Archiv_Index | 02.05.2013 15:58 | Hi,
Hab die Schritte abgearbeitet.
Der weiße Desktop ist verschwunden.
Interaktionen mit windows wieder möglich.
Hier der Fixlog von OTL: Code:
All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Users\Bastian\AppData\Roaming\skype.dat deleted successfully.
C:\Users\Bastian\AppData\Roaming\skype.dat moved successfully.
========== FILES ==========
File\Folder C:\Users\Bastian\AppData\Roaming\skype.dat not found.
C:\Users\Bastian\AppData\Roaming\skype.ini moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: AppData
User: Bastian
->Temp folder emptied: 1594457911 bytes
->Temporary Internet Files folder emptied: 380642538 bytes
->Java cache emptied: 27805 bytes
->FireFox cache emptied: 103238644 bytes
->Google Chrome cache emptied: 62023942 bytes
->Opera cache emptied: 341102214 bytes
->Flash cache emptied: 100221711 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 401408 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 7386958786 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 85291 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 9.507,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 05022013_155608
Files\Folders moved on Reboot...
C:\Users\Bastian\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Bastian\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot... und hier das Ergebnis des Quick Scans
OTL Logfile: Code:
OTL logfile created on: 02.05.2013 16:13:38 - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bastian\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,99 Gb Total Physical Memory | 2,29 Gb Available Physical Memory | 57,50% Memory free
7,98 Gb Paging File | 6,11 Gb Available in Paging File | 76,62% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 689,04 Gb Total Space | 16,10 Gb Free Space | 2,34% Space Free | Partition Type: NTFS
Drive D: | 689,57 Gb Total Space | 64,14 Gb Free Space | 9,30% Space Free | Partition Type: NTFS
Drive F: | 7,83 Gb Total Space | 7,82 Gb Free Space | 99,90% Space Free | Partition Type: FAT32
Computer Name: BASTIAN-PC | User Name: Bastian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.04.26 21:36:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bastian\Desktop\OTL.exe
PRC - [2013.02.26 00:32:22 | 001,260,320 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013.01.26 08:08:30 | 004,480,768 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Bastian\AppData\Local\Akamai\netsession_win.exe
PRC - [2013.01.18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.12.07 00:31:33 | 002,443,800 | ---- | M] () -- C:\ProgramData\BrowserProtect\2.5.986.67\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
PRC - [2012.10.01 17:53:23 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012.09.23 21:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.09.19 16:27:56 | 001,100,680 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe
PRC - [2012.09.19 16:21:14 | 000,795,072 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
PRC - [2012.08.08 13:56:46 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.05.26 13:45:32 | 000,880,496 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012.05.09 15:24:32 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.09 15:24:31 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.03.21 15:07:14 | 000,692,888 | ---- | M] () -- C:\Users\Bastian\AppData\Roaming\BrowserCompanion\tcbhn.exe
PRC - [2011.12.16 08:55:44 | 000,187,696 | ---- | M] (Blabbers Communications LTD) -- C:\Program Files (x86)\BrowserCompanion\BCHelper.exe
PRC - [2011.11.14 00:27:20 | 000,354,416 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe
PRC - [2011.11.14 00:27:18 | 000,433,264 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe
PRC - [2011.11.14 00:27:06 | 000,103,536 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
PRC - [2011.11.13 23:55:18 | 011,839,488 | ---- | M] () -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
PRC - [2011.11.13 22:49:40 | 000,079,872 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
PRC - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011.07.29 22:45:56 | 000,217,256 | ---- | M] (Visicom Media Inc. (Powered by Panda Security)) -- C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe
PRC - [2011.07.20 13:37:54 | 000,206,336 | ---- | M] () -- C:\Program Files (x86)\PC Beschleunigen\PCSUService.exe
PRC - [2011.05.16 11:22:26 | 000,025,464 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe
PRC - [2011.03.30 16:44:58 | 001,324,008 | ---- | M] (Iminent) -- C:\Program Files (x86)\Iminent\IMBooster\IMBooster.exe
PRC - [2010.11.21 11:49:24 | 000,247,608 | ---- | M] () -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.11.20 14:17:55 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
PRC - [2010.11.04 15:18:35 | 000,779,728 | ---- | M] (Symantec Corporation) -- C:\Program Files (x86)\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\18.0.0.128\InstStub.exe
PRC - [2010.10.22 02:00:00 | 002,105,344 | ---- | M] (AVM Berlin) -- C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
PRC - [2010.10.22 02:00:00 | 000,376,832 | ---- | M] (AVM Berlin) -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
PRC - [2010.09.02 22:18:02 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee Security Scan\2.0.189\SSScheduler.exe
PRC - [2010.08.04 14:40:12 | 000,611,872 | ---- | M] () -- C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe
PRC - [2010.05.23 07:39:05 | 000,126,904 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\18.0.0.128\ccSvcHst.exe
PRC - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe
PRC - [2010.01.08 15:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
PRC - [2009.12.18 19:30:04 | 000,093,568 | ---- | M] (North Star com.) -- C:\Program Files (x86)\Northstar\Photo Frame\Photo Frame.exe
PRC - [2009.10.13 11:25:54 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009.10.13 11:25:30 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
PRC - [2009.09.29 16:59:58 | 002,275,360 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Packard Bell\Software Suite SE\SoftSuiteSE.exe
PRC - [2009.06.15 11:22:00 | 000,537,120 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Packard Bell\Software Suite SE\SEDevDetect.exe
PRC - [2009.03.05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
========== Modules (No Company Name) ==========
MOD - [2013.02.14 08:31:05 | 001,840,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\64cf6c356be66bb17c4667d6d8aa467b\System.Web.Services.ni.dll
MOD - [2013.02.14 08:30:27 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll
MOD - [2013.01.10 15:33:23 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013.01.10 15:33:10 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013.01.10 15:33:07 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll
MOD - [2013.01.10 15:33:06 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013.01.10 15:33:01 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2012.12.07 00:31:33 | 002,443,800 | ---- | M] () -- C:\ProgramData\BrowserProtect\2.5.986.67\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
MOD - [2012.12.07 00:30:35 | 002,158,104 | ---- | M] () -- c:\ProgramData\BrowserProtect\2.5.986.67\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll
MOD - [2012.03.21 15:07:14 | 000,692,888 | ---- | M] () -- C:\Users\Bastian\AppData\Roaming\BrowserCompanion\tcbhn.exe
MOD - [2011.08.07 13:54:44 | 000,362,029 | ---- | M] () -- C:\Program Files (x86)\BrowserCompanion\sqlite3.dll
MOD - [2011.03.30 16:45:12 | 000,016,360 | ---- | M] () -- C:\Program Files (x86)\Iminent\IMBooster\de\Iminent.Booster.UI.resources.dll
MOD - [2011.03.30 16:45:06 | 000,236,520 | ---- | M] () -- C:\Program Files (x86)\Iminent\IMBooster\Iminent.Windows.dll
MOD - [2011.03.30 16:45:06 | 000,218,600 | ---- | M] () -- C:\Program Files (x86)\Iminent\IMBooster\Iminent.Workflow.dll
MOD - [2011.03.30 16:45:02 | 000,041,960 | ---- | M] () -- C:\Program Files (x86)\Iminent\IMBooster\Iminent.Business.TinyUrl.dll
MOD - [2011.03.30 16:45:00 | 000,337,896 | ---- | M] () -- C:\Program Files (x86)\Iminent\IMBooster\Iminent.Booster.UI.dll
MOD - [2010.11.13 02:08:41 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.11.05 03:58:50 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll
MOD - [2010.08.04 14:40:12 | 000,611,872 | ---- | M] () -- C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe
MOD - [2010.08.04 11:47:32 | 000,144,896 | ---- | M] () -- C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyHook.dll
MOD - [2008.06.05 08:01:00 | 000,344,064 | ---- | M] () -- C:\Program Files (x86)\Packard Bell\Software Suite SE\sqlite3.dll
========== Services (SafeList) ==========
SRV - [2013.03.29 21:53:56 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013.03.25 15:53:16 | 004,561,152 | ---- | M] () [Auto | Running] -- c:\program files (x86)\common files\akamai/netsession_win_ca0e279.dll -- (Akamai)
SRV - [2013.03.07 16:29:15 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.02.26 00:32:22 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013.01.18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.12.07 00:31:33 | 002,443,800 | ---- | M] () [Auto | Running] -- C:\ProgramData\BrowserProtect\2.5.986.67\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe -- (BrowserProtect)
SRV - [2012.10.01 17:53:23 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012.09.23 21:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.09.19 16:21:14 | 000,795,072 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2012.06.26 15:35:20 | 000,008,704 | ---- | M] (Hi-Rez Studios) [Auto | Paused] -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2012.05.11 18:13:59 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Users\Bastian\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer)
SRV - [2012.05.09 15:24:32 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.09 15:24:31 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.04.05 12:34:26 | 002,143,552 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2011.11.14 00:27:20 | 000,354,416 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2011.11.14 00:27:18 | 000,433,264 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2011.11.13 23:55:18 | 011,839,488 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe -- (VMwareHostd)
SRV - [2011.11.13 22:49:40 | 000,079,872 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService)
SRV - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011.08.29 23:11:04 | 000,846,448 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe -- (VMUSBArbService)
SRV - [2011.08.24 18:33:35 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011.08.04 14:34:48 | 002,329,480 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2011.08.01 18:24:00 | 003,889,424 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2011.07.20 13:37:54 | 000,206,336 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\PC Beschleunigen\PCSUService.exe -- (PCSUService)
SRV - [2010.11.21 11:49:24 | 000,247,608 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.10.22 02:00:00 | 000,376,832 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe -- (AVM WLAN Connection Service)
SRV - [2010.09.02 22:18:02 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\2.0.189\McCHSvc.exe -- (McComponentHostService)
SRV - [2010.06.02 00:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010.05.23 07:39:05 | 000,126,904 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\18.0.0.128\ccSvcHst.exe -- (NIS)
SRV - [2010.04.04 01:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe -- (Updater Service)
SRV - [2010.01.15 23:08:38 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.08 15:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009.10.13 11:25:30 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON)
SRV - [2009.08.18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013.04.07 15:40:14 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2013.04.07 15:40:13 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2012.11.02 16:38:32 | 000,050,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2012.11.01 22:52:50 | 000,075,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
DRV:64bit: - [2012.05.09 15:24:32 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.05.09 15:24:32 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.11.14 00:28:16 | 000,063,088 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:64bit: - [2011.11.14 00:26:30 | 000,030,320 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2011.11.13 22:33:56 | 000,045,680 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2011.11.13 22:33:56 | 000,020,080 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2011.10.01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011.10.01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011.10.01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011.10.01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011.09.15 23:55:03 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011.09.11 09:13:04 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011.08.29 23:11:04 | 000,039,024 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2011.08.08 15:59:12 | 000,116,336 | ---- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:64bit: - [2011.05.25 09:25:48 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.10.22 02:00:00 | 000,460,800 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fwlanusb.sys -- (FWLANUSB)
DRV:64bit: - [2010.10.22 02:00:00 | 000,014,120 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avmeject.sys -- (avmeject)
DRV:64bit: - [2010.03.04 15:43:00 | 000,346,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009.10.13 11:16:40 | 000,409,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 02:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009.07.14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:64bit: - [2008.06.16 03:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV - [2012.03.29 16:32:12 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2005.01.01 11:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://start.funmoods.com/results.php?f=4&q={searchTerms}&a=fmtgl&chnl=fmtgl&cd=2XzutAtN2Y1L1QzuyB0AyBzytDyDzztC0FyDzyzyyB0FtByEtN0D0TzutBtDtCtBtDyCtCyD&cr=145751888
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\URLSearchHook: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files (x86)\Free_Lunch_Design\prxtbFre0.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {707db484-2428-402d-afb5-d85b387544c7} - C:\Program Files (x86)\Mario_Forever\prxtbMari.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {7e111a5c-3d11-4f56-9463-5310c3c69025} - C:\Program Files (x86)\Freeware.de\prxtbFree.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - C:\Program Files (x86)\Softonic_Deutsch\tbSoft.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {a5ae8924-4036-420f-b7f6-a47e4b8f692e} - C:\Program Files (x86)\Free_Lunch_Design_TB\prxtbFree.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{0D0FEE97-5A2B-93A4-6138-0E472D652BF8}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1351351
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://start.funmoods.com/results.php?f=4&q={searchTerms}&a=fmtgl&chnl=fmtgl&cd=2XzutAtN2Y1L1QzuyB0AyBzytDyDzztC0FyDzyzyyB0FtByEtN0D0TzutBtDtCtBtDyCtCyD&cr=145751888
IE - HKLM\..\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}: "URL" = hxxp://search.iminent.com/?appId=&ref=toolbox&q={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = hxxp://search.iminent.com/?appId=7c425fb9-7ef7-4518-ac64-16eb6f515f1a&ref=homepage
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://search.babylon.com/?affID=117116&tt=111212_new_5012_5&babsrc=HP_ss&mntrId=6e077f2400000000000000040ec3238f
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dsl-start.computerbild.de/
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://search.conduit.com?SearchSo [Binary data over 200 bytes]
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://search.conduit.com?SearchSo [Binary data over 200 bytes]
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.iminent.com/?appId=7c425fb9-7ef7-4518-ac64-16eb6f515f1a&ref=homepage
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\InprocServer32 File not found
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files (x86)\Free_Lunch_Design\prxtbFre0.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: {707db484-2428-402d-afb5-d85b387544c7} - C:\Program Files (x86)\Mario_Forever\prxtbMari.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: {7e111a5c-3d11-4f56-9463-5310c3c69025} - C:\Program Files (x86)\Freeware.de\prxtbFree.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No CLSID value found
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - C:\Program Files (x86)\Softonic_Deutsch\tbSoft.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: {a5ae8924-4036-420f-b7f6-a47e4b8f692e} - C:\Program Files (x86)\Free_Lunch_Design_TB\prxtbFree.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\6.3\ytdToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes,Backup.Old.DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{0D0FEE97-5A2B-93A4-6138-0E472D652BF8}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=110819&babsrc=SP_ss&mntrId=6e077f2400000000000000040ec3238f
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=117116&tt=111212_new_5012_5&babsrc=SP_ss&mntrId=6e077f2400000000000000040ec3238f
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw={searchTerms}&tbid=60441
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{280B0013-6C6F-46AC-B26C-4DB01CD76EE9}: "URL" = [String data over 1000 bytes]
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = hxxp://blekkosearch.mystart.com.anonymize-me.de/?anonymto=687474703A2F2F626C656B6B6F7365617263682E6D7973746172742E636F6D2F544F4F4C4241524E414D4553504143452F3F736F757263653D3836616462633532267462703D72626F7826746F6F6C62617269643D626C656B6B6F74625F736F6326753D323031323034323637443737343645423937433031324633363641353243413826713D7B7365617263685465726D737D&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{433C7C34-EC03-4F8A-8AF4-3F9287E28DAE}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&mode=bounce&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E6963712E636F6D2F7365617263682F726573756C74732E7068703F713D7B7365617263685465726D737D2663685F69643D6F7364&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{66F8C690-48F9-4C9E-8FD7-9AF58534C4BB}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&mode=bounce&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{84D95936-777D-4C14-89A9-BFC2C0F9F081}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851647
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{97EEAD43-9BF7-4CEC-8711-9FDFDBDD5F40}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&mode=bounce&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{99928578-79CB-47CB-A544-D2C8ED364531}: "URL" = hxxp://de.search.yahoo.com.anonymize-me.de/?anonymto=687474703A2F2F64652E7365617263682E7961686F6F2E636F6D2F7365617263683F66723D6368722D677265656E747265655F69652665693D7574662D3826696C633D313226747970653D39333738313126703D7B7365617263685465726D737D&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{AC129BF9-68BF-4bc4-A1DC-ECB62712FF99}: "URL" = hxxp://search.kikin.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E6B696B696E2E636F6D2F7365617263682F3F713D7B7365617263685465726D737D&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = hxxp://www.daemon-search.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E6461656D6F6E2D7365617263682E636F6D2F7365617263683F713D7B7365617263685465726D737D&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{B6065B44-CA39-4F48-BBF2-2C9D6DB5E6F3}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&mode=bounce&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{BE9FA53D-D907-422A-BF5F-762D099C8674}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&mode=bounce&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}: "URL" = hxxp://search.iminent.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E696D696E656E742E636F6D2F3F61707049643D267265663D746F6F6C626F7826713D7B7365617263685465726D737D&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\SearchScopes\{EE7164BB-1915-46B3-85D6-27FF8BF8563C}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=b65f5af2-b718-4efe-9e70-0a51bac69774&pid=winsoftware&mode=bounce&k=1
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>
========== FireFox ==========
FF - prefs.js..CT2247187.browser.search.defaultthis.engineName: true
FF - prefs.js..backup.old.browser.search.defaultenginename: "SearchTheWeb"
FF - prefs.js..backup.old.browser.search.selectedEngine: "uTorrentBar_DE Customized Web Search"
FF - prefs.js..browser.startup.homepage: "hxxp://search.conduit.com/?ctid=CT2851647&SearchSource=13"
FF - prefs.js..browser.search.defaultenginename: "SearchTheWeb"
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar_DE Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2851647&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811&ilc=12"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://search.iminent.com/?appId=7c425fb9-7ef7-4518-ac64-16eb6f515f1a&ref=homepage"
FF - prefs.js..extensions.enabledAddons: battlefieldheroespatcher%40ea.com:5.0.127.0
FF - prefs.js..extensions.enabledAddons: ffxtlbr%40babylon.com:1.5.0
FF - prefs.js..extensions.enabledAddons: ffxtlbr%40funmoods.com:1.5.0
FF - prefs.js..extensions.enabledAddons: ytd%40mybrowserbar.com:6.3
FF - prefs.js..extensions.enabledAddons: %7B7d9e1adc-7db1-4eaf-b6c7-7e062074e6be%7D:1.0.0.1
FF - prefs.js..extensions.enabledAddons: %7BACAA314B-EEBA-48e4-AD47-84E31C44796C%7D:1.0.10
FF - prefs.js..extensions.enabledAddons: bbrs_002%40blabbers.com:1.0.5
FF - prefs.js..extensions.enabledAddons: crossriderapp2258%40crossrider.com:0.91.135
FF - prefs.js..extensions.enabledAddons: crossriderapp498%40crossrider.com:0.91.169
FF - prefs.js..extensions.enabledAddons: plugin%40yontoo.com:1.20.02
FF - prefs.js..extensions.enabledAddons: %7B707db484-2428-402d-afb5-d85b387544c7%7D:10.14.65.43
FF - prefs.js..extensions.enabledAddons: %7B7e111a5c-3d11-4f56-9463-5310c3c69025%7D:3.18.0.7
FF - prefs.js..extensions.enabledAddons: %7B872b5b88-9db5-4310-bdd0-ac189557e5f5%7D:10.14.65.43
FF - prefs.js..extensions.enabledAddons: %7Ba5ae8924-4036-420f-b7f6-a47e4b8f692e%7D:3.18.0.7
FF - prefs.js..extensions.enabledAddons: %7Bc840e246-6b95-475e-9bd7-caa1c7eca9f2%7D:3.18.0.7
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31
FF - prefs.js..extensions.enabledItems: battlefieldheroespatcher@ea.com:5.0.127.0
FF - prefs.js..extensions.enabledItems: crossriderapp2258@crossrider.com:0.80.43
FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.5.5
FF - prefs.js..extensions.enabledItems: plugin@yontoo.com:1.20.00
FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:5.7
FF - prefs.js..extensions.enabledItems: youtubedownloader@mybrowserbar.com:5.7
FF - prefs.js..extensions.enabledItems: {707db484-2428-402d-afb5-d85b387544c7}:10.7.1.62
FF - prefs.js..extensions.enabledItems: {7d9e1adc-7db1-4eaf-b6c7-7e062074e6be}:1.0.0.1
FF - prefs.js..extensions.enabledItems: {7e111a5c-3d11-4f56-9463-5310c3c69025}:3.12.3.500
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:10.10.2.10
FF - prefs.js..extensions.enabledItems: {a5ae8924-4036-420f-b7f6-a47e4b8f692e}:3.10.0.1
FF - prefs.js..extensions.enabledItems: {AA994882-F391-4d2e-806F-8908DA4814ED}:2.11.14
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.10
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Bastian\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Bastian\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Bastian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011.10.10 17:18:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.21 19:02:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{58bd07eb-0ee0-4df0-8121-dc9b693373df}: C:\ProgramData\BrowserProtect\2.5.986.67\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension [2012.12.12 15:29:32 | 000,000,000 | ---D | M]
[2012.05.26 12:24:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\Extensions
[2013.03.30 11:18:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions
[2013.03.30 11:18:40 | 000,000,000 | ---D | M] (Mario Forever) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\{707db484-2428-402d-afb5-d85b387544c7}
[2012.04.26 16:31:11 | 000,000,000 | ---D | M] (Blekko search bar) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\{7d9e1adc-7db1-4eaf-b6c7-7e062074e6be}
[2013.03.30 11:18:27 | 000,000,000 | ---D | M] (Freeware.de Community Toolbar) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\{7e111a5c-3d11-4f56-9463-5310c3c69025}
[2013.03.30 11:18:26 | 000,000,000 | ---D | M] (DVDVideoSoftTB) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2013.03.30 11:18:13 | 000,000,000 | ---D | M] (Free Lunch Design TB Community Toolbar) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\{a5ae8924-4036-420f-b7f6-a47e4b8f692e}
[2012.05.26 12:24:58 | 000,000,000 | ---D | M] (kikin plugin) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\{AA994882-F391-4d2e-806F-8908DA4814ED}
[2012.05.24 12:43:22 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2013.03.30 11:18:12 | 000,000,000 | ---D | M] (uTorrentBar_DE Community Toolbar) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\{c840e246-6b95-475e-9bd7-caa1c7eca9f2}
[2011.11.21 19:08:27 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\battlefieldheroespatcher@ea.com
[2012.06.15 09:46:19 | 000,000,000 | ---D | M] (Browser Companion Helper) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com
[2013.03.30 11:18:43 | 000,000,000 | ---D | M] ("I Want This") -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\crossriderapp2258@crossrider.com
[2013.03.30 11:18:42 | 000,000,000 | ---D | M] ("RewardsArcade") -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\crossriderapp498@crossrider.com
[2012.12.12 15:28:33 | 000,000,000 | ---D | M] (Babylon Toolbar) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\ffxtlbr@babylon.com
[2012.06.17 18:25:38 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\ffxtlbr@funmoods.com
[2012.04.08 20:21:29 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\plugin@yontoo.com
[2013.03.30 11:18:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\staged
[2013.03.30 11:18:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\crossriderapp2258@crossrider.com\chrome\content\extensionCode
[2013.03.30 11:18:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\Firefox\Profiles\qlqngrde.default\extensions\crossriderapp498@crossrider.com\chrome\content\extensionCode
[2013.03.21 19:08:42 | 000,021,485 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\plugin@yontoo.com.xpi
[2013.03.21 18:58:28 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\0324adea3b6ec02af09ea4ae9424591b_expire
[2013.03.30 11:19:01 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\0d54de8e14654d562cb9e39a7bd60068_expire
[2013.03.30 11:19:03 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\1048fa0383ec8c1a4365d4bd4fed1de5_expire
[2012.06.13 16:15:35 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\21d2bb231d3c04f5b6434220b2b1cb9e_expire
[2013.03.30 11:19:03 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\24779e9d2de93d13d7e07b527a1684d4_expire
[2013.03.30 11:19:00 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\26b787477fed5f7b805ee78439427910_expire
[2013.03.21 18:58:30 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\292124057d00cb0fa73db6b90d079658_expire
[2012.09.18 18:17:34 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\2a86ac4f3322238b4f27d14a09839275_expire
[2012.06.13 16:15:33 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\3b507b6d0186efd3615b9b9233c5f708_expire
[2013.03.30 11:19:02 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\4d3d10bd28ff623813254a49b26be41f_expire
[2013.03.30 11:19:04 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\530e52021dc20843b1aa62957edeb9f8_expire
[2013.03.30 11:19:04 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\5cdf8a7ef2ec84abac286c67587b78d9_expire
[2012.06.13 16:15:33 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\5d5c3541c8187f3a48d4f72f4374009c_expire
[2012.06.13 16:15:33 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\6a8ef73701ad78f92631ccabc37a9b58_expire
[2013.03.30 11:19:00 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\72891ec935a3d247f2da6562ef29a005_expire
[2013.03.30 11:19:04 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\7a29ec8065b26afe2d5fb4ceac90ac12_expire
[2012.09.18 18:17:35 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\8ffbb13aa6f702b0cafab391f90d1db7_expire
[2012.06.13 16:15:25 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\93aa59562815aa22d93923c7215ac7f1_expire
[2013.03.30 11:18:59 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\a38dbdd1af07f4236d43e8fd995f57a6_expire
[2013.03.30 11:18:59 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\a7e0abb80dabcdbb6dbaec920aa126a0_expire
[2013.03.30 11:19:03 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\b575d9a954d961d8cdfa6596f2c115a9_expire
[2012.09.18 18:17:36 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\b98ec85a6f6b5dca57a81c971a2ec1f5_expire
[2012.06.13 16:15:36 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\bd75b259da6df295d57bcf03a94e1ba6_expire
[2013.03.30 11:18:59 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\bf73732e1f0b76bac435293ba3880579_expire
[2012.08.04 15:56:40 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\dc6668d28979688b1e2066d1dcaef0f6_expire
[2012.09.18 18:17:35 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\e02b35320e5111f1b626466c13c70a0a_expire
[2013.03.30 11:19:03 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\e7d8325da90d91d3c4e7720f0e629e17_expire
[2013.03.30 11:19:02 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\e919434ec29526b28593c426e4264271_expire
[2013.03.30 11:19:02 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\f03527c67e08602d2e4c18ae7867300d_expire
[2013.03.30 11:19:02 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\fa74672918974682c82b8d91dfbe0d6b_expire
[2013.03.30 11:19:02 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\ff4d692d5e7cccbc4b3e9ef4062b1c6f_expire
[2012.12.12 15:28:34 | 000,002,443 | ---- | M] () -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\searchplugins\babylon1.xml
[2013.03.17 21:44:17 | 000,000,921 | ---- | M] () -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\searchplugins\conduit.xml
[2012.05.26 12:25:01 | 000,001,266 | ---- | M] () -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\searchplugins\kikin-search.xml
[2012.06.17 18:25:45 | 000,002,301 | ---- | M] () -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\searchplugins\Search.xml
[2012.12.18 16:37:45 | 000,002,230 | ---- | M] () -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\searchplugins\SearchTheWeb.xml
[2012.05.11 18:14:09 | 000,002,189 | ---- | M] () -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\searchplugins\{0520EBEB-8AEC-420C-8BEC-EFE27FDB9A90}.xml
[2012.05.11 18:14:09 | 000,001,871 | ---- | M] () -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\searchplugins\{3A5A5CD1-3348-4ECF-B7CA-4BCE66728139}.xml
[2012.05.11 18:14:09 | 000,002,078 | ---- | M] () -- C:\Users\Bastian\AppData\Roaming\mozilla\firefox\profiles\qlqngrde.default\searchplugins\{9C47B854-565C-433A-92B2-B96E23A1D9B7}.xml
[2013.03.21 19:02:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.09.26 14:06:19 | 000,000,000 | ---D | M] (YTD Toolbar) -- C:\PROGRAM FILES (X86)\YTD TOOLBAR\FF
[2013.03.07 16:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013.03.07 17:45:15 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.12.12 15:28:09 | 000,002,360 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2013.03.07 17:45:15 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013.03.07 17:45:15 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2013.03.07 17:45:15 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.05.11 18:14:09 | 000,002,452 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\search.xml
[2013.03.07 17:45:15 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.03.07 17:45:15 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - homepage: hxxp://search.babylon.com/?affID=117116&tt=111212_new_5012_5&babsrc=HP_ss&mntrId=6e077f2400000000000000040ec3238f
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: hxxp://search.babylon.com/?affID=117116&tt=111212_new_5012_5&babsrc=HP_ss&mntrId=6e077f2400000000000000040ec3238f
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\7.0.19_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\clbfjfbnelcflpgpklppgplejolacbej\1.0.5_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjacnemeogppppmlcoafbiacilcpngh\1.1.0.0_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcmagccbogebndpoodhhhafmofelpffh\1.23.171_0\crossrider
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcmagccbogebndpoodhhhafmofelpffh\1.23.171_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.11_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\2.1.4_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc\2.3.19.11_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpkbfdhlbdkjohbhnhabfecpmcdlcmff\1.23.14_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk\1.23.137_0\crossrider
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk\1.23.137_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlafpokblfobdnjhhggocaanijghemnd\2.3.19.11_0\
CHR - Extension: No name found = C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Chatvibes Browser Helper) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files (x86)\BrowserCompanion\jsloader.dll ( )
O2 - BHO: (RewardsArcade) - {11111111-1111-1111-1111-110011041198} - C:\Program Files (x86)\RewardsArcade\RewardsArcade.dll (215 Apps)
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.4.9\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Free Lunch Design Toolbar) - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files (x86)\Free_Lunch_Design\prxtbFre0.dll (Conduit Ltd.)
O2 - BHO: (TBSB01620 Class) - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll File not found
O2 - BHO: (Mario Forever Toolbar) - {707db484-2428-402d-afb5-d85b387544c7} - C:\Program Files (x86)\Mario_Forever\prxtbMari.dll (Conduit Ltd.)
O2 - BHO: (Funmoods Helper Object) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll (Funmoods BHO)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Blekko search bar) - {7d9e1adc-7db1-4eaf-b6c7-7e062074e6be} - C:\Program Files (x86)\blekkotb_soc\blekkotb_019X.dll File not found
O2 - BHO: (Freeware.de Toolbar) - {7e111a5c-3d11-4f56-9463-5310c3c69025} - C:\Program Files (x86)\Freeware.de\prxtbFree.dll (Conduit Ltd.)
O2 - BHO: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No CLSID value found.
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (Softonic Deutsch Toolbar) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - C:\Program Files (x86)\Softonic_Deutsch\tbSoft.dll (Conduit Ltd.)
O2 - BHO: (Chatvibes Browser Helper Verifier) - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll ( )
O2 - BHO: (IMinent WebBooster (BHO)) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files (x86)\Iminent\IMBooster4Web\Iminent.WebBooster.dll (Iminent)
O2 - BHO: (Free Lunch Design TB Toolbar) - {a5ae8924-4036-420f-b7f6-a47e4b8f692e} - C:\Program Files (x86)\Free_Lunch_Design_TB\prxtbFree.dll (Conduit Ltd.)
O2 - BHO: (uTorrentBar_DE Toolbar) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll ()
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (Softonic Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files (x86)\kikin\ie_kikin.dll (kikin)
O2 - BHO: (YTD Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\6.3\ytdToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
O2 - BHO: (ICQ Sparberater) - {FE163F11-1919-4257-A280-FF5AF8DAEECB} - C:\Program Files (x86)\icq\Internet Explorer\icq.dll (solute gmbh)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Free Lunch Design Toolbar) - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files (x86)\Free_Lunch_Design\prxtbFre0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Mario Forever Toolbar) - {707db484-2428-402d-afb5-d85b387544c7} - C:\Program Files (x86)\Mario_Forever\prxtbMari.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Blekko search bar) - {7d9e1adc-7db1-4eaf-b6c7-7e062074e6be} - C:\Program Files (x86)\blekkotb_soc\blekkotb_019X.dll File not found
O3 - HKLM\..\Toolbar: (Freeware.de Toolbar) - {7e111a5c-3d11-4f56-9463-5310c3c69025} - C:\Program Files (x86)\Freeware.de\prxtbFree.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Softonic Deutsch Toolbar) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - C:\Program Files (x86)\Softonic_Deutsch\tbSoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Funmoods Toolbar) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll (Funmoods)
O3 - HKLM\..\Toolbar: (Free Lunch Design TB Toolbar) - {a5ae8924-4036-420f-b7f6-a47e4b8f692e} - C:\Program Files (x86)\Free_Lunch_Design_TB\prxtbFree.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (uTorrentBar_DE Toolbar) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Softonic Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (YTD Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\6.3\ytdToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\Toolbar\WebBrowser: (Free Lunch Design Toolbar) - {57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC} - C:\Program Files (x86)\Free_Lunch_Design\prxtbFre0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\Toolbar\WebBrowser: (Mario Forever Toolbar) - {707DB484-2428-402D-AFB5-D85B387544C7} - C:\Program Files (x86)\Mario_Forever\prxtbMari.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\Toolbar\WebBrowser: (Freeware.de Toolbar) - {7E111A5C-3D11-4F56-9463-5310C3C69025} - C:\Program Files (x86)\Freeware.de\prxtbFree.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\Toolbar\WebBrowser: (Free Lunch Design TB Toolbar) - {A5AE8924-4036-420F-B7F6-A47E4B8F692E} - C:\Program Files (x86)\Free_Lunch_Design_TB\prxtbFree.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\..\Toolbar\WebBrowser: (uTorrentBar_DE Toolbar) - {C840E246-6B95-475E-9BD7-CAA1C7ECA9F2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [IntelliType Pro] C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\Bastian\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4:64bit: - HKLM..\Run: [OOTag] C:\Program Files (x86)\Packard Bell\OOBEOffer\ootag.exe (Microsoft)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Anti-phishing Domain Advisor] C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe (Visicom Media Inc. (Powered by Panda Security))
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Search-Results)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [AVMWlanClient] C:\Program Files (x86)\avmwlanstick\wlangui.exe (AVM Berlin)
O4 - HKLM..\Run: [Browser companion helper] C:\Program Files (x86)\BrowserCompanion\BCHelper.exe (Blabbers Communications LTD)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [IMBooster] C:\Program Files (x86)\Iminent\IMBooster\imbooster.exe (Iminent)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [OOTag] C:\Program Files (x86)\Packard Bell\OOBEOffer\OOTag.exe (Microsoft)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [vmware-tray] C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3151336371-207809542-2099419153-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001..\Run: [Akamai NetSession Interface] C:\Users\Bastian\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001..\Run: [DriverScanner] C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe (Uniblue Systems Limited)
O4 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001..\Run: [PC Speed Maximizer] "C:\Program Files (x86)\PC Speed Maximizer\SPMStarter.exe" File not found
O4 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001..\Run: [Software Suite SE] C:\Program Files (x86)\Packard Bell\Software Suite SE\SoftSuiteSE.exe (Acer Incorporated)
O4 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001..\Run: [SPMTray] "C:\Program Files (x86)\PC Speed Maximizer\SPMTray.exe" File not found
O4 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-3151336371-207809542-2099419153-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-3151336371-207809542-2099419153-1000..\RunOnce: [ScrSav] C:\Program Files (x86)\Packard Bell\Screensaver\run_Packard Bell.exe ()
O4 - Startup: C:\Users\Bastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tcbhn.lnk = C:\Users\Bastian\AppData\Roaming\BrowserCompanion\tcbhn.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8:64bit: - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O8:64bit: - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Bastian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Bastian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files (x86)\kikin\ie_kikin.dll (kikin)
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Crawler Screensaver - {CDAFD956-97BE-443D-8EF7-F4F094EB5766} - C:\PROGRA~2\Crawler\SSaver\CSSaver.exe (Crawler.com)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{86B83900-A268-41D0-9BE9-296DB214CC2E}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A56170CD-A544-4A37-978F-8609EB8AF065}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\base64 - No CLSID value found
O18:64bit: - Protocol\Handler\chrome - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\prox - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\base64 {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\chrome {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\prox {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\25986~1.67\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserProtect\2.5.986.67\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-3151336371-207809542-2099419153-1001 Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013.05.01 06:19:52 | 000,548,376 | ---- | M] () - F:\Autoruns.zip -- [ FAT32 ]
O32 - AutoRun File - [2013.05.01 06:25:14 | 000,000,000 | ---D | M] - F:\Autoruns -- [ FAT32 ]
O33 - MountPoints2\{a19de150-f34e-11e0-b065-1078d2701bd6}\Shell - "" = AutoRun
O33 - MountPoints2\{a19de150-f34e-11e0-b065-1078d2701bd6}\Shell\AutoRun\command - "" = F:\pushinst.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.05.02 15:56:08 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.05.02 15:54:48 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Bastian\Desktop\OTL.exe
[2013.04.18 11:39:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\searchplugins
[2013.04.18 11:39:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Extensions
[2013.04.07 16:30:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Tages
[2013.04.05 21:59:18 | 000,000,000 | ---D | C] -- C:\Program Files\Domination
[2013.04.05 15:49:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Paradox Interactive
[2013.04.05 15:49:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paradox Interactive
[9 C:\Users\Bastian\Documents\*.tmp files -> C:\Users\Bastian\Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.05.02 16:18:03 | 001,538,034 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.05.02 16:18:03 | 000,667,892 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.05.02 16:18:03 | 000,628,074 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.05.02 16:18:03 | 000,136,328 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.05.02 16:18:03 | 000,111,980 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.05.02 16:17:08 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.05.02 16:17:08 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.05.02 16:14:10 | 000,001,128 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3151336371-207809542-2099419153-1001UA.job
[2013.05.02 16:11:44 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job
[2013.05.02 16:08:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.05.02 16:08:03 | 3214,233,600 | -HS- | M] () -- C:\hiberfil.sys
[2013.05.01 09:47:26 | 000,000,168 | ---- | M] () -- C:\Users\Bastian\defogger_reenable
[2013.04.26 21:36:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bastian\Desktop\OTL.exe
[2013.04.20 13:13:03 | 000,001,076 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3151336371-207809542-2099419153-1001Core.job
[2013.04.11 19:14:45 | 000,002,388 | ---- | M] () -- C:\Users\Bastian\Desktop\Google Chrome.lnk
[2013.04.11 13:31:31 | 000,338,664 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.04.07 15:40:14 | 000,314,016 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2013.04.07 15:40:13 | 000,043,680 | ---- | M] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2013.04.05 22:04:08 | 000,002,058 | ---- | M] () -- C:\Users\Bastian\Desktop\Domination.lnk
[2013.04.05 22:01:02 | 000,000,092 | ---- | M] () -- C:\Users\Bastian\.lobby
[2013.04.04 15:51:40 | 000,282,296 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.04.04 15:51:40 | 000,282,296 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.04.04 15:51:25 | 000,215,128 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[9 C:\Users\Bastian\Documents\*.tmp files -> C:\Users\Bastian\Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.05.01 09:47:26 | 000,000,168 | ---- | C] () -- C:\Users\Bastian\defogger_reenable
[2013.04.07 15:40:14 | 000,314,016 | ---- | C] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2013.04.07 15:40:13 | 000,043,680 | ---- | C] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2013.04.05 22:04:08 | 000,002,058 | ---- | C] () -- C:\Users\Bastian\Desktop\Domination.lnk
[2013.04.05 22:01:02 | 000,000,092 | ---- | C] () -- C:\Users\Bastian\.lobby
[2013.03.14 18:39:48 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2013.02.25 16:09:34 | 000,114,176 | ---- | C] () -- C:\Users\Bastian\AppData\Roaming\BabMaint.exe
[2012.12.26 10:10:15 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2012.10.10 20:58:04 | 000,000,032 | ---- | C] () -- C:\Windows\CD_Start.INI
[2012.08.12 13:13:53 | 000,069,632 | R--- | C] () -- C:\Windows\SysWow64\xmltok.dll
[2012.08.12 13:13:53 | 000,036,864 | R--- | C] () -- C:\Windows\SysWow64\xmlparse.dll
[2012.08.04 15:22:31 | 000,178,176 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012.07.08 08:55:21 | 000,000,095 | ---- | C] () -- C:\Users\Bastian\AppData\Local\fusioncache.dat
[2012.06.15 09:46:11 | 000,302,425 | ---- | C] () -- C:\Users\Bastian\AppData\Local\funmoods-speeddial.crx
[2012.06.15 09:46:10 | 000,031,470 | ---- | C] () -- C:\Users\Bastian\AppData\Local\funmoods.crx
[2012.05.22 19:53:23 | 000,000,007 | ---- | C] () -- C:\Users\Bastian\user.clk
[2012.04.29 14:21:28 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2012.04.29 14:21:28 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2012.04.29 14:21:28 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2012.04.29 14:19:38 | 000,040,974 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2012.04.21 13:53:57 | 000,007,697 | ---- | C] () -- C:\Users\Bastian\AppData\Roaming\.freeciv-client-rc-2.3
[2012.04.19 12:20:59 | 000,000,218 | ---- | C] () -- C:\Users\Bastian\AppData\Local\recently-used.xbel
[2012.02.20 23:00:49 | 000,110,592 | ---- | C] () -- C:\Windows\SysWow64\duninstall.exe
[2012.02.10 20:03:38 | 000,000,000 | ---- | C] () -- C:\Windows\iPlayer.INI
[2011.11.23 16:35:53 | 000,282,296 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011.11.23 16:35:51 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.09.27 14:00:57 | 001,564,396 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.08.31 18:02:57 | 000,030,439 | ---- | C] () -- C:\Windows\scunin.dat
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012.04.26 19:44:11 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\.freeciv
[2013.04.19 11:32:58 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\.minecraft
[2012.07.20 13:45:41 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\.terasology
[2012.04.19 12:27:39 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Ambient Design
[2011.09.23 14:37:05 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\AnvSoft
[2012.04.21 19:33:25 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Armagetron
[2012.01.19 15:35:14 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Artweaver
[2012.04.21 12:12:01 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Awem
[2013.01.26 00:00:41 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Azureus
[2012.12.12 15:28:54 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\BabSolution
[2012.05.26 13:11:07 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Babylon
[2012.05.26 13:12:13 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\BabylonToolbar
[2012.01.21 19:12:39 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Blender Foundation
[2013.05.02 16:11:37 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\BrowserCompanion
[2012.09.05 21:03:50 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Canneverbe Limited
[2012.11.15 16:59:53 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Carbon
[2012.04.06 17:50:00 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Cities3D
[2011.08.31 18:16:56 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\DAEMON Tools Lite
[2012.05.22 19:13:29 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Deluxe Pacman
[2012.05.11 18:14:09 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\DesktopIconForAmazon
[2012.05.24 13:54:39 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\DVDVideoSoft
[2012.05.24 12:43:21 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\DVDVideoSoftIEHelpers
[2013.03.15 15:16:08 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\File Scout
[2012.03.04 16:21:08 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Firefly Studios
[2012.12.03 14:49:26 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Free Download Manager
[2012.05.07 16:37:38 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\fretsonfire
[2013.04.13 18:25:31 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\ICQ
[2012.01.21 19:20:07 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\inkscape
[2012.07.16 14:22:58 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\IrfanView
[2012.05.26 12:24:58 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\kikin
[2013.03.14 18:39:19 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Leadertech
[2012.01.21 19:25:35 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Nvu
[2012.05.11 18:13:59 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\OCS
[2011.08.31 16:52:06 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\OEM
[2012.08.13 09:45:13 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\OpenCandy
[2011.10.10 19:11:19 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\OpenOffice.org
[2011.09.16 20:10:24 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Opera
[2012.04.26 17:00:34 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\PC Speed Maximizer
[2012.12.14 15:39:34 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\PerformerSoft
[2012.07.16 14:16:06 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\PhotoFiltre
[2012.07.07 16:29:13 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\PhotoScape
[2012.03.04 15:32:27 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\RotMG.Production
[2011.09.08 18:16:48 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Sierra
[2012.01.10 17:06:49 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Sierra Entertainment
[2013.04.07 20:45:50 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\SoftGrid Client
[2012.02.19 10:20:18 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Soldat
[2012.05.13 07:14:49 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Systweak
[2012.02.18 19:21:48 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Teeworlds
[2011.09.20 20:46:39 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\The Creative Assembly
[2012.08.02 19:46:58 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Toblo
[2011.09.27 14:01:24 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\TP
[2012.08.28 10:59:33 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\TS3Client
[2012.06.02 14:34:25 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\ts3overlay
[2012.05.24 13:18:37 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\TuneUp Software
[2012.04.19 12:37:09 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\TuxPaint
[2011.09.23 14:38:05 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Uniblue
[2012.01.02 14:59:21 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\Unity
[2013.05.02 16:21:59 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\uTorrent
[2011.12.24 18:07:42 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\WildTangent
[2012.08.26 16:21:45 | 000,000,000 | ---D | M] -- C:\Users\Bastian\AppData\Roaming\ZombieDriver
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2013.04.13 23:05:08 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?Í) -- C:\Windows\SysNative\ﳰÍ
[2013.04.13 23:05:08 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?Í) -- C:\Windows\SysNative\ﳰÍ
[2013.04.11 20:47:33 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?ª) -- C:\Windows\SysNative\ﳰª
[2013.04.11 20:47:32 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?ª) -- C:\Windows\SysNative\ﳰª
[2013.03.04 20:05:33 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?©) -- C:\Windows\SysNative\ﳰ©
[2013.03.04 20:05:33 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?©) -- C:\Windows\SysNative\ﳰ©
[2013.02.27 21:54:45 | 000,000,000 | ---- | M] ()(C:\Windows\SysNative\?³) -- C:\Windows\SysNative\ﳰ³
[2013.02.27 21:54:45 | 000,000,000 | ---- | C] ()(C:\Windows\SysNative\?³) -- C:\Windows\SysNative\ﳰ³
[2013.02.14 21:33:53 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?´) -- C:\Windows\SysNative\ﳰ´
[2013.02.14 21:33:52 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?´) -- C:\Windows\SysNative\ﳰ´
[2013.02.08 23:40:21 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?±) -- C:\Windows\SysNative\ﳰ±
[2013.02.08 23:40:20 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?±) -- C:\Windows\SysNative\ﳰ±
[2013.02.05 22:29:00 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?Á) -- C:\Windows\SysNative\ﳰÁ
[2013.02.05 22:29:00 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?Á) -- C:\Windows\SysNative\ﳰÁ
[2013.02.02 01:53:20 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?*) -- C:\Windows\SysNative\ﳰ*
[2013.02.02 01:53:20 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?*) -- C:\Windows\SysNative\ﳰ*
[2013.01.21 23:17:27 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?¼) -- C:\Windows\SysNative\ﳰ¼
[2013.01.21 23:17:27 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?¼) -- C:\Windows\SysNative\ﳰ¼
[2013.01.04 22:40:28 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?®) -- C:\Windows\SysNative\ﳰ®
[2013.01.04 22:40:27 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?®) -- C:\Windows\SysNative\ﳰ®
[2012.11.18 11:35:31 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?½) -- C:\Windows\SysNative\ﳰ½
[2012.11.18 11:35:31 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?½) -- C:\Windows\SysNative\ﳰ½
[2012.09.05 22:05:07 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?À) -- C:\Windows\SysNative\ﳰÀ
[2012.09.05 22:05:06 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?À) -- C:\Windows\SysNative\ﳰÀ
[2012.08.26 14:09:58 | 000,002,032 | ---- | M] ()(C:\Windows\SysNative\??????????????????????????????????????????????‹?????????.???3g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g????Dg?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g????Dg?g?g?g?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f.lnk) -- C:\Windows\SysNative\㩃啜敳獲䉜獡楴湡䑜獥瑫灯䡜뛃扲捵敨屲桃楲瑳灯敨慐汯湩*牅条湯㐠孜慐汯湩Ⱪ䌠牨獩潴桰牥⁝㐱‹牅条湯㐠ⴠ䐠獡䔠扲.档灭3ggggggggퟸg힘g휸g훘g홸g햸g㣈g하g㝈g㛨g㴰㘨耀Dg㕨g㔈g㒨g㑈g㏨g㎈g㌨g㋈g㉨gよg⿈g⽨g⺨g⼈g⹈gⳈgⷨgⱨg⮨g㴰⫨耀Dg⨨g⧈g⥨gfffffffffffffffffffffff.lnk
[2012.08.26 14:09:58 | 000,002,032 | ---- | C] ()(C:\Windows\SysNative\??????????????????????????????????????????????‹?????????.???3g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g????Dg?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g?g????Dg?g?g?g?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f?f.lnk) -- C:\Windows\SysNative\㩃啜敳獲䉜獡楴湡䑜獥瑫灯䡜뛃扲捵敨屲桃楲瑳灯敨慐汯湩*牅条湯㐠孜慐汯湩Ⱪ䌠牨獩潴桰牥⁝㐱‹牅条湯㐠ⴠ䐠獡䔠扲.档灭3ggggggggퟸg힘g휸g훘g홸g햸g㣈g하g㝈g㛨g㴰㘨耀Dg㕨g㔈g㒨g㑈g㏨g㎈g㌨g㋈g㉨gよg⿈g⽨g⺨g⼈g⹈gⳈgⷨgⱨg⮨g㴰⫨耀Dg⨨g⧈g⥨gfffffffffffffffffffffff.lnk
[2012.05.23 18:10:33 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\?5) -- C:\Windows\SysNative\ﳰ5
[2012.05.23 18:10:32 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\?5) -- C:\Windows\SysNative\ﳰ5
========== Alternate Data Streams ==========
@Alternate Data Stream - 5632 bytes -> C:\ProgramData:gs5sys
@Alternate Data Stream - 4096 bytes -> C:\Users\Public\Documents\desktop.ini:gs5sys
@Alternate Data Stream - 1536 bytes -> C:\Users\Bastian\Documents\desktop.ini:gs5sys
@Alternate Data Stream - 1536 bytes -> C:\Users\Bastian\Desktop\desktop.ini:gs5sys
< End of report > --- --- ---
[/CODE]
Zur der Frage ob es Fehlermeldungen gab.
Wenn man ZOEK im "Abgesicherten Modus mit Eingabeaufforderung" in cmd als Admin über den runas Befehl starten will gibt er folgende Fehlermeldung aus:
Runas Fehler
1084: Der Dienst kann nicht im abgesicherten Modus gestartet werden.
Wenn man in cmd die explorer.exe startet und dann versucht ZOEK ganz normal über das Kontexmenu als Admin zu starten wird das Program zwar gestartet.
Aber wenn man auf "Run Script" klickt erscheint folgende Fehlermeldung:
Scriptfehler
Zeile 162
Zeichen 6
Fehler Der Dienst kann nicht im abgesicherten Modus gestartet werden.
Code 0 |