:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gamers Digital
[2010.03.08 19:35:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Games
[2012.04.17 00:12:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\GetRightToGo
[2010.03.08 21:42:43 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gogii
[2012.09.08 13:21:19 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\gtk-2.0
[2011.08.07 18:08:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Haushaltsbuch
[2012.03.25 00:45:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ICQ
[2012.04.05 21:08:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IGG
[2011.12.26 14:48:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVU
[2011.12.14 22:23:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVUClient
[2012.07.08 01:14:28 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Jasc
[2012.05.12 17:07:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\KlLauncherST
[2011.11.05 23:06:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Lingo4u
[2011.11.16 00:26:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\LolClient
[2012.03.25 13:36:37 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\MusicNet
[2010.05.28 19:36:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\OpenOffice.org
[2010.06.11 23:59:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Opera
[2011.10.22 16:51:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Origin
[2012.04.09 01:13:44 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayFirst
[2011.06.30 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayPond
[2010.03.07 01:16:25 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Playrix Entertainment
[2010.03.08 21:23:32 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PoBros
[2012.08.08 13:54:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PPlive
[2010.03.09 05:48:03 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Princess Isabella
[2010.04.01 01:41:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ProtectDisc
[2012.10.01 21:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Raptr
[2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2012.04.14 16:06:17 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RenPy
[2010.03.28 15:47:09 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RobinsonCrusoe
[2012.01.10 23:36:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Sony
[2012.07.30 13:39:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Synthesia
[2011.10.16 18:32:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TeamViewer
[2010.03.08 18:55:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TitanicMystery
[2008.06.27 00:59:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TuneUp Software
[2010.02.22 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Turbine
[2010.09.16 13:25:07 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\UAs
[2010.05.25 01:37:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Ubisoft
[2011.07.07 16:58:36 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Unity
[2010.03.08 07:46:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Virtual City
[2010.09.16 13:25:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\xmldm
========== Purity Check ==========
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2011.10.16 18:35:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\.minecraft
[2010.09.15 01:00:21 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5005
[2010.10.04 18:09:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5006
[2010.11.09 17:44:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5008
[2012.09.23 11:30:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Adobe
[2010.03.08 21:06:30 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Anabel
[2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\app
[2012.03.28 22:37:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Apple Computer
[2012.02.14 22:09:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Avira
[2012.08.03 16:04:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Azureus
[2012.03.25 22:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Cat's Eye Games
[2010.09.15 01:00:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\cock
[2012.05.04 23:05:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DAEMON Tools Lite
[2010.03.08 22:51:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dekovir
[2011.08.10 22:18:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DMCache
[2012.10.01 22:51:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DNA
[2010.05.28 23:56:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus 2
[2010.05.28 00:06:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010.05.28 15:06:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010.05.28 00:08:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2012.09.22 14:47:14 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoft
[2012.07.09 13:22:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.04.28 23:46:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EnchantedCavern
[2010.03.09 06:52:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EscapeTheMuseum2
[2012.03.25 16:46:15 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Exent Technologies
[2012.03.25 23:36:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Finstere Liebschaft
[2011.01.04 17:40:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\FOG Downloader
[2012.09.24 15:26:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Free Download Manager
[2012.04.05 00:38:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Friday's games
[2012.04.28 22:10:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gamers Digital
[2010.03.08 19:35:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Games
[2012.04.17 00:12:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\GetRightToGo
[2010.03.08 21:42:43 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gogii
[2012.09.08 13:21:19 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\gtk-2.0
[2011.08.07 18:08:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Haushaltsbuch
[2012.03.25 00:45:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ICQ
[2010.02.21 18:51:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Identities
[2012.04.05 21:08:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IGG
[2011.12.26 14:48:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVU
[2011.12.14 22:23:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVUClient
[2010.03.09 20:56:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\InstallShield
[2012.07.08 01:14:28 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Jasc
[2012.05.12 17:07:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\KlLauncherST
[2011.11.05 23:06:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Lingo4u
[2011.11.16 00:26:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\LolClient
[2010.02.21 20:31:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Macromedia
[2012.09.21 23:52:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Malwarebytes
[2009.07.14 10:56:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Media Center Programs
[2012.08.18 20:31:05 | 000,000,000 | --SD | M] -- C:\Users\Teddy\AppData\Roaming\Microsoft
[2010.09.15 21:23:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Mozilla
[2012.03.25 13:36:37 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\MusicNet
[2012.06.18 15:22:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\NVIDIA
[2010.05.28 19:36:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\OpenOffice.org
[2010.06.11 23:59:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Opera
[2011.10.22 16:51:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Origin
[2012.04.09 01:13:44 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayFirst
[2011.06.30 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayPond
[2010.03.07 01:16:25 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Playrix Entertainment
[2010.03.08 21:23:32 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PoBros
[2012.08.08 13:54:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PPlive
[2010.03.09 05:48:03 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Princess Isabella
[2010.04.01 01:41:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ProtectDisc
[2012.10.01 21:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Raptr
[2012.05.06 22:21:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Real
[2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2012.04.14 16:06:17 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RenPy
[2010.03.28 15:47:09 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RobinsonCrusoe
[2012.01.10 23:36:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Sony
[2012.07.30 13:39:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Synthesia
[2011.10.16 18:32:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TeamViewer
[2010.03.08 18:55:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TitanicMystery
[2008.06.27 00:59:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TuneUp Software
[2010.02.22 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Turbine
[2010.09.16 13:25:07 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\UAs
[2010.05.25 01:37:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Ubisoft
[2011.07.07 16:58:36 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Unity
[2010.03.08 07:46:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Virtual City
[2010.02.21 19:06:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\WinRAR
[2012.05.12 20:30:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Xfire
[2010.09.16 13:25:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\xmldm
< %APPDATA%\*.exe /s >
[2012.04.29 01:03:37 | 000,310,208 | ---- | M] (Georgia Institute of Technology) -- C:\Users\Teddy\AppData\Roaming\Azureus\plugins\mlab\ShaperProbeC.exe
[2012.04.05 21:08:12 | 000,726,814 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IGG\Web3D\\unins000.exe
[2011.11.01 18:34:52 | 000,013,312 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\devicefingerprint.exe
[2011.11.03 21:04:14 | 000,158,208 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\devicefingerprint_old.exe
[2011.11.21 21:03:22 | 000,053,504 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUClient.exe
[2011.11.21 21:03:22 | 000,022,784 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe
[2011.11.21 21:03:24 | 000,097,200 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUupdater.exe
[2011.07.30 01:55:56 | 000,009,728 | ---- | M] (Mozilla Corporation) -- C:\Users\Teddy\AppData\Roaming\IMVUClient\plugin-container.exe
[2011.12.14 22:23:04 | 000,077,973 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\Uninstall.exe
[2011.04.28 20:51:30 | 000,049,664 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\w9xpopen.exe
[2011.11.01 19:00:38 | 000,134,144 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\WriteMiniDump.exe
[2011.12.14 22:20:05 | 023,223,800 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\installer\SetupImvu_update.exe
[2010.03.24 14:19:14 | 000,038,784 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2010.03.21 18:27:59 | 000,010,134 | R--- | M] () -- C:\Users\Teddy\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2012.08.07 21:44:21 | 005,527,872 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLite\Update\PPLite_Update.exe
[2012.06.13 05:10:04 | 000,464,288 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\PPLive.exe
[2012.08.07 22:32:29 | 000,328,985 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\uninst.exe
[2012.06.13 05:09:32 | 000,236,448 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\crashreporter.exe
[2012.06.13 05:09:34 | 000,130,976 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\hwcheck.exe
[2012.06.13 05:09:48 | 000,464,288 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\PPLiveU.exe
[2012.06.13 05:09:52 | 000,099,744 | ---- | M] (PPTV) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\PPTVIconBubble.exe
[2012.06.13 04:55:04 | 000,202,112 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\PPTVLauncher.exe
[2012.06.13 04:55:04 | 000,046,456 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\RepairSetup.exe
[2012.06.13 04:55:02 | 000,032,120 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\SkinConverter.exe
[2010.04.24 22:07:25 | 000,443,912 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\setup3.11\setup.exe
[2011.01.26 17:59:11 | 000,510,120 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\setup3.13\setup.exe
[2012.09.25 21:09:07 | 000,449,176 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\temp\~Upg0\rnupgagent.exe
[2012.09.25 21:09:07 | 000,449,176 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe
[2012.09.27 00:11:56 | 027,433,440 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\stub_data\RealPlayer.exe
[2012.09.27 00:10:07 | 000,760,128 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\stub_exe\RealPlayer.exe
< %SYSTEMDRIVE%\*.exe >
[2011.12.23 03:39:35 | 2059,036,792 | ---- | M] (Acresso Software Inc.) -- C:\LuviniaInstaller_1010040.exe
< MD5 for: AGP440.SYS  >
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
< MD5 for: IASTORV.SYS  >
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\drivers\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0033117673c16921\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys
[2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
[2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys
< MD5 for: NETLOGON.DLL  >
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
< MD5 for: NVSTOR.SYS  >
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\drivers\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_38e464dbe521cc7f\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
< MD5 for: USER32.DLL  >
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\System32\user32.dll
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
[2004.08.03 17:53:30 | 000,574,464 | ---- | M] (Microsoft Corporation) MD5=F18CDF551E5223255CF7F0D124B829EF -- C:\Joymax\DMO\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
< MD5 for: WININIT.EXE  >
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
< MD5 for: WINLOGON.EXE  >
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.05.23 13:25:15 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\Windows\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
<           >
[2009.07.14 06:53:46 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.07.14 06:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2012.06.11 13:48:17 | 000,000,436 | -H-- | C] () -- C:\Windows\Tasks\Norton Security Scan for Teddy.job
[2012.07.21 19:33:49 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.09.27 00:10:00 | 000,000,366 | ---- | C] () -- C:\Windows\Tasks\ReclaimerUpdateXML_Teddy.job
[2012.09.27 00:10:01 | 000,000,370 | ---- | C] () -- C:\Windows\Tasks\ReclaimerUpdateFiles_Teddy.job
[2012.09.27 00:10:02 | 000,000,376 | ---- | C] () -- C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Teddy.job

< End of report >

Alt 02.10.2012, 14:56   #20
/// Winkelfunktion
/// TB-Süch-Tiger™
Rechner mit MyStart by IncrediBar infiziert. - Standard

Rechner mit MyStart by IncrediBar infiziert.

Du hast es dann aber nicht von meinem extra angebenen Downloadlink runtergeladen
In diesem Log steht immer noch eine alte Version drin

Logfiles bitte immer in CODE-Tags posten

Alt 02.10.2012, 22:07   #21
Rechner mit MyStart by IncrediBar infiziert. - Standard

Rechner mit MyStart by IncrediBar infiziert.

Ich bin ein braver Teddy, ich hab auf das OTL in deinem Post geklickt.

Alt 03.10.2012, 18:11   #22
/// Winkelfunktion
/// TB-Süch-Tiger™
Rechner mit MyStart by IncrediBar infiziert. - Standard

Rechner mit MyStart by IncrediBar infiziert.

Wirklich? Kann ich mir kaum vorstellen. Mach es bitte nochmal, da müsste nun Version oder höher sein
Logfiles bitte immer in CODE-Tags posten

Alt 05.10.2012, 22:07   #23
Rechner mit MyStart by IncrediBar infiziert. - Standard

Rechner mit MyStart by IncrediBar infiziert.

Püh .. anzuzweifeln, dass ich brav bin ... du bist kein Charmeur.

OTL logfile created on: 05.10.2012 22:11:14 - Run 3
OTL by OldTimer - Version     Folder = C:\Users\Teddy\Downloads
 Professional  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 1,86 Gb Available Physical Memory | 62,11% Memory free
6,00 Gb Paging File | 4,61 Gb Available in Paging File | 76,88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 307,62 Gb Total Space | 67,44 Gb Free Space | 21,92% Space Free | Partition Type: NTFS
Drive E: | 623,88 Gb Total Space | 535,91 Gb Free Space | 85,90% Space Free | Partition Type: NTFS
Drive I: | 1,87 Gb Total Space | 0,28 Gb Free Space | 15,21% Space Free | Partition Type: FAT32
Computer Name: TEDDY-PC | User Name: Teddy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.10.05 22:10:25 | 000,601,088 | ---- | M] (OldTimer Tools) -- C:\Users\Teddy\Downloads\OTL.exe
PRC - [2012.10.03 11:51:37 | 000,296,096 | ---- | M] (RealNetworks, Inc.) -- C:\Programme\Real\RealPlayer\Update\realsched.exe
PRC - [2012.08.10 18:59:52 | 004,440,896 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Teddy\AppData\Local\Akamai\netsession_win.exe
PRC - [2012.08.08 22:55:44 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.05.31 15:00:22 | 000,445,624 | ---- | M] (Sony) -- C:\Programme\Sony\Sony PC Companion\PCCompanion.exe
PRC - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012.05.15 11:28:16 | 001,820,480 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe
PRC - [2012.05.15 11:27:34 | 000,857,920 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2012.05.15 05:21:28 | 000,461,176 | ---- | M] (PPLive Corporation) -- C:\Programme\Common Files\PPLiveNetwork\PPAP.exe
PRC - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.05.08 22:52:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.08 22:52:24 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.08 22:52:24 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.04.30 11:57:42 | 000,067,072 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe
PRC - [2012.04.29 09:31:36 | 004,901,744 | ---- | M] (Exent Technologies Ltd.) -- C:\Programme\FreeRide Games\GPlayer.exe
PRC - [2012.04.16 20:51:46 | 000,066,992 | ---- | M] (Raptr, Inc) -- C:\Programme\Raptr\raptr.exe
PRC - [2012.04.16 20:51:46 | 000,043,952 | ---- | M] (Raptr, Inc) -- C:\Programme\Raptr\raptr_im.exe
PRC - [2011.09.01 19:18:54 | 004,862,384 | ---- | M] (Exent Technologies Ltd.) -- C:\Programme\Free Ride Games\GPlayer.exe
PRC - [2011.07.16 06:31:12 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.06.17 19:33:04 | 000,272,528 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee Security Scan\3.0.207\SSScheduler.exe
PRC - [2011.06.09 14:06:06 | 000,507,624 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Common Files\Java\Java Update\jucheck.exe
PRC - [2011.02.26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.01.26 08:45:58 | 000,870,120 | ---- | M] () -- C:\Windows\System32\atwtusb.exe
PRC - [2011.01.17 18:37:40 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe
PRC - [2011.01.17 18:37:40 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin
PRC - [2010.12.24 09:31:08 | 007,134,952 | ---- | M] () -- C:\Windows\System32\WTMKM.exe
PRC - [2010.05.13 21:55:53 | 000,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Users\Teddy\Program Files\DNA\btdna.exe
PRC - [2010.03.18 11:26:08 | 000,172,328 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version5\TeamViewer_Service.exe
PRC - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.07.14 03:14:42 | 000,181,760 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\TabTip.exe
PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.07.14 03:14:38 | 001,173,504 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.07.14 03:14:21 | 000,294,400 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\InputPersonalization.exe
========== Modules (No Company Name) ==========
MOD - [2012.05.24 11:50:32 | 000,203,776 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\MExplorer.dll
MOD - [2012.05.23 11:38:36 | 000,583,680 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PhoneUpdate.dll
MOD - [2012.05.15 05:21:14 | 000,522,600 | ---- | M] () -- C:\Programme\Common Files\PPLiveNetwork\\MngModule.dll
MOD - [2012.04.30 11:57:42 | 000,067,072 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe
MOD - [2012.04.30 11:57:42 | 000,039,936 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\TMonitorAPI.dll
MOD - [2012.03.25 13:51:43 | 000,985,088 | ---- | M] () -- C:\Programme\OpenOffice.org 3\program\libxml2.dll
MOD - [2012.02.20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012.02.20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2012.02.17 19:53:28 | 000,494,592 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtNetwork.pyd
MOD - [2012.02.17 19:53:24 | 001,661,952 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtCore.pyd
MOD - [2012.02.17 19:53:20 | 000,313,856 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtWebKit.pyd
MOD - [2012.02.17 19:53:06 | 005,809,664 | ---- | M] () -- C:\Programme\Raptr\PyQt4.QtGui.pyd
MOD - [2012.02.17 19:52:26 | 000,067,584 | ---- | M] () -- C:\Programme\Raptr\sip.pyd
MOD - [2011.11.21 04:20:46 | 001,949,696 | ---- | M] () -- C:\Programme\Raptr\libtorrent.pyd
MOD - [2011.10.24 20:49:56 | 002,717,595 | ---- | M] () -- C:\Programme\Raptr\heliotrope._purple.pyd
MOD - [2011.09.09 01:47:40 | 001,183,699 | ---- | M] () -- C:\Programme\Raptr\liboscar.dll
MOD - [2011.09.09 01:47:36 | 001,640,221 | ---- | M] () -- C:\Programme\Raptr\libjabber.dll
MOD - [2011.09.09 01:47:32 | 001,052,194 | ---- | M] () -- C:\Programme\Raptr\libymsg.dll
MOD - [2011.09.09 01:47:22 | 000,495,680 | ---- | M] () -- C:\Programme\Raptr\plugins\libaim.dll
MOD - [2011.09.09 01:47:22 | 000,483,306 | ---- | M] () -- C:\Programme\Raptr\plugins\libicq.dll
MOD - [2011.09.09 01:47:16 | 000,655,356 | ---- | M] () -- C:\Programme\Raptr\plugins\libirc.dll
MOD - [2011.09.09 01:47:16 | 000,603,326 | ---- | M] () -- C:\Programme\Raptr\plugins\ssl-nss.dll
MOD - [2011.09.09 01:47:14 | 000,497,782 | ---- | M] () -- C:\Programme\Raptr\plugins\libyahoojp.dll
MOD - [2011.09.09 01:47:14 | 000,474,199 | ---- | M] () -- C:\Programme\Raptr\plugins\ssl.dll
MOD - [2011.09.09 01:47:10 | 001,306,387 | ---- | M] () -- C:\Programme\Raptr\plugins\libmsn.dll
MOD - [2011.09.09 01:47:04 | 000,565,461 | ---- | M] () -- C:\Programme\Raptr\plugins\libxmpp.dll
MOD - [2011.09.09 01:46:56 | 000,506,276 | ---- | M] () -- C:\Programme\Raptr\plugins\libyahoo.dll
MOD - [2011.07.07 14:54:36 | 000,233,984 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\Report.dll
MOD - [2011.02.15 20:17:28 | 001,213,633 | ---- | M] () -- C:\Programme\Raptr\libxml2-2.dll
MOD - [2011.02.15 20:17:28 | 000,417,501 | ---- | M] () -- C:\Programme\Raptr\sqlite3.dll
MOD - [2010.12.24 09:31:08 | 007,134,952 | ---- | M] () -- C:\Windows\System32\WTMKM.exe
MOD - [2010.11.23 01:06:22 | 000,055,808 | ---- | M] () -- C:\Programme\Raptr\zlib1.dll
MOD - [2010.11.23 00:57:34 | 000,167,936 | ---- | M] () -- C:\Programme\Raptr\win32gui.pyd
MOD - [2010.11.23 00:57:34 | 000,111,104 | ---- | M] () -- C:\Programme\Raptr\win32file.pyd
MOD - [2010.11.23 00:57:34 | 000,096,256 | ---- | M] () -- C:\Programme\Raptr\win32api.pyd
MOD - [2010.11.23 00:57:34 | 000,036,352 | ---- | M] () -- C:\Programme\Raptr\win32process.pyd
MOD - [2010.11.23 00:57:18 | 000,141,312 | ---- | M] () -- C:\Programme\Raptr\gobject._gobject.pyd
MOD - [2010.11.23 00:57:06 | 000,263,168 | ---- | M] () -- C:\Programme\Raptr\win32com.shell.shell.pyd
MOD - [2010.11.23 00:56:56 | 000,354,304 | ---- | M] () -- C:\Programme\Raptr\pythoncom26.dll
MOD - [2010.11.23 00:56:56 | 000,110,592 | ---- | M] () -- C:\Programme\Raptr\pywintypes26.dll
MOD - [2010.11.23 00:56:26 | 000,324,608 | ---- | M] () -- C:\Programme\Raptr\PIL._imaging.pyd
MOD - [2010.11.23 00:56:02 | 000,805,376 | ---- | M] () -- C:\Programme\Raptr\_ssl.pyd
MOD - [2010.11.23 00:56:02 | 000,583,680 | ---- | M] () -- C:\Programme\Raptr\unicodedata.pyd
MOD - [2010.11.23 00:56:02 | 000,356,864 | ---- | M] () -- C:\Programme\Raptr\_hashlib.pyd
MOD - [2010.11.23 00:56:02 | 000,127,488 | ---- | M] () -- C:\Programme\Raptr\pyexpat.pyd
MOD - [2010.11.23 00:56:02 | 000,087,040 | ---- | M] () -- C:\Programme\Raptr\_ctypes.pyd
MOD - [2010.11.23 00:56:02 | 000,044,544 | ---- | M] () -- C:\Programme\Raptr\_sqlite3.pyd
MOD - [2010.11.23 00:56:02 | 000,043,008 | ---- | M] () -- C:\Programme\Raptr\_socket.pyd
MOD - [2010.11.23 00:56:02 | 000,009,216 | ---- | M] () -- C:\Programme\Raptr\winsound.pyd
MOD - [2010.01.11 16:44:54 | 000,053,248 | ---- | M] () -- C:\Programme\Sony\Sony PC Companion\VObject.dll
MOD - [2008.09.16 21:18:06 | 000,132,608 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
========== Services (SafeList) ==========
SRV - [2012.09.22 20:50:22 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.09.20 22:42:33 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.09.06 20:37:25 | 004,537,664 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_5891ae0.dll -- (Akamai)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.05.08 22:52:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.05.08 22:52:24 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.04.29 09:26:24 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012.01.18 14:38:28 | 000,155,320 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Programme\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
SRV - [2011.06.17 19:33:04 | 000,237,008 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Programme\McAfee Security Scan\3.0.207\McCHSvc.exe -- (McComponentHostService)
SRV - [2011.01.26 08:45:58 | 000,870,120 | ---- | M] () [Auto | Running] -- C:\Windows\System32\atwtusb.exe -- (WTService)
SRV - [2010.03.28 10:50:19 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010.03.18 11:26:08 | 000,172,328 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5)
SRV - [2009.12.16 19:26:00 | 003,453,712 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2009.07.14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva380.sys -- (XDva380)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (aoc6lxmn)
DRV - [2012.09.17 21:31:15 | 000,076,800 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\SSHDRV84.sys -- (SSHDRV84)
DRV - [2012.07.07 11:07:44 | 000,025,200 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2012.07.07 11:07:44 | 000,012,400 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt)
DRV - [2012.05.15 12:26:00 | 011,354,944 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012.05.12 17:59:30 | 000,013,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\apf003.sys -- (apf003)
DRV - [2012.05.08 22:52:24 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.08 22:52:24 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.12.15 16:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.11.22 10:25:22 | 000,046,184 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto | Running] -- C:\Programme\FreeRide Games\X6XSEx.sys -- (X6XSEx_Pr148)
DRV - [2010.11.22 09:25:22 | 000,046,184 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto | Running] -- C:\Programme\Free Ride Games\X6XSEx.sys -- (X6XSEx)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.05.23 13:25:15 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2009.09.23 03:19:31 | 000,294,912 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcvmm.sys -- (vpcvmm)
DRV - [2009.09.23 03:19:31 | 000,055,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV - [2009.09.23 03:18:08 | 000,078,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpcusb.sys -- (vpcusb)
DRV - [2009.09.23 03:18:07 | 000,165,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpchbus.sys -- (vpcbus)
DRV - [2009.08.20 12:38:24 | 000,006,144 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\walvhid.sys -- (vhidmini)
DRV - [2009.07.14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009.07.14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009.07.14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009.07.14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009.07.14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009.07.14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2009.03.08 13:15:14 | 000,006,144 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\moufiltr.sys -- (moufiltr)
DRV - [2009.01.19 20:31:56 | 000,277,544 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2007.07.03 15:05:00 | 000,162,944 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RT25USBAP.SYS -- (RT25USBAP)
DRV - [2006.06.27 09:56:50 | 000,031,872 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\superwebcam.sys -- (SUPERWEBCAM)
DRV - [2005.06.20 10:12:00 | 000,215,040 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\sis163u.sys -- (SIS163u)
DRV - [2005.02.26 09:25:52 | 000,091,527 | ---- | M] (VM) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbVM31b.sys -- (ZSMC301b)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://zynga.com/
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 78 5E 77 19 B3 CA 01  [binary data]
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {90b49673-5506-483e-b92b-ca0265bd9ca8} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =;<local>;*.local
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://search.bearshare.net"
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:
FF - prefs.js..extensions.enabledItems: {ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}:
FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:
FF - prefs.js..extensions.enabledItems: ocr@babylon.com:1.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@exent.com/npExentControl,version= C:\Program Files\FreeRide Games\npExentControl.dll (Exent Technologies Ltd.)
FF - HKLM\Software\MozillaPlugins\@exent.com/npExentCtl,version= C:\Program Files\Free Ride Games\npExentCtl.dll (Exent Technologies Ltd.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF - HKLM\Software\MozillaPlugins\@pptv.com/plugin: C:\Program Files\Internet Explorer\PPLite\plugin\\npplugin2.dll (PPLive Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version= c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version= c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version= C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version= C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version= c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@zylom.com/ZylomGamesPlayer: C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKCU\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Users\Teddy\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKCU\Software\MozillaPlugins\@g2.com/iggweb3dupdater: C:\Users\Teddy\AppData\Roaming\IGG\Web3D\\NPIGGWeb3DUpdater.dll (IGG)
FF - HKCU\Software\MozillaPlugins\@g2.com/joyconnectshell: C:\Users\Teddy\AppData\Roaming\IGG\Web3D\\NPJoyConnectShell.dll (IGG)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Teddy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.10.03 11:51:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.10.03 11:51:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.03 11:51:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.03 11:52:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}: C:\Users\Teddy\Program Files\DNA [2012.10.05 20:04:34 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{ED0CF0C8-62F1-4865-A3FD-2E2A2B50FAFA}: C:\Users\Teddy\AppData\Roaming\5008 [2010.11.09 17:44:47 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Teddy\AppData\Roaming\IDM\idmmzcc5
[2012.03.25 13:37:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Teddy\AppData\Roaming\mozilla\Extensions
[2012.09.22 20:50:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions
[2011.08.04 17:38:17 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.03.25 13:37:02 | 000,000,000 | ---D | M] (Wincore Mediabar) -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}
[2012.09.22 00:21:33 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-1.xml
[2012.03.25 20:28:36 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-2.xml
[2012.09.22 00:11:34 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-3.xml
[2012.03.11 00:30:33 | 000,001,056 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin.xml
[2012.09.22 20:50:26 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.09.15 23:30:05 | 000,000,000 | ---D | M] (Babylon Translation Activation) -- C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com
[2012.09.22 20:50:22 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 06:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012.10.03 11:51:42 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2009.03.24 12:10:44 | 000,114,688 | ---- | M] (Zylom) -- C:\Program Files\mozilla firefox\plugins\npzylomgamesplayer.dll
[2012.09.22 20:50:20 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.22 20:50:20 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.09.22 20:50:20 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.09.22 20:50:20 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.09.22 20:50:20 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.09.22 20:50:20 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome  ==========
CHR - homepage: 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: 
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\pdf.dll
CHR - plugin: Perion plugin (Enabled) = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Zylom Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
CHR - plugin: AhnLab MyKeyDefense 2.5 (Enabled) = C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Exent\u00AE AOD Gecko Plugin (Enabled) = C:\Program Files\Free Ride Games\npExentCtl.dll
CHR - plugin: Exent\u00AE AOD Gecko Plugin (Enabled) = C:\Program Files\FreeRide Games\npExentControl.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\\npGoogleUpdate3.dll
CHR - plugin: PPLive PPTV Plugin (Enabled) = C:\Program Files\Internet Explorer\PPLite\plugin\\npplugin2.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Media Go Detector (Enabled) = C:\Program Files\Sony\Media Go\npmediago.dll
CHR - plugin: PlayStation(R)Network Downloader Check Plug-in (Enabled) = C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Teddy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: IGG Web3D Updater NP Plugin for Mozilla (Enabled) = C:\Users\Teddy\AppData\Roaming\IGG\Web3D\\NPIGGWeb3DUpdater.dll
CHR - plugin: JoyConnect NP Plugin for Mozilla (Enabled) = C:\Users\Teddy\AppData\Roaming\IGG\Web3D\\NPJoyConnectShell.dll
CHR - plugin: DNA Plug-in (Enabled) = C:\Users\Teddy\Program Files\DNA\plugins\npbtdna.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - Extension: YouTube = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\
CHR - Extension: Teddy Bear = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gocdpcbhljdnfjpoknadapdpjokmfoif\1_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: New tab for Chrome\u2122 = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\
CHR - Extension: FastestChrome \u2013 Schneller browsen = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmffncokckfccddfenhkhnllmlobdahm\6.8.6_0\
CHR - Extension: Vuze Remote = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\\
CHR - Extension: Google Mail = C:\Users\Teddy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (DataMngr) - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Programme\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll (MusicLab, LLC)
O2 - BHO: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programme\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No CLSID value found.
O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found.
O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {90B49673-5506-483E-B92B-CA0265BD9CA8} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [MacrokeyManager] C:\Windows\System32\WTMKM.exe ()
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\.DEFAULT..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-18..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-19..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-20..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Akamai NetSession Interface] C:\Users\Teddy\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [BitTorrent DNA] C:\Users\Teddy\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Exetender_148] C:\Program Files\FreeRide Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [PlayNC Launcher]  File not found
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [PPAP] C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe (PPLive Corporation)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Raptr] C:\Programme\Raptr\raptrstub.exe (Raptr, Inc)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001..\Run: [Sony PC Companion] C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Sony)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Web-Suche - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-21-3026671440-3571442614-196133993-1005\..Trusted Domains: sony.com ([]* in )
O16 - DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095}  (ExentInf1 Class)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}  (ExentInf Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{14B43710-DFCA-4ADB-8A04-DFA39535C9DF}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1537B177-72F8-4837-A69C-4491A1A46E4D}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B1D98BB-9065-4F58-B709-0608A62BE7C8}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{769B5C26-4B44-47FB-B41A-27AC47E2AB05}: DhcpNameServer =
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Programme\Common Files\microsoft shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell - "" = AutoRun
O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell\AutoRun\command - "" = H:\Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare Software.lnk -  - File not found
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Registrierungsprogramm ausführen.lnk - C:\Programme\WiFiConnector\NintendoWFCReg.exe - ()
MsConfig - StartUpFolder: C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk - C:\Programme\OpenOffice.org 3\program\quickstart.exe - ()
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= -  File not found
MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
MsConfig - StartUpReg: TkBellExe - hkey= - key= - c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
MsConfig - State: "startup" - 0
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D} - Microsoft .NET Framework 1.1 Security Update (KB953297)
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012.10.05 21:33:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012.10.05 21:31:49 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2012.10.05 21:31:46 | 000,000,000 | ---D | C] -- C:\Users\Teddy\AppData\Local\Google
[2012.10.03 11:52:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2012.09.22 22:49:29 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.09.22 22:40:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
[2012.09.22 22:09:47 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee Security Scan
[2012.09.22 22:09:42 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan
[2012.09.22 22:09:42 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2012.09.22 20:50:26 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012.09.22 20:50:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.09.22 09:25:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2012.09.21 23:52:20 | 000,000,000 | ---D | C] -- C:\Users\Teddy\AppData\Roaming\Malwarebytes
[2012.09.21 23:52:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.21 23:52:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.21 23:52:05 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.21 23:52:05 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.09.21 23:47:14 | 000,000,000 | ---D | C] -- C:\Users\Teddy\Start Menu
[2012.09.21 13:56:14 | 000,000,000 | ---D | C] -- C:\Program Files\Perion
[2012.09.17 21:26:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gathering
[2012.09.16 14:10:02 | 000,000,000 | ---D | C] -- C:\Users\Teddy\Desktop\Neuer Ordner
[2012.09.15 22:56:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SWF Studio
[2012.09.15 22:55:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prelusion
[2012.09.06 21:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cornelsen
[2012.09.06 21:48:24 | 000,000,000 | ---D | C] -- C:\Program Files\Cornelsen
[1 C:\Users\Teddy\AppData\Roaming\*.tmp files -> C:\Users\Teddy\AppData\Roaming\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.10.05 21:42:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.05 21:36:03 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.05 21:36:00 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.05 21:33:05 | 000,002,193 | ---- | M] () -- C:\Users\Teddy\Desktop\Google Chrome.lnk
[2012.10.05 20:11:51 | 000,020,720 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.05 20:11:51 | 000,020,720 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.05 20:04:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.05 20:04:13 | 2415,255,552 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.05 15:43:49 | 000,627,443 | ---- | M] () -- C:\Users\Teddy\Desktop\Komplexarbeit Handke.pdf
[2012.10.03 23:35:34 | 000,666,270 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.10.03 23:35:34 | 000,625,116 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.10.03 23:35:34 | 000,135,198 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.10.03 23:35:34 | 000,110,754 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.10.03 11:52:11 | 000,001,012 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012.10.03 11:51:39 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2012.10.02 23:19:04 | 000,414,198 | ---- | M] () -- C:\Users\Teddy\Desktop\bookmarks_02.10.12.html
[2012.10.02 23:15:55 | 000,001,775 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2012.10.01 12:28:17 | 000,164,648 | ---- | M] () -- C:\Users\Teddy\Desktop\buntesleben.jpg
[2012.09.24 15:26:33 | 000,513,501 | ---- | M] () -- C:\Users\Teddy\Desktop\adwcleaner.exe
[2012.09.23 10:27:49 | 000,000,436 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Teddy.job
[2012.09.22 22:40:55 | 000,002,040 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2012.09.22 22:40:55 | 000,002,040 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2012.09.22 22:07:34 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012.09.22 11:38:23 | 000,000,298 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2012.09.21 23:52:07 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.09.21 22:57:03 | 000,003,405 | ---- | M] () -- C:\Users\Teddy\.recently-used.xbel
[2012.09.17 21:31:15 | 000,076,800 | ---- | M] () -- C:\Windows\System32\drivers\SSHDRV84.sys
[2012.09.17 21:30:33 | 000,000,000 | ---- | M] () -- C:\Users\Public\Documents\PCD549.L!C
[2012.09.17 21:26:18 | 000,000,616 | ---- | M] () -- C:\Users\Public\Desktop\Holiday World.lnk
[2012.09.15 22:55:51 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Gilbert Goodmate.lnk
[2012.09.07 20:55:14 | 000,315,280 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.06 21:49:47 | 000,001,101 | ---- | M] () -- C:\Users\Public\Desktop\At the Cutting Edge.lnk
[1 C:\Users\Teddy\AppData\Roaming\*.tmp files -> C:\Users\Teddy\AppData\Roaming\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.10.05 21:33:05 | 000,002,193 | ---- | C] () -- C:\Users\Teddy\Desktop\Google Chrome.lnk
[2012.10.05 21:31:52 | 000,001,096 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.05 21:31:51 | 000,001,092 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.05 15:43:46 | 000,627,443 | ---- | C] () -- C:\Users\Teddy\Desktop\Komplexarbeit Handke.pdf
[2012.10.03 11:52:11 | 000,001,012 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012.10.02 23:15:55 | 000,001,787 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2012.10.02 23:15:55 | 000,001,775 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2012.10.02 23:08:54 | 000,414,198 | ---- | C] () -- C:\Users\Teddy\Desktop\bookmarks_02.10.12.html
[2012.10.01 12:28:28 | 000,164,648 | ---- | C] () -- C:\Users\Teddy\Desktop\buntesleben.jpg
[2012.09.26 12:50:47 | 000,602,972 | ---- | C] () -- C:\Users\Teddy\Desktop\DSC_0151.JPG
[2012.09.24 15:26:32 | 000,513,501 | ---- | C] () -- C:\Users\Teddy\Desktop\adwcleaner.exe
[2012.09.22 22:09:42 | 000,002,040 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2012.09.22 22:09:42 | 000,002,040 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2012.09.22 22:07:34 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012.09.22 22:07:34 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012.09.22 20:50:24 | 000,001,100 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.09.22 11:11:09 | 000,000,298 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2012.09.21 23:52:07 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.09.21 22:57:03 | 000,003,405 | ---- | C] () -- C:\Users\Teddy\.recently-used.xbel
[2012.09.17 21:31:15 | 000,076,800 | ---- | C] () -- C:\Windows\System32\drivers\SSHDRV84.sys
[2012.09.17 21:30:33 | 000,000,000 | ---- | C] () -- C:\Users\Public\Documents\PCD549.L!C
[2012.09.17 21:26:18 | 000,000,616 | ---- | C] () -- C:\Users\Public\Desktop\Holiday World.lnk
[2012.09.15 22:55:51 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Gilbert Goodmate.lnk
[2012.09.06 21:49:47 | 000,001,101 | ---- | C] () -- C:\Users\Public\Desktop\At the Cutting Edge.lnk
[2012.08.22 22:48:13 | 000,000,232 | ---- | C] () -- C:\Users\Teddy\.KanjiGymLight
[2012.08.13 17:53:37 | 000,000,059 | ---- | C] () -- C:\Windows\RUNAWAY.INI
[2012.05.18 17:40:39 | 000,010,525 | ---- | C] () -- C:\Windows\System32\Default_3.ini
[2012.05.18 17:40:39 | 000,010,283 | ---- | C] () -- C:\Windows\System32\Default_2.ini
[2012.05.18 17:40:39 | 000,009,917 | ---- | C] () -- C:\Windows\System32\Default_1.ini
[2012.05.18 17:40:39 | 000,000,738 | ---- | C] () -- C:\Windows\System32\MKProfile.ini
[2012.05.18 17:40:36 | 000,000,105 | R--- | C] () -- C:\ProgramData\Ppster.ini
[2012.05.18 17:40:30 | 000,870,120 | ---- | C] () -- C:\Windows\System32\atwtusb.exe
[2012.05.18 17:40:28 | 007,134,952 | ---- | C] () -- C:\Windows\System32\WTMKM.exe
[2012.05.18 17:40:23 | 000,045,056 | ---- | C] () -- C:\Windows\System32\InstallService.exe
[2012.05.18 17:40:22 | 003,683,560 | ---- | C] () -- C:\Windows\System32\Control Panel_Betteryless.exe
[2012.05.18 17:40:20 | 000,148,200 | ---- | C] () -- C:\Windows\System32\Calibration.exe
[2012.05.18 17:40:12 | 000,835,072 | ---- | C] () -- C:\Windows\RmTablet.exe
[2012.05.18 17:40:11 | 000,010,708 | ---- | C] () -- C:\Windows\System32\aiptbl.ini
[2012.05.15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
[2012.05.12 17:59:30 | 000,016,304 | ---- | C] () -- C:\Windows\System32\apl003.sys
[2012.05.12 17:59:30 | 000,013,232 | ---- | C] () -- C:\Windows\System32\apf003.sys
[2012.04.16 23:36:22 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2012.04.14 22:56:32 | 000,000,000 | ---- | C] () -- C:\Users\Teddy\__ng3d.lock
[2012.03.25 12:13:13 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2012.03.04 01:19:48 | 000,000,410 | ---- | C] () -- C:\Windows\{27018D57-D152-44EF-BCE0-5E3B3445EABE}_WiseFW.ini
[2011.12.23 03:43:56 | 000,230,752 | ---- | C] () -- C:\Windows\patchw32.dll
[2011.12.23 03:43:56 | 000,118,176 | ---- | C] () -- C:\Windows\patchw.dll
[2010.11.17 17:57:56 | 000,006,936 | ---- | C] () -- C:\Windows\Go Screensaver.ini
[2010.09.15 21:26:32 | 000,000,148 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\urhtps.dat
[2010.05.28 15:06:46 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_3
[2010.05.28 00:08:52 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_1
[2010.05.28 00:06:06 | 000,000,169 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\D2Info0
[2010.05.28 00:06:06 | 000,000,008 | ---- | C] () -- C:\Users\Teddy\AppData\Roaming\DofusAppId0_2
[2010.04.18 18:08:31 | 000,032,256 | ---- | C] () -- C:\Users\Teddy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.02.21 20:31:04 | 000,000,093 | ---- | C] () -- C:\Users\Teddy\AppData\Local\fusioncache.dat
========== ZeroAccess Check ==========
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
"" = %SystemRoot%\system32\shell32.dll -- [2010.07.27 16:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011.10.16 18:35:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\.minecraft
[2010.09.15 01:00:21 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5005
[2010.10.04 18:09:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5006
[2010.11.09 17:44:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5008
[2010.03.08 21:06:30 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Anabel
[2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\app
[2012.08.03 16:04:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Azureus
[2012.03.25 22:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Cat's Eye Games
[2010.09.15 01:00:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\cock
[2012.05.04 23:05:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DAEMON Tools Lite
[2010.03.08 22:51:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dekovir
[2011.08.10 22:18:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DMCache
[2012.10.05 22:34:49 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DNA
[2010.05.28 23:56:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus 2
[2010.05.28 00:06:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010.05.28 15:06:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010.05.28 00:08:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2012.09.22 14:47:14 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoft
[2012.07.09 13:22:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.04.28 23:46:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EnchantedCavern
[2010.03.09 06:52:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EscapeTheMuseum2
[2012.03.25 16:46:15 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Exent Technologies
[2012.03.25 23:36:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Finstere Liebschaft
[2011.01.04 17:40:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\FOG Downloader
[2012.10.03 08:42:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Free Download Manager
[2012.04.05 00:38:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Friday's games
[2012.04.28 22:10:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gamers Digital
[2010.03.08 19:35:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Games
[2012.04.17 00:12:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\GetRightToGo
[2010.03.08 21:42:43 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gogii
[2012.09.08 13:21:19 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\gtk-2.0
[2011.08.07 18:08:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Haushaltsbuch
[2012.03.25 00:45:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ICQ
[2012.04.05 21:08:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IGG
[2011.12.26 14:48:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVU
[2011.12.14 22:23:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVUClient
[2012.07.08 01:14:28 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Jasc
[2012.05.12 17:07:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\KlLauncherST
[2011.11.05 23:06:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Lingo4u
[2011.11.16 00:26:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\LolClient
[2012.03.25 13:36:37 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\MusicNet
[2010.05.28 19:36:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\OpenOffice.org
[2010.06.11 23:59:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Opera
[2011.10.22 16:51:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Origin
[2012.04.09 01:13:44 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayFirst
[2011.06.30 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayPond
[2010.03.07 01:16:25 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Playrix Entertainment
[2010.03.08 21:23:32 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PoBros
[2012.08.08 13:54:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PPlive
[2010.03.09 05:48:03 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Princess Isabella
[2010.04.01 01:41:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ProtectDisc
[2012.10.05 20:04:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Raptr
[2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2012.04.14 16:06:17 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RenPy
[2010.03.28 15:47:09 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RobinsonCrusoe
[2012.01.10 23:36:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Sony
[2012.07.30 13:39:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Synthesia
[2011.10.16 18:32:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TeamViewer
[2010.03.08 18:55:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TitanicMystery
[2008.06.27 00:59:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TuneUp Software
[2010.02.22 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Turbine
[2010.09.16 13:25:07 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\UAs
[2010.05.25 01:37:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Ubisoft
[2011.07.07 16:58:36 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Unity
[2010.03.08 07:46:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Virtual City
[2010.09.16 13:25:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\xmldm
========== Purity Check ==========
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2011.10.16 18:35:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\.minecraft
[2010.09.15 01:00:21 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5005
[2010.10.04 18:09:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5006
[2010.11.09 17:44:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\5008
[2012.09.23 11:30:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Adobe
[2010.03.08 21:06:30 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Anabel
[2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\app
[2012.03.28 22:37:50 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Apple Computer
[2012.02.14 22:09:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Avira
[2012.08.03 16:04:47 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Azureus
[2012.03.25 22:51:34 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Cat's Eye Games
[2010.09.15 01:00:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\cock
[2012.05.04 23:05:11 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DAEMON Tools Lite
[2010.03.08 22:51:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dekovir
[2011.08.10 22:18:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DMCache
[2012.10.05 22:34:49 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DNA
[2010.05.28 23:56:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus 2
[2010.05.28 00:06:06 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010.05.28 15:06:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010.05.28 00:08:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2012.09.22 14:47:14 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoft
[2012.07.09 13:22:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.04.28 23:46:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EnchantedCavern
[2010.03.09 06:52:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\EscapeTheMuseum2
[2012.03.25 16:46:15 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Exent Technologies
[2012.03.25 23:36:52 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Finstere Liebschaft
[2011.01.04 17:40:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\FOG Downloader
[2012.10.03 08:42:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Free Download Manager
[2012.04.05 00:38:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Friday's games
[2012.04.28 22:10:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gamers Digital
[2010.03.08 19:35:31 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Games
[2012.04.17 00:12:42 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\GetRightToGo
[2010.03.08 21:42:43 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Gogii
[2012.09.08 13:21:19 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\gtk-2.0
[2011.08.07 18:08:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Haushaltsbuch
[2012.03.25 00:45:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ICQ
[2010.02.21 18:51:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Identities
[2012.04.05 21:08:13 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IGG
[2011.12.26 14:48:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVU
[2011.12.14 22:23:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\IMVUClient
[2010.03.09 20:56:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\InstallShield
[2012.07.08 01:14:28 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Jasc
[2012.05.12 17:07:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\KlLauncherST
[2011.11.05 23:06:04 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Lingo4u
[2011.11.16 00:26:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\LolClient
[2010.02.21 20:31:46 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Macromedia
[2012.09.21 23:52:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Malwarebytes
[2009.07.14 10:56:56 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Media Center Programs
[2012.08.18 20:31:05 | 000,000,000 | --SD | M] -- C:\Users\Teddy\AppData\Roaming\Microsoft
[2010.09.15 21:23:18 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Mozilla
[2012.03.25 13:36:37 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\MusicNet
[2012.06.18 15:22:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\NVIDIA
[2010.05.28 19:36:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\OpenOffice.org
[2010.06.11 23:59:55 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Opera
[2011.10.22 16:51:41 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Origin
[2012.04.09 01:13:44 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayFirst
[2011.06.30 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PlayPond
[2010.03.07 01:16:25 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Playrix Entertainment
[2010.03.08 21:23:32 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PoBros
[2012.08.08 13:54:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\PPlive
[2010.03.09 05:48:03 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Princess Isabella
[2010.04.01 01:41:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\ProtectDisc
[2012.10.05 20:04:57 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Raptr
[2012.05.06 22:21:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Real
[2010.05.28 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2012.04.14 16:06:17 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RenPy
[2010.03.28 15:47:09 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\RobinsonCrusoe
[2012.01.10 23:36:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Sony
[2012.07.30 13:39:02 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Synthesia
[2011.10.16 18:32:20 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TeamViewer
[2010.03.08 18:55:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TitanicMystery
[2008.06.27 00:59:01 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\TuneUp Software
[2010.02.22 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Turbine
[2010.09.16 13:25:07 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\UAs
[2010.05.25 01:37:29 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Ubisoft
[2011.07.07 16:58:36 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Unity
[2010.03.08 07:46:24 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Virtual City
[2010.02.21 19:06:16 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\WinRAR
[2012.05.12 20:30:08 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\Xfire
[2010.09.16 13:25:23 | 000,000,000 | ---D | M] -- C:\Users\Teddy\AppData\Roaming\xmldm
< %APPDATA%\*.exe /s >
[2012.04.29 01:03:37 | 000,310,208 | ---- | M] (Georgia Institute of Technology) -- C:\Users\Teddy\AppData\Roaming\Azureus\plugins\mlab\ShaperProbeC.exe
[2012.04.05 21:08:12 | 000,726,814 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IGG\Web3D\\unins000.exe
[2011.11.01 18:34:52 | 000,013,312 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\devicefingerprint.exe
[2011.11.03 21:04:14 | 000,158,208 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\devicefingerprint_old.exe
[2011.11.21 21:03:22 | 000,053,504 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUClient.exe
[2011.11.21 21:03:22 | 000,022,784 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe
[2011.11.21 21:03:24 | 000,097,200 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\IMVUupdater.exe
[2011.07.30 01:55:56 | 000,009,728 | ---- | M] (Mozilla Corporation) -- C:\Users\Teddy\AppData\Roaming\IMVUClient\plugin-container.exe
[2011.12.14 22:23:04 | 000,077,973 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\Uninstall.exe
[2011.04.28 20:51:30 | 000,049,664 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\w9xpopen.exe
[2011.11.01 19:00:38 | 000,134,144 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\WriteMiniDump.exe
[2011.12.14 22:20:05 | 023,223,800 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\IMVUClient\installer\SetupImvu_update.exe
[2010.03.24 14:19:14 | 000,038,784 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2010.03.21 18:27:59 | 000,010,134 | R--- | M] () -- C:\Users\Teddy\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2012.08.07 21:44:21 | 005,527,872 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLite\Update\PPLite_Update.exe
[2012.06.13 05:10:04 | 000,464,288 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\PPLive.exe
[2012.08.07 22:32:29 | 000,328,985 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\uninst.exe
[2012.06.13 05:09:32 | 000,236,448 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\crashreporter.exe
[2012.06.13 05:09:34 | 000,130,976 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\hwcheck.exe
[2012.06.13 05:09:48 | 000,464,288 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\PPLiveU.exe
[2012.06.13 05:09:52 | 000,099,744 | ---- | M] (PPTV) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\PPTVIconBubble.exe
[2012.06.13 04:55:04 | 000,202,112 | ---- | M] (PPLive Corporation) -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\PPTVLauncher.exe
[2012.06.13 04:55:04 | 000,046,456 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\RepairSetup.exe
[2012.06.13 04:55:02 | 000,032,120 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\PPlive\PPLive\\SkinConverter.exe
[2010.04.24 22:07:25 | 000,443,912 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\setup3.11\setup.exe
[2011.01.26 17:59:11 | 000,510,120 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\setup3.13\setup.exe
[2012.09.25 21:09:07 | 000,449,176 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\temp\~Upg0\rnupgagent.exe
[2012.09.25 21:09:07 | 000,449,176 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe
[2012.09.27 00:11:56 | 027,433,440 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\stub_data\RealPlayer.exe
[2012.09.27 00:10:07 | 000,760,128 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Teddy\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\stub_exe\RealPlayer.exe
< %SYSTEMDRIVE%\*.exe >
[2011.12.23 03:39:35 | 2059,036,792 | ---- | M] (Acresso Software Inc.) -- C:\LuviniaInstaller_1010040.exe
< MD5 for: AGP440.SYS  >
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
< MD5 for: IASTORV.SYS  >
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\drivers\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0033117673c16921\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys
[2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
[2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys
< MD5 for: NETLOGON.DLL  >
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
< MD5 for: NVSTOR.SYS  >
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\drivers\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_38e464dbe521cc7f\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
< MD5 for: USER32.DLL  >
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\System32\user32.dll
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
[2004.08.03 17:53:30 | 000,574,464 | ---- | M] (Microsoft Corporation) MD5=F18CDF551E5223255CF7F0D124B829EF -- C:\Joymax\DMO\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
< MD5 for: WININIT.EXE  >
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
< MD5 for: WINLOGON.EXE  >
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.05.23 13:25:15 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\Windows\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
<           >
[2009.07.14 06:53:46 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.07.14 06:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2012.06.11 13:48:17 | 000,000,436 | -H-- | C] () -- C:\Windows\Tasks\Norton Security Scan for Teddy.job
[2012.07.21 19:33:49 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.10.05 21:31:51 | 000,001,092 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.10.05 21:31:52 | 000,001,096 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

< End of report >

Alt 07.10.2012, 05:19   #24
/// Winkelfunktion
/// TB-Süch-Tiger™
Rechner mit MyStart by IncrediBar infiziert. - Standard

Rechner mit MyStart by IncrediBar infiziert.

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://zynga.com/
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 78 5E 77 19 B3 CA 01  [binary data]
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {90b49673-5506-483e-b92b-ca0265bd9ca8} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - No CLSID value found
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=740&systemid=2&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =;<local>;*.local
FF - prefs.js..browser.startup.homepage: "http://search.bearshare.net"
FF - prefs.js..extensions.enabledItems: ocr@babylon.com:1.1
FF - user.js - File not found
[2011.08.04 17:38:17 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.03.25 13:37:02 | 000,000,000 | ---D | M] (Wincore Mediabar) -- C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}
[2012.09.22 00:21:33 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-1.xml
[2012.03.25 20:28:36 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-2.xml
[2012.09.22 00:11:34 | 000,000,950 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-3.xml
[2012.03.11 00:30:33 | 000,001,056 | ---- | M] () -- C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin.xml
[2012.09.15 23:30:05 | 000,000,000 | ---D | M] (Babylon Translation Activation) -- C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DataMngr) - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Programme\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll (MusicLab, LLC)
O2 - BHO: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No CLSID value found.
O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found.
O3 - HKU\S-1-5-21-3026671440-3571442614-196133993-1001\..\Toolbar\WebBrowser: (no name) - {90B49673-5506-483E-B92B-CA0265BD9CA8} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell - "" = AutoRun
O33 - MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\Shell\AutoRun\command - "" = H:\Startme.exe
C:\Program Files\BearShare Applications
C:\Users\Teddy\Downloads\PageRage (1).exe
C:\Users\Teddy\Downloads\PageRage (2).exe
ipconfig /flushdns /c
Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
Logfiles bitte immer in CODE-Tags posten

Alt 07.10.2012, 11:24   #25
Rechner mit MyStart by IncrediBar infiziert. - Standard

Rechner mit MyStart by IncrediBar infiziert.

Danke, dass du dir so viel Mühe machst.

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}\ not found.
HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully!
HKU\S-1-5-21-3026671440-3571442614-196133993-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\ not found.
Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found.
Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{90b49673-5506-483e-b92b-ca0265bd9ca8} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90b49673-5506-483e-b92b-ca0265bd9ca8}\ not found.
Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.
Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{f92a9fe4-2850-4198-b9d5-279880e49b16} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f92a9fe4-2850-4198-b9d5-279880e49b16}\ not found.
HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Registry key HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}\ not found.
HKU\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
Prefs.js: "hxxp://search.bearshare.net" removed from browser.startup.homepage
Prefs.js: ocr@babylon.com:1.1 removed from extensions.enabledItems
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img folder moved successfully.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} scheduled to be moved on reboot.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\components folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\searchbar folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\options folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\icons folder moved successfully.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\uwa folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio\images folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio\css folder moved successfully.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\images folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default\scripts folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default\images folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default\css folder moved successfully.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\css folder moved successfully.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin scheduled to be moved on reboot.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox\thumbs folder moved successfully.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets scheduled to be moved on reboot.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\modules folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\lib folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\data\search folder moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\data folder moved successfully.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} scheduled to be moved on reboot.
C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-1.xml moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-2.xml moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin-3.xml moved successfully.
C:\Users\Teddy\AppData\Roaming\mozilla\firefox\profiles\6opagoar.default\searchplugins\icqplugin.xml moved successfully.
C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com\chrome\skin folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com\chrome\content folder moved successfully.
C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com\chrome folder moved successfully.
Folder move failed. C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com scheduled to be moved on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B939CF93-F2CB-443d-956C-DC523D85C9DB}\ deleted successfully.
Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B939CF93-F2CB-443d-956C-DC523D85C9DB}\ .
C:\Programme\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\ not found.
C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\ not found.
File C:\Programme\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3}\ not found.
Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}\ not found.
Registry value HKEY_USERS\S-1-5-21-3026671440-3571442614-196133993-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{90B49673-5506-483E-B92B-CA0265BD9CA8} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90B49673-5506-483E-B92B-CA0265BD9CA8}\ not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ec1ecc54-3bb8-11e1-b707-9d3c6c7a4d59}\ not found.
File H:\Startme.exe not found.
========== FILES ==========
C:\Users\Teddy\__ng3d.lock moved successfully.
C:\Users\Teddy\AppData\Roaming\5005\components folder moved successfully.
Folder move failed. C:\Users\Teddy\AppData\Roaming\5005 scheduled to be moved on reboot.
C:\Users\Teddy\AppData\Roaming\5006\components folder moved successfully.
Folder move failed. C:\Users\Teddy\AppData\Roaming\5006 scheduled to be moved on reboot.
C:\Users\Teddy\AppData\Roaming\5008\components folder moved successfully.
Folder move failed. C:\Users\Teddy\AppData\Roaming\5008 scheduled to be moved on reboot.
C:\Users\Teddy\AppData\Roaming\cock folder moved successfully.
C:\Users\Teddy\AppData\Roaming\xmldm folder moved successfully.
File\Folder C:\Users\Teddy\AppData\Roaming\kock not found.
C:\Users\Teddy\AppData\Roaming\UAs folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\components folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\searchbar folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\options folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\icons folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\uwa folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio\images folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio\css folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\images folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default\scripts folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default\css folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\css folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox\thumbs folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\modules folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\lib folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\data\search folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\data folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension\content folder moved successfully.
C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension\components folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\BearShare\Skins\Images folder moved successfully.
C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview\images folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\BearShare\Skins\html\images folder moved successfully.
C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble\images folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\BearShare\Skins\html\cdripview folder moved successfully.
C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview\images folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview\images folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins scheduled to be moved on reboot.
C:\Program Files\BearShare Applications\BearShare\HTML\Images folder moved successfully.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\HTML scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications scheduled to be moved on reboot.
C:\Users\Teddy\Downloads\cnet2_realistair_installer_exe.exe moved successfully.
C:\Users\Teddy\Downloads\PageRage (1).exe moved successfully.
C:\Users\Teddy\Downloads\PageRage (2).exe moved successfully.
C:\Users\Teddy\Downloads\PageRage.exe moved successfully.
File\Folder C:\Users\Teddy\Downloads\SoftonicDownloader_fuer_animation-shop.exe not found.
< ipconfig /flushdns /c >
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Teddy\Downloads\cmd.bat deleted successfully.
C:\Users\Teddy\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 41620 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
User: Teddy
->Temp folder emptied: 840799 bytes
->Temporary Internet Files folder emptied: 7666723 bytes
->Java cache emptied: 2954041 bytes
->FireFox cache emptied: 66617881 bytes
->Google Chrome cache emptied: 309407136 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 45507 bytes
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 41620 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6854 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 370,00 mb
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version log created on 10072012_121509

Files\Folders moved on Reboot...
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content\widgets scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}\chrome scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\mozilla\Firefox\Profiles\6opagoar.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} scheduled to be moved on reboot.
Folder move failed. C:\Programme\Mozilla Firefox\extensions\ocr@babylon.com scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\5005 scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\5006 scheduled to be moved on reboot.
Folder move failed. C:\Users\Teddy\AppData\Roaming\5008 scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\HTML scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\HTML scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\radio scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels\default scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib\panels scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin\lib scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\skin scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets\com.djboxservice.dj.DJBox scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content\widgets scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome\content scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\chrome scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr\FirefoxExtension scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar\Datamngr scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\MediaBar scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\videosview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\colorsbubble scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\artistsview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html\albumsview scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins\html scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\Skins scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare\HTML scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications\BearShare scheduled to be moved on reboot.
Folder move failed. C:\Program Files\BearShare Applications scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.

Edit: Beim Neustart kommt eine Nachricht, dass "der Player" nicht richtig installiert wurde. Weißt du vielleicht welcher Player gemeint ist?

Und noch schlimmer ... wenn ich bei eigenen Datein oder Systemsteuerung und so gehen will, dann kommt da nur die Meldung "Schnittstelle wird nicht unterstützt".

Geändert von TDBear (07.10.2012 um 12:14 Uhr)

Alt 07.10.2012, 19:05   #26
/// Winkelfunktion
/// TB-Süch-Tiger™
Rechner mit MyStart by IncrediBar infiziert. - Standard

Rechner mit MyStart by IncrediBar infiziert.

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

Logfiles bitte immer in CODE-Tags posten


Themen zu Rechner mit MyStart by IncrediBar infiziert.
administrator, adware.hotbar.rb, anti-malware, appdata, autostart, browser, dateien, explorer, gelöscht, gen, google, helper, hängt, infiziert, infiziert., install.exe, löschen, lösung, malwarebytes, microsoft, problem, pup.bundleinstaller.bi, quarantäne, rechner, recycle.bin, roaming, software, speicher, this, trojan.spyeyes.wc, trojan.toggle, uninstall.exe

Ähnliche Themen: Rechner mit MyStart by IncrediBar infiziert.

  1. MyStart/Incredibar
    Plagegeister aller Art und deren Bekämpfung - 05.10.2013 (9)
  2. MyStart by IncrediBar.com
    Log-Analyse und Auswertung - 06.05.2013 (11)
  3. Infiziert mit http://mystart.incredibar.com
    Plagegeister aller Art und deren Bekämpfung - 14.01.2013 (1)
  4. MyStart by IncrediBar.com
    Log-Analyse und Auswertung - 14.10.2012 (17)
  5. Mystart.Incredibar
    Plagegeister aller Art und deren Bekämpfung - 14.10.2012 (37)
  6. mystart.incredibar infiziert mit Google Chrome
    Plagegeister aller Art und deren Bekämpfung - 02.10.2012 (38)
  7. mystart.incredibar.com
    Log-Analyse und Auswertung - 29.09.2012 (2)
  8. MyStart Incredibar auf Rechner entdeckt, was kann ich tun?
    Plagegeister aller Art und deren Bekämpfung - 16.09.2012 (43)
  9. mystart.incredibar infiziert
    Plagegeister aller Art und deren Bekämpfung - 15.09.2012 (12)
  10. mystart.incredibar.com/mb167?a=6OyHKtQsfR&loc=FF_NT >> wie bekomme ich das wieder vom Rechner
    Plagegeister aller Art und deren Bekämpfung - 14.09.2012 (33)
  11. Wie entfernt man das mystart.incredibar.com-zeug vom Rechner
    Log-Analyse und Auswertung - 09.09.2012 (4)
  12. MyStart @ Incredibar und MyStart Search trotz Deinstallation des Programms
    Plagegeister aller Art und deren Bekämpfung - 09.09.2012 (2)
  13. MySTart by Incredibar
    Plagegeister aller Art und deren Bekämpfung - 30.08.2012 (1)
  14. Rechner ist mit "Incredibar" / Trojaner infiziert
    Plagegeister aller Art und deren Bekämpfung - 09.08.2012 (9)
  15. MyStart incredibar
    Log-Analyse und Auswertung - 23.07.2012 (1)
  16. Mystart Incredibar
    Log-Analyse und Auswertung - 16.07.2012 (7)
  17. mystart.incredibar.com
    Log-Analyse und Auswertung - 07.06.2012 (9)

Zum Thema Rechner mit MyStart by IncrediBar infiziert. - Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code: - Rechner mit MyStart by IncrediBar infiziert....
Du betrachtest: Rechner mit MyStart by IncrediBar infiziert. auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.