eurocatch | 12.02.2012 19:06 | Alles klar. Danke.
so dann nun als Code-Tag
OTL
OTL Logfile: Code:
OTL logfile created on: 2/12/2012 12:33:22 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Hasi\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: Vereinigte Staaten von Amerika | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.74 Gb Available Physical Memory | 58.14% Memory free
6.21 Gb Paging File | 4.84 Gb Available in Paging File | 77.89% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116.44 Gb Total Space | 26.01 Gb Free Space | 22.33% Space Free | Partition Type: NTFS
Drive D: | 106.68 Gb Total Space | 106.58 Gb Free Space | 99.91% Space Free | Partition Type: NTFS
Computer Name: HASI-PC | User Name: Hasi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Hasi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
PRC - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Bandoo\Bandoo.exe (Bandoo Media Inc.)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\ParetoLogic\FileCure\FileCure.exe (ParetoLogic)
PRC - C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)
PRC - C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (MyWebSearch.com)
PRC - C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE (MyWebSearch.com)
PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\Software Informer\softinfo.exe (Informer Technologies, Inc.)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
PRC - C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe (ScanSoft, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\311bc26c3ed83409589eb6bae0eeb86e\System.Runtime.Remoting.ni.dll ()
MOD - C:\Users\Hasi\AppData\Roaming\Mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\{18c2d815-3a16-4493-9004-77949214a70e}\components\RadioWMPCoreGecko10.dll ()
MOD - C:\Program Files\ManyCam\Bin\cximagecrt.dll ()
MOD - C:\Program Files\ManyCam\Bin\CrashRpt.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6bc98e9b5eedaa8f71c5454d36a4b772\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8645de531003807d00822e03986a075d\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\8f3b3ab45e3e5fa61aa6cbfe2a8b61af\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\cbfa4bf002c1abaf94ba8634139727eb\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\9e53d9921c4bb153f1ffbe1ae0e1b615\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Windows\System32\msjetoledb40.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56ita.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56esp.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56brz.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56kor.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56ger.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56fra.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56dnk.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56jpn.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56cht.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56chs.dll ()
========== Win32 Services (SafeList) ==========
SRV - (FLEXnet Licensing Manager) -- File not found
SRV - (AntiVirMailService) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirFirewallService) -- C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG)
SRV - (Bandoo Coordinator) -- C:\Program Files\Bandoo\Bandoo.exe (Bandoo Media Inc.)
SRV - (BBSvc) -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (MyWebSearchService) -- C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE (MyWebSearch.com)
SRV - (SwitchBoard) -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (TeamViewer5) -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Adobe Version Cue CS3) -- C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)
========== Driver Services (SafeList) ==========
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avfwot) -- C:\Windows\System32\drivers\avfwot.sys (Avira GmbH)
DRV - (avfwim) -- C:\Windows\System32\drivers\avfwim.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ManyCam) -- C:\Windows\System32\drivers\ManyCam.sys (ManyCam LLC.)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (SCREAMINGBDRIVER) -- C:\Windows\System32\drivers\ScreamingBAudio.sys (Screaming Bee LLC)
DRV - (TsLwWfF) -- C:\Windows\System32\drivers\TsLwWfF.sys (TamoSoft)
DRV - (ewusbnet) -- C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) -- C:\Windows\System32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (tcpipBM) -- C:\Windows\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (NETw3v32) Intel(R) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (kbfiltr) -- C:\Windows\System32\drivers\kbfiltr.sys ( )
DRV - (MTsensor) -- C:\Windows\System32\drivers\ATKACPI.sys (ATK0100)
DRV - (smserial) -- C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://start.facemoods.com/?a=umail3&s={searchTerms}&f=4
IE - HKLM\..\URLSearchHook: {18c2d815-3a16-4493-9004-77949214a70e} - C:\Program Files\Messenger_Plus_Live_Switzerland-_DE\tbMess.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hiergehtslos.de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKCU\..\URLSearchHook: {18c2d815-3a16-4493-9004-77949214a70e} - C:\Program Files\Messenger_Plus_Live_Switzerland-_DE\tbMess.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local;*.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledItems: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f}:2.5.6.0
FF - prefs.js..extensions.enabledItems: dvscontextmenuy@dvdvideosoft.com:1.0
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
FF - prefs.js..extensions.enabledItems: {18c2d815-3a16-4493-9004-77949214a70e}:3.2.3.3
FF - prefs.js..keyword.URL: "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRxdm117YYCH&ptb=bPN2T9RIHJKe8Nac0uR2dQ&psa=&ind=2010111115&ptnrS=GRxdm117YYCH&si=3140&st=kwd&n=77cfdc8b&searchfor="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll (MyWebSearch.com)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: c:\Program Files\Sony\Media Go\npmediago.dll (Sony Creative Software Inc)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\Hasi\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2010/03/06 12:40:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\1.bin [2010/11/11 21:56:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2011/03/11 10:47:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\HBLite@HBLite.com: C:\Program Files\HBLite\bin\11.0.363.0\firefox\extensions [2011/04/16 19:52:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2011/06/05 23:39:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/02/11 21:52:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/12/05 20:56:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/11 21:52:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/27 13:53:12 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\ffox@bandoo.com: C:\Users\Hasi\AppData\Roaming\Mozilla\Firefox\Profiles/kzh3jbl7.default\extensions\ffox@bandoo.com [2011/07/18 22:40:20 | 000,000,000 | ---D | M]
[2009/08/04 22:23:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hasi\AppData\Roaming\mozilla\Extensions
[2012/01/31 17:40:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions
[2012/01/10 13:31:53 | 000,000,000 | ---D | M] (Messenger Plus Live Switzerland- DE Community Toolbar) -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\{18c2d815-3a16-4493-9004-77949214a70e}
[2011/02/26 15:29:58 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/27 02:28:17 | 000,000,000 | ---D | M] (XfireXO) -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
[2012/01/08 23:57:13 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012/01/11 23:34:12 | 000,000,000 | ---D | M] (BitTorrentBar Community Toolbar) -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2010/10/31 15:47:36 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/01/31 17:40:27 | 000,000,000 | ---D | M] (TranslatorBar 3.2 Community Toolbar) -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\{c55f5517-246e-4426-b745-ee25b08eb8b4}
[2012/01/08 22:23:06 | 000,000,000 | ---D | M] (softonic-de3 Community Toolbar) -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}
[2010/02/05 17:08:43 | 000,000,000 | ---D | M] (DVDVideoSoft Toolbar) -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
[2011/04/24 10:13:27 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\DTToolbar@toolbarnet.com
[2011/03/23 11:49:55 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\engine@conduit.com
[2011/07/18 22:40:20 | 000,000,000 | ---D | M] (Bandoo for Firefox) -- C:\Users\Hasi\AppData\Roaming\mozilla\Firefox\Profiles\kzh3jbl7.default\extensions\ffox@bandoo.com
[2010/02/04 16:45:40 | 000,002,254 | ---- | M] () -- C:\Users\Hasi\AppData\Roaming\Mozilla\Firefox\Profiles\kzh3jbl7.default\searchplugins\askcom.xml
[2011/03/21 15:18:36 | 000,000,879 | ---- | M] () -- C:\Users\Hasi\AppData\Roaming\Mozilla\Firefox\Profiles\kzh3jbl7.default\searchplugins\conduit.xml
[2011/04/14 16:30:40 | 000,002,055 | ---- | M] () -- C:\Users\Hasi\AppData\Roaming\Mozilla\Firefox\Profiles\kzh3jbl7.default\searchplugins\daemon-search.xml
[2010/11/12 23:07:23 | 000,010,058 | ---- | M] () -- C:\Users\Hasi\AppData\Roaming\Mozilla\Firefox\Profiles\kzh3jbl7.default\searchplugins\mywebsearch.xml
[2011/12/22 01:29:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/12/22 01:29:16 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/02/03 19:17:08 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 20:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/02 22:18:37 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011/04/18 13:00:10 | 000,002,191 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/10/02 22:18:37 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/10/02 22:18:37 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011/04/25 17:32:19 | 000,002,049 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml
[2010/10/26 16:57:38 | 000,002,036 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrchppcb.xml
[2011/10/02 22:18:37 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011/10/02 22:18:37 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011/10/02 22:18:37 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
O1 HOSTS File: ([2011/04/13 15:57:43 | 000,001,798 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com
O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
O2 - BHO: (Messenger Plus Live Switzerland- DE Toolbar) - {18c2d815-3a16-4493-9004-77949214a70e} - C:\Program Files\Messenger_Plus_Live_Switzerland-_DE\tbMess.dll (Conduit Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O2 - BHO: (BandooIEPlugin Class) - {EB5CEE80-030A-4ED8-8E20-454E9C68380F} - C:\Program Files\Bandoo\Plugins\IE\ieplugin.dll (Bandoo Media Inc.)
O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
O3 - HKLM\..\Toolbar: (Messenger Plus Live Switzerland- DE Toolbar) - {18c2d815-3a16-4493-9004-77949214a70e} - C:\Program Files\Messenger_Plus_Live_Switzerland-_DE\tbMess.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Messenger Plus Live Switzerland- DE Toolbar) - {18C2D815-3A16-4493-9004-77949214A70E} - C:\Program Files\Messenger_Plus_Live_Switzerland-_DE\tbMess.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (softonic-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [Adobe_ID0EYTHM] C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (MyWebSearch.com)
O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)
O4 - HKLM..\Run: [OPSE reminder] C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [OpwareSE2] C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [fsm] File not found
O4 - HKCU..\Run: [ManyCam] C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)
O4 - HKCU..\Run: [Software Informer] C:\Program Files\Software Informer\softinfo.exe (Informer Technologies, Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\Hasi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O8 - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found
O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Easy-WebPrint - Drucken - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Vorschau - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Hasi\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Hasi\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found
O8 - Extra context menu item: Save YouTube Video as MP3 - C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll (DVSTeam)
O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O9 - Extra 'Tools' menuitem : &Gears-Einstellungen - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1E1B9E92-693A-41A0-8B77-7C6FB225FE29}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E0FAA126-C53A-4EE0-A8B6-9F6C007902BC}: DhcpNameServer = 139.7.30.126 139.7.30.125
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (c:\progra~1\bandoo\bndhook.dll) -c:\Program Files\Bandoo\BndHook.dll (Discordia Limited)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Hasi\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Hasi\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{142dc5d4-926e-11e0-9ce0-002215ee5e28}\Shell - "" = AutoRun
O33 - MountPoints2\{142dc5d4-926e-11e0-9ce0-002215ee5e28}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{43c00110-673e-11e0-b929-001e101f7f74}\Shell - "" = AutoRun
O33 - MountPoints2\{43c00110-673e-11e0-b929-001e101f7f74}\Shell\AutoRun\command - "" = H:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{76f3facd-6694-11e0-81b2-002215ee5e28}\Shell - "" = AutoRun
O33 - MountPoints2\{76f3facd-6694-11e0-81b2-002215ee5e28}\Shell\AutoRun\command - "" = "F:\Adobe CS5\Set-up.exe"
O33 - MountPoints2\{d5bb1f84-4bc1-11e0-a463-002215ee5e28}\Shell - "" = AutoRun
O33 - MountPoints2\{d5bb1f84-4bc1-11e0-a463-002215ee5e28}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{d5bb1f8a-4bc1-11e0-a463-001e101f63cf}\Shell - "" = AutoRun
O33 - MountPoints2\{d5bb1f8a-4bc1-11e0-a463-001e101f63cf}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/12 00:29:01 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Hasi\Desktop\OTL.exe
[2012/02/11 21:20:51 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{9C6DF979-CCEA-4CE0-BECC-BF6E179F2B10}
[2012/02/11 21:20:29 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{8EE76D91-ACCC-4240-8B56-70C85A90ABDB}
[2012/02/11 16:16:31 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{8677BB50-0488-4B0E-9811-3CB12A359A97}
[2012/02/11 16:16:14 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{F03D72E8-2B19-473F-93DE-0F8596FB04FB}
[2012/02/11 10:22:09 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{E86671E3-0248-442F-AD2A-CB4489D3F9DD}
[2012/02/10 16:32:29 | 000,000,000 | ---D | C] -- C:\Users\Hasi\Desktop\Wrestling_Logo
[2012/02/10 16:31:50 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{FE0500C7-1728-402A-A29B-DCDC126BFA91}
[2012/02/10 12:59:31 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{15032FE1-BC94-4B41-B9B9-DC56D181DD51}
[2012/02/09 23:51:31 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{3B725305-42EC-4153-A6C6-A3A146CB0729}
[2012/02/09 23:50:40 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{8650ADCF-82F8-47E5-94E7-8DBA4DD64CBF}
[2012/02/09 09:14:34 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{37360869-98AC-4057-B3F5-62CAFC49E13C}
[2012/02/09 09:14:32 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{E32B7120-C497-405D-BC82-556ACB9E2221}
[2012/02/08 16:02:20 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{367A5F9E-48B4-4161-AD60-4E9CC677A5BF}
[2012/02/08 16:01:59 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{3FC0A8A4-3E82-4947-94F7-F2C9FF259F65}
[2012/02/07 13:10:09 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{7DC8DDCD-3B34-4DE1-AB46-478B18CEA542}
[2012/02/07 13:09:46 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{3FE88DCC-219D-4061-AE0D-370EDBB0E1E9}
[2012/02/06 09:20:46 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{09969E73-3133-4129-B571-E99E414C721A}
[2012/02/06 09:20:09 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{0DC237E8-07AB-49B3-B909-0469D0074C70}
[2012/02/05 13:04:13 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{F304311B-7947-45AB-BCEC-77FC2C43D5AD}
[2012/02/05 13:04:01 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{AA998308-2616-4ED1-B5EF-853762185FBF}
[2012/02/04 16:13:43 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{8B055CD7-81A5-4DF8-B5EE-4ADDD6B334B2}
[2012/02/04 10:31:26 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{E483C49C-6F8E-475F-BB8B-154BA3679C95}
[2012/02/04 09:25:34 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{013DFE52-9F3B-4DE6-AAAD-C76554FC5CF0}
[2012/02/03 19:16:48 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{AF5BA0C1-7907-4B43-B76F-BFF81C5C1E5C}
[2012/02/03 19:16:15 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{0E80110C-60D4-4AF1-8F61-A8E17BB61444}
[2012/02/03 19:16:04 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{B3D5B6EC-F803-4792-8BBC-DAB77A5D8B6E}
[2012/02/03 14:07:47 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{236F1F3B-FB50-4509-B1E5-BC9FCE1BE7FF}
[2012/02/02 09:10:53 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{42F38362-8B31-449E-824E-E3EDC81ACAF0}
[2012/02/02 09:10:48 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{E514614E-F9AA-443E-B5F3-127BDACB6E2E}
[2012/02/01 14:16:00 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{5BD56524-E349-48E5-9652-A71D42BA2DB5}
[2012/02/01 14:15:49 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{5589C3A1-E964-47AF-9DB6-8390D1732FE4}
[2012/01/31 14:07:34 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{A94BA8C9-EF35-481B-8348-878D3279BAD9}
[2012/01/31 14:06:59 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{5748DF97-62EE-413A-A5C4-6B54E0286CD5}
[2012/01/30 09:25:27 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{62839E0D-8B1E-4103-884A-314DDF826A89}
[2012/01/30 09:25:22 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{D120D664-A32E-4F0F-A787-5EC4546F5D0D}
[2012/01/28 18:26:06 | 000,000,000 | ---D | C] -- C:\Users\Hasi\Desktop\Kaffebecher_my
[2012/01/28 13:12:11 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{212FB84A-9CBF-4DA5-B4D7-26CA1F672DE5}
[2012/01/28 13:11:48 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{93B302B5-995C-4980-A934-A4C7F574E38F}
[2012/01/28 12:41:26 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{5AE373DD-DF69-47F9-80FF-495B41A029E6}
[2012/01/28 12:41:07 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{03A66B48-3630-4CC5-8754-E05EED84D217}
[2012/01/27 13:48:16 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{1A6B43A0-9F5E-49AB-BAF4-F539F13719B7}
[2012/01/27 13:47:51 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{C0E69E06-0CC3-426C-BD86-841C95093AA5}
[2012/01/26 09:27:32 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{3D7A060E-77F8-407C-A0CB-0C65E2A7968D}
[2012/01/26 09:27:20 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{FAFEAE86-FC37-4C16-ADA4-22A4EBDBF1A6}
[2012/01/25 13:44:21 | 000,000,000 | ---D | C] -- C:\Users\Hasi\Desktop\Logo_2smu_my
[2012/01/24 10:46:17 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{B3253211-D3FF-4F34-B32A-DB2E00ECBB3A}
[2012/01/23 09:26:01 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{BBC47A17-831F-4032-A188-0265DA891EAE}
[2012/01/23 09:25:50 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{997B4F02-2A5F-4F6F-8591-41C80BDC821A}
[2012/01/22 22:37:30 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{1711E5B6-06B2-4C65-A1E3-6634225F7BE3}
[2012/01/22 14:53:26 | 000,000,000 | ---D | C] -- C:\Users\Hasi\Desktop\TTBFAT
[2012/01/22 12:18:27 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{FC9B56E6-765A-4024-A65A-D8D9C00023F3}
[2012/01/22 04:48:53 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{CEE53F4E-5C8C-4F90-9255-B156E9509FBB}
[2012/01/21 21:41:19 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{AC2CC064-4E6C-4EF0-BFBC-DC08D27A3274}
[2012/01/21 21:41:03 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{0A476FA8-6F11-4CF6-AAAF-5F5AAA31B7A0}
[2012/01/21 04:26:52 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{3323ADC1-DAD0-4FCA-901F-B3ACE0B68C98}
[2012/01/21 04:26:29 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{1BF7E666-A834-4C8D-8DF4-91A4BA03348E}
[2012/01/20 15:49:59 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{F1C4684F-8FCF-45E0-8109-E74A13FEDC59}
[2012/01/19 14:26:05 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{C1663A19-7E06-4CF1-A9B3-A1C7924AA50B}
[2012/01/19 14:25:38 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{57F65ED4-770C-4813-882C-2D5A0B3105F4}
[2012/01/18 13:13:34 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{66DE3803-D227-4E40-A1EF-47DB34C1560C}
[2012/01/18 13:13:08 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{96FD1B2B-DE34-4D50-B7CF-0265978A848A}
[2012/01/17 13:12:09 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{A5DB6A61-DBB9-4715-8450-E3DDBAB90F72}
[2012/01/17 13:11:46 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{FD68E234-7E87-4F06-8315-18C6497B7CF6}
[2012/01/17 12:51:41 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{71E5EE73-B004-4958-BC6A-CDA6766C36C7}
[2012/01/16 12:56:44 | 000,000,000 | ---D | C] -- C:\Users\Hasi\Desktop\Shuggie Otis
[2012/01/16 09:34:06 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{FB32F0A5-F6C7-4DB8-9A71-07CF24D90ECC}
[2012/01/16 09:33:57 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{E381B436-0D70-49AA-9E08-B87BE0FAB157}
[2012/01/15 15:29:44 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{BF66E3B5-3E6D-4804-B47C-E342612667EA}
[2012/01/15 15:29:16 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{BDC66E6E-6321-447E-9BD5-138F6BF040E1}
[2012/01/14 18:50:25 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{4E70EB0F-529F-4157-B0F2-1FCFF9C0D08B}
[2012/01/13 20:09:34 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{963E082F-4AF5-4530-9662-44439D4CFA20}
[2012/01/13 20:09:07 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{76AC041F-5955-438B-9FC5-44DD824C62FA}
[2012/01/13 13:11:50 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{56706B88-72C8-4A22-B33A-AC917DF7B592}
[2012/01/13 13:11:32 | 000,000,000 | ---D | C] -- C:\Users\Hasi\AppData\Local\{5B3162FC-B3FB-4524-9627-9D8D388A7957}
[2009/12/30 20:37:06 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Hasi\AppData\Roaming\pcouffin.sys
[2009/08/05 07:45:26 | 000,005,632 | ---- | C] ( ) -- C:\Windows\System32\drivers\kbfiltr.sys
========== Files - Modified Within 30 Days ==========
[2012/02/12 00:29:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Hasi\Desktop\OTL.exe
[2012/02/12 00:26:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/02/11 23:53:01 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/11 23:53:01 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/11 23:51:59 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/11 21:57:20 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{2CC87FF0-D2DF-426A-A2BF-CABE4C869B1E}.job
[2012/02/11 21:53:17 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/11 21:53:11 | 000,000,378 | ---- | M] () -- C:\Windows\tasks\FileCure Startup.job
[2012/02/11 21:52:53 | 3220,430,848 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/08 22:35:14 | 000,000,680 | ---- | M] () -- C:\Users\Hasi\AppData\Local\d3d9caps.dat
[2012/02/08 18:00:00 | 000,000,442 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Registration3.job
[2012/02/06 11:46:09 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/02/06 11:46:09 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/02/06 11:46:08 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012/02/06 11:46:08 | 000,126,454 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012/02/03 17:47:07 | 000,084,992 | ---- | M] () -- C:\Users\Hasi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/31 04:45:00 | 000,000,362 | ---- | M] () -- C:\Windows\tasks\FileCure Default.job
[2012/01/27 13:53:12 | 000,001,854 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/01/27 00:21:24 | 000,237,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2012/01/23 13:50:35 | 004,185,272 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/01/22 14:53:02 | 119,938,002 | ---- | M] () -- C:\Users\Hasi\Desktop\TTBFAT.zip
========== Files Created - No Company Name ==========
[2012/02/11 21:52:53 | 3220,430,848 | -HS- | C] () -- C:\hiberfil.sys
[2012/01/27 13:53:12 | 000,001,854 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/01/27 13:53:12 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012/01/22 14:50:21 | 119,938,002 | ---- | C] () -- C:\Users\Hasi\Desktop\TTBFAT.zip
[2012/01/12 22:21:29 | 000,001,456 | ---- | C] () -- C:\Users\Hasi\AppData\Local\Adobe Für Web speichern 12.0 Prefs
[2011/08/31 19:00:52 | 000,000,532 | ---- | C] () -- C:\Windows\MAXLINK.INI
[2011/08/31 18:56:04 | 000,434,176 | ---- | C] () -- C:\Windows\System32\CNQL3203.DLL
[2011/07/25 22:47:02 | 000,107,520 | RHS- | C] () -- C:\Windows\System32\TAKDSDecoder.dll
[2011/07/18 22:40:09 | 001,524,112 | ---- | C] () -- C:\Windows\System32\bandoolmx.dll
[2011/03/03 16:55:26 | 000,008,704 | ---- | C] () -- C:\Windows\System32\CNMVS79.DLL
[2011/03/01 21:24:56 | 002,463,976 | ---- | C] () -- C:\Windows\System32\NPSWF32.dll
[2010/10/28 13:26:20 | 000,000,552 | ---- | C] () -- C:\Users\Hasi\AppData\Local\d3d8caps.dat
[2010/10/06 22:03:39 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2010/02/23 22:49:51 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/02/07 15:28:10 | 000,000,048 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010/02/02 08:54:30 | 000,001,041 | ---- | C] () -- C:\Users\Hasi\AppData\Roaming\vso_ts_preview.xml
[2010/02/02 07:04:44 | 001,391,379 | ---- | C] () -- C:\Windows\System32\ffmpegmt.dll
[2010/02/02 07:04:43 | 000,684,636 | ---- | C] () -- C:\Windows\System32\unins000.exe
[2010/02/02 07:04:43 | 000,029,818 | ---- | C] () -- C:\Windows\System32\unins000.dat
[2010/01/24 17:41:08 | 000,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll
[2010/01/24 17:41:08 | 000,045,056 | ---- | C] () -- C:\Windows\System32\unredmon.exe
[2010/01/24 17:41:00 | 000,000,043 | ---- | C] () -- C:\Windows\gswin32.ini
[2010/01/15 20:57:40 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/01/15 20:50:12 | 000,032,256 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2009/12/30 20:41:50 | 000,290,816 | ---- | C] () -- C:\Windows\System32\decdll.dll
[2009/12/30 20:37:06 | 000,087,608 | ---- | C] () -- C:\Users\Hasi\AppData\Roaming\inst.exe
[2009/12/30 20:37:06 | 000,007,887 | ---- | C] () -- C:\Users\Hasi\AppData\Roaming\pcouffin.cat
[2009/12/30 20:37:06 | 000,001,144 | ---- | C] () -- C:\Users\Hasi\AppData\Roaming\pcouffin.inf
[2009/09/24 11:20:49 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/24 11:20:48 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/20 18:54:12 | 000,084,992 | ---- | C] () -- C:\Users\Hasi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/12 19:55:17 | 000,000,680 | ---- | C] () -- C:\Users\Hasi\AppData\Local\d3d9caps.dat
[2009/08/05 07:45:30 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2009/08/05 07:45:29 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2009/08/05 07:45:29 | 000,159,146 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2009/08/05 07:02:09 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009/08/04 23:12:23 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/06/16 13:25:02 | 000,121,512 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2008/04/16 10:30:52 | 000,628,742 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008/04/16 10:30:52 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008/04/16 10:30:52 | 000,126,454 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008/04/16 10:30:52 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2008/04/16 10:01:43 | 000,000,010 | ---- | C] () -- C:\Windows\System32\ABLKSR.ini
[2007/09/20 11:33:52 | 004,426,841 | ---- | C] () -- C:\Windows\System32\libavcodec.dll
[2007/09/20 11:33:52 | 000,849,136 | ---- | C] () -- C:\Windows\System32\ff_x264.dll
[2007/09/20 11:33:52 | 000,815,104 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2007/09/20 11:33:52 | 000,741,376 | ---- | C] () -- C:\Windows\System32\audxlib.dll
[2007/09/20 11:33:52 | 000,557,469 | ---- | C] () -- C:\Windows\System32\libmplayer.dll
[2007/09/20 11:33:52 | 000,336,384 | ---- | C] () -- C:\Windows\System32\ff_libfaad2.dll
[2007/09/20 11:33:52 | 000,256,512 | ---- | C] () -- C:\Windows\System32\ff_kernelDeint.dll
[2007/09/20 11:33:52 | 000,237,056 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll
[2007/09/20 11:33:52 | 000,216,064 | ---- | C] () -- C:\Windows\System32\ff_libdts.dll
[2007/09/20 11:33:52 | 000,176,640 | ---- | C] () -- C:\Windows\System32\ff_samplerate.dll
[2007/09/20 11:33:52 | 000,151,552 | ---- | C] () -- C:\Windows\System32\ff_libmad.dll
[2007/09/20 11:33:52 | 000,146,098 | ---- | C] () -- C:\Windows\System32\libmpeg2_ff.dll
[2007/09/20 11:33:52 | 000,143,360 | ---- | C] () -- C:\Windows\System32\ff_theora.dll
[2007/09/20 11:33:52 | 000,126,976 | ---- | C] () -- C:\Windows\System32\ff_liba52.dll
[2007/09/20 11:33:52 | 000,117,760 | ---- | C] () -- C:\Windows\System32\ff_tremor.dll
[2007/09/20 11:33:52 | 000,098,304 | ---- | C] () -- C:\Windows\System32\ff_wmv9.dll
[2007/09/20 11:33:52 | 000,097,280 | ---- | C] () -- C:\Windows\System32\ff_realaac.dll
[2007/09/20 11:33:52 | 000,095,744 | ---- | C] () -- C:\Windows\System32\ff_unrar.dll
[2007/09/20 11:33:52 | 000,084,480 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2006/11/02 13:53:49 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 13:44:53 | 004,185,272 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 11:33:01 | 000,595,996 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,104,070 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/11/01 07:54:30 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2005/05/06 18:06:00 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[1997/06/14 13:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
========== LOP Check ==========
[2011/03/20 00:32:27 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\AnvSoft
[2011/04/14 22:09:10 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Azureus
[2011/07/19 08:47:18 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Bandoo
[2011/02/24 18:51:27 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\BitTorrent
[2011/03/11 10:49:03 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Bytemobile
[2011/08/31 19:31:24 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Canon
[2011/03/03 17:01:44 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\CD-LabelPrint
[2011/06/08 16:49:04 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/12/16 22:13:54 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\DAEMON Tools Lite
[2012/02/10 00:44:43 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\DVDVideoSoft
[2011/12/21 20:09:06 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/02/02 00:00:31 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\FileZilla
[2011/10/31 09:25:55 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Free Download Manager
[2011/04/16 19:52:42 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\HBLite
[2010/02/05 22:46:21 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\HLSW
[2010/03/03 23:28:14 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Leadertech
[2010/10/07 01:13:28 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\ManyCam
[2010/01/13 21:52:17 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Octoshape
[2009/09/08 21:32:39 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\OpenOffice.org
[2010/01/26 23:56:36 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Publish Providers
[2011/08/31 19:01:07 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\ScanSoft
[2010/01/07 09:03:04 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Screaming Bee
[2010/01/24 17:52:04 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Softland
[2012/02/11 21:57:48 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Software Informer
[2010/06/22 00:57:56 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Sony
[2010/06/21 23:53:02 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Sony Setup
[2011/08/16 11:53:57 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/01/01 05:28:47 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\SWiSH Max3
[2010/01/17 03:03:44 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\TeamViewer
[2011/10/06 13:02:59 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\TuneUpMedia
[2010/01/01 03:23:36 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Ubisoft
[2011/02/24 18:03:59 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Uniblue
[2012/02/12 00:37:31 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\uTorrent
[2011/03/11 10:49:02 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Vodafone
[2011/03/11 10:58:02 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Vodafone Mobile Connect
[2011/05/05 18:09:51 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\Vso
[2010/10/07 02:58:48 | 000,000,000 | ---D | M] -- C:\Users\Hasi\AppData\Roaming\WebcamMax
[2012/01/31 04:45:00 | 000,000,362 | ---- | M] () -- C:\Windows\Tasks\FileCure Default.job
[2012/02/11 21:53:11 | 000,000,378 | ---- | M] () -- C:\Windows\Tasks\FileCure Startup.job
[2012/02/08 18:00:00 | 000,000,442 | ---- | M] () -- C:\Windows\Tasks\ParetoLogic Registration3.job
[2012/02/10 01:40:14 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/02/11 21:57:20 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{2CC87FF0-D2DF-426A-A2BF-CABE4C869B1E}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 64 bytes -> C:\Users\Hasi\Documents\left4dead#03.avi:TOC.WMV
@Alternate Data Stream - 12 bytes -> C:\Windows\System32:{4B9A1497-0817-47C4-9612-D6A1C53ACF57}
< End of report > --- --- --- |