Ja die habe ich.
Ich habe auch noch das OTLpe Log vor der Bereinigung OTL.txt vor Bereinigung
OTL Logfile: Code:
OTL logfile created on: 11/15/2013 9:45:03 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
64bit-Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.10.9200.16721)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86)
Drive C: | 100.00 Mb Total Space | 75.83 Mb Free Space | 75.83% Space Free | Partition Type: NTFS
Drive E: | 283.99 Gb Total Space | 28.06 Gb Free Space | 9.88% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2013/05/27 00:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2010/09/22 11:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/06/11 07:27:26 | 000,868,896 | ---- | M] (Acer Incorporated) [Auto] -- E:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2010/04/20 18:34:40 | 000,202,752 | ---- | M] (AMD) [Auto] -- E:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/01/28 18:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto] -- E:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2013/11/12 13:04:07 | 000,061,536 | ---- | M] (Microsoft Corporation) [Auto] -- E:\ProgramData\qzjrwvj6.pss -- (Winmgmt)
SRV - [2013/11/08 13:13:28 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand] -- E:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/10/09 12:10:14 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- E:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/09/05 13:41:47 | 000,622,648 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- E:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService)
SRV - [2013/08/20 03:20:44 | 000,084,024 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013/08/20 03:20:13 | 000,815,160 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- E:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService)
SRV - [2013/08/20 03:20:01 | 000,108,088 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013/05/10 02:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/13 06:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto] -- E:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/03/29 08:33:08 | 000,598,312 | ---- | M] (Nero AG) [Auto] -- E:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) @C:\Program Files (x86)
SRV - [2011/03/21 07:21:24 | 000,632,832 | ---- | M] (Nokia) [On_Demand] -- E:\Program Files (x86)\Nokia\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010/07/14 05:34:44 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand] -- E:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/06/28 08:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) [Auto] -- E:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2010/06/22 01:34:48 | 000,321,104 | ---- | M] (Dritek System Inc.) [Auto] -- E:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2010/05/26 21:41:06 | 000,305,520 | ---- | M] (Egis Technology Inc.) [On_Demand] -- E:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe -- (MWLService)
SRV - [2010/03/18 07:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/08 08:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto] -- E:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/08/27 10:09:10 | 001,253,376 | ---- | M] (MAGIX AG) [Auto] -- E:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/02/06 10:02:14 | 000,109,056 | ---- | M] (ArcSoft Inc.) [Auto] -- E:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2008/10/24 09:35:44 | 000,128,296 | ---- | M] () [Auto] -- E:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService)
SRV - [2008/08/07 04:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand] -- E:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2007/05/31 11:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 11:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2004/10/11 22:47:06 | 000,098,304 | ---- | M] () [Auto] -- E:\Program Files (x86)\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor)
SRV - [2004/10/11 21:40:38 | 000,118,784 | ---- | M] () [Auto] -- E:\Program Files (x86)\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe -- (PhotoshopElementsDeviceConnect)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/09/05 13:41:48 | 000,105,344 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto] -- E:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2013/08/20 03:20:52 | 000,132,088 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System] -- E:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2013/08/08 11:42:22 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System] -- E:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2012/03/08 11:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2012/01/10 05:12:26 | 000,222,464 | ---- | M] (Dexetek ) [Kernel | On_Demand] -- E:\Windows\System32\drivers\DxVGrb.sys -- (DxVGrb)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 05:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010/06/17 04:18:28 | 000,246,376 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- E:\Windows\System32\Drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010/06/03 14:59:00 | 004,171,328 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010/05/14 16:48:28 | 000,384,040 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:64bit: - [2010/04/20 20:15:04 | 006,406,144 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atipmdag.sys -- (amdkmdag)
DRV:64bit: - [2010/04/20 17:39:36 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/01/26 22:05:00 | 000,231,328 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2009/08/23 04:55:32 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot] -- E:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2009/06/10 15:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/02 21:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System] -- E:\Windows\System32\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009/06/02 21:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System] -- E:\Windows\System32\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009/06/02 21:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System] -- E:\Windows\System32\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2008/08/28 06:44:42 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand] -- E:\Windows\System32\drivers\pccsmcfdx64.sys -- (pccsmcfd)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Fiete_ON_E\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.google.de/
IE - HKU\Fiete_ON_E\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5552&r=273612100715l0424z145v4742108q
IE - HKU\Fiete_ON_E\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\Fiete_ON_E\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\Fiete_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.fbdownloader.com/?channel=sfus205
IE - HKU\Fiete_ON_E\..\URLSearchHook: {7e111a5c-3d11-4f56-9463-5310c3c69025} - Reg Error: Key error. File not found
IE - HKU\Fiete_ON_E\..\URLSearchHook: {b106b661-3e1b-4015-af5c-195e909f35c6} - Reg Error: Key error. File not found
IE - HKU\Fiete_ON_E\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKU\Fiete_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\LocalService_ON_E\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKU\NetworkService_ON_E\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKU\NetworkService_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaultthis.engineName: "NCH DE Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.fbdownloader.com/search.php?channel=sfde205&q="
FF - prefs.js..browser.search.order.1: "Delta Search"
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..browser.startup.homepage: "hxxp://search.fbdownloader.com/?channel=sfde205"
FF - prefs.js..keyword.URL: "hxxp://search.fbdownloader.com/search.php?channel=sfde205&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\System32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer: E:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE: File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: E:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: E:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: E:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: E:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/22 09:07:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/09/12 08:27:32 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{58bd07eb-0ee0-4df0-8121-dc9b693373df}: C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
[2011/01/14 05:21:58 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Fiete\AppData\Roaming\Mozilla\Extensions
[2011/01/14 05:21:58 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Fiete\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2013/10/14 14:30:36 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Fiete\AppData\Roaming\Mozilla\Firefox\Profiles\nm34zs2n.default\extensions
[2013/09/22 14:42:43 | 000,000,000 | ---D | M] (Freeware.de Community Toolbar) -- E:\Users\Fiete\AppData\Roaming\Mozilla\Firefox\Profiles\nm34zs2n.default\extensions\{7e111a5c-3d11-4f56-9463-5310c3c69025}
[2013/09/22 14:42:41 | 000,000,000 | ---D | M] (NCH DE Community Toolbar) -- E:\Users\Fiete\AppData\Roaming\Mozilla\Firefox\Profiles\nm34zs2n.default\extensions\{b106b661-3e1b-4015-af5c-195e909f35c6}
[2012/01/09 12:31:25 | 000,000,000 | ---D | M] (Babylon) -- E:\Users\Fiete\AppData\Roaming\Mozilla\Firefox\Profiles\nm34zs2n.default\extensions\ffxtlbr@babylon.com
[2013/02/08 15:36:50 | 000,000,000 | ---D | M] (Delta Toolbar) -- E:\Users\Fiete\AppData\Roaming\Mozilla\Firefox\Profiles\nm34zs2n.default\extensions\ffxtlbr@delta.com
[2011/02/08 03:49:04 | 000,000,915 | ---- | M] () -- E:\Users\Fiete\AppData\Roaming\Mozilla\Firefox\Profiles\nm34zs2n.default\searchplugins\conduit.xml
[2013/02/08 15:36:51 | 000,001,294 | ---- | M] () -- E:\Users\Fiete\AppData\Roaming\Mozilla\Firefox\Profiles\nm34zs2n.default\searchplugins\delta.xml
[2013/02/08 18:28:36 | 000,006,874 | ---- | M] () -- E:\Users\Fiete\AppData\Roaming\Mozilla\Firefox\Profiles\nm34zs2n.default\searchplugins\fbdownloader_search.xml
[2013/02/20 03:04:16 | 000,002,384 | ---- | M] () -- E:\Users\Fiete\AppData\Roaming\Mozilla\Firefox\Profiles\nm34zs2n.default\searchplugins\search.xml
[2013/05/22 15:15:51 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\Extensions
[2013/07/02 02:42:53 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/11/08 13:13:31 | 000,000,000 | ---D | M] (Default) -- E:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/07/02 02:42:46 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\distribution\extensions
[2013/07/02 02:42:46 | 000,000,000 | ---D | M] (WEB.DE MailCheck) -- E:\Program Files (x86)\Mozilla Firefox\distribution\extensions\toolbar@web.de
File not found (No name found) --
() (No name found) -- E:\USERS\FIETE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NM34ZS2N.DEFAULT\EXTENSIONS\TOOLBAR@WEB.DE.XPI
[2013/09/03 08:53:52 | 000,187,248 | ---- | M] (Adobe Systems Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2011/02/05 05:43:08 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll
[2011/02/05 05:43:08 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll
[2011/02/05 05:43:08 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll
[2011/02/05 05:43:08 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll
[2011/02/05 05:43:08 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll
[2011/02/05 05:43:08 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll
[2011/02/05 05:43:08 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll
[2013/02/08 15:36:43 | 000,006,484 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live ID-Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - E:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - E:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - E:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - E:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - E:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\Fiete_ON_E\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\Fiete_ON_E\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKU\Fiete_ON_E\..\Toolbar\WebBrowser: (no name) - {7E111A5C-3D11-4F56-9463-5310C3C69025} - No CLSID value found.
O3 - HKU\Fiete_ON_E\..\Toolbar\WebBrowser: (no name) - {B106B661-3E1B-4015-AF5C-195E909F35C6} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Acer ePower Management] E:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [ETDWare] E:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [mwlDaemon] E:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] E:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] E:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe ARM] E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ArcSoft Connection Service] E:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avgnt] E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BackupManagerTray] E:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] E:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] E:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [LManager] E:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [NBAgent] E:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [OrderReminder] E:\Program Files (x86)\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard)
O4 - HKLM..\Run: [QuickTime Task] E:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [StartCCC] E:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] E:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKU\LocalService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_E..\RunOnce: [mctadmin] File not found
O4 - HKU\NetworkService_ON_E..\RunOnce: [mctadmin] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKU\Fiete_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - E:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - E:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - E:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - E:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - E:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\Program Files (x86)\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - E:\Windows\System32\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - E:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - E:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - E:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - E:\Windows\System32\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - E:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - E:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000013 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000014 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000015 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000016 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000017 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000018 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000019 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - E:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - E:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - E:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - E:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - E:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - E:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - E:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - E:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - E:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - E:\Windows\System32\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - E:\Windows\System32\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - E:\Windows\System32\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - E:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - E:\Windows\System32\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - E:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - E:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - E:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - E:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - E:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - E:\Windows\System32\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - E:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - E:\Windows\System32\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - E:\Windows\System32\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - E:\Windows\System32\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - E:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (livessp) - E:\Windows\System32\livessp.dll (Microsoft Corp.)
O30 - LSA: Security Packages - (kerberos) - E:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - E:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - E:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - E:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - E:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - E:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - E:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{6b2995c5-0baa-11e0-906b-88ae1d813a19}\Shell - "" = AutoRun
O33 - MountPoints2\{6b2995c5-0baa-11e0-906b-88ae1d813a19}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{81188436-c83b-11e0-9f35-88ae1d813a19}\Shell - "" = AutoRun
O33 - MountPoints2\{81188436-c83b-11e0-9f35-88ae1d813a19}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2013/11/12 13:04:07 | 000,061,536 | ---- | C] (Microsoft Corporation) -- E:\ProgramData\qzjrwvj6.pss
[2013/11/12 13:04:02 | 000,131,072 | ---- | C] (Microsoft Corporation) -- E:\ProgramData\6jvwrjzq.dss
[2013/11/08 15:09:36 | 000,000,000 | ---D | C] -- E:\Users\Fiete\AppData\Local\{12629308-C230-436E-B1AC-2ED7B83D2025}
[2013/11/04 15:15:29 | 000,000,000 | ---D | C] -- E:\Users\Fiete\AppData\Local\{945B236A-598C-447D-BE18-E76B57135686}
[2013/11/02 15:04:27 | 000,000,000 | ---D | C] -- E:\Users\Fiete\AppData\Local\{2BBEB3B0-30C9-4503-AE4A-97C36428B0D6}
[2013/11/01 15:33:21 | 000,000,000 | ---D | C] -- E:\Users\Fiete\AppData\Local\{BE2E8CC1-F74A-4D09-BB9C-212AD942AF29}
[2013/10/27 15:50:23 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\OnlineFotoservice
[2013/10/27 14:57:54 | 000,000,000 | ---D | C] -- E:\Users\Fiete\AppData\Local\{2852E9FC-3C43-430C-8906-860A91EC74EB}
[2013/10/24 15:54:27 | 000,000,000 | ---D | C] -- E:\Users\Fiete\AppData\Local\{D3AE76BD-6339-4001-9AE3-4077E6337142}
[2013/10/23 14:16:38 | 000,000,000 | ---D | C] -- E:\Users\Fiete\AppData\Local\{E90F1997-0069-4B64-BF08-AF3C3B6EF5CB}
[2013/10/22 13:32:08 | 000,000,000 | ---D | C] -- E:\Users\Fiete\AppData\Local\{92CEE15E-1D3F-44C8-8747-696A84F44974}
[2013/10/21 14:24:58 | 000,000,000 | ---D | C] -- E:\Users\Fiete\Documents\Nero
[2013/10/19 15:01:21 | 000,000,000 | ---D | C] -- E:\Users\Fiete\AppData\Local\{441CF273-D3F2-4224-8395-501463FFB2D9}
[2013/10/18 17:10:21 | 000,000,000 | ---D | C] -- E:\Users\Fiete\AppData\Local\{89ACA6CD-B3CE-4A5B-A0A2-C2DAB8282608}
[2013/10/17 15:20:59 | 000,000,000 | ---D | C] -- E:\Users\Fiete\AppData\Local\{765E9206-B200-4D1D-B330-E99AFC9AE151}
========== Files - Modified Within 30 Days ==========
[2013/11/15 14:58:36 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat
[2013/11/15 14:58:17 | 3015,884,800 | -HS- | M] () -- E:\hiberfil.sys
[2013/11/15 14:25:53 | 000,000,051 | ---- | M] () -- E:\.directory
[2013/11/15 13:41:27 | 000,000,050 | ---- | M] () -- E:\Users\Fiete\AppData\Local\.directory
[2013/11/14 14:09:33 | 095,025,368 | ---- | M] () -- E:\ProgramData\qzjrwvj6.bxx
[2013/11/14 14:09:26 | 000,000,000 | ---- | M] () -- E:\ProgramData\qzjrwvj6.fvv
[2013/11/14 14:09:09 | 000,000,006 | -H-- | M] () -- E:\Windows\tasks\SA.DAT
[2013/11/12 19:35:59 | 009,880,457 | -H-- | M] () -- E:\Users\Fiete\AppData\Local\IconCache.db
[2013/11/12 19:10:03 | 000,000,884 | ---- | M] () -- E:\Windows\tasks\Adobe Flash Player Updater.job
[2013/11/12 15:51:09 | 000,009,696 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/11/12 15:51:09 | 000,009,696 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/11/12 13:04:44 | 000,000,285 | ---- | M] () -- E:\ProgramData\qzjrwvj6.reg
[2013/11/12 13:04:07 | 000,061,536 | ---- | M] (Microsoft Corporation) -- E:\ProgramData\qzjrwvj6.pss
[2013/11/12 13:04:02 | 000,131,072 | ---- | M] (Microsoft Corporation) -- E:\ProgramData\6jvwrjzq.dss
[2013/11/12 12:30:03 | 001,507,104 | ---- | M] () -- E:\Windows\System32\PerfStringBackup.INI
[2013/11/12 12:30:03 | 000,657,666 | ---- | M] () -- E:\Windows\System32\perfh007.dat
[2013/11/12 12:30:03 | 000,618,912 | ---- | M] () -- E:\Windows\System32\perfh009.dat
[2013/11/12 12:30:03 | 000,131,024 | ---- | M] () -- E:\Windows\System32\perfc007.dat
[2013/11/12 12:30:03 | 000,107,232 | ---- | M] () -- E:\Windows\System32\perfc009.dat
[2013/11/11 04:23:28 | 000,000,047 | ---- | M] () -- E:\Windows\Ulead32.INI
[2013/11/08 13:13:46 | 000,002,052 | ---- | M] () -- E:\Users\Fiete\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/11/03 12:45:55 | 000,001,024 | RH-- | M] () -- E:\Users\Public\Documents\NTIMMV9Acer.dll
[2013/10/29 16:42:06 | 000,001,134 | ---- | M] () -- E:\Users\Public\Desktop\dm-Fotowelt.lnk
[2013/10/23 14:05:10 | 000,000,675 | ---- | M] () -- E:\Windows\win.ini
========== Files Created - No Company Name ==========
[2013/11/15 14:25:53 | 000,000,051 | ---- | C] () -- E:\.directory
[2013/11/15 13:41:27 | 000,000,050 | ---- | C] () -- E:\Users\Fiete\AppData\Local\.directory
[2013/11/12 13:04:44 | 000,000,285 | ---- | C] () -- E:\ProgramData\qzjrwvj6.reg
[2013/11/12 13:04:06 | 000,000,000 | ---- | C] () -- E:\ProgramData\qzjrwvj6.fvv
[2013/11/12 13:04:03 | 095,025,368 | ---- | C] () -- E:\ProgramData\qzjrwvj6.bxx
[2013/10/10 11:04:32 | 002,220,368 | ---- | C] () -- E:\Users\Fiete\AppData\Local\omesuperv.exe
[2013/02/11 16:51:30 | 000,007,832 | ---- | C] () -- E:\Windows\CDPlayer.ini
[2012/12/13 16:29:31 | 000,000,024 | ---- | C] () -- E:\Windows\SysWow64\LOGL2DI_COINST.DAT
[2012/12/02 11:14:34 | 000,000,032 | ---- | C] () -- E:\Windows\CD_Start.INI
[2012/08/24 13:25:39 | 000,000,056 | -H-- | C] () -- E:\Windows\SysWow64\ezsidmv.dat
[2012/08/24 12:19:34 | 000,000,032 | ---- | C] () -- E:\Windows\Menu.INI
[2012/01/23 16:24:18 | 000,000,040 | ---- | C] () -- E:\Windows\iltwain.ini
[2011/10/20 10:37:08 | 000,004,096 | -H-- | C] () -- E:\Users\Fiete\AppData\Local\keyfile3.drm
[2011/08/06 15:32:17 | 000,000,046 | ---- | C] () -- E:\Windows\Speed.INI
[2011/06/15 14:42:35 | 000,000,069 | ---- | C] () -- E:\Windows\NeroDigital.ini
[2011/06/04 18:22:15 | 000,252,928 | ---- | C] () -- E:\Windows\SysWow64\DShowRdpFilter.dll
[2011/03/08 15:33:11 | 000,000,000 | ---- | C] () -- E:\Windows\PhEdit.INI
[2011/03/04 14:41:08 | 000,111,932 | ---- | C] () -- E:\Windows\SysWow64\EPPICPrinterDB.dat
[2011/03/04 14:41:08 | 000,031,053 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern131.dat
[2011/03/04 14:41:08 | 000,027,417 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern121.dat
[2011/03/04 14:41:08 | 000,026,154 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern1.dat
[2011/03/04 14:41:08 | 000,024,903 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern3.dat
[2011/03/04 14:41:08 | 000,021,390 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern5.dat
[2011/03/04 14:41:08 | 000,020,148 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern2.dat
[2011/03/04 14:41:08 | 000,011,811 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern4.dat
[2011/03/04 14:41:08 | 000,004,943 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern6.dat
[2011/03/04 14:41:08 | 000,001,146 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_DU.dat
[2011/03/04 14:41:08 | 000,001,139 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_PT.dat
[2011/03/04 14:41:08 | 000,001,139 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_BP.dat
[2011/03/04 14:41:08 | 000,001,136 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_ES.dat
[2011/03/04 14:41:08 | 000,001,129 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_FR.dat
[2011/03/04 14:41:08 | 000,001,129 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_CF.dat
[2011/03/04 14:41:08 | 000,001,120 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_IT.dat
[2011/03/04 14:41:08 | 000,001,107 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_GE.dat
[2011/03/04 14:41:08 | 000,001,104 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_EN.dat
[2011/03/04 14:41:08 | 000,000,097 | ---- | C] () -- E:\Windows\SysWow64\PICSDK.ini
[2011/02/07 16:40:27 | 000,000,046 | ---- | C] () -- E:\Windows\mxcdr.INI
[2011/01/27 06:55:11 | 000,000,052 | ---- | C] () -- E:\Windows\Relax.ini
[2011/01/26 16:13:27 | 000,000,016 | -H-- | C] () -- E:\Users\Fiete\AppData\Local\mxfilerelatedcache.mxc2
[2011/01/08 10:34:46 | 000,000,400 | ---- | C] () -- E:\Windows\ODBC.INI
[2011/01/08 10:07:12 | 000,000,209 | ---- | C] () -- E:\Windows\ODBCINST.INI
[2010/12/20 13:22:23 | 000,000,600 | ---- | C] () -- E:\Users\Fiete\AppData\Roaming\winscp.rnd
[2010/12/20 13:04:31 | 000,000,047 | ---- | C] () -- E:\Windows\Ulead32.INI
[2010/12/20 13:03:48 | 000,007,680 | ---- | C] () -- E:\Windows\SysWow64\drivers\Onsreged.sys
[2010/12/20 13:03:47 | 000,285,216 | ---- | C] () -- E:\Windows\SysWow64\drivers\Onsio.sys
[2010/12/20 12:44:13 | 000,000,600 | ---- | C] () -- E:\Users\Fiete\AppData\Local\PUTTY.RND
[2010/12/20 12:44:06 | 000,000,319 | ---- | C] () -- E:\Windows\homeDVD-Filme4.INI
[2010/12/20 12:41:31 | 000,019,968 | ---- | C] () -- E:\Windows\SysWow64\cpuinf32.dll
[2010/12/20 12:36:17 | 000,000,088 | ---- | C] () -- E:\Windows\magix.ini
[2010/12/20 12:35:37 | 000,001,208 | ---- | C] () -- E:\Windows\mgxoschk.ini
[2010/12/16 13:48:48 | 001,535,546 | ---- | C] () -- E:\Windows\SysWow64\PerfStringBackup.INI
[2010/12/11 16:28:22 | 000,106,496 | R--- | C] () -- E:\Windows\SysWow64\vshp1020.dll
[2010/12/11 16:28:21 | 000,397,312 | R--- | C] () -- E:\Windows\SysWow64\zshp1020.exe
[2010/12/11 16:20:38 | 009,880,457 | -H-- | C] () -- E:\Users\Fiete\AppData\Local\IconCache.db
[2010/12/11 15:31:08 | 000,022,528 | ---- | C] () -- E:\Users\Fiete\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/11 15:16:49 | 000,144,312 | ---- | C] () -- E:\Users\Fiete\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/09/08 04:46:42 | 004,497,993 | ---- | C] () -- E:\Windows\SysWow64\libavcodec.dll
[2010/09/08 04:46:42 | 001,529,856 | ---- | C] () -- E:\Windows\SysWow64\ff_samplerate.dll
[2010/09/08 04:46:42 | 001,212,665 | ---- | C] () -- E:\Windows\SysWow64\ffmpegmt.dll
[2010/09/08 04:46:42 | 000,903,723 | ---- | C] () -- E:\Windows\SysWow64\ff_x264.dll
[2010/09/08 04:46:42 | 000,880,220 | ---- | C] () -- E:\Windows\SysWow64\xvidcore.dll
[2010/09/08 04:46:42 | 000,336,384 | ---- | C] () -- E:\Windows\SysWow64\ff_libfaad2.dll
[2010/09/08 04:46:42 | 000,324,096 | ---- | C] () -- E:\Windows\SysWow64\TomsMoComp_ff.dll
[2010/09/08 04:46:42 | 000,248,320 | ---- | C] () -- E:\Windows\SysWow64\ff_kernelDeint.dll
[2010/09/08 04:46:42 | 000,216,576 | ---- | C] () -- E:\Windows\SysWow64\ff_libdts.dll
[2010/09/08 04:46:42 | 000,151,552 | ---- | C] () -- E:\Windows\SysWow64\ff_libmad.dll
[2010/09/08 04:46:42 | 000,145,408 | ---- | C] () -- E:\Windows\SysWow64\libmpeg2_ff.dll
[2010/09/08 04:46:42 | 000,142,291 | ---- | C] () -- E:\Windows\SysWow64\libmplayer.dll
[2010/09/08 04:46:42 | 000,121,856 | ---- | C] () -- E:\Windows\SysWow64\ff_liba52.dll
[2010/09/08 04:46:42 | 000,116,736 | ---- | C] () -- E:\Windows\SysWow64\ff_tremor.dll
[2010/09/08 04:46:42 | 000,097,792 | ---- | C] () -- E:\Windows\SysWow64\ff_unrar.dll
[2010/09/08 03:45:00 | 000,100,864 | ---- | C] () -- E:\Windows\SysWow64\ff_wmv9.dll
[2010/09/08 03:09:46 | 000,108,032 | ---- | C] () -- E:\Windows\SysWow64\ff_vfw.dll
[2010/09/07 02:07:09 | 000,000,000 | ---- | C] () -- E:\Windows\ativpsrm.bin
[2010/08/14 03:45:18 | 000,249,856 | ---- | C] () -- E:\Windows\SysWow64\dxr.dll
[2010/08/14 03:45:10 | 000,358,400 | ---- | C] () -- E:\Windows\SysWow64\gdsmux.exe
[2010/08/14 03:43:52 | 000,150,528 | ---- | C] () -- E:\Windows\SysWow64\mkx.dll
[2010/08/14 03:43:42 | 000,109,568 | ---- | C] () -- E:\Windows\SysWow64\avi.dll
[2010/08/14 03:43:34 | 000,141,824 | ---- | C] () -- E:\Windows\SysWow64\mp4.dll
[2010/08/14 03:43:22 | 000,123,392 | ---- | C] () -- E:\Windows\SysWow64\ogm.dll
[2010/08/14 03:42:54 | 000,113,152 | ---- | C] () -- E:\Windows\SysWow64\dsmux.exe
[2010/08/14 03:42:48 | 000,154,112 | ---- | C] () -- E:\Windows\SysWow64\ts.dll
[2010/08/14 03:42:10 | 000,097,792 | ---- | C] () -- E:\Windows\SysWow64\avs.dll
[2010/08/14 03:42:06 | 000,137,728 | ---- | C] () -- E:\Windows\SysWow64\mkv2vfr.exe
[2010/08/14 03:41:54 | 000,093,184 | ---- | C] () -- E:\Windows\SysWow64\avss.dll
[2010/08/14 03:40:02 | 000,080,384 | ---- | C] () -- E:\Windows\SysWow64\mkzlib.dll
[2010/08/14 03:39:58 | 000,024,576 | ---- | C] () -- E:\Windows\SysWow64\mkunicode.dll
[2010/08/04 22:36:18 | 000,002,093 | ---- | C] () -- E:\Windows\SysWow64\atipblag.dat
[2010/07/14 05:20:19 | 000,131,984 | ---- | C] () -- E:\ProgramData\FullRemove.exe
[2009/08/11 16:21:26 | 000,087,552 | ---- | C] () -- E:\Windows\SysWow64\ac3config.exe
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat
[2009/07/14 00:32:39 | 000,043,318 | ---- | C] () -- E:\Windows\Fonts\GlobalUserInterface.CompositeFont
[2009/07/14 00:32:39 | 000,029,779 | ---- | C] () -- E:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:39 | 000,026,489 | ---- | C] () -- E:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:39 | 000,026,040 | ---- | C] () -- E:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:35:42 | 000,001,405 | ---- | C] () -- E:\Windows\msdfmap.ini
[2009/07/13 21:34:57 | 000,000,675 | ---- | C] () -- E:\Windows\win.ini
[2009/07/13 21:34:57 | 000,000,219 | ---- | C] () -- E:\Windows\system.ini
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- E:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:25:04 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat
[2009/06/07 11:24:04 | 000,180,224 | ---- | C] () -- E:\Windows\SysWow64\xvidvfw.dll
[2009/01/10 17:15:44 | 000,159,744 | ---- | C] () -- E:\Windows\SysWow64\mmfinfo.dll
[2008/11/06 10:37:32 | 003,596,288 | ---- | C] () -- E:\Windows\SysWow64\qt-dx331.dll
[2007/10/13 04:30:20 | 000,000,137 | ---- | C] () -- E:\Windows\SysWow64\Registration.ini
[2007/04/27 02:43:58 | 000,120,200 | ---- | C] () -- E:\Windows\SysWow64\DLLDEV32i.dll
[2003/02/20 11:53:42 | 000,005,702 | ---- | C] () -- E:\Windows\SysWow64\OUTLPERF.INI
========== LOP Check ==========
[2011/05/07 11:31:19 | 000,000,000 | ---D | M] -- E:\ProgramData\AAV
[2010/07/14 05:29:22 | 000,000,000 | ---D | M] -- E:\ProgramData\Acer
[2010/12/11 15:15:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data
[2013/02/08 15:36:36 | 000,000,000 | ---D | M] -- E:\ProgramData\Babylon
[2010/07/14 05:38:44 | 000,000,000 | ---D | M] -- E:\ProgramData\BackupManager
[2011/06/11 10:40:52 | 000,000,000 | ---D | M] -- E:\ProgramData\Canneverbe Limited
[2012/12/13 11:03:24 | 000,000,000 | ---D | M] -- E:\ProgramData\CLSK
[2012/12/14 15:19:00 | 000,000,000 | ---D | M] -- E:\ProgramData\Conexant
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents
[2010/12/11 15:15:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente
[2010/07/14 05:45:27 | 000,000,000 | ---D | M] -- E:\ProgramData\EgisTec IPS
[2010/07/14 05:18:39 | 000,000,000 | ---D | M] -- E:\ProgramData\eSobi
[2010/12/11 15:15:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites
[2012/12/11 13:21:23 | 000,000,000 | ---D | M] -- E:\ProgramData\Installations
[2012/12/13 11:11:28 | 000,000,000 | ---D | M] -- E:\ProgramData\install_clap
[2011/12/08 16:31:44 | 000,000,000 | ---D | M] -- E:\ProgramData\MAGIX
[2011/02/09 04:59:04 | 000,000,000 | ---D | M] -- E:\ProgramData\NCH Swift Sound
[2012/12/12 13:32:22 | 000,000,000 | ---D | M] -- E:\ProgramData\NokiaMusic
[2010/07/14 05:24:51 | 000,000,000 | ---D | M] -- E:\ProgramData\OberonGameConsole
[2010/12/11 15:18:16 | 000,000,000 | ---D | M] -- E:\ProgramData\oem
[2011/03/04 14:51:31 | 000,000,000 | ---D | M] -- E:\ProgramData\Panasonic
[2011/01/02 14:36:50 | 000,000,000 | ---D | M] -- E:\ProgramData\Partner
[2012/02/12 14:24:49 | 000,000,000 | ---D | M] -- E:\ProgramData\PC Suite
[2012/12/13 15:50:48 | 000,000,000 | ---D | M] -- E:\ProgramData\SmartSound Software Inc
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu
[2010/12/11 15:15:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü
[2013/11/15 14:27:00 | 000,000,000 | ---D | M] -- E:\ProgramData\Temp
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates
[2013/11/15 13:58:26 | 000,000,000 | ---D | M] -- E:\ProgramData\tmp
[2012/12/14 15:21:26 | 000,000,000 | ---D | M] -- E:\ProgramData\Ulead Systems
[2010/12/16 16:04:09 | 000,000,000 | ---D | M] -- E:\ProgramData\VirtualizedApplications
[2010/12/11 15:15:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen
[2013/10/30 18:28:42 | 000,032,632 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2013/11/11 03:46:39 | 103,681,534 | ---- | M] ()(E:\Windows\SysWow64\????) -- E:\Windows\SysWow64\꒗掬Ḭ”
[2013/11/11 03:46:39 | 103,681,534 | ---- | C] ()(E:\Windows\SysWow64\????) -- E:\Windows\SysWow64\꒗掬Ḭ”
[2013/10/09 13:20:04 | 100,163,860 | ---- | M] ()(E:\Windows\SysWow64\????) -- E:\Windows\SysWow64\印⬨Ḭˆ
[2013/10/09 13:20:04 | 100,163,860 | ---- | C] ()(E:\Windows\SysWow64\????) -- E:\Windows\SysWow64\印⬨Ḭˆ
[2013/09/23 07:46:43 | 098,646,441 | ---- | M] ()(E:\Windows\SysWow64\???) -- E:\Windows\SysWow64\쒱Ḭ
[2013/09/23 07:46:43 | 098,646,441 | ---- | C] ()(E:\Windows\SysWow64\???) -- E:\Windows\SysWow64\쒱Ḭ
[2013/09/12 15:22:02 | 097,373,152 | ---- | M] ()(E:\Windows\SysWow64\???¡) -- E:\Windows\SysWow64\笣죢Ḭ¡
[2013/09/12 11:48:52 | 097,373,152 | ---- | C] ()(E:\Windows\SysWow64\???¡) -- E:\Windows\SysWow64\笣죢Ḭ¡
[2013/08/21 13:31:15 | 099,712,133 | ---- | M] ()(E:\Windows\SysWow64\???) -- E:\Windows\SysWow64\코蝤Ḭ
[2013/08/21 12:48:46 | 099,712,133 | ---- | C] ()(E:\Windows\SysWow64\???) -- E:\Windows\SysWow64\코蝤Ḭ
========== Alternate Data Streams ==========
@Alternate Data Stream - 120 bytes -> E:\ProgramData\Temp:DAF232F8
< End of report > --- --- --- |