sternchen222 | 04.11.2011 20:10 | Ist erledigt! Danke, dass du hier so schnell reagierst :) Code:
OTL logfile created on: 04.11.2011 19:51:04 - Run 3
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\So\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19154)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,75 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 56,95% Memory free
4,70 Gb Paging File | 3,48 Gb Available in Paging File | 74,10% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 77,02 Gb Total Space | 15,07 Gb Free Space | 19,56% Space Free | Partition Type: NTFS
Drive D: | 72,03 Gb Total Space | 38,21 Gb Free Space | 53,04% Space Free | Partition Type: NTFS
Drive E: | 29,95 Gb Total Space | 23,53 Gb Free Space | 78,58% Space Free | Partition Type: FAT32
Drive F: | 44,52 Gb Total Space | 39,13 Gb Free Space | 87,88% Space Free | Partition Type: NTFS
Computer Name: PCSO | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.09.21 06:41:35 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.09.21 06:41:29 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.08.24 15:15:26 | 000,074,240 | ---- | M] (Freemake) -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
PRC - [2011.06.04 16:44:12 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\So\Desktop\OTL.exe
PRC - [2010.11.15 20:02:50 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2009.04.11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\conime.exe
========== Modules (SafeList) ==========
MOD - [2011.06.04 16:44:12 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\So\Desktop\OTL.exe
MOD - [2010.08.31 16:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2008.01.19 09:00:40 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (usprserv)
SRV:64bit: - [2007.03.29 13:21:16 | 000,433,152 | ---- | M] (Sphinx Software) [Auto | Running] -- C:\Program Files\VistaFirewallControl\VistaFirewallService.exe -- (VistaFirewallService)
SRV - [2011.10.15 16:08:04 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.09.21 06:41:35 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.09.21 06:41:29 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.08.24 15:15:26 | 000,074,240 | ---- | M] (Freemake) [Auto | Running] -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe -- (FreemakeUtilsService)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.03.30 05:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011.09.21 06:41:36 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.09.21 06:41:36 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\DRIVERS\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.02.11 22:23:34 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:64bit: - [2009.10.01 01:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:64bit: - [2009.08.29 17:22:42 | 000,136,192 | ---- | M] () [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\acedrv05.sys -- (acedrv05)
DRV:64bit: - [2009.03.25 16:48:00 | 000,153,128 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s1018mdm.sys -- (s1018mdm)
DRV:64bit: - [2009.03.25 16:48:00 | 000,146,472 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s1018unic.sys -- (s1018unic) Sony Ericsson Device 1018 USB Ethernet Emulation (WDM)
DRV:64bit: - [2009.03.25 16:48:00 | 000,133,160 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s1018mgmt.sys -- (s1018mgmt) Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM)
DRV:64bit: - [2009.03.25 16:48:00 | 000,128,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s1018obex.sys -- (s1018obex)
DRV:64bit: - [2009.03.25 16:48:00 | 000,113,704 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s1018bus.sys -- (s1018bus) Sony Ericsson Device 1018 driver (WDM)
DRV:64bit: - [2009.03.25 16:48:00 | 000,034,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s1018nd5.sys -- (s1018nd5) Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS)
DRV:64bit: - [2009.03.25 16:48:00 | 000,019,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s1018mdfl.sys -- (s1018mdfl)
DRV:64bit: - [2008.11.11 22:40:17 | 000,868,848 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\Drivers\sptd.sys -- (sptd)
DRV:64bit: - [2008.05.16 11:33:06 | 000,158,760 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s0016mdm.sys -- (s0016mdm)
DRV:64bit: - [2008.05.16 11:33:06 | 000,151,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s0016unic.sys -- (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM)
DRV:64bit: - [2008.05.16 11:33:06 | 000,137,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s0016mgmt.sys -- (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM)
DRV:64bit: - [2008.05.16 11:33:06 | 000,136,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s0016obex.sys -- (s0016obex)
DRV:64bit: - [2008.05.16 11:33:06 | 000,034,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s0016nd5.sys -- (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS)
DRV:64bit: - [2008.05.16 11:33:04 | 000,019,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s0016mdfl.sys -- (s0016mdfl)
DRV:64bit: - [2008.05.16 11:32:56 | 000,115,240 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s0016bus.sys -- (s0016bus) Sony Ericsson Device 0016 driver (WDM)
DRV:64bit: - [2008.01.19 08:09:56 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\serscan.sys -- (StillCam)
DRV:64bit: - [2008.01.19 07:36:12 | 000,119,296 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\irda.sys -- (irda)
DRV:64bit: - [2008.01.19 07:36:11 | 000,027,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\irsir.sys -- (irsir)
DRV:64bit: - [2007.12.10 14:21:56 | 000,109,096 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\s3017bus.sys -- (s3017bus) Sony Ericsson Device 3017 driver (WDM)
DRV:64bit: - [2006.09.18 22:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\Wbem\ntfs.mof -- (Ntfs)
DRV - [2007.02.20 17:28:43 | 000,144,812 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\dump_wmimmc.sys -- (dump_wmimmc)
DRV - [2005.01.04 19:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Speedbit Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.speedbit.com/search.aspx?aff=grbr_0&q="
FF - prefs.js..browser.search.order.1: "Speedbit Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de"
FF - prefs.js..extensions.enabledItems: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f}:2.5.6.0
FF - prefs.js..extensions.enabledItems: {2122962a-1424-fffe-19af-bba2ef3eff4a}:1.0
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:2.5.6.0
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9
FF - prefs.js..keyword.URL: "hxxp://search.speedbit.com/search.aspx?aff=grbr_0&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "chrome://browser-region/locale/region.properties"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.startup.homepage: "hxxp://www.daemon-search.com/default"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties"
FF - HKLM\software\mozilla\Firefox\Extensions\\fmdownloader@gmail.com: C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ [2011.09.03 14:11:31 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\searchpredict@speedbit.com: C:\Program Files (x86)\SearchPredict\PRFireFox
FF - HKLM\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: C:\Program Files (x86)\SpeedBit Video Downloader\SPFireFox
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.06.25 13:14:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.10.12 12:10:20 | 000,000,000 | ---D | M]
[2009.01.10 12:52:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\mozilla\Extensions
[2011.11.04 17:38:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\7yhd92ub.default\extensions
[2009.08.23 13:08:09 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\7yhd92ub.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.04.04 23:36:01 | 000,000,000 | ---D | M] (YouTube Downloader for Facebook) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\7yhd92ub.default\extensions\{2122962a-1424-fffe-19af-bba2ef3eff4a}
[2011.04.25 12:09:35 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\7yhd92ub.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.06.10 18:37:11 | 000,000,000 | ---D | M] (myBabylon English Toolbar) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\7yhd92ub.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2010.02.26 17:22:12 | 000,000,000 | ---D | M] (DVDVideoSoft Toolbar) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\7yhd92ub.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
[2009.12.22 16:41:46 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\7yhd92ub.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2010.02.26 17:22:25 | 000,000,873 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\7yhd92ub.default\searchplugins\conduit.xml
[2011.05.07 10:22:13 | 000,002,342 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\7yhd92ub.default\searchplugins\icq-search.xml
[2011.09.03 14:04:19 | 000,000,950 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\7yhd92ub.default\searchplugins\icqplugin-1.xml
[2011.05.13 19:13:02 | 000,000,950 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\7yhd92ub.default\searchplugins\icqplugin.xml
[2011.10.12 13:00:25 | 000,002,520 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\7yhd92ub.default\searchplugins\speedbit.xml
[2011.05.07 10:24:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
File not found (No name found) --
[2011.09.03 14:11:31 | 000,000,000 | ---D | M] (Freemake Video Downloader Plugin) -- C:\PROGRAM FILES (X86)\FREEMAKE\FREEMAKE VIDEO DOWNLOADER\BROWSERPLUGIN\FIREFOX
[2011.06.25 13:14:19 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010.01.01 09:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.06.10 18:37:09 | 000,002,226 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2010.01.01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010.01.01 09:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.04.02 10:38:32 | 000,002,047 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
[2010.01.01 09:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.01.01 09:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.01.01 09:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2006.09.18 22:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKLM\..\Toolbar: (@msdxmLC.dll,-1@1033,&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\Users\user\AppData\Local\CDRunner\MSDXM.ocx ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4:64bit: - HKLM..\Run: [VistaFirewallControl] C:\Programme\VistaFirewallControl\VistaFirewallControl.exe (Sphinx Software)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10n_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O9 - Extra Button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - File not found
O9 - Extra 'Tools' menuitem : ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - File not found
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.68.161.141 217.68.161.171
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\Users\user\AppData\Local\CDRunner\MSDXM.ocx ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{060a9c05-b08d-11dd-baf3-00138ffc017b}\Shell - "" = AutoRun
O33 - MountPoints2\{060a9c05-b08d-11dd-baf3-00138ffc017b}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk - - File not found
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader - Schnellstart.lnk - C:\PROGRA~2\Adobe\READER~1.0\Reader\READER~1.EXE - (Adobe Systems Incorporated)
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk - C:\PROGRA~2\Adobe\READER~1.0\Reader\ADOBEC~1.EXE - (Adobe Systems Incorporated)
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk - - File not found
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: avgnt - hkey= - key= - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
MsConfig:64bit - StartUpReg: DXM6Patch_981116 - hkey= - key= - C:\Windows\p_981116.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg: ICQ Lite - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: LDM - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: LogitechGalleryRepair - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: LogitechImageStudioTray - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: LVCOMS - hkey= - key= - C:\Program Files (x86)\Common Files\Logitech\QCDriver3\LVCOMS.EXE (Logitech Inc.)
MsConfig:64bit - StartUpReg: QCDriverInstaller - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: RealTray - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: Skype - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: SunJavaUpdateSched - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: SweetIM - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: WinampAgent - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: WMPNSCFG - hkey= - key= - File not found
MsConfig:64bit - State: "startup" - Reg Error: Key error.
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: WudfPf - Driver
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - Microsoft NetShow Player
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Windows Media Player 5.2
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\Windows\SysWow64\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\SysWow64\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.scg726 - C:\Windows\SysWow64\Scg726.acm (SHARP Corporation)
Drivers32: msacm.voxacm160 - C:\Windows\SysWow64\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.dvsd - C:\Windows\SysWow64\pdvcodec.dll (Matsushita Electric Industrial Co., Ltd.)
Drivers32: vidc.mp42 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mp43 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mpg4 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.VP60 - C:\Windows\SysWow64\vp6vfw.dll (EA.com/On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWow64\vp6vfw.dll (EA.com/On2.com)
Drivers32: vidc.VP62 - C:\Windows\SysWow64\vp6vfw.dll (EA.com/On2.com)
Drivers32: vidc.xvid - C:\Windows\SysWow64\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011.11.04 17:53:23 | 002,322,184 | ---- | C] (ESET) -- C:\Users\user\Desktop\esetsmartinstaller_enu.exe
[2011.11.04 17:40:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011.11.03 19:14:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.11.03 19:14:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.10.27 11:42:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2011.10.12 13:00:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SpeedBit
[2011.10.12 13:00:09 | 000,172,032 | ---- | C] (Jin Hui E-mail: jinhui@jcomsoft.com Web: hxxp://www.jcomsoft.com) -- C:\Windows\SysWow64\AniGIF.ocx
[2011.10.12 13:00:09 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedBit
[2007.02.07 18:13:00 | 000,369,152 | ---- | C] (NVIDIA Corporation) -- C:\Programme\NVUninst.exe
[2007.02.07 18:13:00 | 000,369,152 | ---- | C] (NVIDIA Corporation) -- C:\Programme\nvudisp.exe
========== Files - Modified Within 30 Days ==========
[2011.11.04 19:31:50 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.11.04 19:31:50 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.11.04 19:11:54 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.11.04 17:53:25 | 002,322,184 | ---- | M] (ESET) -- C:\Users\user\Desktop\esetsmartinstaller_enu.exe
[2011.11.04 17:32:16 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.11.04 17:32:05 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2011.11.04 17:31:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.11.03 19:14:17 | 000,000,952 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.11.03 11:46:40 | 001,445,116 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.11.03 11:46:40 | 000,628,504 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.11.03 11:46:40 | 000,595,798 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.11.03 11:46:40 | 000,126,054 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.11.03 11:46:40 | 000,103,872 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.11.01 18:29:31 | 000,000,860 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.10.29 21:02:45 | 000,000,020 | ---- | M] () -- C:\Users\user\defogger_reenable
[2011.10.12 17:20:45 | 000,257,256 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.10.12 13:00:08 | 000,109,216 | ---- | M] () -- C:\Windows\SysWow64\EasyHook64.dll
[2011.10.12 13:00:08 | 000,090,784 | ---- | M] () -- C:\Windows\SysWow64\EasyHook32.dll
[2011.10.12 12:10:20 | 000,001,921 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
========== Files Created - No Company Name ==========
[2011.11.03 19:14:17 | 000,000,952 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.10.29 21:02:45 | 000,000,020 | ---- | C] () -- C:\Users\user\defogger_reenable
[2011.10.12 13:00:23 | 000,109,216 | ---- | C] () -- C:\Windows\SysWow64\EasyHook64.dll
[2011.10.12 13:00:23 | 000,090,784 | ---- | C] () -- C:\Windows\SysWow64\EasyHook32.dll
[2011.04.02 10:49:58 | 000,005,061 | ---- | C] () -- C:\ProgramData\jdhdxjyu.jga
[2011.02.20 14:36:09 | 000,000,467 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2011.02.11 22:23:34 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2010.03.17 13:56:38 | 000,005,048 | ---- | C] () -- C:\ProgramData\mtbjfghn.xbe
[2010.01.03 21:20:41 | 000,004,913 | ---- | C] () -- C:\ProgramData\mnjemahv.gza
[2010.01.03 20:54:04 | 000,005,052 | ---- | C] () -- C:\ProgramData\xqkcebzs.dik
[2009.11.27 21:11:37 | 000,034,610 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009.11.27 21:09:12 | 000,034,610 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009.08.29 17:22:42 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\acedrv05.dll
[2009.08.22 22:49:42 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009.08.22 22:49:07 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009.08.22 22:48:34 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.08.22 10:24:49 | 000,000,732 | ---- | C] () -- C:\Users\user\AppData\Local\d3d9caps64.dat
[2009.02.25 18:15:42 | 000,283,070 | ---- | C] () -- C:\Users\user\AppData\Local\vdrapet_nav.dat
[2009.02.25 18:15:12 | 000,000,328 | ---- | C] () -- C:\Users\user\AppData\Local\vdrapet_navps.dat
[2009.02.25 18:15:11 | 000,000,089 | ---- | C] () -- C:\Users\user\AppData\Local\vdrapet.bat
[2009.02.25 18:15:09 | 000,002,906 | ---- | C] () -- C:\Users\user\AppData\Local\vdrapet.dat
[2009.01.27 16:04:28 | 000,275,267 | ---- | C] () -- C:\Users\user\AppData\Local\zmrfjfb_nav.dat
[2009.01.27 16:03:57 | 000,002,905 | ---- | C] () -- C:\Users\user\AppData\Local\zmrfjfb.dat
[2009.01.27 16:03:57 | 000,000,311 | ---- | C] () -- C:\Users\user\AppData\Local\zmrfjfb_navps.dat
[2009.01.27 16:03:57 | 000,000,089 | ---- | C] () -- C:\Users\user\AppData\Local\zmrfjfb.bat
[2009.01.20 19:53:46 | 000,003,680 | ---- | C] () -- C:\Users\user\AppData\Roaming\Sys2657a.DLL
[2008.11.12 17:43:36 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2008.08.22 11:07:16 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008.06.27 08:49:18 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2007.02.24 18:05:13 | 000,000,060 | ---- | C] () -- C:\Windows\mpsettings.ini
[2007.02.24 17:54:18 | 000,524,288 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2007.02.24 17:54:18 | 000,139,264 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2007.02.21 14:30:55 | 000,000,241 | ---- | C] () -- C:\Windows\QSync.INI
[2007.02.21 14:26:41 | 000,000,792 | ---- | C] () -- C:\Windows\_delis32.ini
[2007.02.21 14:25:07 | 000,081,920 | ---- | C] () -- C:\Windows\bwUnin-6.1.4.36-8876480L.exe
[2007.02.18 17:10:19 | 000,144,812 | ---- | C] () -- C:\Windows\SysWow64\drivers\dump_wmimmc.sys
[2007.02.18 15:14:17 | 000,061,952 | ---- | C] () -- C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.02.18 13:39:52 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2007.02.17 15:49:18 | 000,000,047 | ---- | C] () -- C:\Windows\wininit.ini
[2007.02.17 14:47:32 | 000,010,240 | ---- | C] () -- C:\Windows\SysWow64\vidx16.dll
[2007.02.07 18:13:00 | 006,802,354 | ---- | C] () -- C:\Programme\NvCpl.dl_
[2007.02.07 18:13:00 | 004,976,822 | ---- | C] () -- C:\Programme\nvDispS.dl_
[2007.02.07 18:13:00 | 004,937,205 | ---- | C] () -- C:\Programme\data1.cab
[2007.02.07 18:13:00 | 004,547,123 | ---- | C] () -- C:\Programme\nvoglv64.dl_
[2007.02.07 18:13:00 | 004,478,646 | ---- | C] () -- C:\Programme\nvlddmkm.sy_
[2007.02.07 18:13:00 | 003,747,051 | ---- | C] () -- C:\Programme\nvd3dumx.dl_
[2007.02.07 18:13:00 | 003,425,576 | ---- | C] () -- C:\Programme\nvoglv32.dl_
[2007.02.07 18:13:00 | 003,167,904 | ---- | C] () -- C:\Programme\nvViTvS.dl_
[2007.02.07 18:13:00 | 003,136,116 | ---- | C] () -- C:\Programme\nvDispSR.dl_
[2007.02.07 18:13:00 | 002,787,424 | ---- | C] () -- C:\Programme\nvGameS.dl_
[2007.02.07 18:13:00 | 002,772,524 | ---- | C] () -- C:\Programme\nvd3dum.dl_
[2007.02.07 18:13:00 | 002,700,075 | ---- | C] () -- C:\Programme\nvViTvSR.dl_
[2007.02.07 18:13:00 | 001,619,145 | ---- | C] () -- C:\Programme\nvMoblSR.dl_
[2007.02.07 18:13:00 | 001,477,239 | ---- | C] () -- C:\Programme\nvwgf2umx.dl_
[2007.02.07 18:13:00 | 001,442,231 | ---- | C] () -- C:\Programme\nvwss.dl_
[2007.02.07 18:13:00 | 001,104,385 | ---- | C] () -- C:\Programme\nvGameSR.dl_
[2007.02.07 18:13:00 | 000,983,968 | ---- | C] () -- C:\Programme\nvwssr.dl_
[2007.02.07 18:13:00 | 000,940,236 | ---- | C] () -- C:\Programme\nvwgf2um.dl_
[2007.02.07 18:13:00 | 000,923,140 | ---- | C] () -- C:\Programme\nvcplui.ex_
[2007.02.07 18:13:00 | 000,729,554 | ---- | C] () -- C:\Programme\nvMoblS.dl_
[2007.02.07 18:13:00 | 000,459,544 | ---- | C] () -- C:\Programme\engine32.cab
[2007.02.07 18:13:00 | 000,435,969 | ---- | C] () -- C:\Programme\setup.ibt
[2007.02.07 18:13:00 | 000,368,989 | ---- | C] () -- C:\Programme\DPInst.ex_
[2007.02.07 18:13:00 | 000,339,712 | ---- | C] () -- C:\Programme\nvcpluir.dl_
[2007.02.07 18:13:00 | 000,247,609 | ---- | C] () -- C:\Programme\setup.inx
[2007.02.07 18:13:00 | 000,237,685 | ---- | C] () -- C:\Programme\nvdspJPN.chm
[2007.02.07 18:13:00 | 000,223,301 | ---- | C] () -- C:\Programme\nvdspKOR.chm
[2007.02.07 18:13:00 | 000,222,683 | ---- | C] () -- C:\Programme\nvdspTHA.chm
[2007.02.07 18:13:00 | 000,218,823 | ---- | C] () -- C:\Programme\nvdspELL.chm
[2007.02.07 18:13:00 | 000,218,813 | ---- | C] () -- C:\Programme\nvdspCHT.chm
[2007.02.07 18:13:00 | 000,213,815 | ---- | C] () -- C:\Programme\nvdspCHS.chm
[2007.02.07 18:13:00 | 000,210,619 | ---- | C] () -- C:\Programme\nvdspSKY.chm
[2007.02.07 18:13:00 | 000,209,771 | ---- | C] () -- C:\Programme\nvapi64.dl_
[2007.02.07 18:13:00 | 000,209,645 | ---- | C] () -- C:\Programme\nvdspRUS.chm
[2007.02.07 18:13:00 | 000,207,771 | ---- | C] () -- C:\Programme\nvdspSLV.chm
[2007.02.07 18:13:00 | 000,207,223 | ---- | C] () -- C:\Programme\nvdspHUN.chm
[2007.02.07 18:13:00 | 000,206,647 | ---- | C] () -- C:\Programme\nvdspPLK.chm
[2007.02.07 18:13:00 | 000,206,549 | ---- | C] () -- C:\Programme\nvdspHEB.chm
[2007.02.07 18:13:00 | 000,204,597 | ---- | C] () -- C:\Programme\nvdspTRK.chm
[2007.02.07 18:13:00 | 000,204,403 | ---- | C] () -- C:\Programme\nvdspCSY.chm
[2007.02.07 18:13:00 | 000,201,575 | ---- | C] () -- C:\Programme\nvdspARA.chm
[2007.02.07 18:13:00 | 000,200,469 | ---- | C] () -- C:\Programme\nvdspDEU.chm
[2007.02.07 18:13:00 | 000,199,129 | ---- | C] () -- C:\Programme\nvdspFIN.chm
[2007.02.07 18:13:00 | 000,198,663 | ---- | C] () -- C:\Programme\nvdspITA.chm
[2007.02.07 18:13:00 | 000,196,205 | ---- | C] () -- C:\Programme\nvdspNLD.chm
[2007.02.07 18:13:00 | 000,195,673 | ---- | C] () -- C:\Programme\nvdspPTG.chm
[2007.02.07 18:13:00 | 000,195,361 | ---- | C] () -- C:\Programme\nvdspPTB.chm
[2007.02.07 18:13:00 | 000,193,581 | ---- | C] () -- C:\Programme\nvdspESN.chm
[2007.02.07 18:13:00 | 000,193,463 | ---- | C] () -- C:\Programme\nvdspESM.chm
[2007.02.07 18:13:00 | 000,189,993 | ---- | C] () -- C:\Programme\nvdspFRA.chm
[2007.02.07 18:13:00 | 000,188,933 | ---- | C] () -- C:\Programme\nvdspDAN.chm
[2007.02.07 18:13:00 | 000,187,583 | ---- | C] () -- C:\Programme\nvdspSVE.chm
[2007.02.07 18:13:00 | 000,187,317 | ---- | C] () -- C:\Programme\nvdspNOR.chm
[2007.02.07 18:13:00 | 000,182,726 | ---- | C] () -- C:\Programme\nvdspENG.chm
[2007.02.07 18:13:00 | 000,180,024 | ---- | C] () -- C:\Programme\nvexpbar.dl_
[2007.02.07 18:13:00 | 000,179,765 | ---- | C] () -- C:\Programme\nvmccs.dl_
[2007.02.07 18:13:00 | 000,176,756 | ---- | C] () -- C:\Programme\setup.bmp
[2007.02.07 18:13:00 | 000,174,806 | ---- | C] () -- C:\Programme\nvwks.chm
[2007.02.07 18:13:00 | 000,167,166 | ---- | C] () -- C:\Programme\nvMccsSR.dl_
[2007.02.07 18:13:00 | 000,165,141 | ---- | C] () -- C:\Programme\nvdsp.chm
[2007.02.07 18:13:00 | 000,150,523 | ---- | C] () -- C:\Programme\nvapi.dl_
[2007.02.07 18:13:00 | 000,144,702 | ---- | C] () -- C:\Programme\nvMccsS.dl_
[2007.02.07 18:13:00 | 000,121,583 | ---- | C] () -- C:\Programme\nv3dJPN.chm
[2007.02.07 18:13:00 | 000,118,515 | ---- | C] () -- C:\Programme\nvcpl.chm
[2007.02.07 18:13:00 | 000,116,419 | ---- | C] () -- C:\Programme\nv3dTHA.chm
[2007.02.07 18:13:00 | 000,114,785 | ---- | C] () -- C:\Programme\nv3dKOR.chm
[2007.02.07 18:13:00 | 000,112,929 | ---- | C] () -- C:\Programme\nv3dELL.chm
[2007.02.07 18:13:00 | 000,112,507 | ---- | C] () -- C:\Programme\nv3dCHT.chm
[2007.02.07 18:13:00 | 000,112,329 | ---- | C] () -- C:\Programme\nvcpljpn.chm
[2007.02.07 18:13:00 | 000,111,801 | ---- | C] () -- C:\Programme\nv3dHEB.chm
[2007.02.07 18:13:00 | 000,111,149 | ---- | C] () -- C:\Programme\nvcpltha.chm
[2007.02.07 18:13:00 | 000,110,855 | ---- | C] () -- C:\Programme\nv3dPLK.chm
[2007.02.07 18:13:00 | 000,110,495 | ---- | C] () -- C:\Programme\nvcplell.chm
[2007.02.07 18:13:00 | 000,110,193 | ---- | C] () -- C:\Programme\nv3dARA.chm
[2007.02.07 18:13:00 | 000,109,903 | ---- | C] () -- C:\Programme\nv3dTRK.chm
[2007.02.07 18:13:00 | 000,109,697 | ---- | C] () -- C:\Programme\nv3dSKY.chm
[2007.02.07 18:13:00 | 000,109,653 | ---- | C] () -- C:\Programme\nvcplplk.chm
[2007.02.07 18:13:00 | 000,109,511 | ---- | C] () -- C:\Programme\nvcpltrk.chm
[2007.02.07 18:13:00 | 000,109,375 | ---- | C] () -- C:\Programme\nvcplslv.chm
[2007.02.07 18:13:00 | 000,109,255 | ---- | C] () -- C:\Programme\nv3dRUS.chm
[2007.02.07 18:13:00 | 000,109,143 | ---- | C] () -- C:\Programme\nvcplsky.chm
[2007.02.07 18:13:00 | 000,108,949 | ---- | C] () -- C:\Programme\nvcplheb.chm
[2007.02.07 18:13:00 | 000,108,949 | ---- | C] () -- C:\Programme\nvcplfin.chm
[2007.02.07 18:13:00 | 000,108,857 | ---- | C] () -- C:\Programme\nv3dCHS.chm
[2007.02.07 18:13:00 | 000,108,793 | ---- | C] () -- C:\Programme\nvcplhun.chm
[2007.02.07 18:13:00 | 000,108,619 | ---- | C] () -- C:\Programme\nv3dESN.chm
[2007.02.07 18:13:00 | 000,108,587 | ---- | C] () -- C:\Programme\nvcplkor.chm
[2007.02.07 18:13:00 | 000,108,497 | ---- | C] () -- C:\Programme\nvcplcsy.chm
[2007.02.07 18:13:00 | 000,108,491 | ---- | C] () -- C:\Programme\nvcplrus.chm
[2007.02.07 18:13:00 | 000,108,161 | ---- | C] () -- C:\Programme\nv3dDEU.chm
[2007.02.07 18:13:00 | 000,108,159 | ---- | C] () -- C:\Programme\nvcplcht.chm
[2007.02.07 18:13:00 | 000,107,901 | ---- | C] () -- C:\Programme\nv3dCSY.chm
[2007.02.07 18:13:00 | 000,107,787 | ---- | C] () -- C:\Programme\nvcplara.chm
[2007.02.07 18:13:00 | 000,107,715 | ---- | C] () -- C:\Programme\nvcplesn.chm
[2007.02.07 18:13:00 | 000,107,513 | ---- | C] () -- C:\Programme\nv3dSLV.chm
[2007.02.07 18:13:00 | 000,107,365 | ---- | C] () -- C:\Programme\nvcplita.chm
[2007.02.07 18:13:00 | 000,107,051 | ---- | C] () -- C:\Programme\nv3dESM.chm
[2007.02.07 18:13:00 | 000,106,941 | ---- | C] () -- C:\Programme\nvcplchs.chm
[2007.02.07 18:13:00 | 000,106,877 | ---- | C] () -- C:\Programme\nv3dHUN.chm
[2007.02.07 18:13:00 | 000,106,659 | ---- | C] () -- C:\Programme\nvcplptg.chm
[2007.02.07 18:13:00 | 000,106,571 | ---- | C] () -- C:\Programme\nvcplptb.chm
[2007.02.07 18:13:00 | 000,106,513 | ---- | C] () -- C:\Programme\nvcpldeu.chm
[2007.02.07 18:13:00 | 000,106,245 | ---- | C] () -- C:\Programme\nvcplesm.chm
[2007.02.07 18:13:00 | 000,106,081 | ---- | C] () -- C:\Programme\nv3dFIN.chm
[2007.02.07 18:13:00 | 000,105,249 | ---- | C] () -- C:\Programme\nvcplsve.chm
[2007.02.07 18:13:00 | 000,105,211 | ---- | C] () -- C:\Programme\nvcplnld.chm
[2007.02.07 18:13:00 | 000,105,121 | ---- | C] () -- C:\Programme\nvcplfra.chm
[2007.02.07 18:13:00 | 000,105,025 | ---- | C] () -- C:\Programme\nvcplnor.chm
[2007.02.07 18:13:00 | 000,104,809 | ---- | C] () -- C:\Programme\nvcpldan.chm
[2007.02.07 18:13:00 | 000,104,399 | ---- | C] () -- C:\Programme\nv3dITA.chm
[2007.02.07 18:13:00 | 000,104,183 | ---- | C] () -- C:\Programme\nvcpleng.chm
[2007.02.07 18:13:00 | 000,102,981 | ---- | C] () -- C:\Programme\nv3dPTG.chm
[2007.02.07 18:13:00 | 000,102,633 | ---- | C] () -- C:\Programme\nv3dPTB.chm
[2007.02.07 18:13:00 | 000,102,439 | ---- | C] () -- C:\Programme\nv3dDAN.chm
[2007.02.07 18:13:00 | 000,102,065 | ---- | C] () -- C:\Programme\nv3dNLD.chm
[2007.02.07 18:13:00 | 000,101,943 | ---- | C] () -- C:\Programme\nv3dSVE.chm
[2007.02.07 18:13:00 | 000,101,863 | ---- | C] () -- C:\Programme\nv3dFRA.chm
[2007.02.07 18:13:00 | 000,100,923 | ---- | C] () -- C:\Programme\nv3dNOR.chm
[2007.02.07 18:13:00 | 000,099,167 | ---- | C] () -- C:\Programme\nv3dENG.chm
[2007.02.07 18:13:00 | 000,095,638 | ---- | C] () -- C:\Programme\NvColor.ex_
[2007.02.07 18:13:00 | 000,090,934 | ---- | C] () -- C:\Programme\nv3d.chm
[2007.02.07 18:13:00 | 000,068,593 | ---- | C] () -- C:\Programme\setup.skin
[2007.02.07 18:13:00 | 000,060,169 | ---- | C] () -- C:\Programme\nvmobJPN.chm
[2007.02.07 18:13:00 | 000,058,989 | ---- | C] () -- C:\Programme\nvmobKOR.chm
[2007.02.07 18:13:00 | 000,058,989 | ---- | C] () -- C:\Programme\nvmobCHT.chm
[2007.02.07 18:13:00 | 000,058,975 | ---- | C] () -- C:\Programme\nvmobTHA.chm
[2007.02.07 18:13:00 | 000,058,433 | ---- | C] () -- C:\Programme\nvmobELL.chm
[2007.02.07 18:13:00 | 000,058,265 | ---- | C] () -- C:\Programme\nvmobHEB.chm
[2007.02.07 18:13:00 | 000,058,009 | ---- | C] () -- C:\Programme\nvmobCHS.chm
[2007.02.07 18:13:00 | 000,057,505 | ---- | C] () -- C:\Programme\nvmobPLK.chm
[2007.02.07 18:13:00 | 000,057,271 | ---- | C] () -- C:\Programme\nvmobARA.chm
[2007.02.07 18:13:00 | 000,057,135 | ---- | C] () -- C:\Programme\nvmobHUN.chm
[2007.02.07 18:13:00 | 000,057,085 | ---- | C] () -- C:\Programme\nvmobTRK.chm
[2007.02.07 18:13:00 | 000,057,065 | ---- | C] () -- C:\Programme\nvmobRUS.chm
[2007.02.07 18:13:00 | 000,057,003 | ---- | C] () -- C:\Programme\nvmobSKY.chm
[2007.02.07 18:13:00 | 000,056,769 | ---- | C] () -- C:\Programme\nvmobSLV.chm
[2007.02.07 18:13:00 | 000,056,641 | ---- | C] () -- C:\Programme\nvmobFIN.chm
[2007.02.07 18:13:00 | 000,056,411 | ---- | C] () -- C:\Programme\nvmobCSY.chm
[2007.02.07 18:13:00 | 000,055,905 | ---- | C] () -- C:\Programme\nvmobITA.chm
[2007.02.07 18:13:00 | 000,055,873 | ---- | C] () -- C:\Programme\nvmobDEU.chm
[2007.02.07 18:13:00 | 000,055,639 | ---- | C] () -- C:\Programme\nvmobPTG.chm
[2007.02.07 18:13:00 | 000,055,539 | ---- | C] () -- C:\Programme\nvmobESM.chm
[2007.02.07 18:13:00 | 000,055,527 | ---- | C] () -- C:\Programme\nvmobESN.chm
[2007.02.07 18:13:00 | 000,055,457 | ---- | C] () -- C:\Programme\nvmobNLD.chm
[2007.02.07 18:13:00 | 000,055,387 | ---- | C] () -- C:\Programme\nvmobSVE.chm
[2007.02.07 18:13:00 | 000,055,351 | ---- | C] () -- C:\Programme\nvmobPTB.chm
[2007.02.07 18:13:00 | 000,055,343 | ---- | C] () -- C:\Programme\nvmobFRA.chm
[2007.02.07 18:13:00 | 000,055,235 | ---- | C] () -- C:\Programme\nvmobNOR.chm
[2007.02.07 18:13:00 | 000,055,183 | ---- | C] () -- C:\Programme\nvmobDAN.chm
[2007.02.07 18:13:00 | 000,054,994 | ---- | C] () -- C:\Programme\nvmob.chm
[2007.02.07 18:13:00 | 000,054,939 | ---- | C] () -- C:\Programme\nvmobENG.chm
[2007.02.07 18:13:00 | 000,038,693 | ---- | C] () -- C:\Programme\NvMCTray.dl_
[2007.02.07 18:13:00 | 000,036,075 | ---- | C] () -- C:\Programme\nvcpl.cp_
[2007.02.07 18:13:00 | 000,035,171 | ---- | C] () -- C:\Programme\nv_disp.inf
[2007.02.07 18:13:00 | 000,033,121 | ---- | C] () -- C:\Programme\nvsvc64.dl_
[2007.02.07 18:13:00 | 000,029,080 | ---- | C] () -- C:\Programme\data1.hdr
[2007.02.07 18:13:00 | 000,025,008 | ---- | C] () -- C:\Programme\NvApps.xm_
[2007.02.07 18:13:00 | 000,011,089 | ---- | C] () -- C:\Programme\NvwsApps.xm_
[2007.02.07 18:13:00 | 000,007,772 | ---- | C] () -- C:\Programme\nvmccsrs.dl_
[2007.02.07 18:13:00 | 000,003,411 | ---- | C] () -- C:\Programme\nvdisp.nvu
[2007.02.07 18:13:00 | 000,000,862 | ---- | C] () -- C:\Programme\setup.ini
[2007.02.07 18:13:00 | 000,000,512 | ---- | C] () -- C:\Programme\data2.cab
[2007.02.07 18:13:00 | 000,000,510 | ---- | C] () -- C:\Programme\layout.bin
[2007.02.07 18:13:00 | 000,000,431 | ---- | C] () -- C:\Programme\setup.iss
[2006.11.02 16:37:05 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:37:14 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006.11.02 13:24:17 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006.11.02 13:18:17 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006.11.02 10:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
========== LOP Check ==========
[2011.05.09 05:32:07 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.05.19 13:30:36 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\elsterformular
[2010.01.08 22:07:40 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FLVPlayer4Free
[2010.01.09 20:12:57 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FreeFLVConverter
[2010.12.12 18:32:49 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Neoretix
[2010.03.22 11:57:03 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Sony
[2010.03.22 11:52:55 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Sony Setup
[2011.11.03 21:46:38 | 000,032,530 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2009.02.01 13:07:38 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Adobe
[2011.04.03 00:37:24 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Avira
[2009.03.17 20:33:02 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DivX
[2011.05.09 05:32:07 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.05.19 13:30:36 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\elsterformular
[2010.01.08 22:07:40 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FLVPlayer4Free
[2010.01.09 20:12:57 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FreeFLVConverter
[2007.02.17 15:58:48 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Macromedia
[2011.04.03 14:07:02 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Malwarebytes
[2006.11.02 16:07:25 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Media Center Programs
[2011.03.01 16:59:13 | 000,000,000 | --SD | M] -- C:\Users\user\AppData\Roaming\Microsoft
[2009.01.10 12:52:14 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Mozilla
[2010.12.12 18:32:49 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Neoretix
[2007.02.17 15:38:31 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\OpenOffice.org2
[2010.03.22 11:57:03 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Sony
[2010.03.22 11:52:55 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Sony Setup
[2007.02.20 20:01:42 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\teamspeak2
[2007.02.17 15:13:25 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\vlc
[2009.01.14 16:43:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\WinRAR
< %APPDATA%\*.exe /s >
[2010.03.22 11:56:12 | 000,010,134 | R--- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Installer\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}\ARPPRODUCTICON.exe
[2010.11.16 20:55:32 | 002,596,864 | ---- | M] (Neoretix Laboratory) -- C:\Users\user\AppData\Roaming\Neoretix\TubeHunter Ultra\TubeHunter.exe
[2010.03.22 11:53:42 | 032,494,896 | ---- | M] (Apple Inc.) -- C:\Users\user\AppData\Roaming\Sony Setup\9234765D-29DF-48d0-93FB-284B7B6009B9\QuickTimeInstaller.exe
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2006.11.02 13:03:16 | 000,062,056 | ---- | M] (Microsoft Corporation) MD5=5CCDD13BC602AE33CD8B62D33C29AB72 -- C:\Windows\SysNative\drivers\AGP440.sys
[2008.01.19 09:09:09 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008.01.19 09:09:09 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
< MD5 for: ATAPI.SYS >
[2008.03.07 13:29:17 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=05001E1FACCE49DB895B8526B05C7302 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_37cb142cf6008bc1\atapi.sys
[2008.01.19 09:07:46 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2008.03.07 13:29:17 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=BB55C79E0595D8CFBE4A80A3C9EB77EA -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\atapi.sys
[2009.04.11 08:15:00 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SysNative\drivers\atapi.sys
[2009.04.11 08:15:00 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006.11.02 12:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\SysNative\cngaudit.dll
[2006.11.02 12:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: IASTORV.SYS >
[2008.01.19 09:11:31 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
[2006.11.02 12:51:48 | 000,280,680 | ---- | M] (Intel Corporation) MD5=72C3EE7EA3CD75A772E62AE0E5DF8B8C -- C:\Windows\SysNative\drivers\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2008.01.19 09:03:01 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2006.11.02 10:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_61f43b1d27cd0ab4\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009.04.11 08:11:16 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\SysNative\netlogon.dll
[2009.04.11 08:11:16 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008.01.19 08:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
[2006.11.02 12:18:47 | 000,684,032 | ---- | M] (Microsoft Corporation) MD5=BFAB28B54DF41208CF3490FF26E53FD9 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_579f90caf36c48b9\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2006.11.02 13:02:51 | 000,048,232 | ---- | M] (NVIDIA Corporation) MD5=94C5334040A5D500897F4C5FD12AEEDE -- C:\Windows\SysNative\drivers\nvstor.sys
[2008.01.19 09:08:50 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008.01.19 08:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2006.11.02 12:19:09 | 000,239,616 | ---- | M] (Microsoft Corporation) MD5=32EF13F20B28966D29DE5EABE036431D -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_91f5bbe3948dcf74\scecli.dll
[2008.01.19 09:03:55 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2006.11.02 10:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_9c4a6635c8ee916f\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009.04.11 08:11:23 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\SysNative\scecli.dll
[2009.04.11 08:11:23 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
< MD5 for: USER32.DLL >
[2006.11.02 10:44:25 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=00B53DCA0408CCD8F6BAF13994F6E3A0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_3174f01b5d2fa18f\user32.dll
[2007.04.04 19:02:17 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=296BA70E2A302E639CBD9E2A32DC65C4 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_31ad02315d0545af\user32.dll
[2008.01.19 09:04:23 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=32B87D215905F648EBE36A621978442C -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_295707c525b9f068\user32.dll
[2008.01.19 08:32:19 | 000,648,192 | ---- | M] (Microsoft Corporation) MD5=3D691030DBD3BD75DE1501BE54F0D425 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll
[2007.04.04 19:02:17 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=437C1C0CB2A42EA20083F21E9CAEF461 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_32359eb27623cc22\user32.dll
[2007.04.04 19:02:19 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=707CD582A4F93DB789336A5CE9527970 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_275857df28a483b4\user32.dll
[2006.11.02 12:19:10 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=95D5555CC7BD8F520996E35D36491EEF -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_272045c928cedf94\user32.dll
[2009.04.11 07:26:45 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\SysWOW64\user32.dll
[2009.04.11 07:26:45 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_35972b23573c7daf\user32.dll
[2007.04.04 19:02:18 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=E4E3ED1E0D1D8C33A9C94ABEA1C8BC96 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_27e0f46041c30a27\user32.dll
[2009.04.11 08:11:27 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysNative\user32.dll
[2009.04.11 08:11:27 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_2b4280d122dbbbb4\user32.dll
< MD5 for: USERINIT.EXE >
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 10:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
[2006.11.02 12:16:15 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=46D5B6B80E4A5997F508F938F96B7628 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_3610939d8d22586d\userinit.exe
[2008.01.19 09:00:41 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008.01.19 09:00:41 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
< MD5 for: WININIT.EXE >
[2008.01.19 08:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008.01.19 08:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.19 09:00:45 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\SysNative\wininit.exe
[2008.01.19 09:00:45 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
[2006.11.02 12:16:20 | 000,122,368 | ---- | M] (Microsoft Corporation) MD5=6F92CE5B50283B0C0A7A539ED552039A -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_8ada9256bfc30704\wininit.exe
[2006.11.02 10:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
< MD5 for: WINLOGON.EXE >
[2009.04.11 08:11:08 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009.04.11 08:11:08 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008.01.19 09:00:45 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 12:16:20 | 000,397,312 | ---- | M] (Microsoft Corporation) MD5=9642EED809219A2F914DD8E40A09C48B -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_c9aada9e9063dc57\winlogon.exe
[2006.11.02 10:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 08:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2008.01.19 07:37:47 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2008.01.19 07:37:47 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_aba53c58802b1777\ws2ifsl.sys
[2006.11.02 10:47:52 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=C4EE49DB7EADC812DBC0ECCF2E7FB929 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_a96e7a5c834006a3\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< End of report > |