OTL Scan 2:
OTL Logfile: Code:
OTL logfile created on: 10.10.2010 12:50:09 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\Justus\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 21,00% Memory free
8,00 Gb Paging File | 4,00 Gb Available in Paging File | 48,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,75 Gb Total Space | 140,42 Gb Free Space | 30,15% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JUSTUS-PC
Current User Name: Justus
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Justus\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\StarCraft II\Versions\Base16605\SC2.exe (Blizzard Entertainment, Inc.)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Hotspot Shield\bin\openvpntray.exe ()
PRC - C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe ()
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe ()
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe ()
PRC - C:\Program Files (x86)\Orbitdownloader\orbitnet.exe (Orbitdownloader.com)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\ROCCAT\Kone Mouse\KoneHID.EXE (ROCCAT)
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
PRC - C:\Program Files (x86)\ROCCAT\Kone Mouse\osd.exe (ROCCAT)
PRC - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Justus\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (SandraAgentSrv) -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\RpcAgentSrv.exe (SiSoftware)
SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) -- C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Akamai) -- c:\program files (x86)\common files\akamai\netsession_win_062a651.dll ()
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (HssTrayService) -- C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE ()
SRV - (HotspotShieldService) -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe ()
SRV - (HssWd) -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe ()
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (TeamViewer5) -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (ICQ Service) -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe ()
SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (taphss) -- C:\Windows\SysNative\drivers\taphss.sys (AnchorFree Inc)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (npf) -- C:\Windows\SysNative\drivers\npf.sys (CACE Technologies, Inc.)
DRV:64bit: - (phaudlwr) -- C:\Windows\SysNative\drivers\phaudlwr.sys (Philips Applied Technologies)
DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (SANDRA) -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x64\Sandra.sys (SiSoftware)
DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) -- C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) -- C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) -- C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (s3cap) -- C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) -- C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (cmuda3) -- C:\Windows\SysNative\drivers\cmudax3.sys (C-Media Inc)
DRV:64bit: - (KoneFltr) -- C:\Windows\SysNative\drivers\Kone.sys (ROCCAT Ltd)
DRV:64bit: - (SPC520m) -- C:\Windows\SysNative\drivers\SPC520m.sys (Philips )
DRV:64bit: - (SPC520) -- C:\Windows\SysNative\drivers\SPC520.sys (Philips )
DRV - (adfs) -- C:\Windows\SysWow64\drivers\adfs.sys (Adobe Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Orbit Downloader Start
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN, Messenger und Hotmail sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 66 76 D2 A5 24 AE CA 01 [binary data]
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "hxxp://search.orbitdownloader.com"
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.6.6.117
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.10
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.2.0185
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: {9611b826-9719-45bf-ba55-671c7bf6fd6d}:1.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: ffxtlbr@Facemoods.com:1.1.0
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.1&q="
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties"
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.08.08 11:26:05 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.08.08 11:26:05 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2010.09.06 14:39:29 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2010.07.25 18:59:50 | 000,000,000 | ---D | M] -- C:\Users\Justus\AppData\Roaming\mozilla\Extensions
[2010.07.25 18:59:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Justus\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.08.11 20:26:09 | 000,000,000 | ---D | M] -- C:\Users\Justus\AppData\Roaming\mozilla\Firefox\Profiles\fiyz9xu8.default\extensions
[2010.03.06 12:19:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Justus\AppData\Roaming\mozilla\Firefox\Profiles\fiyz9xu8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.03.28 20:24:58 | 000,000,000 | ---D | M] (Streamed Video) -- C:\Users\Justus\AppData\Roaming\mozilla\Firefox\Profiles\fiyz9xu8.default\extensions\{9611b826-9719-45bf-ba55-671c7bf6fd6d}
[2010.04.17 00:06:34 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Justus\AppData\Roaming\mozilla\Firefox\Profiles\fiyz9xu8.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010.04.16 12:30:15 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\Justus\AppData\Roaming\mozilla\Firefox\Profiles\fiyz9xu8.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2010.04.16 12:30:15 | 000,000,000 | ---D | M] -- C:\Users\Justus\AppData\Roaming\mozilla\Firefox\Profiles\fiyz9xu8.default\extensions\DTToolbar@toolbarnet.com
[2010.08.08 12:48:09 | 000,000,000 | ---D | M] -- C:\Users\Justus\AppData\Roaming\mozilla\Firefox\Profiles\fiyz9xu8.default\extensions\ffxtlbr@Facemoods.com
[2010.02.18 06:31:28 | 000,000,000 | ---D | M] -- C:\Users\Justus\AppData\Roaming\mozilla\Firefox\Profiles\fiyz9xu8.default\extensions\toolbar@ask.com
[2010.02.18 05:38:29 | 000,002,254 | ---- | M] () -- C:\Users\Justus\AppData\Roaming\Mozilla\FireFox\Profiles\fiyz9xu8.default\searchplugins\askcom.xml
[2010.02.27 18:19:00 | 000,002,055 | ---- | M] () -- C:\Users\Justus\AppData\Roaming\Mozilla\FireFox\Profiles\fiyz9xu8.default\searchplugins\daemon-search.xml
[2010.08.08 11:26:18 | 000,000,950 | ---- | M] () -- C:\Users\Justus\AppData\Roaming\Mozilla\FireFox\Profiles\fiyz9xu8.default\searchplugins\icqplugin-1.xml
[2010.08.08 12:48:15 | 000,000,950 | ---- | M] () -- C:\Users\Justus\AppData\Roaming\Mozilla\FireFox\Profiles\fiyz9xu8.default\searchplugins\icqplugin-2.xml
[2010.04.25 15:54:52 | 000,000,947 | ---- | M] () -- C:\Users\Justus\AppData\Roaming\Mozilla\FireFox\Profiles\fiyz9xu8.default\searchplugins\icqplugin.xml
[2010.02.22 17:13:18 | 000,003,915 | ---- | M] () -- C:\Users\Justus\AppData\Roaming\Mozilla\FireFox\Profiles\fiyz9xu8.default\searchplugins\sweetim.xml
[2010.08.08 12:48:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions
[2010.03.09 14:50:40 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files (x86)\mozilla firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.04.25 08:18:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.04.25 08:18:34 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2009.09.21 12:00:44 | 001,447,328 | ---- | M] (1 mal 1 Software GmbH) -- C:\Program Files (x86)\mozilla firefox\plugins\NpFv522.dll
[2010.03.28 00:28:04 | 000,238,776 | ---- | M] (Pando Networks) -- C:\Program Files (x86)\mozilla firefox\plugins\npPandoWebInst.dll
[2010.07.12 18:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2010.08.08 11:26:04 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.08.08 11:26:04 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.07.27 10:44:36 | 000,002,037 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchwfxt1.xml
[2010.08.08 11:26:04 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.08.08 11:26:04 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.08.08 11:26:04 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\hssie\HssIE_64.dll (AnchorFree Inc.)
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.8.1\bh\facemoods.dll (facemoods.com BHO)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\hssie\HssIE.dll (AnchorFree Inc.)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.8.1\facemoodsTlbr.dll (facemoods.com)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4:64bit: - HKLM..\Run: [CmPCIaudio] C:\Windows\Syswow64\CMICNFG3.DLL (C-Media Corporation)
O4:64bit: - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [facemoods] C:\Program Files (x86)\facemoods.com\facemoods\1.4.8.1\facemoodssrv.exe (facemoods.com)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Kone] C:\Program Files (x86)\ROCCAT\Kone Mouse\KoneHID.EXE (ROCCAT)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EA Core] C:\Program Files (x86)\Electronic Arts\EADM\Core.exe File not found
O4 - HKCU..\Run: [ISUSPM] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Speech Recognition] C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [System] C:\Users\Justus\Music\lst.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O8:64bit: - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: RF - Formular ausfüllen - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8:64bit: - Extra context menu item: RF - Formular speichern - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8:64bit: - Extra context menu item: RF - Menü anpassen - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8:64bit: - Extra context menu item: RF - RoboForm-Leiste ein/aus - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: RF - Formular ausfüllen - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RF - Formular speichern - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: RF - Menü anpassen - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: RF - RoboForm-Leiste ein/aus - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Ausfüllen - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : RF - Formular ausfüllen - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Speichern - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : RF - Formular speichern - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RF - RoboForm-Leiste ein/aus - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files (x86)\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files (x86)\ICQ7.0\ICQ.exe (ICQ, LLC.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex64-2.2.5.0.cab (DLM Control)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab (DLM Control)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~3\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~3\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~3\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.02.15 01:31:57 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{1c91ecf3-23e5-11df-b48c-002354693d12}\Shell - "" = AutoRun
O33 - MountPoints2\{1c91ecf3-23e5-11df-b48c-002354693d12}\Shell\AutoRun\command - "" = F:\start_CD.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010.10.09 10:11:55 | 000,000,000 | ---D | C] -- C:\Users\Justus\AppData\Roaming\Malwarebytes
[2010.10.09 10:11:43 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010.10.09 10:11:41 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010.10.09 10:11:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.10.09 10:11:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010.10.09 10:10:30 | 000,576,512 | ---- | C] (OldTimer Tools) -- C:\Users\Justus\Desktop\OTL.exe
[2010.10.09 10:09:26 | 006,153,648 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Justus\Desktop\mbam-setup.exe
[2010.10.07 22:14:05 | 000,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Users\Justus\Desktop\HiJackThis.exe
[2010.10.07 20:44:02 | 000,000,000 | ---D | C] -- C:\Users\Justus\Desktop\NWT
[2010.10.04 20:04:19 | 000,000,000 | ---D | C] -- C:\ProgramData\ROCCAT
[2010.10.04 20:04:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ROCCAT
[2010.10.04 19:57:13 | 000,000,000 | ---D | C] -- C:\Users\Justus\Desktop\ROCCAT_KONE_DRV1.41_FW1.41
[2010.10.04 19:47:16 | 000,000,000 | ---D | C] -- C:\Users\Justus\AppData\Roaming\ROCCAT
[2010.09.30 15:39:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared
[2010.09.29 18:07:13 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ks.sys
[2010.09.28 12:53:07 | 000,000,000 | ---D | C] -- C:\Users\Justus\Desktop\wordpress
[2010.09.26 21:27:05 | 000,000,000 | ---D | C] -- C:\Users\Justus\Desktop\Homepage
[2010.09.23 13:59:46 | 000,198,656 | ---- | C] (DeathSoft™) -- C:\Users\Justus\Desktop\WoWEmuHacker5.exe
[2010.09.23 13:59:46 | 000,000,000 | ---D | C] -- C:\Users\Justus\Desktop\WEHBGS
[2010.09.22 15:28:27 | 000,000,000 | ---D | C] -- C:\Users\Justus\Desktop\JustusTest
[2010.09.19 11:02:16 | 000,000,000 | ---D | C] -- C:\Users\Justus\AppData\Roaming\Audacity
[2010.09.19 11:02:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity 1.3 Beta (Unicode)
[2010.09.19 06:18:41 | 000,000,000 | ---D | C] -- C:\Users\Justus\AppData\Local\CrashRpt
[2010.09.19 00:26:52 | 000,000,000 | ---D | C] -- C:\Users\Justus\Desktop\Call of Duty 6
[2010.09.19 00:25:08 | 000,000,000 | ---D | C] -- C:\Users\Justus\Desktop\PoRTaL
[2010.09.18 11:40:01 | 000,000,000 | ---D | C] -- C:\Users\Justus\Documents\The Lord of the Rings Online
[2010.09.18 11:40:01 | 000,000,000 | ---D | C] -- C:\Users\Justus\AppData\Local\The Lord of the Rings Online
[2010.09.17 17:22:45 | 000,000,000 | ---D | C] -- C:\Users\Justus\AppData\Roaming\Turbine
[2010.09.17 13:23:54 | 000,000,000 | ---D | C] -- C:\Users\Justus\Documents\My Downloads
[2010.09.17 13:23:51 | 000,000,000 | ---D | C] -- C:\Users\Justus\AppData\Roaming\GetRightToGo
[2010.09.17 13:23:35 | 000,415,466 | ---- | C] (Codemasters Online) -- C:\Users\Justus\Desktop\LOTROEU_Mirkwood_Standalone_Patch_European_ENGB.exe
[2010.09.17 13:22:40 | 000,000,000 | ---D | C] -- C:\Users\Justus\AppData\Local\Turbine
[2010.09.17 13:21:00 | 000,000,000 | ---D | C] -- C:\Users\Justus\AppData\Local\ApplicationHistory
[2010.09.17 13:18:50 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\URTTEMP
[2010.09.17 12:55:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Codemasters
[2010.09.15 15:13:02 | 002,441,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iertutil.dll
[2010.09.12 13:06:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2010.09.12 13:06:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NSSx64
[2010.09.12 13:06:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Security Scan
[2010.09.12 13:06:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2010.09.12 13:06:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NSSx64\0207030.022
[2010.09.12 13:06:40 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2010.09.12 13:06:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller
[2010.09.11 18:55:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mad Scientist Productions
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.10.10 12:55:05 | 003,932,160 | -HS- | M] () -- C:\Users\Justus\ntuser.dat
[2010.10.10 12:54:04 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010.10.10 12:45:40 | 000,001,302 | ---- | M] () -- C:\Users\Justus\Desktop\Log
[2010.10.10 09:36:35 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.10.10 09:36:35 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.10.10 09:29:35 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010.10.10 09:29:24 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.10.10 09:29:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.10.10 09:29:16 | 3220,529,152 | -HS- | M] () -- C:\hiberfil.sys
[2010.10.10 09:27:55 | 000,000,500 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Justus.job
[2010.10.09 10:11:45 | 000,001,009 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.10.09 10:10:29 | 006,153,648 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Justus\Desktop\mbam-setup.exe
[2010.10.08 15:23:12 | 004,647,212 | -H-- | M] () -- C:\Users\Justus\AppData\Local\IconCache.db
[2010.10.06 14:10:51 | 000,576,512 | ---- | M] (OldTimer Tools) -- C:\Users\Justus\Desktop\OTL.exe
[2010.09.30 17:29:19 | 805,792,189 | ---- | M] () -- C:\Users\Justus\Desktop\HC_Traingscamp_Vol.2.zip.ob!
[2010.09.30 16:12:32 | 000,009,216 | ---- | M] () -- C:\Users\Justus\Desktop\Milieu Bild.doc
[2010.09.30 16:12:19 | 000,164,352 | ---- | M] () -- C:\Users\Justus\Desktop\Sinus Milieus.doc
[2010.09.30 14:12:19 | 000,011,264 | ---- | M] () -- C:\Users\Justus\Desktop\Zusatzt.doc
[2010.09.30 14:12:02 | 000,012,552 | ---- | M] () -- C:\Users\Justus\Desktop\Zusatzt.odt
[2010.09.30 13:59:54 | 000,150,618 | ---- | M] () -- C:\Users\Justus\Desktop\Sinus-Milieus_de.JPG
[2010.09.30 13:50:56 | 000,338,003 | ---- | M] () -- C:\Users\Justus\Desktop\Die_Sinus-Milieus_in_Deutschland_2010.jpg
[2010.09.30 13:39:13 | 000,195,138 | ---- | M] () -- C:\Users\Justus\Desktop\Unbenannt 1.odt
[2010.09.19 11:02:13 | 000,001,042 | ---- | M] () -- C:\Users\Justus\Desktop\Audacity 1.3 Beta (Unicode).lnk
[2010.09.17 13:21:01 | 000,000,094 | ---- | M] () -- C:\Users\Justus\AppData\Local\fusioncache.dat
[2010.09.17 13:20:32 | 001,649,862 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2010.09.17 13:20:32 | 000,910,128 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010.09.17 13:20:32 | 000,439,488 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2010.09.17 13:20:32 | 000,384,070 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010.09.17 13:20:32 | 000,004,956 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.09.15 21:44:58 | 000,014,126 | ---- | M] () -- C:\Users\Justus\Documents\GOOD%20or%20Bad.doc_0.odt
[2010.09.15 21:14:48 | 000,011,264 | ---- | M] () -- C:\Users\Justus\Desktop\GOOD or Bad.doc
[2010.09.15 21:14:48 | 000,000,114 | -H-- | M] () -- C:\Users\Justus\Desktop\.~lock.GOOD or Bad.doc#
[2010.09.12 13:06:43 | 000,001,085 | ---- | M] () -- C:\Users\Public\Desktop\Norton Security Scan.lnk
[2010.09.12 13:06:41 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\NSSx64\0207030.022\isolate.ini
[2010.09.11 18:16:29 | 000,002,266 | ---- | M] () -- C:\Users\Public\Desktop\EA Download Manager.lnk
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.10.10 12:45:39 | 000,001,302 | ---- | C] () -- C:\Users\Justus\Desktop\Log
[2010.10.09 10:11:45 | 000,001,009 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.10.03 19:34:54 | 805,792,189 | ---- | C] () -- C:\Users\Justus\Desktop\HC_Traingscamp_Vol.2.zip.ob!
[2010.09.30 14:12:16 | 000,011,264 | ---- | C] () -- C:\Users\Justus\Desktop\Zusatzt.doc
[2010.09.30 14:12:01 | 000,012,552 | ---- | C] () -- C:\Users\Justus\Desktop\Zusatzt.odt
[2010.09.30 14:08:57 | 000,164,352 | ---- | C] () -- C:\Users\Justus\Desktop\Sinus Milieus.doc
[2010.09.30 13:59:54 | 000,150,618 | ---- | C] () -- C:\Users\Justus\Desktop\Sinus-Milieus_de.JPG
[2010.09.30 13:50:56 | 000,338,003 | ---- | C] () -- C:\Users\Justus\Desktop\Die_Sinus-Milieus_in_Deutschland_2010.jpg
[2010.09.30 13:39:29 | 000,009,216 | ---- | C] () -- C:\Users\Justus\Desktop\Milieu Bild.doc
[2010.09.30 13:39:11 | 000,195,138 | ---- | C] () -- C:\Users\Justus\Desktop\Unbenannt 1.odt
[2010.09.28 12:51:23 | 003,300,043 | ---- | C] () -- C:\Users\Justus\Desktop\latest(1).zip
[2010.09.23 13:59:46 | 000,000,675 | ---- | C] () -- C:\Users\Justus\Desktop\WEHLanguage.ini
[2010.09.23 13:59:46 | 000,000,580 | ---- | C] () -- C:\Users\Justus\Desktop\WEH5ColorConfig.ini
[2010.09.22 15:27:42 | 003,246,833 | ---- | C] () -- C:\Users\Justus\Desktop\aida32ee_393.zip
[2010.09.19 11:02:13 | 000,001,042 | ---- | C] () -- C:\Users\Justus\Desktop\Audacity 1.3 Beta (Unicode).lnk
[2010.09.18 17:37:01 | 000,014,126 | ---- | C] () -- C:\Users\Justus\Documents\GOOD%20or%20Bad.doc_0.odt
[2010.09.17 13:21:01 | 000,000,094 | ---- | C] () -- C:\Users\Justus\AppData\Local\fusioncache.dat
[2010.09.17 13:19:20 | 000,004,956 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.09.15 21:14:48 | 000,000,114 | -H-- | C] () -- C:\Users\Justus\Desktop\.~lock.GOOD or Bad.doc#
[2010.09.15 21:14:44 | 000,011,264 | ---- | C] () -- C:\Users\Justus\Desktop\GOOD or Bad.doc
[2010.09.12 13:06:44 | 000,000,500 | -H-- | C] () -- C:\Windows\tasks\Norton Security Scan for Justus.job
[2010.09.12 13:06:43 | 000,001,085 | ---- | C] () -- C:\Users\Public\Desktop\Norton Security Scan.lnk
[2010.09.12 13:06:41 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\NSSx64\0207030.022\isolate.ini
[2010.09.11 18:54:53 | 000,327,655 | ---- | C] () -- C:\Users\Justus\Desktop\TS3InstallHelper.exe
[2010.09.11 18:47:20 | 005,682,679 | ---- | C] () -- C:\Users\Justus\Desktop\awesome.package
[2010.09.11 16:59:23 | 004,931,515 | ---- | C] () -- C:\Users\Justus\Desktop\awesome(2).zip
[2010.09.11 16:59:18 | 004,931,515 | ---- | C] () -- C:\Users\Justus\Desktop\awesome(1).zip
[2010.09.11 16:59:08 | 004,931,515 | ---- | C] () -- C:\Users\Justus\Desktop\awesome.zip
[2010.07.23 17:26:24 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2010.07.23 17:26:20 | 000,018,960 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2010.04.02 18:40:26 | 001,970,176 | ---- | C] () -- C:\Windows\SysWow64\d3dx9.dll
[2010.04.02 17:17:34 | 000,179,091 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010.03.12 22:17:17 | 000,197,120 | ---- | C] () -- C:\Windows\patchw32.dll
[2010.03.09 14:52:05 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.02.27 23:21:12 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
[2010.02.15 13:47:50 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\VmixP6.dll
[2010.02.15 13:47:50 | 000,000,188 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.cfl
[2010.02.15 13:47:29 | 000,002,641 | ---- | C] () -- C:\Windows\cmudax3.ini
[2010.02.15 13:47:29 | 000,002,123 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.cfg
[2010.02.15 13:47:29 | 000,000,183 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.imi
[2010.02.15 13:27:09 | 000,000,064 | ---- | C] () -- C:\ProgramData\sandra.ldb
[2010.02.15 13:12:20 | 012,427,264 | ---- | C] () -- C:\ProgramData\sandra.mda
[2010.02.15 12:54:41 | 000,002,205 | ---- | C] () -- C:\Windows\cmudaxp.ini
[2009.11.16 18:33:38 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.07 13:27:20 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\vbzlib1.dll
[2009.04.02 14:30:14 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
< End of report > --- --- --- |