OTL Logfile: Code:
OTL logfile created on: 29.03.2013 17:04:09 - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = F:\Programs\OTLPE
64bit-Windows 7 Home Premium (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 57,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 75,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 454,74 Gb Total Space | 207,94 Gb Free Space | 45,73% Space Free | Partition Type: NTFS
Drive F: | 436,59 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive H: | 1,88 Gb Total Space | 1,88 Gb Free Space | 100,00% Space Free | Partition Type: FAT
Computer Name: CLEOPATRA | User Name: Rachel
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2012.11.29 16:06:08 | 000,029,536 | ---- | M] (TuneUp Software) [Auto] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV:64bit: - [2009.11.30 18:51:18 | 000,571,248 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV:64bit: - [2009.11.25 18:06:06 | 000,821,760 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VAIO Smart Network\VSNService.exe -- (VSNService)
SRV:64bit: - [2009.10.30 08:50:40 | 001,165,680 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent)
SRV:64bit: - [2009.09.16 22:28:42 | 000,167,424 | ---- | M] (Intel Corporation) [Disabled] -- C:\Program Files\Sony\VAIO Care\collsvc.exe -- (SampleCollector) Intel(R)
SRV:64bit: - [2009.09.16 12:27:12 | 000,480,624 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV:64bit: - [2009.09.08 17:09:20 | 000,110,960 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe -- (VcmXmlIfHelper)
SRV:64bit: - [2009.09.01 20:42:00 | 000,361,840 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe -- (VcmINSMgr)
SRV - [2013.03.28 15:12:36 | 000,109,064 | ---- | M] (Wajam) [Auto] -- C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe -- (WajamUpdater)
SRV - [2013.03.26 11:00:47 | 002,569,168 | ---- | M] () [Auto] -- C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe -- (BrowserProtect)
SRV - [2013.03.20 10:38:50 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.02.05 16:48:00 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand] -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe -- (McComponentHostService)
SRV - [2013.01.08 12:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Auto] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.12.14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.12.14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.11.29 16:06:12 | 002,401,632 | ---- | M] (TuneUp Software) [Auto] -- C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012.11.29 16:06:08 | 000,029,536 | ---- | M] (TuneUp Software) [Auto] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
SRV - [2011.10.01 08:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011.10.01 08:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.12.14 21:06:24 | 002,320,920 | ---- | M] (Intel Corporation) [Disabled] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2009.12.14 21:06:08 | 000,268,824 | ---- | M] (Intel Corporation) [Disabled] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2009.12.01 21:03:52 | 000,204,648 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2009.11.20 23:25:24 | 000,013,336 | ---- | M] (Intel Corporation) [Disabled] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
SRV - [2009.10.24 02:18:54 | 000,360,224 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2009.10.15 15:34:36 | 000,427,304 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2009.10.15 15:34:36 | 000,091,432 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe -- (SOHPlMgr)
SRV - [2009.10.15 15:34:36 | 000,075,048 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2009.10.15 15:34:34 | 000,120,104 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2009.10.15 15:34:34 | 000,070,952 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe -- (SOHDBSvr)
SRV - [2009.09.14 18:24:08 | 000,206,336 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe -- (VzCdbSvc)
SRV - [2009.09.14 18:24:08 | 000,069,632 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe -- (VAIO Entertainment TV Device Arbitration Service)
SRV - [2009.09.14 17:53:48 | 000,642,416 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.11.09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Disabled] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
========== Driver Services (SafeList) ==========
DRV - [2012.09.19 10:50:50 | 000,011,880 | ---- | M] (TuneUp Software) [Kernel | On_Demand] -- C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.delta-search.com/?affID=119370&tt=190313_wo3&babsrc=HP_ss&mntrId=EA5F7EDD08E105F3
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEC&bmod=EU01
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.google.de/ [binary data]
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-search.com/?affID=119370&tt=190313_wo3&babsrc=HP_ss&mntrId=EA5F7EDD08E105F3
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\..\URLSearchHook: {f4e6547e-325b-403c-a3bb-ad29ed37a92f} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://search.babylon.com/home?affID=66604&tt=3412_5
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEC&bmod=EU01
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.google.de/ [binary data]
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/home?affID=66604&tt=3412_5
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=b17dd988-7e92-4466-a449-9d35fa128580&affid=113129&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=b17dd988-7e92-4466-a449-9d35fa128580&affid=113129&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\..\URLSearchHook: {f4e6547e-325b-403c-a3bb-ad29ed37a92f} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "Plasmoo"
FF - prefs.js..browser.search.defaulturl: "hxxp://de.search.yahoo.com/search?fr=mkg030&p="
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Delta Search"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.delta-search.com/?affID=119370&tt=190313_wo3&babsrc=HP_ss&mntrId=EA5F7EDD08E105F3"
FF - prefs.js..extensions.enabledItems: engine@plasmoo.com:1.0.0.32
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.7
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8312
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.14.1.100010
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:3.6.0.10
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "hxxp://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.startup.homepage: "hxxp://search.babylon.com/home?affID=66604&tt=3412_5"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "hxxp://search.sweetim.com/search.asp?src=2&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programme\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE: File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Rachel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 13.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.19 12:00:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.03.19 12:00:25 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{33044118-6597-4D2F-ABEA-7974BB185379}: C:\Users\Rachel\AppData\Roaming\13001.056 [2012.11.11 16:10:40 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}: C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi [2013.03.28 15:12:36 | 000,037,909 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{0F827075-B026-42F3-885D-98981EE7B1AE}: C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension [2013.03.29 13:28:22 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.19 12:00:26 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.03.19 12:00:25 | 000,000,000 | ---D | M]
[2011.01.06 17:15:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rachel\AppData\Roaming\mozilla\Extensions
[2013.03.29 13:33:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions
[2012.12.28 00:29:25 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012.04.20 10:21:15 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.05.30 23:36:21 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2013.03.29 13:33:29 | 000,000,000 | ---D | M] (DealPly Shopping) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\amo@dealplyshopping.com
[2011.05.05 16:01:22 | 000,000,000 | ---D | M] (Plasmoo Search Engine) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\engine@plasmoo.com
[2013.03.29 13:28:29 | 000,000,000 | ---D | M] ("Giant Savings Extension") -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\extension21810@extension21810.com
[2013.03.29 13:28:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\ffxtlbr@babylon.com
[2013.03.29 13:28:06 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\ffxtlbr@delta.com
[2013.03.29 13:28:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\extension21810@extension21810.com\chrome
[2013.03.29 13:28:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\extension21810@extension21810.com\defaults
[2013.03.29 13:28:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\extension21810@extension21810.com\locale
[2013.03.29 13:28:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\extension21810@extension21810.com\skin
[2013.03.29 13:28:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rachel\AppData\Roaming\mozilla\Firefox\Profiles\5ejf25rz.default\extensions\extension21810@extension21810.com\chrome\content\extensionCode
[2012.12.27 08:44:43 | 000,002,404 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\askcom.xml
[2011.10.10 23:13:26 | 000,001,832 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\bing.xml
[2011.08.14 13:55:16 | 000,000,931 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\conduit.xml
[2013.03.29 13:28:08 | 000,001,294 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\delta.xml
[2012.06.06 04:18:29 | 000,000,950 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\icqplugin-1.xml
[2012.01.18 00:55:31 | 000,000,950 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\icqplugin-2.xml
[2012.02.29 11:19:58 | 000,000,950 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\icqplugin-3.xml
[2012.03.04 10:52:27 | 000,000,950 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\icqplugin-4.xml
[2012.04.05 11:51:53 | 000,000,950 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\icqplugin-5.xml
[2012.04.07 13:53:39 | 000,000,950 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\icqplugin-6.xml
[2012.04.25 22:17:40 | 000,000,950 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\icqplugin-7.xml
[2012.05.09 07:50:08 | 000,000,950 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\icqplugin-8.xml
[2012.06.12 16:18:47 | 000,000,950 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\icqplugin-9.xml
[2011.11.16 15:57:46 | 000,001,056 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\icqplugin.xml
[2011.04.28 18:42:58 | 000,001,975 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\plasmoo.xml
[2012.08.26 13:53:33 | 000,004,003 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\sweetim.xml
[2012.12.14 15:29:12 | 000,002,615 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\5ejf25rz.default\searchplugins\Web Search.xml
[2011.10.02 21:42:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.10.02 21:42:16 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) --
[2012.11.11 16:10:40 | 000,000,000 | ---D | M] (Java Link Helper) -- C:\USERS\RACHEL\APPDATA\ROAMING\13001.056
() (No name found) -- C:\USERS\RACHEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5EJF25RZ.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}.XPI
() (No name found) -- C:\USERS\RACHEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5EJF25RZ.DEFAULT\EXTENSIONS\ADAPTER@BABYLONTC.COM.XPI
() (No name found) -- C:\USERS\RACHEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5EJF25RZ.DEFAULT\EXTENSIONS\OCR@BABYLON.COM.XPI
[2012.06.06 22:40:00 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.04.20 10:13:35 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.03.29 13:27:57 | 000,006,508 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012.04.20 10:13:35 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.04.20 10:13:35 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.04.20 10:13:35 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.04.20 10:13:35 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.04.20 10:13:35 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Programme\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Giant Savings Extension) - {11111111-1111-1111-1111-110211181110} - C:\Program Files (x86)\Giant Savings Extension\Giant Savings Extension.dll (215 Apps)
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
O2 - BHO: (DealPly) - {EF7BD87A-8024-11E2-F316-F3E56188709B} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly)
O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found.
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000\..\Toolbar\WebBrowser: (no name) - {F4E6547E-325B-403C-A3BB-AD29ED37A92F} - No CLSID value found.
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found.
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004\..\Toolbar\WebBrowser: (no name) - {F4E6547E-325B-403C-A3BB-AD29ED37A92F} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000..\Run: [{F5352366-F8C4-9BF5-5EC6-F342F2F00ACD}] File not found
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000..\Run: [Facebook Update] C:\Users\Rachel\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000..\Run: [iexploer.exe] File not found
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000..\Run: [Messenger (Yahoo!)] File not found
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000..\Run: [MobileDocuments] File not found
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000..\Run: [oqmo.exe] File not found
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000..\Run: [Spotify] C:\Users\Rachel\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000..\Run: [Spotify Web Helper] C:\Users\Rachel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000..\Run: [Userinit] C:\Users\Rachel\AppData\Roaming\appConf32.exe ()
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004..\Run: [{F5352366-F8C4-9BF5-5EC6-F342F2F00ACD}] File not found
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004..\Run: [iexploer.exe] File not found
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004..\Run: [MobileDocuments] File not found
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004..\Run: [oqmo.exe] File not found
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004..\Run: [Spotify] C:\Users\Rachel\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004..\Run: [Spotify Web Helper] C:\Users\Rachel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1004..\Run: [Userinit] File not found
O4 - HKLM..\RunOnce: [Del187774550] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [SPReview] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found
O4 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000..\RunOnce: [Del187774550] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15:64bit: - S-1-5-21-4256632923-2440940942-3152827771-1000\..Trusted Domains: fritz.box ([]* in Local intranet)
O15:64bit: - S-1-5-21-4256632923-2440940942-3152827771-1000\..Trusted Ranges: Range1 ([*] in Local intranet)
O15:64bit: - S-1-5-21-4256632923-2440940942-3152827771-1004\..Trusted Domains: fritz.box ([]* in Local intranet)
O15:64bit: - S-1-5-21-4256632923-2440940942-3152827771-1004\..Trusted Ranges: Range1 ([*] in Local intranet)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261125~1.80\{c16c1~1\browse~1.dll) - C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\System32\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000 Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-4256632923-2440940942-3152827771-1000 Winlogon: Shell - (C:\Users\Rachel\AppData\Roaming\skype.dat) - C:\Users\Rachel\AppData\Roaming\skype.dat ()
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - File not found
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\Windows\SysWow64\VESWinlogon.dll (Sony Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.03.24 12:06:41 | 000,000,053 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{3dbfee48-b838-11df-a68f-f07bcbf09134}\Shell - "" = AutoRun
O33 - MountPoints2\{3dbfee48-b838-11df-a68f-f07bcbf09134}\Shell\AutoRun\command - "" = G:\pushinst.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2013.03.29 14:32:31 | 000,000,000 | ---D | C] -- C:\Users\Familie\AppData\Roaming\Malwarebytes
[2013.03.29 13:46:59 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Roaming\Malwarebytes
[2013.03.29 13:46:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.03.29 13:46:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.03.29 13:46:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.03.29 13:36:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
[2013.03.29 13:36:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RegClean Pro
[2013.03.29 13:33:30 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Roaming\DealPly
[2013.03.29 13:33:28 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
[2013.03.29 13:33:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DealPly
[2013.03.29 13:30:52 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MiPony
[2013.03.29 13:30:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony
[2013.03.29 13:30:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MiPony
[2013.03.29 13:28:47 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Local\Giant Savings Extension
[2013.03.29 13:28:31 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Local\Updater21810
[2013.03.29 13:28:30 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QTRAX
[2013.03.29 13:28:24 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserProtect
[2013.03.29 13:28:22 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Local\Downloaded Installations
[2013.03.29 13:28:19 | 000,000,000 | ---D | C] -- C:\ProgramData\BrowserProtect
[2013.03.29 13:28:09 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Roaming\BabSolution
[2013.03.29 13:28:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Giant Savings Extension
[2013.03.29 13:28:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Delta
[2013.03.29 13:28:02 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Roaming\Delta
[2013.03.29 13:27:55 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
[2013.03.29 13:27:52 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Local\Wajam
[2013.03.29 13:27:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wajam
[2013.03.29 13:27:43 | 000,000,000 | ---D | C] -- C:\Users\Familie\AppData\Roaming\DSite
[2013.03.29 13:27:43 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Roaming\Babylon
[2013.03.29 13:27:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2013.03.29 13:12:03 | 000,000,000 | ---D | C] -- C:\Users\Familie\Desktop\insta
[2013.03.20 19:43:58 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcore6.dll
[2013.03.20 19:43:58 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcore6.dll
[2013.03.20 19:43:58 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcsvc6.dll
[2013.03.20 19:43:58 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc6.dll
[2013.03.20 19:43:53 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcorehc.dll
[2013.03.20 19:43:53 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcorehc.dll
[2013.03.20 19:43:53 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll
[2013.03.20 19:43:53 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncsi.dll
[2013.03.20 19:43:53 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netevent.dll
[2013.03.20 19:43:53 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netevent.dll
[2013.03.19 12:00:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013.03.19 12:00:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2013.03.19 11:13:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013.03.19 11:11:51 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013.03.19 11:11:50 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013.03.19 11:11:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2013.03.19 11:11:50 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013.03.19 10:18:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2013.03.18 19:00:24 | 000,000,000 | ---D | C] -- C:\Users\Rachel\AppData\Local\Facebook
[2013.03.16 07:30:42 | 004,546,560 | ---- | C] (Google Inc.) -- C:\Windows\SysWow64\GPhotos.scr
[2013.03.16 07:30:42 | 004,546,560 | ---- | C] (Google Inc.) -- C:\Windows\System32\GPhotos.scr
[2013.03.13 03:03:26 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2013.03.13 03:03:26 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.03.13 03:03:26 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.03.13 03:03:26 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013.03.13 03:03:26 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
[2013.03.13 03:03:25 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013.03.13 03:03:25 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.03.13 03:03:25 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013.03.13 03:03:25 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.03.13 03:03:24 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013.03.13 03:03:24 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.03.13 03:03:24 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2013.03.13 03:03:24 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.03.13 03:03:23 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
[2013.03.13 03:03:23 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.03.13 03:03:23 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.03.13 03:03:23 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2013.03.02 22:59:29 | 000,000,000 | ---D | C] -- C:\Users\Rachel\Desktop\bet
[2013.03.01 10:49:28 | 000,000,000 | ---D | C] -- C:\Users\Rachel\Desktop\Grundrechte Beck Entscheidungen
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Users\Rachel\AppData\Roaming\*.tmp files -> C:\Users\Rachel\AppData\Roaming\*.tmp -> ]
[2 C:\Users\Public\Documents\*.tmp files -> C:\Users\Public\Documents\*.tmp -> ]
[17 C:\Users\Rachel\Desktop\*.tmp files -> C:\Users\Rachel\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.03.29 16:58:47 | 000,001,350 | ---- | M] () -- C:\Users\Familie\Desktop\Clean Registry for Free!.lnk
[2013.03.29 16:58:23 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.03.29 16:57:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.03.29 16:57:34 | 3106,455,552 | -HS- | M] () -- C:\hiberfil.sys
[2013.03.29 14:42:07 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.03.29 14:33:07 | 000,001,426 | ---- | M] () -- C:\Users\Rachel\Desktop\Registry kostenlos entrümpeln!.lnk
[2013.03.29 14:25:07 | 000,000,286 | ---- | M] () -- C:\Windows\tasks\RegClean Pro_UPDATES.job
[2013.03.29 14:25:07 | 000,000,278 | ---- | M] () -- C:\Windows\tasks\RegClean Pro_DEFAULT.job
[2013.03.29 13:46:57 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.29 13:46:57 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.03.29 13:36:07 | 000,001,054 | ---- | M] () -- C:\Users\Public\Desktop\RegClean Pro.lnk
[2013.03.29 13:36:07 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
[2013.03.29 13:33:03 | 000,002,283 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013.03.29 13:33:03 | 000,002,259 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013.03.29 13:30:52 | 000,001,007 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk
[2013.03.29 13:30:52 | 000,001,007 | ---- | M] () -- C:\Users\Familie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk
[2013.03.29 13:30:52 | 000,000,999 | ---- | M] () -- C:\Users\Rachel\Desktop\MiPony.lnk
[2013.03.29 13:30:52 | 000,000,999 | ---- | M] () -- C:\Users\Familie\Desktop\MiPony.lnk
[2013.03.29 13:30:52 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony
[2013.03.29 13:28:40 | 000,002,359 | ---- | M] () -- C:\Users\Rachel\Desktop\Qtrax Player.lnk
[2013.03.29 13:28:08 | 000,000,000 | ---- | M] () -- C:\END
[2013.03.29 13:21:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.03.29 13:08:00 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4256632923-2440940942-3152827771-1000UA.job
[2013.03.28 22:58:17 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4256632923-2440940942-3152827771-1000Core.job
[2013.03.24 19:32:50 | 000,000,004 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\skype.ini
[2013.03.23 01:23:05 | 000,088,339 | ---- | M] () -- C:\Users\Rachel\Desktop\74629_1724325437614_7097595_n.jpg
[2013.03.22 18:53:43 | 000,049,042 | ---- | M] () -- C:\Users\Rachel\Desktop\Report7b7ee5ce-599e-4eb6-8c87-8e524ed469cb.pdf
[2013.03.21 18:06:31 | 000,115,808 | ---- | M] () -- C:\Users\Rachel\Desktop\Report8ba0956f-240a-41b5-aed6-e67103e41a07.pdf
[2013.03.20 10:38:50 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.03.20 10:38:50 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013.03.20 10:38:50 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.03.20 10:38:50 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013.03.20 03:16:44 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msclmd.dll
[2013.03.20 03:16:44 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msclmd.dll
[2013.03.19 19:43:09 | 002,097,497 | ---- | M] () -- C:\Users\Rachel\Desktop\IMG_2874.JPG
[2013.03.19 12:03:08 | 000,000,025 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\urhtps.dat
[2013.03.19 12:00:11 | 000,001,845 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013.03.19 12:00:11 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013.03.19 11:13:04 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013.03.19 11:13:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013.03.19 10:18:59 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2013.03.19 10:17:48 | 000,002,515 | ---- | M] () -- C:\Users\Rachel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2013.03.19 10:17:48 | 000,002,503 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
[2013.03.19 10:17:48 | 000,002,491 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2013.03.18 10:42:26 | 000,100,437 | ---- | M] () -- C:\Users\Rachel\Desktop\FB.jpg
[2013.03.16 07:30:42 | 004,546,560 | ---- | M] (Google Inc.) -- C:\Windows\SysWow64\GPhotos.scr
[2013.03.16 07:30:42 | 004,546,560 | ---- | M] (Google Inc.) -- C:\Windows\System32\GPhotos.scr
[2013.03.13 03:03:15 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013.03.05 20:12:30 | 001,003,769 | ---- | M] () -- C:\Users\Rachel\Desktop\ooo.jpg
[2013.03.05 19:58:07 | 000,686,442 | ---- | M] () -- C:\Users\Rachel\Desktop\rom.jpg
[2013.03.04 22:09:56 | 002,118,314 | ---- | M] () -- C:\Users\Rachel\Desktop\jessy.jpg
[2013.03.04 20:44:01 | 000,020,516 | ---- | M] () -- C:\Users\Rachel\Desktop\terrence-j.jpg
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Users\Rachel\AppData\Roaming\*.tmp files -> C:\Users\Rachel\AppData\Roaming\*.tmp -> ]
[2 C:\Users\Public\Documents\*.tmp files -> C:\Users\Public\Documents\*.tmp -> ]
[17 C:\Users\Rachel\Desktop\*.tmp files -> C:\Users\Rachel\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.03.29 13:46:57 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.29 13:36:14 | 000,000,286 | ---- | C] () -- C:\Windows\tasks\RegClean Pro_UPDATES.job
[2013.03.29 13:36:14 | 000,000,278 | ---- | C] () -- C:\Windows\tasks\RegClean Pro_DEFAULT.job
[2013.03.29 13:36:10 | 000,001,426 | ---- | C] () -- C:\Users\Rachel\Desktop\Registry kostenlos entrümpeln!.lnk
[2013.03.29 13:36:07 | 000,001,054 | ---- | C] () -- C:\Users\Public\Desktop\RegClean Pro.lnk
[2013.03.29 13:30:52 | 000,001,007 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk
[2013.03.29 13:30:52 | 000,001,007 | ---- | C] () -- C:\Users\Familie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk
[2013.03.29 13:30:52 | 000,000,999 | ---- | C] () -- C:\Users\Rachel\Desktop\MiPony.lnk
[2013.03.29 13:30:52 | 000,000,999 | ---- | C] () -- C:\Users\Familie\Desktop\MiPony.lnk
[2013.03.29 13:28:40 | 000,002,389 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk
[2013.03.29 13:28:40 | 000,002,359 | ---- | C] () -- C:\Users\Rachel\Desktop\Qtrax Player.lnk
[2013.03.29 13:27:58 | 000,000,000 | ---- | C] () -- C:\END
[2013.03.24 15:23:38 | 000,000,004 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\skype.ini
[2013.03.23 01:23:34 | 000,088,339 | ---- | C] () -- C:\Users\Rachel\Desktop\74629_1724325437614_7097595_n.jpg
[2013.03.22 18:53:43 | 000,049,042 | ---- | C] () -- C:\Users\Rachel\Desktop\Report7b7ee5ce-599e-4eb6-8c87-8e524ed469cb.pdf
[2013.03.21 18:06:31 | 000,115,808 | ---- | C] () -- C:\Users\Rachel\Desktop\Report8ba0956f-240a-41b5-aed6-e67103e41a07.pdf
[2013.03.19 19:36:50 | 002,097,497 | ---- | C] () -- C:\Users\Rachel\Desktop\IMG_2874.JPG
[2013.03.19 12:00:11 | 000,001,845 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013.03.19 11:13:04 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013.03.18 19:00:56 | 000,000,932 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4256632923-2440940942-3152827771-1000UA.job
[2013.03.18 19:00:55 | 000,000,910 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4256632923-2440940942-3152827771-1000Core.job
[2013.03.18 10:42:56 | 000,100,437 | ---- | C] () -- C:\Users\Rachel\Desktop\FB.jpg
[2013.03.05 20:12:29 | 001,003,769 | ---- | C] () -- C:\Users\Rachel\Desktop\ooo.jpg
[2013.03.05 19:58:07 | 000,686,442 | ---- | C] () -- C:\Users\Rachel\Desktop\rom.jpg
[2013.03.04 22:09:55 | 002,118,314 | ---- | C] () -- C:\Users\Rachel\Desktop\jessy.jpg
[2013.03.04 20:44:09 | 000,020,516 | ---- | C] () -- C:\Users\Rachel\Desktop\terrence-j.jpg
[2012.12.27 09:26:37 | 000,000,090 | ---- | C] () -- C:\Windows\WININIT.INI
[2012.11.11 16:10:49 | 000,007,720 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\BAcroIEHelpe227.dll
[2012.10.31 18:47:38 | 000,007,720 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\BAcroIEHelpe221.dll
[2012.10.30 11:00:19 | 000,007,720 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\BAcroIEHelpe220.dll
[2012.10.15 08:47:39 | 000,007,424 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\BAcroIEHelpe217.dll
[2012.10.04 14:21:39 | 000,007,424 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\BAcroIEHelpe213.dll
[2012.09.27 19:14:17 | 000,007,424 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\BAcroIEHelpe209.dll
[2012.08.29 17:02:23 | 000,006,400 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\BAcroIEHelpe203.dll
[2012.08.23 20:34:53 | 000,006,400 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\BAcroIEHelpe197.dll
[2012.08.21 17:30:26 | 000,006,400 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\BAcroIEHelpe196.dll
[2012.07.20 22:07:11 | 000,268,944 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\AcroIEHelpe172.dll
[2012.07.08 17:23:25 | 000,000,025 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\urhtps.dat
[2012.01.11 21:47:32 | 000,086,016 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\skype.dat
[2011.08.26 15:57:15 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2011.07.03 05:05:20 | 000,000,000 | ---- | C] () -- C:\Users\Rachel\AppData\Local\{FFA0F69A-F703-48AC-B4AD-E412B21AC715}
[2011.02.11 15:46:30 | 000,012,841 | ---- | C] () -- C:\Users\Rachel\AppData\Roaming\UserTile.png
[2010.11.19 23:30:46 | 000,012,288 | ---- | C] () -- C:\Users\Rachel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.09.21 15:58:13 | 001,556,172 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.09.12 16:32:36 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.05.20 11:06:57 | 000,002,119 | ---- | C] () -- C:\Windows\SysWow64\McOEMAppRules.dat
[2010.05.19 23:08:54 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.05.19 22:45:17 | 000,870,544 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2010.05.19 22:45:17 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010.05.19 22:45:17 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010.05.19 22:45:15 | 000,050,036 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2010.05.19 22:45:14 | 000,127,896 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2010.05.19 22:45:08 | 000,028,732 | ---- | C] () -- C:\Windows\SysWow64\ativvsny.dat
[2010.05.19 22:45:08 | 000,026,936 | ---- | C] () -- C:\Windows\SysWow64\ativvsnl.dat
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2008.12.09 16:23:13 | 000,052,176 | RHS- | C] () -- C:\Users\Rachel\AppData\Roaming\appconf32.exe
========== LOP Check ==========
[2011.08.26 18:52:17 | 000,000,000 | -HSD | M] -- C:\Users\Rachel\AppData\Roaming\.#
[2012.06.26 02:45:03 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.011
[2012.06.29 10:48:10 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.012
[2012.07.01 21:57:40 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.013
[2012.07.03 20:35:08 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.014
[2012.07.04 22:46:31 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.015
[2012.07.06 21:51:08 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.016
[2012.07.06 22:48:16 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.017
[2012.07.07 22:33:04 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.018
[2012.07.08 12:39:09 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.019
[2012.07.09 21:01:40 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.020
[2012.07.11 00:11:37 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.021
[2012.07.11 21:35:58 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.022
[2012.07.12 21:56:10 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.023
[2012.07.13 22:14:12 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.024
[2012.07.14 20:24:55 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.025
[2012.07.17 20:43:37 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.026
[2012.07.18 11:00:28 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.027
[2012.07.20 22:06:57 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.028
[2012.07.25 09:36:28 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.029
[2012.07.27 20:37:58 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.030
[2012.07.28 16:38:29 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.031
[2012.07.30 13:24:13 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.032
[2012.07.31 18:02:33 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.033
[2012.08.06 15:54:17 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.034
[2012.08.11 20:11:24 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.040
[2012.08.15 11:32:04 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.041
[2012.08.31 10:11:56 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.042
[2012.09.23 00:39:16 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.045
[2012.10.04 19:09:19 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.047
[2012.10.05 23:09:27 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.048
[2012.10.08 13:04:33 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.049
[2012.10.09 15:15:27 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.050
[2012.10.17 19:18:41 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.051
[2012.10.30 11:00:11 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.053
[2012.10.31 18:47:30 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.055
[2012.11.11 16:10:40 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13001.056
[2012.06.07 23:53:59 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13002
[2012.06.08 11:57:41 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13003
[2012.06.12 16:18:46 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13004
[2012.06.13 18:23:02 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13005
[2012.06.15 18:06:42 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13006
[2012.06.18 20:41:42 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13007
[2012.06.19 20:13:15 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\13008
[2011.02.22 19:16:07 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\Auslogics
[2013.03.29 13:28:10 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\BabSolution
[2013.03.29 13:27:43 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\Babylon
[2013.03.29 13:33:30 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\DealPly
[2013.03.29 13:28:02 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\Delta
[2012.12.27 08:53:35 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\DVDVideoSoft
[2012.12.27 09:20:13 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\go
[2012.08.27 16:18:48 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\kock
[2012.12.09 14:24:14 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\OpenCandy
[2011.08.26 18:31:20 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\SoftGrid Client
[2013.03.24 22:16:21 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\Spotify
[2013.03.29 13:36:09 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\Systweak
[2011.12.24 18:32:29 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\TIPP10
[2010.09.21 15:59:15 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\TP
[2012.12.09 14:25:30 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\TuneUp Software
[2013.03.24 15:22:45 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\UAs
[2011.12.28 19:40:36 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\Vaubp
[2013.03.24 15:22:45 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\xmldm
[2011.12.28 13:00:21 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\Ymuxor
[2012.10.06 20:46:45 | 000,000,000 | ---D | M] -- C:\Users\Familie\AppData\Roaming\Babylon
[2013.03.29 13:27:43 | 000,000,000 | ---D | M] -- C:\Users\Familie\AppData\Roaming\DSite
[2012.08.28 15:08:38 | 000,000,000 | ---D | M] -- C:\Users\Familie\AppData\Roaming\Systweak
[2012.12.12 20:56:50 | 000,000,000 | ---D | M] -- C:\Users\Familie\AppData\Roaming\TuneUp Software
[2013.03.19 11:12:46 | 000,000,000 | ---D | M] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2010.09.03 14:59:05 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2013.03.29 13:27:43 | 000,000,000 | ---D | M] -- C:\ProgramData\Babylon
[2013.03.29 13:28:19 | 000,000,000 | ---D | M] -- C:\ProgramData\BrowserProtect
[2012.12.09 14:24:56 | 000,000,000 | -H-D | M] -- C:\ProgramData\Common Files
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2010.09.03 14:59:05 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2011.08.20 12:44:49 | 000,000,000 | ---D | M] -- C:\ProgramData\Easybits GO
[2010.05.20 11:05:03 | 000,000,000 | ---D | M] -- C:\ProgramData\Evernote
[2010.09.03 14:59:05 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2011.02.02 16:36:46 | 000,000,000 | ---D | M] -- C:\ProgramData\ICQ
[2010.09.25 01:36:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Partner
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2010.09.03 14:59:05 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2012.08.19 20:40:38 | 000,000,000 | ---D | M] -- C:\ProgramData\Systweak
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2012.12.09 14:25:30 | 000,000,000 | ---D | M] -- C:\ProgramData\TuneUp Software
[2010.05.20 11:26:05 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall
[2010.09.27 22:26:29 | 000,000,000 | ---D | M] -- C:\ProgramData\VirtualizedApplications
[2010.09.03 14:59:05 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2010.11.11 18:43:00 | 000,000,000 | ---D | M] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2012.12.09 14:24:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2013.03.28 22:58:17 | 000,000,910 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4256632923-2440940942-3152827771-1000Core.job
[2013.03.29 13:08:00 | 000,000,932 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4256632923-2440940942-3152827771-1000UA.job
[2013.03.29 14:25:07 | 000,000,278 | ---- | M] () -- C:\Windows\Tasks\RegClean Pro_DEFAULT.job
[2013.03.29 14:25:07 | 000,000,286 | ---- | M] () -- C:\Windows\Tasks\RegClean Pro_UPDATES.job
[2013.01.22 18:54:52 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > --- --- ---
Das ist der Report- wie kann ich diesen nun entfernen???
und vielen dank für deine Hilfe!!! |