Eine Frage...ich kann mir vorstellen, dass ihr hier echt fast Fließbandarbeit macht, aber wenn Du eventuell ein bisschen Zeit hast, könntest Du mir erklären, was der CustomScan genau jetzt gerade macht? Ersetzt es Dateien?  
danke schonmal  
Das Log...   Code:  
 OTL logfile created on: 27.11.2012 15:14:50 - Run 2 
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Boje\Desktop 
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation 
Internet Explorer (Version = 9.0.8112.16421) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
3,92 Gb Total Physical Memory | 2,20 Gb Available Physical Memory | 56,26% Memory free 
7,83 Gb Paging File | 6,06 Gb Available in Paging File | 77,39% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 451,01 Gb Total Space | 41,68 Gb Free Space | 9,24% Space Free | Partition Type: NTFS 
Drive E: | 931,28 Gb Total Space | 331,21 Gb Free Space | 35,56% Space Free | Partition Type: FAT32 
  
Computer Name: BOJE-PC | User Name: Boje | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans 
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Processes (SafeList) ========== 
  
PRC - [2012.11.26 23:03:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Boje\Desktop\OTL.exe 
PRC - [2012.10.30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe 
PRC - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe 
PRC - [2012.10.30 23:50:56 | 000,133,912 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\afwServ.exe 
PRC - [2012.10.02 12:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe 
PRC - [2012.09.29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe 
PRC - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 
PRC - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 
PRC - [2012.07.27 12:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 
PRC - [2012.07.24 21:28:22 | 000,387,440 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe 
PRC - [2012.07.24 21:26:42 | 000,474,992 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe 
PRC - [2010.12.21 00:24:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 
PRC - [2010.12.21 00:24:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 
PRC - [2010.12.14 07:21:34 | 000,974,912 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe 
PRC - [2010.11.30 03:04:00 | 001,997,416 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe 
PRC - [2010.11.29 04:31:42 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 
PRC - [2010.08.21 00:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE 
PRC - [2010.08.12 00:19:16 | 000,781,536 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe 
PRC - [2010.03.18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 
PRC - [2010.03.10 13:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe 
PRC - [2009.05.06 17:53:50 | 001,220,608 | ---- | M] (MAGIX AG) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe 
  
   ========== Modules (No Company Name) ========== 
  
MOD - [2010.08.12 00:19:34 | 000,077,024 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll 
MOD - [2010.08.12 00:19:32 | 000,109,792 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll 
MOD - [2010.08.12 00:19:32 | 000,072,928 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll 
MOD - [2010.08.12 00:19:30 | 000,232,672 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll 
MOD - [2010.08.12 00:19:30 | 000,126,176 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll 
MOD - [2010.08.12 00:19:30 | 000,119,008 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll 
MOD - [2010.08.12 00:19:26 | 001,121,504 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll 
MOD - [2010.08.12 00:19:16 | 000,781,536 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe 
  
   ========== Services (SafeList) ========== 
  
SRV - [2012.11.16 11:03:31 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) 
SRV - [2012.11.14 10:01:01 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) 
SRV - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) 
SRV - [2012.10.30 23:50:56 | 000,133,912 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\afwServ.exe -- (avast! Firewall) 
SRV - [2012.10.02 12:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service) 
SRV - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) 
SRV - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) 
SRV - [2012.07.27 12:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) 
SRV - [2012.07.24 21:36:22 | 000,078,072 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE -- (HssTrayService) 
SRV - [2012.07.24 21:32:10 | 000,404,848 | ---- | M] (AnchorFree Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv) 
SRV - [2012.07.24 21:28:22 | 000,387,440 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -- (HssWd) 
SRV - [2012.07.24 21:26:42 | 000,474,992 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe -- (hshld) 
SRV - [2012.07.13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) 
SRV - [2010.12.21 00:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) 
SRV - [2010.12.21 00:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) 
SRV - [2010.12.17 20:41:32 | 001,515,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) 
SRV - [2010.12.17 20:28:46 | 000,340,240 | ---- | M] () [Disabled | Stopped] -- C:\Programme\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS) 
SRV - [2010.12.17 20:26:50 | 000,836,880 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) 
SRV - [2010.12.14 07:21:34 | 000,974,912 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service) 
SRV - [2010.12.14 07:21:30 | 001,298,496 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service) 
SRV - [2010.11.30 03:04:00 | 001,997,416 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService) 
SRV - [2010.11.29 21:00:56 | 000,149,504 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Programme\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost) 
SRV - [2010.11.29 04:31:42 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) 
SRV - [2010.10.29 19:20:58 | 000,236,016 | ---- | M] (CyberLink) [Disabled | Stopped] -- c:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe -- (CLKMSVC10_9EC60124) 
SRV - [2010.09.23 00:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) 
SRV - [2010.09.21 20:49:00 | 002,286,976 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) 
SRV - [2010.09.04 07:15:22 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12) 
SRV - [2010.09.04 07:14:26 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM) 
SRV - [2010.08.26 02:28:54 | 002,823,000 | ---- | M] (Dell, Inc.) [Auto | Running] -- C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe -- (NOBU) 
SRV - [2010.08.21 00:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService) 
SRV - [2010.08.18 21:43:38 | 000,463,912 | R--- | M] (Ericsson AB) [Disabled | Stopped] -- C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe -- (WMCoreService) 
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) 
SRV - [2010.03.18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon) 
SRV - [2010.03.10 13:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2) 
SRV - [2010.01.09 20:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc) 
SRV - [2010.01.09 20:20:56 | 000,174,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose64) 
SRV - [2009.11.18 03:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Disabled | Stopped] -- C:\Programme\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters) 
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) 
SRV - [2009.05.06 17:53:50 | 001,220,608 | ---- | M] (MAGIX AG) [Auto | Running] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs) 
SRV - [2008.08.07 10:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) 
SRV - [2007.05.31 16:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) 
SRV - [2007.05.31 16:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV:64bit: - [2012.10.30 23:51:56 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi) 
DRV:64bit: - [2012.10.30 23:51:55 | 000,984,144 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx) 
DRV:64bit: - [2012.10.30 23:51:55 | 000,370,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP) 
DRV:64bit: - [2012.10.30 23:51:55 | 000,262,656 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswNdis2.sys -- (aswNdis2) 
DRV:64bit: - [2012.10.30 23:51:55 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) 
DRV:64bit: - [2012.10.30 23:51:55 | 000,021,136 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswKbd.sys -- (aswKbd) 
DRV:64bit: - [2012.10.30 23:51:53 | 000,132,864 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswFW.sys -- (aswFW) 
DRV:64bit: - [2012.10.30 23:51:53 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk) 
DRV:64bit: - [2012.10.15 17:59:28 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr) 
DRV:64bit: - [2012.09.29 19:54:26 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) 
DRV:64bit: - [2012.09.21 10:26:08 | 000,012,368 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswNdis.sys -- (aswNdis) 
DRV:64bit: - [2012.08.21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) 
DRV:64bit: - [2012.07.10 03:48:18 | 000,041,704 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\hssdrv6.sys -- (HssDRV6) 
DRV:64bit: - [2012.07.09 12:42:54 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64) 
DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) 
DRV:64bit: - [2011.12.09 18:45:00 | 000,060,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (iBtFltCoex) 
DRV:64bit: - [2011.11.15 00:13:00 | 000,327,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf) 
DRV:64bit: - [2011.06.10 05:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) 
DRV:64bit: - [2011.05.25 00:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\taphss.sys -- (taphss) 
DRV:64bit: - [2011.05.10 07:06:14 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl) 
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) 
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) 
DRV:64bit: - [2011.01.13 02:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) 
DRV:64bit: - [2010.12.22 10:08:48 | 008,505,856 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) 
DRV:64bit: - [2010.12.17 18:06:32 | 001,404,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) 
DRV:64bit: - [2010.12.15 18:02:04 | 000,174,168 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR) 
DRV:64bit: - [2010.12.14 14:18:50 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux) 
DRV:64bit: - [2010.12.13 18:34:14 | 000,027,760 | ---- | M] (ST Microelectronics) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelern.sys -- (Acceler) 
DRV:64bit: - [2010.12.12 15:18:36 | 000,121,960 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvstusb.sys -- (NvStUSB) 
DRV:64bit: - [2010.11.30 03:04:00 | 000,025,576 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt) 
DRV:64bit: - [2010.11.29 21:00:04 | 000,016,120 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB) 
DRV:64bit: - [2010.11.29 14:23:18 | 012,252,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) 
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) 
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) 
DRV:64bit: - [2010.11.20 10:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus) 
DRV:64bit: - [2010.11.19 19:34:26 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) 
DRV:64bit: - [2010.11.19 19:34:26 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) 
DRV:64bit: - [2010.11.12 13:40:50 | 000,155,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) 
DRV:64bit: - [2010.10.20 01:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) 
DRV:64bit: - [2010.10.15 17:28:18 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) 
DRV:64bit: - [2010.08.20 11:05:12 | 000,021,616 | ---- | M] (ST Microelectronics) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stdcfltn.sys -- (stdcfltn) 
DRV:64bit: - [2010.08.12 16:51:30 | 000,175,168 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt) 
DRV:64bit: - [2010.07.30 23:42:12 | 000,274,984 | ---- | M] (Ericsson AB) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WwanUsbMp64.sys -- (WwanUsbServ) 
DRV:64bit: - [2010.07.13 03:38:06 | 000,029,288 | ---- | M] (Quanta Computer) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\qicflt.sys -- (qicflt) 
DRV:64bit: - [2010.06.24 19:53:38 | 000,060,968 | ---- | M] (Ericsson AB) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\d554scard.sys -- (d554scard) 
DRV:64bit: - [2010.04.27 19:02:50 | 000,468,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Mbm3Mdm.sys -- (Mbm3Mdm) 
DRV:64bit: - [2010.04.27 19:02:50 | 000,416,328 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Mbm3DevMt.sys -- (Mbm3DevMt) 
DRV:64bit: - [2010.04.27 19:02:50 | 000,378,952 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Mbm3CBus.sys -- (Mbm3CBus) 
DRV:64bit: - [2010.04.27 19:02:50 | 000,019,528 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Mbm3mdfl.sys -- (Mbm3mdfl) 
DRV:64bit: - [2010.03.19 09:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) 
DRV:64bit: - [2010.03.03 20:30:30 | 000,030,248 | ---- | M] (Ericsson AB) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wwussf64.sys -- (ecnssndisfltr) 
DRV:64bit: - [2010.03.03 20:30:30 | 000,026,664 | ---- | M] (Ericsson AB) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wwuss64.sys -- (ecnssndis) 
DRV:64bit: - [2010.02.27 08:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd) 
DRV:64bit: - [2010.01.26 05:18:20 | 000,096,296 | ---- | M] (Ericsson AB) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\d554gps64.sys -- (d554gps) 
DRV:64bit: - [2009.11.10 14:50:18 | 000,014,336 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\copperhd.sys -- (copperhd) 
DRV:64bit: - [2009.07.16 03:57:56 | 000,492,008 | ---- | M] (AfaTech                  ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AF9035BDA.sys -- (AF9035BDA) 
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) 
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) 
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) 
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) 
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) 
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) 
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) 
DRV:64bit: - [2009.04.29 15:28:30 | 000,030,208 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\KMWDFILTER.sys -- (KMWDFILTER) 
DRV:64bit: - [2006.11.01 18:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr) 
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =  
IE:64bit: - HKLM\..\SearchScopes\{478A9541-707F-48C2-9B0F-D58250139783}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm 
IE - HKLM\..\SearchScopes,DefaultScope =  
IE - HKLM\..\SearchScopes\{4AF14EC5-1B63-4AEC-A4D1-DF07669A838E}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox 
  
  
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =  
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =  
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =  
  
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =  
  
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1000\..\SearchScopes,DefaultScope =  
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.msn.com/?ocid=ie9hp 
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.de/ [binary data] 
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ 
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1002\..\SearchScopes,DefaultScope =  
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1002\..\SearchScopes\{8B73BC7E-40B5-45D2-8358-F61400B8B661}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=IE9SRC 
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1002\..\SearchScopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}: "URL" = hxxp://search.hotspotshield.com/g/results.php?c=s&q={searchTerms} 
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1002\..\SearchScopes\{EF72745C-AF7E-4D1C-A235-4DBB14381D89}: "URL" = hxxp://www.google.de/search?q={searchTerms} 
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
IE - HKU\S-1-5-21-722063460-768948207-1063682938-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local 
   ========== FireFox ========== 
  
FF - prefs.js..browser.search.defaultenginename: "Hotspot Shield Private Search" 
FF - prefs.js..browser.search.selectedEngine: "Hotspot Shield Private Search" 
FF - prefs.js..browser.startup.homepage: "https://www.google.de/" 
FF - prefs.js..extensions.enabledAddons: 2020Player_IKEA@2020Technologies.com:5.0.94.0 
FF - prefs.js..extensions.enabledAddons: togglepersona@davidvincent.tld:1.0.9 
FF - prefs.js..extensions.enabledAddons: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.145 
FF - prefs.js..extensions.enabledAddons: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:6.3.0.11079 
FF - prefs.js..extensions.enabledAddons: NoiaFoxoption@davidvincent.tld:2.0.6 
FF - prefs.js..extensions.enabledAddons: wrc@avast.com:7.0.1474 
FF - prefs.js..network.proxy.no_proxies_on: "*.local" 
FF - prefs.js..network.proxy.type: 0 
FF - user.js - File not found 
  
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found 
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) 
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) 
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found 
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) 
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll () 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () 
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) 
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) 
FF - HKLM\Software\MozillaPlugins\@gametap.com/npdd,version=1.0: C:\Program Files (x86)\Downloader\npdd.dll (Metaboli) 
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found 
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) 
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) 
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) 
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) 
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101727.dll (Amazon.com, Inc.) 
  
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011.03.25 07:09:07 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.01.03 23:22:42 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012.11.27 09:36:18 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.16 11:03:31 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.16\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.07.31 16:22:12 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.16\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2012.08.21 14:32:37 | 000,000,000 | ---D | M] 
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.16 11:03:31 | 000,000,000 | ---D | M] 
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins 
  
[2011.05.03 20:15:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Boje\AppData\Roaming\mozilla\Extensions 
[2011.05.03 20:15:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Boje\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} 
[2012.11.24 21:31:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Boje\AppData\Roaming\mozilla\Firefox\Profiles\wilnpep9.default\extensions 
[2012.07.03 19:33:05 | 000,000,000 | ---D | M] (20-20 3D Viewer - IKEA) -- C:\Users\Boje\AppData\Roaming\mozilla\Firefox\Profiles\wilnpep9.default\extensions\2020Player_IKEA@2020Technologies.com 
[2012.11.21 17:20:36 | 000,065,957 | ---- | M] () (No name found) -- C:\Users\Boje\AppData\Roaming\mozilla\firefox\profiles\wilnpep9.default\extensions\NoiaFoxoption@davidvincent.tld.xpi 
[2012.06.16 14:28:17 | 000,009,880 | ---- | M] () (No name found) -- C:\Users\Boje\AppData\Roaming\mozilla\firefox\profiles\wilnpep9.default\extensions\togglepersona@davidvincent.tld.xpi 
[2012.11.19 18:42:05 | 002,278,298 | ---- | M] () (No name found) -- C:\Users\Boje\AppData\Roaming\mozilla\firefox\profiles\wilnpep9.default\extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi 
[2012.11.24 21:31:32 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\Boje\AppData\Roaming\mozilla\firefox\profiles\wilnpep9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi 
[2012.11.27 14:31:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions 
[2012.11.16 11:03:28 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} 
[2012.01.03 23:22:42 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5 
[2012.11.27 09:36:18 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF 
[2012.11.16 11:03:31 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll 
[2012.01.29 15:02:49 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml 
[2012.10.10 14:46:19 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml 
[2012.01.29 15:02:49 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml 
[2012.01.29 15:02:49 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml 
[2012.01.29 15:02:49 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml 
[2012.01.29 15:02:49 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml 
   ========== Chrome  ========== 
  
CHR - homepage: hxxp://www.google.com 
CHR - homepage: hxxp://www.google.com 
CHR - Extension: Google Drive = C:\Users\Boje\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\ 
CHR - Extension: YouTube = C:\Users\Boje\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ 
CHR - Extension: Google-Suche = C:\Users\Boje\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ 
CHR - Extension: avast! WebRep = C:\Users\Boje\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\ 
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Boje\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\ 
CHR - Extension: Google Mail = C:\Users\Boje\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ 
  
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts 
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL File not found 
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) 
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) 
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) 
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) 
O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.) 
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll File not found 
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) 
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) 
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) 
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) 
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) 
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.) 
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) 
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. 
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) 
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. 
O4 - HKLM..\Run: []  File not found 
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) 
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) 
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) 
O4 - HKU\S-1-5-21-722063460-768948207-1063682938-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) 
O4 - HKU\S-1-5-21-722063460-768948207-1063682938-1000..\Run: [WirelessManager] C:\Program Files (x86)\Dell\Dell Mobile Broadband Manager\WirelessManager.exe (Ericsson AB) 
O4 - HKLM..\RunOnce: [DSUpdateLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe (Dell) 
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks) 
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found 
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found 
O4 - HKU\S-1-5-21-722063460-768948207-1063682938-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 
O7 - HKU\S-1-5-21-722063460-768948207-1063682938-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 
O7 - HKU\S-1-5-21-722063460-768948207-1063682938-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0 
O8:64bit: - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) 
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Boje\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () 
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) 
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) 
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Boje\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () 
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) 
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) 
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) 
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) 
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) 
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) 
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) 
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) 
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) 
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) 
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) 
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) 
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) 
O1364bit: - gopher Prefix: missing 
O13 - gopher Prefix: missing 
O15 - HKU\S-1-5-21-722063460-768948207-1063682938-1002\..Trusted Domains: navigram.com ([]http in Vertrauenswürdige Sites) 
O15 - HKU\S-1-5-21-722063460-768948207-1063682938-1002\..Trusted Domains: navigram.com ([www] https in Vertrauenswürdige Sites) 
O16:64bit: - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.) 
O16:64bit: - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} hxxp://navigram.com/engine/v1026/Navigram.cab (Reg Error: Key error.) 
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) 
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) 
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) 
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{554E7F8B-0A6E-4D9A-A087-3F3568EC1F9A}: NameServer = 8.8.8.8 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95F55382-CBC5-4DB1-A2E4-639DCA7264AD}: DhcpNameServer = 212.23.115.148 212.23.97.2 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EFA94165-44FE-4EA4-BED2-84FF945BB600}: NameServer = 134.147.222.4 
O18:64bit: - Protocol\Handler\livecall - No CLSID value found 
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) 
O18:64bit: - Protocol\Handler\msnim - No CLSID value found 
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found 
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) 
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found 
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found 
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) 
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) 
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) 
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation) 
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation) 
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) 
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) 
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. 
O32 - HKLM CDRom: AutoRun - 1 
O34 - HKLM BootExecute: (autocheck autochk *) 
O35:64bit: - HKLM\..comfile [open] -- "%1" %* 
O35:64bit: - HKLM\..exefile [open] -- "%1" %* 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* 
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* 
O37 - HKLM\...com [@ = comfile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) 
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) 
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) 
  
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Audible Download Manager.lnk -  - File not found 
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NuvaTime.lnk -  - File not found 
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TMMonitor.lnk - C:\PROGRA~2\ArcSoft\TOTALM~1.5\TMMONI~1.EXE - (ArcSoft, Inc.) 
MsConfig:64bit - StartUpFolder: C:^Users^Boje^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ctfmon.lnk -  - File not found 
MsConfig:64bit - StartUpFolder: C:^Users^Boje^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Warner Bros.lnk - C:\PROGRA~2\WARNER~1.DIG\WARNER~1.EXE - () 
MsConfig:64bit - StartUpFolder: C:^Users^Boje^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Überwachungstool für die Intel® Turbo-Boost-Technik 2.0.lnk - C:\Programme\Intel\TurboBoost\SignalIslandUi.exe - (Intel® Corporation) 
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) 
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) 
MsConfig:64bit - StartUpReg: AppleSyncNotifier - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.) 
MsConfig:64bit - StartUpReg: APSDaemon - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) 
MsConfig:64bit - StartUpReg: ArcSoft Connection Service - hkey= - key= - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.) 
MsConfig:64bit - StartUpReg: avgnt - hkey= - key= -  File not found 
MsConfig:64bit - StartUpReg: BDRegion - hkey= - key= - c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe (cyberlink) 
MsConfig:64bit - StartUpReg: BTMTrayAgent - hkey= - key= - C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) 
MsConfig:64bit - StartUpReg: Copperhead - hkey= - key= - C:\Program Files (x86)\Razer\Copperhead\razerhid.exe () 
MsConfig:64bit - StartUpReg: dcmsvc - hkey= - key= - C:\Program Files (x86)\dcmsvc\dcmsvc.exe () 
MsConfig:64bit - StartUpReg: Dell DataSafe Online - hkey= - key= - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.) 
MsConfig:64bit - StartUpReg: Dell Webcam Central - hkey= - key= - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd) 
MsConfig:64bit - StartUpReg: DellStage - hkey= - key= - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe () 
MsConfig:64bit - StartUpReg: Desktop Disc Tool - hkey= - key= - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe () 
MsConfig:64bit - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () 
MsConfig:64bit - StartUpReg: EPSON Stylus DX4400 Series - hkey= - key= - C:\Windows\SysNative\spool\DRIVERS\x64\3\E_IATICAE.EXE (SEIKO EPSON CORPORATION) 
MsConfig:64bit - StartUpReg: FreeFallProtection - hkey= - key= - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe () 
MsConfig:64bit - StartUpReg: HotKeysCmds - hkey= - key= - C:\Windows\SysNative\hkcmd.exe (Intel Corporation) 
MsConfig:64bit - StartUpReg: IgfxTray - hkey= - key= - C:\Windows\SysNative\igfxtray.exe (Intel Corporation) 
MsConfig:64bit - StartUpReg: IntelTBRunOnce - hkey= - key= - C:\Windows\SysNative\wscript.exe (Microsoft Corporation) 
MsConfig:64bit - StartUpReg: IntelWireless - hkey= - key= - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation) 
MsConfig:64bit - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) 
MsConfig:64bit - StartUpReg: Microsoft Default Manager - hkey= - key= - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation) 
MsConfig:64bit - StartUpReg: MobileDocuments - hkey= - key= -  File not found 
MsConfig:64bit - StartUpReg: NCsoft Launcher - hkey= - key= -  File not found 
MsConfig:64bit - StartUpReg: NVHotkey - hkey= - key= - C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) 
MsConfig:64bit - StartUpReg: PDVD9LanguageShortcut - hkey= - key= - c:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.) 
MsConfig:64bit - StartUpReg: Persistence - hkey= - key= - C:\Windows\SysNative\igfxpers.exe (Intel Corporation) 
MsConfig:64bit - StartUpReg: QuickSet - hkey= - key= - c:\Programme\Dell\QuickSet\quickset.exe (Dell Inc.) 
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.) 
MsConfig:64bit - StartUpReg: RemoteControl9 - hkey= - key= - c:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.) 
MsConfig:64bit - StartUpReg: RoxWatchTray - hkey= - key= - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions) 
MsConfig:64bit - StartUpReg: RtHDVBg - hkey= - key= - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) 
MsConfig:64bit - StartUpReg: RTHDVCPL - hkey= - key= - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) 
MsConfig:64bit - StartUpReg: Steam - hkey= - key= -  File not found 
MsConfig:64bit - StartUpReg: SynTPEnh - hkey= - key= - C:\Programme\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) 
MsConfig:64bit - StartUpReg: Windows Mobile Device Center - hkey= - key= - C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation) 
MsConfig:64bit - State: "startup" - Reg Error: Key error. 
MsConfig:64bit - State: "services" - Reg Error: Key error. 
  
  
SafeBootMin:64bit: AppMgmt - Service 
SafeBootMin:64bit: Base - Driver Group 
SafeBootMin:64bit: Boot Bus Extender - Driver Group 
SafeBootMin:64bit: Boot file system - Driver Group 
SafeBootMin:64bit: File system - Driver Group 
SafeBootMin:64bit: Filter - Driver Group 
SafeBootMin:64bit: HelpSvc - Service 
SafeBootMin:64bit: MCODS - Reg Error: Value error. 
SafeBootMin:64bit: PCI Configuration - Driver Group 
SafeBootMin:64bit: PNP Filter - Driver Group 
SafeBootMin:64bit: Primary disk - Driver Group 
SafeBootMin:64bit: sacsvr - Service 
SafeBootMin:64bit: SCSI Class - Driver Group 
SafeBootMin:64bit: System Bus Extender - Driver Group 
SafeBootMin:64bit: vmms - Service 
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
SafeBootMin: AppMgmt - Service 
SafeBootMin: Base - Driver Group 
SafeBootMin: Boot Bus Extender - Driver Group 
SafeBootMin: Boot file system - Driver Group 
SafeBootMin: File system - Driver Group 
SafeBootMin: Filter - Driver Group 
SafeBootMin: HelpSvc - Service 
SafeBootMin: MCODS - Reg Error: Value error. 
SafeBootMin: PCI Configuration - Driver Group 
SafeBootMin: PNP Filter - Driver Group 
SafeBootMin: Primary disk - Driver Group 
SafeBootMin: sacsvr - Service 
SafeBootMin: SCSI Class - Driver Group 
SafeBootMin: System Bus Extender - Driver Group 
SafeBootMin: vmms - Service 
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
  
SafeBootNet:64bit: AppMgmt - Service 
SafeBootNet:64bit: Base - Driver Group 
SafeBootNet:64bit: Boot Bus Extender - Driver Group 
SafeBootNet:64bit: Boot file system - Driver Group 
SafeBootNet:64bit: File system - Driver Group 
SafeBootNet:64bit: Filter - Driver Group 
SafeBootNet:64bit: HelpSvc - Service 
SafeBootNet:64bit: MCODS - Reg Error: Value error. 
SafeBootNet:64bit: Messenger - Service 
SafeBootNet:64bit: NDIS Wrapper - Driver Group 
SafeBootNet:64bit: NetBIOSGroup - Driver Group 
SafeBootNet:64bit: NetDDEGroup - Driver Group 
SafeBootNet:64bit: Network - Driver Group 
SafeBootNet:64bit: NetworkProvider - Driver Group 
SafeBootNet:64bit: PCI Configuration - Driver Group 
SafeBootNet:64bit: PNP Filter - Driver Group 
SafeBootNet:64bit: PNP_TDI - Driver Group 
SafeBootNet:64bit: Primary disk - Driver Group 
SafeBootNet:64bit: rdsessmgr - Service 
SafeBootNet:64bit: sacsvr - Service 
SafeBootNet:64bit: SCSI Class - Driver Group 
SafeBootNet:64bit: Streams Drivers - Driver Group 
SafeBootNet:64bit: System Bus Extender - Driver Group 
SafeBootNet:64bit: TDI - Driver Group 
SafeBootNet:64bit: vmms - Service 
SafeBootNet:64bit: WudfUsbccidDriver - Driver 
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net 
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient 
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService 
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans 
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers 
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
SafeBootNet: AppMgmt - Service 
SafeBootNet: Base - Driver Group 
SafeBootNet: Boot Bus Extender - Driver Group 
SafeBootNet: Boot file system - Driver Group 
SafeBootNet: File system - Driver Group 
SafeBootNet: Filter - Driver Group 
SafeBootNet: HelpSvc - Service 
SafeBootNet: MCODS - Reg Error: Value error. 
SafeBootNet: Messenger - Service 
SafeBootNet: NDIS Wrapper - Driver Group 
SafeBootNet: NetBIOSGroup - Driver Group 
SafeBootNet: NetDDEGroup - Driver Group 
SafeBootNet: Network - Driver Group 
SafeBootNet: NetworkProvider - Driver Group 
SafeBootNet: PCI Configuration - Driver Group 
SafeBootNet: PNP Filter - Driver Group 
SafeBootNet: PNP_TDI - Driver Group 
SafeBootNet: Primary disk - Driver Group 
SafeBootNet: rdsessmgr - Service 
SafeBootNet: sacsvr - Service 
SafeBootNet: SCSI Class - Driver Group 
SafeBootNet: Streams Drivers - Driver Group 
SafeBootNet: System Bus Extender - Driver Group 
SafeBootNet: TDI - Driver Group 
SafeBootNet: vmms - Service 
SafeBootNet: WudfUsbccidDriver - Driver 
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net 
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient 
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService 
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans 
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers 
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
  
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll 
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack 
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE 
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx 
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help 
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools 
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements 
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player 
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access 
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll 
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings 
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install 
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding 
ActiveX:64bit: {BCE2E75D-EE14-48F8-990E-AC87C57FFB84} - Bing Bar 
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts 
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help 
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface 
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework 
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework 
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP 
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig 
ActiveX:64bit: >{BB89BA8E-2153-4651-A4EC-E63ED120FA89} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) 
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework 
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll 
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack 
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE 
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx 
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help 
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools 
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements 
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player 
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access 
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings 
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install 
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding 
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts 
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help 
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface 
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework 
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP 
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig 
  
Drivers32:64bit: msacm.ac3filter - ac3filter64.acm () 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) 
Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm () 
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) 
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.) 
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.) 
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com) 
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com) 
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.) 
  
CREATERESTOREPOINT 
Restore point Set: OTL Restore Point 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2012.11.27 14:14:00 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Boje\Desktop\tdsskiller.exe 
[2012.11.27 14:05:39 | 004,732,416 | ---- | C] (AVAST Software) -- C:\Users\Boje\Desktop\aswMBR.exe 
[2012.11.27 11:42:31 | 000,132,864 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFW.sys 
[2012.11.27 11:41:49 | 000,262,656 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswNdis2.sys 
[2012.11.27 11:41:49 | 000,021,136 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswKbd.sys 
[2012.11.27 11:41:42 | 000,012,368 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswNdis.sys 
[2012.11.27 11:40:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security 
[2012.11.27 09:37:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 
[2012.11.27 09:36:53 | 000,000,000 | ---D | C] -- C:\Users\Boje\AppData\Local\Google 
[2012.11.27 09:36:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google 
[2012.11.27 09:36:49 | 000,370,288 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys 
[2012.11.27 09:36:49 | 000,025,232 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys 
[2012.11.27 09:36:43 | 000,059,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys 
[2012.11.27 09:36:43 | 000,054,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys 
[2012.11.27 09:36:42 | 000,984,144 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys 
[2012.11.27 09:36:39 | 000,285,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe 
[2012.11.27 09:36:39 | 000,071,600 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys 
[2012.11.27 09:36:03 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr 
[2012.11.27 09:36:01 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe 
[2012.11.27 09:35:49 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software 
[2012.11.27 09:35:49 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software 
[2012.11.27 08:16:45 | 000,000,000 | ---D | C] -- C:\Program Files\SyncToy 2.1 
[2012.11.27 08:15:58 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework 
[2012.11.26 23:03:43 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Boje\Desktop\OTL.exe 
[2012.11.26 22:44:06 | 000,000,000 | ---D | C] -- C:\Users\Boje\AppData\Roaming\Malwarebytes 
[2012.11.26 22:43:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware 
[2012.11.26 22:43:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes 
[2012.11.26 22:43:50 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys 
[2012.11.26 22:43:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware 
[2012.11.16 11:03:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox 
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] 
   ========== Files - Modified Within 30 Days ========== 
  
[2012.11.27 15:18:00 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
[2012.11.27 15:18:00 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
[2012.11.27 15:17:29 | 001,613,340 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI 
[2012.11.27 15:17:29 | 000,697,082 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat 
[2012.11.27 15:17:29 | 000,652,360 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat 
[2012.11.27 15:17:29 | 000,148,346 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat 
[2012.11.27 15:17:29 | 000,121,292 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat 
[2012.11.27 15:10:10 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job 
[2012.11.27 15:09:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat 
[2012.11.27 15:09:38 | 3153,727,488 | -HS- | M] () -- C:\hiberfil.sys 
[2012.11.27 14:48:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job 
[2012.11.27 14:23:02 | 000,480,125 | ---- | M] () -- C:\Users\Boje\Desktop\adwcleaner.exe 
[2012.11.27 14:23:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job 
[2012.11.27 14:14:02 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Boje\Desktop\tdsskiller.exe 
[2012.11.27 14:12:02 | 000,000,512 | ---- | M] () -- C:\Users\Boje\Desktop\MBR.dat 
[2012.11.27 14:06:13 | 004,732,416 | ---- | M] (AVAST Software) -- C:\Users\Boje\Desktop\aswMBR.exe 
[2012.11.27 11:41:48 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt 
[2012.11.27 11:40:00 | 000,001,960 | ---- | M] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk 
[2012.11.27 10:16:55 | 000,000,016 | -H-- | M] () -- C:\Users\Boje\Documents\SyncToy_29dc841f-4687-4f7b-a11e-b666db4c41ee.dat 
[2012.11.27 09:37:52 | 000,002,291 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk 
[2012.11.26 23:03:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Boje\Desktop\OTL.exe 
[2012.11.26 23:02:56 | 000,000,000 | ---- | M] () -- C:\Users\Boje\defogger_reenable 
[2012.11.26 22:47:59 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 
[2012.11.26 21:36:51 | 095,023,320 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad 
[2012.11.19 18:21:45 | 000,509,368 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT 
[2012.10.30 23:51:56 | 000,059,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys 
[2012.10.30 23:51:55 | 000,984,144 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys 
[2012.10.30 23:51:55 | 000,370,288 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys 
[2012.10.30 23:51:55 | 000,262,656 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswNdis2.sys 
[2012.10.30 23:51:55 | 000,071,600 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys 
[2012.10.30 23:51:55 | 000,021,136 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswKbd.sys 
[2012.10.30 23:51:53 | 000,132,864 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFW.sys 
[2012.10.30 23:51:53 | 000,025,232 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys 
[2012.10.30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr 
[2012.10.30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe 
[2012.10.30 23:50:30 | 000,285,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe 
[2012.10.30 21:30:05 | 000,002,008 | -H-- | M] () -- C:\Users\Boje\Documents\Default.rdp 
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] 
   ========== Files Created - No Company Name ========== 
  
[2012.11.27 14:22:57 | 000,480,125 | ---- | C] () -- C:\Users\Boje\Desktop\adwcleaner.exe 
[2012.11.27 14:12:02 | 000,000,512 | ---- | C] () -- C:\Users\Boje\Desktop\MBR.dat 
[2012.11.27 11:40:00 | 000,001,960 | ---- | C] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk 
[2012.11.27 10:16:55 | 000,000,016 | -H-- | C] () -- C:\Users\Boje\Documents\SyncToy_29dc841f-4687-4f7b-a11e-b666db4c41ee.dat 
[2012.11.27 09:37:52 | 000,002,291 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk 
[2012.11.27 09:37:03 | 000,001,106 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job 
[2012.11.27 09:37:02 | 000,001,102 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job 
[2012.11.27 09:36:39 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt 
[2012.11.27 08:16:45 | 000,002,585 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SyncToy 2.1(x64).lnk 
[2012.11.26 23:02:56 | 000,000,000 | ---- | C] () -- C:\Users\Boje\defogger_reenable 
[2012.11.26 22:47:21 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 
[2012.11.26 21:27:42 | 095,023,320 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad 
[2012.11.19 09:54:25 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 
[2012.11.19 09:43:45 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 
[2011.12.13 17:50:01 | 001,096,306 | ---- | C] () -- C:\Users\Boje\Wocheneinteilung_Wanne-Eickel_ab_11_12_2011_2946923.pdf.zip 
[2011.07.17 09:58:42 | 000,000,034 | ---- | C] () -- C:\Windows\cdplayer.ini 
[2011.07.11 11:46:32 | 000,007,256 | ---- | C] () -- C:\Windows\mgxoschk.ini 
[2011.07.11 09:43:53 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll 
[2011.06.21 08:52:16 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\cd.dat 
[2011.05.11 20:02:51 | 000,001,474 | ---- | C] () -- C:\Users\Boje\.recently-used.xbel 
[2011.04.09 18:18:52 | 000,000,000 | ---- | C] () -- C:\Users\Boje\AppData\Local\rx_image32.Cache 
[2011.03.29 19:23:21 | 000,006,656 | ---- | C] () -- C:\Users\Boje\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 
[2011.03.28 19:19:38 | 001,591,234 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI 
[2011.03.25 08:58:54 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll 
[2011.03.25 08:58:16 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin 
[2011.03.25 08:58:14 | 000,206,952 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin 
[2011.03.25 08:58:12 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin 
[2007.03.12 18:59:00 | 000,299,008 | ---- | C] () -- C:\Program Files\navigram_register.exe 
   ========== ZeroAccess Check ========== 
  
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 
  
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 
  
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Apartment 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Apartment 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Free 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] 
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Free 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Both 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] 
   ========== LOP Check ========== 
  
[2011.07.14 18:49:09 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Amazon 
[2011.04.09 12:22:12 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\com.warnerbros.DigitalCopyManager.449F66ACC381FDC604DC2AA255FEECEEBBBEE1E5.1 
[2011.12.21 21:56:13 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\DVDVideoSoft 
[2011.09.07 19:50:08 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\DVDVideoSoftIEHelpers 
[2011.05.30 16:45:39 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\GetRightToGo 
[2011.05.11 20:02:51 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\gtk-2.0 
[2012.02.13 22:11:28 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\MAGIX 
[2011.09.19 20:03:44 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\MusicBrainz 
[2011.05.16 15:57:11 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\RIFT 
[2011.07.20 16:44:32 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\SoftGrid Client 
[2011.03.31 15:44:56 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\The Creative Assembly 
[2011.05.03 20:15:13 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Thunderbird 
[2011.04.01 11:38:45 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\TP 
[2011.05.15 15:34:19 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\TS3Client 
[2012.04.01 14:16:40 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\WindSolutions 
[2011.03.29 19:27:26 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\WirelessManager 
[2011.03.29 19:27:25 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\WMCore 
   ========== Purity Check ========== 
  
  
   ========== Custom Scans ========== 
   < %SYSTEMDRIVE%\*. > 
[2011.04.09 18:32:40 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN 
[2011.03.25 07:08:02 | 000,000,000 | ---D | M] -- C:\apps 
[2011.03.28 18:41:37 | 000,000,000 | ---D | M] -- C:\dell 
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings 
[2011.03.28 17:32:01 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen 
[2011.03.25 08:59:22 | 000,000,000 | ---D | M] -- C:\Drivers 
[2011.03.25 06:32:57 | 000,000,000 | ---D | M] -- C:\Intel 
[2011.07.20 16:49:43 | 000,000,000 | RH-D | M] -- C:\MSOCache 
[2009.07.14 04:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs 
[2012.11.27 09:35:49 | 000,000,000 | R--D | M] -- C:\Program Files 
[2012.11.27 09:43:36 | 000,000,000 | R--D | M] -- C:\Program Files (x86) 
[2012.11.27 15:13:15 | 000,000,000 | -H-D | M] -- C:\ProgramData 
[2011.03.28 17:32:01 | 000,000,000 | -HSD | M] -- C:\Programme 
[2011.03.28 17:56:08 | 000,000,000 | -HSD | M] -- C:\System Recovery 
[2012.11.27 15:17:54 | 000,000,000 | -HSD | M] -- C:\System Volume Information 
[2011.11.03 20:33:06 | 000,000,000 | ---D | M] -- C:\Temp 
[2011.03.28 17:32:08 | 000,000,000 | R--D | M] -- C:\Users 
[2012.11.27 09:36:03 | 000,000,000 | ---D | M] -- C:\Windows 
   < %ALLUSERSPROFILE%\Application Data\*. > 
   < %ALLUSERSPROFILE%\Application Data\*.exe /s > 
   < %APPDATA%\*. > 
[2012.06.16 14:35:18 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Adobe 
[2011.07.14 18:49:09 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Amazon 
[2012.10.16 19:18:56 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Apple Computer 
[2012.04.03 14:00:11 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\ArcSoft 
[2011.04.09 12:22:12 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\com.warnerbros.DigitalCopyManager.449F66ACC381FDC604DC2AA255FEECEEBBBEE1E5.1 
[2012.05.16 21:07:09 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Corel 
[2011.03.28 17:54:16 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Creative 
[2011.03.28 19:36:03 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\CyberLink 
[2011.03.28 17:54:22 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Dell 
[2011.03.28 17:54:17 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Dell Touch Zone 
[2012.11.26 21:28:15 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\DivX 
[2011.12.21 21:56:13 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\DVDVideoSoft 
[2011.09.07 19:50:08 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\DVDVideoSoftIEHelpers 
[2011.05.30 16:45:39 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\GetRightToGo 
[2011.05.11 20:02:51 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\gtk-2.0 
[2011.03.28 17:53:51 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Identities 
[2011.05.06 16:34:06 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\InstallShield 
[2011.03.28 17:32:14 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Intel 
[2011.03.28 18:32:35 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Macromedia 
[2011.03.28 18:20:59 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Macrovision 
[2012.02.13 22:11:28 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\MAGIX 
[2012.11.26 22:44:06 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Malwarebytes 
[2009.07.14 19:18:18 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Media Center Programs 
[2012.07.11 15:24:20 | 000,000,000 | --SD | M] -- C:\Users\Boje\AppData\Roaming\Microsoft 
[2012.02.01 20:38:10 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Mozilla 
[2011.09.19 20:03:44 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\MusicBrainz 
[2011.03.31 12:21:07 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\NVIDIA 
[2011.05.16 15:57:11 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\RIFT 
[2011.04.09 18:18:51 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Roxio 
[2011.03.28 18:26:15 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Roxio Burn 
[2012.05.31 15:25:57 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Skype 
[2011.07.20 16:44:32 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\SoftGrid Client 
[2011.03.31 15:44:56 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\The Creative Assembly 
[2011.05.03 20:15:13 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\Thunderbird 
[2011.04.01 11:38:45 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\TP 
[2011.05.15 15:34:19 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\TS3Client 
[2012.04.01 14:16:40 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\WindSolutions 
[2011.03.29 19:27:26 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\WirelessManager 
[2011.03.29 19:27:25 | 000,000,000 | ---D | M] -- C:\Users\Boje\AppData\Roaming\WMCore 
   < %APPDATA%\*.exe /s > 
[2012.04.16 15:45:16 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Boje\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 
[2012.06.16 14:29:46 | 000,117,427 | ---- | M] (Adobe Systems, Inc.) -- C:\Users\Boje\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\digitaleditions\digitaleditions.exe 
   < %SYSTEMROOT%\system32\drivers\*.sys /lockedfiles > 
   < %SYSTEMROOT%\System32\config\*.sav > 
   < %SYSTEMROOT%\*. /mp /s > 
   < %SYSTEMROOT%\system32\*.dll /lockedfiles > 
   <           > 
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT 
[2009.07.14 06:08:49 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT 
[2012.03.31 18:17:31 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job 
[2012.11.27 09:37:02 | 000,001,102 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 
[2012.11.27 09:37:03 | 000,001,106 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job   
< End of report >      |