3.
Extras: Code:
OTL Extras logfile created on: 11/17/2011 2:46:06 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Tarik\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
6.00 Gb Total Physical Memory | 4.27 Gb Available Physical Memory | 71.12% Memory free
12.00 Gb Paging File | 9.74 Gb Available in Paging File | 81.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 917.81 Gb Total Space | 717.59 Gb Free Space | 78.18% Space Free | Partition Type: NTFS
Drive D: | 13.60 Gb Total Space | 1.68 Gb Free Space | 12.39% Space Free | Partition Type: NTFS
Drive G: | 232.88 Gb Total Space | 150.81 Gb Free Space | 64.76% Space Free | Partition Type: NTFS
Computer Name: TARIK-HP | User Name: Tarik | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{11BA2B00-1495-47B8-BFA8-D08C605AB2CC}" = Windows Live Family Safety
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{31A6FA40-E935-11E0-95F9-F04DA23A5C58}" = Vegas Pro 11.0 (64-bit)
"{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1" = MotioninJoy ds3 driver version 0.6.0001
"{33C19CDE-E935-11E0-A0DA-F04DA23A5C58}" = MSVCRT Redists
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{51317AF5-D39F-49EC-A4B5-87451466B837}" = AMD Fuel
"{54E192A6-AA33-1963-C96A-26AA7A3B41B4}" = ccc-utility64
"{5857E7BE-2F6F-D41A-42B2-B668B19A5F30}" = AMD Media Foundation Decoders
"{5B08AF35-B699-4A44-BB89-3E51E70611E8}" = HP MediaSmart SmartMenu
"{5DF57DB1-D971-3DA3-B4BB-F6FC7D73A997}" = AMD Drag and Drop Transcoding
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile-Gerätecenter
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{C9608300-11F5-11E0-A64B-0013D3D69929}" = MSVCRT Redists
"{CEA21F20-DBF4-464C-8B81-28B8508AFDDD}" = Windows Live Family Safety
"{CFF9D801-1EC4-B8F5-2CAB-4A1790C95A18}" = ATI Catalyst Install Manager
"{D3A82E80-D0A5-11DF-B425-0013D3D69929}" = Vegas Pro 10.0 (64-bit)
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D79A02E9-6713-4335-9668-AAC7474C0C0E}" = HP Vision Hardware Diagnostics
"{D81C035E-D0A5-11DF-9450-0013D3D69929}" = MSVCRT Redists
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX 64" = Adobe Flash Player 10 ActiveX 64-bit
"CCleaner" = CCleaner
"GenArts SapphireEdge Plug-ins for OFX_is1" = GenArts SapphireEdge Plug-ins 1.0 for OFX
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"NVIDIA Drivers" = NVIDIA Drivers
"WinRAR archiver" = WinRAR 4.00 (64-Bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{19A492A0-888F-44A0-9B21-D91700763F62}" = Catalyst Control Center - Branding
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1C7108CF-774A-11E0-B3C5-0013D3D69929}" = Vegas Pro 10.0
"{1D7CE340-70C3-4848-BCCF-215950328A4C}" = Facebook Video Calling 1.0.0.8953
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{229B6751-774A-11E0-BCAE-0013D3D69929}" = MSVCRT Redists
"{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 22
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{30D659E4-4405-6925-CDCF-EB8CD0C80DAC}" = Catalyst Control Center Graphics Previews Common
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3CA2B4FD-AEF2-ED4F-F5E5-0095DDA47AC7}" = Adobe Download Assistant
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}" = LightScribe System Software
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{5D4C60AA-84E6-4E1A-8A68-69970D387BE1}" = TuneUp Utilities Language Pack (de-DE)
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{60DE7978-4F13-5584-5E53-DCEE1CB115A5}" = AMD VISION Engine Control Center
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.1.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72D90DB3-A16A-4545-B555-868471101833}" = HP Setup
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{85268C72-C609-E50A-7AB3-9B3582DFEE66}" = CCC Help English
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0407-1000-0000000FF1CE}_Office14.SingleImage_{594128C9-2CDF-43CE-8103-DC100CF013B6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{AFF8C8F4-E4BB-891F-8636-5E71F946C5B6}" = Catalyst Control Center InstallProxy
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B95B1BA9-F887-4B3C-8D3A-CCD4C4675120}" = Microsoft Default Manager
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}" = HP Support Assistant
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DE77FE3F-A33D-499A-87AD-5FC406617B40}" = HP Update
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"aTube Catcher" = aTube Catcher
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"DivX Setup.divx.com" = DivX-Setup
"Foxit Creator" = Foxit Creator
"Foxit Reader" = Foxit Reader
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"JDownloader" = JDownloader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.2.1300
"Mozilla Firefox 8.0 (x86 de)" = Mozilla Firefox 8.0 (x86 de)
"Mp3tag" = Mp3tag v2.49
"MusicStationNetstaller" = MusicStation
"NewBlue 3D Explosions for Windows" = NewBlue 3D Explosions for Windows
"NewBlue 3D Transformations for Windows" = NewBlue 3D Transformations for Windows
"NewBlue Art Blends for Windows" = NewBlue Art Blends for Windows
"NewBlue Art Effects for Windows" = NewBlue Art Effects for Windows
"NewBlue Film Effects for Windows" = NewBlue Film Effects for Windows
"NewBlue Motion Blends for Windows" = NewBlue Motion Blends for Windows
"NewBlue Motion Effects for Windows" = NewBlue Motion Effects for Windows
"NewBlue Video Essentials for Windows" = NewBlue Video Essentials for Windows
"Office14.SingleImage" = Microsoft Office Home and Business 2010
"PDF Complete" = PDF Complete Special Edition
"RocketDock_is1" = RocketDock 1.3.5
"TuneUp Utilities 2011" = TuneUp Utilities 2011
"WinLiveSuite" = Windows Live Essentials
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report > OTL: Code:
OTL logfile created on: 11/17/2011 2:46:06 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Tarik\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
6.00 Gb Total Physical Memory | 4.27 Gb Available Physical Memory | 71.12% Memory free
12.00 Gb Paging File | 9.74 Gb Available in Paging File | 81.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 917.81 Gb Total Space | 717.59 Gb Free Space | 78.18% Space Free | Partition Type: NTFS
Drive D: | 13.60 Gb Total Space | 1.68 Gb Free Space | 12.39% Space Free | Partition Type: NTFS
Drive G: | 232.88 Gb Total Space | 150.81 Gb Free Space | 64.76% Space Free | Partition Type: NTFS
Computer Name: TARIK-HP | User Name: Tarik | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/17 14:44:43 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Tarik\Downloads\OTL.exe
PRC - [2011/11/09 13:50:10 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/06/28 15:55:22 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/03/28 16:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2011/03/28 15:15:04 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011/03/28 15:14:56 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/04/23 21:00:00 | 000,514,232 | ---- | M] (EasyBits Software AS) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2010/01/18 19:21:08 | 000,568,888 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
PRC - [2009/10/15 00:53:20 | 000,635,416 | ---- | M] (PDF Complete Inc) -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe
PRC - [2008/11/20 19:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
PRC - [2007/09/02 12:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.exe
========== Modules (No Company Name) ==========
MOD - [2011/11/09 13:50:10 | 001,989,592 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/09/25 07:03:16 | 006,277,280 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2010/01/18 19:21:08 | 000,568,888 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
MOD - [2007/09/02 12:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.exe
MOD - [2007/09/02 12:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/09/16 15:44:36 | 000,036,160 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
SRV:64bit: - [2011/05/25 04:03:38 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011/05/24 22:18:38 | 000,365,568 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/03/05 02:25:36 | 000,209,000 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp)
SRV:64bit: - [2010/03/05 02:25:34 | 000,496,232 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM))
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2011/09/16 15:51:20 | 002,027,840 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2011/09/16 15:44:28 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/06/28 15:55:22 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/06/21 14:57:34 | 000,085,560 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe -- (HP Support Assistant Service)
SRV - [2011/03/28 16:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)
SRV - [2011/03/28 15:15:04 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/10/15 00:53:20 | 000,635,416 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2007/05/31 16:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 16:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/11/01 22:58:14 | 000,117,520 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV:64bit: - [2011/08/31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011/06/28 15:55:22 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011/06/28 15:55:22 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011/05/25 05:26:56 | 009,359,872 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/05/25 03:25:42 | 000,309,760 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/03/30 19:46:44 | 000,114,704 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/09/22 23:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010/08/19 18:24:34 | 000,074,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2010/04/08 00:12:02 | 000,124,944 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010/03/04 12:26:58 | 000,349,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvmf6264.sys -- (NVNET)
DRV:64bit: - [2010/02/18 08:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2011/05/10 10:52:12 | 000,481,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2011/05/10 10:52:12 | 000,136,824 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/02/10 09:22:58 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPDSK/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPDSK/4
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "Google.de"
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.backup.ftp: "98.166.234.138"
FF - prefs.js..network.proxy.backup.ftp_port: 8085
FF - prefs.js..network.proxy.backup.socks: "98.166.234.138"
FF - prefs.js..network.proxy.backup.socks_port: 8085
FF - prefs.js..network.proxy.backup.ssl: "98.166.234.138"
FF - prefs.js..network.proxy.backup.ssl_port: 8085
FF - prefs.js..network.proxy.ftp: "68.169.39.192"
FF - prefs.js..network.proxy.ftp_port: 22085
FF - prefs.js..network.proxy.http: "68.169.39.192"
FF - prefs.js..network.proxy.http_port: 22085
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "68.169.39.192"
FF - prefs.js..network.proxy.socks_port: 22085
FF - prefs.js..network.proxy.ssl: "68.169.39.192"
FF - prefs.js..network.proxy.ssl_port: 22085
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Tarik\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/05/08 15:24:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/05/08 15:24:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/09 13:50:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/07 22:43:53 | 000,000,000 | ---D | M]
[2011/03/31 12:40:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tarik\AppData\Roaming\mozilla\Extensions
[2011/11/15 00:01:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tarik\AppData\Roaming\mozilla\Firefox\Profiles\79wa8i6p.default\extensions
[2011/10/05 08:52:10 | 000,002,401 | ---- | M] () -- C:\Users\Tarik\AppData\Roaming\Mozilla\Firefox\Profiles\79wa8i6p.default\searchplugins\askcom.xml
[2011/11/09 17:32:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\TARIK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\79WA8I6P.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\TARIK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\79WA8I6P.DEFAULT\EXTENSIONS\FINDER@MEINGUTSCHEINCODE.DE.XPI
[2011/11/09 13:50:10 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/01/01 09:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010/01/01 09:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010/01/01 09:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010/01/01 09:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Tarik\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5C5B8455-A49D-4FC1-8E82-BD73DF535F3A}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O27:64bit: - HKLM IFEO\ezsecshield.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\ezsecshield.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/07/01 15:23:43 | 000,000,000 | R--D | M] - G:\autorun -- [ NTFS ]
O32 - Unable to obtain root file information for disk G:\
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/17 10:06:03 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{58C47C14-2F37-4212-A8C8-06D631DABC38}
[2011/11/17 10:05:50 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{CDE349A0-3FD1-40B3-B26D-2D512A4193A6}
[2011/11/16 20:52:44 | 001,564,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Tarik\Desktop\TDSSKiller.exe
[2011/11/16 12:26:20 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{6EDC96CF-70D2-4ED3-97C1-585C2C5BFD26}
[2011/11/16 12:26:08 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{B95BAF7C-92AB-4E60-814B-D032A1C11FE8}
[2011/11/15 18:55:12 | 000,000,000 | ---D | C] -- C:\Users\Tarik\Documents\OFX Presets
[2011/11/15 17:29:41 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{864F6873-79C6-4B82-B165-F596FF9443B4}
[2011/11/15 17:29:26 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{A6E0ADC7-7B61-458A-AFDB-ADDE890B2DEB}
[2011/11/15 00:31:14 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{CE68F8B0-8323-4E6C-BD7A-2DD385D8350E}
[2011/11/15 00:31:01 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{C7E02587-ECF6-42AB-AE10-195ED19EC478}
[2011/11/14 22:34:08 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Roaming\Malwarebytes
[2011/11/14 22:33:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/14 22:33:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/11/14 22:33:43 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/11/14 22:33:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/14 21:22:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Tools Security
[2011/11/14 21:22:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2011/11/14 21:19:11 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2011/11/14 12:30:33 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{CA8F7788-D333-416D-A424-B67918D4A732}
[2011/11/14 12:30:21 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{E98A1CCA-B7F9-43F1-B0C9-7787C16DE465}
[2011/11/13 21:15:30 | 000,000,000 | ---D | C] -- C:\Users\Tarik\Documents\Hörbuch
[2011/11/13 21:05:06 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{C9DDE7A6-2C7B-4CB3-B16E-A56508734A19}
[2011/11/13 21:04:53 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{C03462B5-712E-48CC-9574-3DA1D9791343}
[2011/11/13 09:04:06 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{7A3599DA-FD12-4FDB-93A4-3988F9DBE3C3}
[2011/11/13 09:03:52 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{1B01A0B9-48F9-422A-990D-CC7AD704025E}
[2011/11/12 10:59:19 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{13A121A4-AC2E-489A-ACED-C5E4D633CC81}
[2011/11/12 10:59:08 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{9D24F2E8-717E-47CB-B0D6-97F3CE157FF8}
[2011/11/11 22:58:39 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{DD178FEE-9F2F-4DD3-901A-402E92CC5EA3}
[2011/11/11 22:58:27 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{67E05047-5FAD-4124-A2B6-75BEA77A634A}
[2011/11/11 10:57:56 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{1EA9DD86-73EA-4D65-BD9D-AA0091BECACC}
[2011/11/11 10:57:41 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{D96036F6-82D3-451E-A939-366293381B69}
[2011/11/11 00:10:05 | 000,000,000 | ---D | C] -- C:\Users\Tarik\Documents\Quali 2010
[2011/11/11 00:09:20 | 000,000,000 | ---D | C] -- C:\Users\Tarik\Documents\Links2
[2011/11/11 00:08:48 | 000,000,000 | ---D | C] -- C:\Users\Tarik\Documents\Meine empfangenen Dateien
[2011/11/11 00:01:22 | 000,000,000 | ---D | C] -- C:\Users\Tarik\Documents\Photoshop
[2011/11/10 23:59:50 | 000,000,000 | ---D | C] -- C:\Users\Tarik\Documents\Sony Vegas
[2011/11/10 11:39:12 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{798F60D4-0C40-43B6-B4B6-614FCF2BF5A8}
[2011/11/10 11:39:01 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{23AC28EB-D829-4A34-BABD-00B74A9F56AC}
[2011/11/10 00:04:35 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\Facebook
[2011/11/09 23:38:34 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{F65050C3-FFFF-4AA3-9C0A-8A51B181147C}
[2011/11/09 23:38:22 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{8ECBE330-F342-44CB-A32A-02B176934D87}
[2011/11/09 11:37:42 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{4645F517-EF7E-4FD2-8D0E-D26B6B676F3E}
[2011/11/09 11:37:29 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{03E18D2A-D0E2-44BB-AF28-8AB1D34AAA3E}
[2011/11/08 23:16:14 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{4B637F14-14EA-4933-AA9B-34D1B9328EA9}
[2011/11/08 23:16:01 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{1D54B9D2-DF01-4192-A9BC-E93FDD114FB0}
[2011/11/08 11:15:33 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{4A92C528-D8F7-4135-81AA-BBBA178E3598}
[2011/11/08 11:15:20 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{20D0B301-BE7A-435F-BD3C-C58AE881314C}
[2011/11/07 20:50:04 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2011/11/07 17:10:49 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{9BA818B0-77C7-43CC-8AA1-16DF4D17515D}
[2011/11/07 17:10:33 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{70DCF78A-F80D-4CF5-A93C-1C4D6FA9F9D3}
[2011/11/06 23:34:29 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{6CA0EB60-A7A3-41CB-8944-566F35B027FA}
[2011/11/06 11:33:56 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{A448F4DC-E21E-41BF-A573-C9FFA14774EA}
[2011/11/06 11:33:39 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{1B02F3A4-97C7-4916-B961-FDAA168BEEA4}
[2011/11/05 16:04:45 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{573D1738-C157-4908-8C05-2646E25E8CDA}
[2011/11/05 16:04:26 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{31CC02F7-31B2-4E5C-8D16-3652D9BF3E1A}
[2011/11/04 23:20:48 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{0FE081F2-130A-4D7A-BFF1-76EA7C245231}
[2011/11/04 23:20:37 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{3AD3AE58-E7A0-42BF-8F35-32114ECBF853}
[2011/11/04 11:20:06 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{D23716BE-6041-446D-A8D8-51A3CE2F1A1B}
[2011/11/04 11:19:54 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{D1ADA8F5-E048-42BF-A374-21CB1F24A398}
[2011/11/03 20:22:44 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{B3149E1F-375F-45C1-B8DF-B6FF394F7237}
[2011/11/03 20:22:32 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{1ABFDCF9-BF1A-48BB-8198-C6B431A0EAC9}
[2011/11/03 08:22:01 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{2E57C71B-2791-4876-BA02-117A22B5AD60}
[2011/11/03 08:21:48 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{7D07CAA3-063B-4D81-9C7D-6537B18B6627}
[2011/11/02 18:56:18 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{095DF9A8-AB33-41FE-899F-6C9705069FC0}
[2011/11/02 18:56:05 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{E81719A6-9D6F-4497-8D12-C6F400890756}
[2011/11/01 23:30:54 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{7E6F863C-97AB-4946-B5E9-0600136AA57E}
[2011/11/01 23:30:43 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{00F69401-1B11-41BC-B9EB-3AC8AEB00168}
[2011/11/01 11:30:14 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{46BE2058-0C7D-401A-AA17-458C486FEE3C}
[2011/11/01 11:30:02 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{5CDAD7B6-172B-49FE-A1CA-AA5D33CCBAF3}
[2011/10/31 23:26:31 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{5BAC46B5-31E2-47CC-BBB8-7F0D7FD83888}
[2011/10/31 23:26:19 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{CE1953CA-8D19-4198-ABFC-6BBAA4F2C13B}
[2011/10/31 11:14:13 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{E3DE74F4-1B7E-4C0C-9CC6-5703E94CA988}
[2011/10/31 11:13:59 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{17CCB99A-50E4-43CE-9B94-79B18E91EBBF}
[2011/10/30 23:13:32 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{9C85C78C-62D7-4FC5-A243-993F931D9566}
[2011/10/30 23:13:20 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{4F0B5EBA-AC19-405B-886A-EF41F2759637}
[2011/10/30 11:12:53 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{35926FE3-BBA7-4F12-92AC-FFE6655A1F1F}
[2011/10/30 11:12:41 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{BD25716A-C11F-4ABF-B874-D226EA86DCFB}
[2011/10/29 23:12:14 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{B2A3859C-ECBE-4FA4-8DF1-D765B86EC299}
[2011/10/29 23:12:03 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{A21F202E-BFAC-4068-9373-06A1379AEB5E}
[2011/10/29 11:11:36 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{C7D47131-CB38-4A39-90EB-0604C71D1D35}
[2011/10/29 11:11:24 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{CE2176F9-590D-4A1F-AE67-0010488D5B8A}
[2011/10/28 23:10:57 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{38413A2D-154A-4177-BEF3-DF2DB471895C}
[2011/10/28 23:10:45 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{CC751866-8EE4-454D-A43C-A95DF28862A2}
[2011/10/28 11:10:18 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{4B5D20EF-EEE1-48D4-AC00-CA71F6B34D23}
[2011/10/28 11:10:06 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{BAE744CE-7C32-489B-8E28-91DA71559E57}
[2011/10/27 23:09:39 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{2222ED6E-C3A9-4AA7-B193-F99AC58F0C97}
[2011/10/27 23:09:27 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{7C5ABA93-F4D8-46F0-9908-1770832048CB}
[2011/10/27 11:08:59 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{A3567F77-6FFF-4288-B3BF-3A1F11D55375}
[2011/10/27 11:08:32 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{FE0835F6-12E9-4C9C-864E-E2285563B947}
[2011/10/26 12:20:42 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{239DB737-E6B2-4793-B544-C853C064A4D2}
[2011/10/26 12:20:30 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{61EE020C-08CE-46E6-AABA-56AD6CD683EB}
[2011/10/25 11:28:52 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{B6B1C5C4-AA40-4A76-82D0-A86E6430C1D1}
[2011/10/25 11:28:39 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{78859CD7-0CFF-4A9B-BA2E-8B3E6CBB253A}
[2011/10/24 21:56:43 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{0DDC3E53-0DCF-4F09-8D34-6BBFD725A46C}
[2011/10/24 21:56:32 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{B407D6E1-416D-464D-A7AD-5FB0827979DC}
[2011/10/24 09:56:01 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{FF532406-76C2-4BCD-B2CE-9BE80B0ADD83}
[2011/10/24 09:55:49 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{52F9747B-36B8-4867-BDCA-D4AC4790DE51}
[2011/10/23 16:53:09 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{B405E183-7B77-4ACB-A1A6-BC536B841A8F}
[2011/10/23 16:52:48 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{1856462E-FEEE-47D3-8A4F-8FCBE5BD0727}
[2011/10/22 20:50:49 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{0B9F10AF-81FD-4045-812E-2EA72E9A0715}
[2011/10/22 20:50:19 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{E4F01377-29D8-4D71-8D3C-FF24D5AB6B16}
[2011/10/21 23:10:00 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{512F5EC5-0362-4968-8DF5-33D3DF456FF6}
[2011/10/21 23:09:48 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{090E5F39-476D-4ABA-A02A-27D67B13493C}
[2011/10/21 11:09:18 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{6E23105D-3B57-4203-8970-CFBD25E81E2F}
[2011/10/21 11:09:05 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{679C9EC2-5F0F-4B81-8AFD-C6110E6D239C}
[2011/10/20 11:38:16 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{48786813-C3F5-474C-A883-751B6FCB7D2F}
[2011/10/20 11:38:04 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{F14C98CF-FBEA-4E96-BB2B-AC8705D47FA1}
[2011/10/18 22:57:52 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{FB188636-3959-4DA9-AA45-B8DB70E4E3A2}
[2011/10/18 22:57:40 | 000,000,000 | ---D | C] -- C:\Users\Tarik\AppData\Local\{621493C3-44FE-4B12-9EED-9CDFA6CC365C}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/17 12:22:50 | 000,015,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/17 12:22:50 | 000,015,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/17 12:15:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/17 12:15:18 | 536,322,047 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/17 00:09:02 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2069348105-253727359-2489619733-1000UA.job
[2011/11/17 00:09:01 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2069348105-253727359-2489619733-1000Core.job
[2011/11/16 20:51:48 | 001,545,858 | ---- | M] () -- C:\Users\Tarik\Desktop\tdsskiller.zip
[2011/11/16 12:21:12 | 001,564,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Tarik\Desktop\TDSSKiller.exe
[2011/11/14 23:09:00 | 000,000,000 | ---- | M] () -- C:\Users\Tarik\defogger_reenable
[2011/11/14 22:46:03 | 000,684,297 | ---- | M] () -- C:\Users\Tarik\Desktop\unhide.exe
[2011/11/14 22:33:51 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/14 21:24:08 | 001,845,358 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2011/11/14 21:17:49 | 000,000,432 | ---- | M] () -- C:\ProgramData\gohO3ZswT2WugB
[2011/11/14 21:11:05 | 000,000,288 | ---- | M] () -- C:\ProgramData\~gohO3ZswT2WugB
[2011/11/14 21:11:05 | 000,000,216 | ---- | M] () -- C:\ProgramData\~gohO3ZswT2WugBr
[2011/11/11 19:45:20 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForTarik.job
[2011/11/09 17:33:35 | 004,912,240 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/03 13:53:20 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/03 13:53:20 | 000,653,928 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011/11/03 13:53:20 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/11/03 13:53:20 | 000,129,800 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011/11/03 13:53:20 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/11/01 22:58:14 | 000,117,520 | ---- | M] (MotioninJoy) -- C:\Windows\SysNative\drivers\MijXfilt.sys
[2011/10/24 13:17:25 | 000,000,317 | ---- | M] () -- C:\Windows\MSUTIL.INI
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/16 20:51:48 | 001,545,858 | ---- | C] () -- C:\Users\Tarik\Desktop\tdsskiller.zip
[2011/11/14 23:09:00 | 000,000,000 | ---- | C] () -- C:\Users\Tarik\defogger_reenable
[2011/11/14 22:45:53 | 000,684,297 | ---- | C] () -- C:\Users\Tarik\Desktop\unhide.exe
[2011/11/14 22:33:51 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/14 21:23:00 | 001,845,358 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2011/11/14 20:43:29 | 000,000,216 | ---- | C] () -- C:\ProgramData\~gohO3ZswT2WugBr
[2011/11/14 20:43:28 | 000,000,288 | ---- | C] () -- C:\ProgramData\~gohO3ZswT2WugB
[2011/11/14 20:43:17 | 000,000,432 | ---- | C] () -- C:\ProgramData\gohO3ZswT2WugB
[2011/11/10 00:04:55 | 000,000,928 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2069348105-253727359-2489619733-1000UA.job
[2011/11/10 00:04:54 | 000,000,906 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2069348105-253727359-2489619733-1000Core.job
[2011/10/05 20:57:28 | 000,000,317 | ---- | C] () -- C:\Windows\MSUTIL.INI
[2011/05/24 22:44:26 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/05/09 19:51:57 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2011/04/09 13:44:56 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2011/03/31 21:45:26 | 000,000,056 | ---- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011/03/17 18:51:44 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010/12/02 04:30:41 | 000,009,988 | ---- | C] () -- C:\Windows\SysWow64\ezdigsgn.dat
[2010/12/02 03:58:59 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/09/28 13:00:12 | 000,012,800 | ---- | C] () -- C:\Windows\LPRES.DLL
[2010/01/22 23:04:16 | 000,000,605 | ---- | C] () -- C:\Windows\m3jpeg.ini
[2009/07/14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/04/15 12:51:18 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\Azureus
[2011/06/05 08:50:55 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/04/11 18:50:13 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\Foxit Software
[2011/04/01 13:36:11 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\MotioninJoy
[2011/11/12 13:11:56 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\Mp3tag
[2011/04/05 17:59:22 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\Publish Providers
[2011/04/09 22:31:51 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\Raptr
[2011/10/24 11:03:37 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\Sony
[2011/10/04 09:41:47 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\Sony Creative Software Inc
[2011/05/12 23:01:29 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\TuneUp Software
[2011/04/08 19:25:52 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\WinBatch
[2011/04/29 23:00:41 | 000,000,000 | ---D | M] -- C:\Users\Tarik\AppData\Roaming\Windows Live Writer
[2011/11/17 00:09:01 | 000,000,906 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2069348105-253727359-2489619733-1000Core.job
[2011/11/17 00:09:02 | 000,000,928 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2069348105-253727359-2489619733-1000UA.job
[2011/10/01 07:35:41 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 153 bytes -> C:\ProgramData\Temp:DFC5A2B2
< End of report > |