Armina01 | 19.04.2013 23:22 | Code:
SystemLook 30.07.11 by jpshortstuff
Log created at 23:58 on 19/04/2013 by Armin01
Administrator - Elevation successful
No Context: Code:
========== filefind ==========
Searching for "*lyrics*"
C:\Old_C\Programme\iTunes\iTunes.Resources\ca.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\cs.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\da.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\de.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\el.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\en.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\en_GB.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\es.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\fi.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\fr.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\hr.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\hu.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\it.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\ja.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\ko.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\nb.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\nl.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\pl.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\pt.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\pt_PT.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\ro.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\ru.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\sk.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\sv.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\th.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\tr.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\uk.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\zh_CN.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Old_C\Programme\iTunes\iTunes.Resources\zh_TW.lproj\CleanLyrics.png --a---- 4039 bytes [12:16 20/02/2013] [12:16 20/02/2013] 357922D796C4AB56ACB274EC1C89ED4B
C:\Program Files\AutoLyrics\AutoLyricsUpdater.exe --a---- 115200 bytes [23:13 27/02/2013] [23:13 27/02/2013] 84DC08F59CDE010D15D893F5B8598764
C:\Program Files\ChessBase\Ludwig3\Ribbons\Large\CopyLyrics32.png --a---- 727 bytes [10:09 03/02/2011] [10:09 03/02/2011] EB29BCB16929A707147AA6BFFAB2AA91
C:\Program Files\ChessBase\Ludwig3\Ribbons\Large\Lyrics32.png --a---- 525 bytes [10:09 03/02/2011] [10:09 03/02/2011] 087CA4632938A7634B8C6A54C2EBE239
C:\Program Files\ChessBase\Ludwig3\Ribbons\Large\PasteLyrics32.png --a---- 1601 bytes [10:09 03/02/2011] [10:09 03/02/2011] A8B5F7620859E554F53E0888F1F977A0
C:\Program Files\ChessBase\Ludwig3\Ribbons\Large\ResetLyrics32.png --a---- 1632 bytes [10:09 03/02/2011] [10:09 03/02/2011] 9A04252E42914A8CACDAB7DE94151045
C:\Program Files\ChessBase\Ludwig3\Ribbons\Small\CopyLyrics16.png --a---- 600 bytes [10:15 03/02/2011] [10:15 03/02/2011] 6302F9208E05AD5391BAE7662DBAF493
C:\Program Files\ChessBase\Ludwig3\Ribbons\Small\Lyrics16.png --a---- 397 bytes [10:14 03/02/2011] [10:14 03/02/2011] CD26F24A80FA606A7CDF406EF28E1F17
C:\Program Files\ChessBase\Ludwig3\Ribbons\Small\PasteLyrics16.png --a---- 742 bytes [10:14 03/02/2011] [10:14 03/02/2011] D032F1FBD54E7254D17E71B2F2FC4594
C:\Program Files\ChessBase\Ludwig3\Ribbons\Small\ResetLyrics16.png --a---- 786 bytes [10:14 03/02/2011] [10:14 03/02/2011] 9B23D7F9FA9CC135A240D7AD33E11C28
C:\Users\Armin01\Music\MusicBee\MusicBeeLibrary.lyrics --a---- 4096000 bytes [14:12 08/05/2011] [14:13 08/05/2011] 64000993DDC9D6D7B47C71810E7D8321
C:\Windows\System32\Tasks\Auto Lyrics Update --a---- 3032 bytes [11:39 07/04/2013] [11:39 07/04/2013] 2327888B133E82B6A48FAF323719C431
C:\Windows\Tasks\Auto Lyrics Update.job --a---- 380 bytes [11:39 07/04/2013] [20:32 19/04/2013] 6D52C0B50CB5E0BA5259BD08DF6B6121
========== folderfind ==========
Searching for "*lyrics*"
C:\Program Files\AutoLyrics dr----- [11:39 07/04/2013]
========== regfind ==========
Searching for "lyrics"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\AutoLyrics]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\autolyrics@man-soft.net]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\hitlistlyrics.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\lyrics-finden.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\nellyslyrics.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\hitlistlyrics.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\lyrics-finden.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\nellyslyrics.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers]
"C:\Program Files\AutoLyrics\AutoLyricsUpdater.exe"="RunAsAdmin"
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"autolyrics@man-soft.net"="C:\Program Files\AutoLyrics\FF\"
[HKEY_CURRENT_USER\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers]
"C:\Program Files\AutoLyrics\AutoLyricsUpdater.exe"="RunAsAdmin"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{995C1CF5-54FF-11D3-8BDA-00600893B1B6}]
@="DirectMusicLyricsTrack"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{995C1CF5-54FF-11D3-8BDA-00600893B1B6}\ProgID]
@="Microsoft.DirectMusicLyricsTrack.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{995C1CF5-54FF-11D3-8BDA-00600893B1B6}\VersionIndependentProgID]
@="Microsoft.DirectMusicLyricsTrack"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAEB9E85-4694-4F9B-85CB-2F28987872D7}]
@="Auto Lyrics"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAEB9E85-4694-4F9B-85CB-2F28987872D7}\InprocServer32]
@="C:\Program Files\AutoLyrics\autolrcs.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicLyricsTrack]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicLyricsTrack]
@="DirectMusicLyricsTrack"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicLyricsTrack\CurVer]
@="Microsoft.DirectMusicLyricsTrack.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicLyricsTrack.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicLyricsTrack.1]
@="DirectMusicLyricsTrack"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{17F475E0-3D3C-4E09-9CCC-0B8CFFBB7A09}\1.0\0\win32]
@="C:\Program Files\AutoLyrics\autolrcs.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{17F475E0-3D3C-4E09-9CCC-0B8CFFBB7A09}\1.0\HELPDIR]
@="C:\Program Files\AutoLyrics"
[HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\pkcdkfohdadbjmlfejhncigcbfkiaamf]
"Path"="C:\Program Files\AutoLyrics\Chrome.crx"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{DAEB9E85-4694-4F9B-85CB-2F28987872D7}]
@="Auto Lyrics"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1684BD8280271AA4EBCF2BF3F5F3F588]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\cs.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1B337650BD75A8447ACA255EC00921BB]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\pt_PT.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D12D3E35CC76E54194B1892CF7872E3]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\nl.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2AF1D4904A1595B44AB24E1233B6DE48]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\it.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34D573917B74C3C4A93DC9156D09FFE1]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\fi.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\38557E31BCD092A47805A5A4AAFB7134]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\en_GB.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\593B4DCF3E67DF34F9CCC0464D5CD37D]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\sk.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5E2FF340BB1A92B43A2FF31BC7C5452E]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\fr.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E2A14135B4C5D4499B84D456690129]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\hu.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76AFFAA8C1E4D5B44ACB1BFE883C6457]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\es.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\78757AF88C1266A4B955A79077BD332C]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\zh_CN.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\78AF7F024EB2DF443A0DD854AB03E8BD]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\de.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E3A4277FC5E48741B528BE1F26259B8]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\uk.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\85F5EB82BE91E584E8672A3B6B8D7941]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\sv.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88BE25F3D489F2E44BC02B254D27345C]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\zh_TW.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CD17B7D79A83744D8D7FEF63342E933]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\el.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\90F21C90C8B465A458EB634F638E6FB8]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\ko.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9B88E86CC0D89BB488C7FA77DA5D0DF7]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\th.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9BEC3D9652229D44E8F898DD60656451]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\ja.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5DCACB78037A3B46A15FD0D4439FAAC]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\tr.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC84AD6CB744DF44DA19392B9FCA8AE9]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\ca.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B8AC4450797418A489B2526AD4DD720A]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\pt.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA2C88F35DC4C8A4F9068A27AB3A7E3B]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\en.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C0F00CBE7562F3E4688ABAD227116C10]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\ro.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C35F6754F418A1C40A31724D57558614]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\ru.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEBC2437C536C02409FB5DA1C8BEC090]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\hr.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DAA49214FA0598C43A5149E18AF9C137]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\nb.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F296671CA5854D642A485B82AAD2DF9A]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\da.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFE308594FA40184E89695DDD7F31219]
"FC87286296BF89D47BE0FBCEC1CD2A52"="C:\Old_C\Programme\iTunes\iTunes.Resources\pl.lproj\CleanLyrics.png"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\hitlistlyrics.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\lyrics-finden.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\nellyslyrics.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\hitlistlyrics.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\lyrics-finden.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\nellyslyrics.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\autolyrics@man-soft.net]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\autolyrics@man-soft.net]
"DisplayName"="Auto Lyrics"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\autolyrics@man-soft.net]
"UninstallString"="C:\Program Files\AutoLyrics\uninstall.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ACD6F502-8D96-45AD-B661-9748BBC915FB}]
"Path"="\Auto Lyrics Update"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Auto Lyrics Update]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pkcdkfohdadbjmlfejhncigcbfkiaamf]
"Path"="C:\Program Files\AutoLyrics\Chrome.crx"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\hitlistlyrics.com]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\lyrics-finden.com]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\nellyslyrics.com]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\hitlistlyrics.com]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\lyrics-finden.com]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\nellyslyrics.com]
[HKEY_USERS\S-1-5-21-306692126-4049508593-1777269419-1000\Software\AppDataLow\Software\AutoLyrics]
[HKEY_USERS\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\autolyrics@man-soft.net]
[HKEY_USERS\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\hitlistlyrics.com]
[HKEY_USERS\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\lyrics-finden.com]
[HKEY_USERS\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\nellyslyrics.com]
[HKEY_USERS\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\hitlistlyrics.com]
[HKEY_USERS\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\lyrics-finden.com]
[HKEY_USERS\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\nellyslyrics.com]
[HKEY_USERS\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers]
"C:\Program Files\AutoLyrics\AutoLyricsUpdater.exe"="RunAsAdmin"
[HKEY_USERS\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Mozilla\Firefox\Extensions]
"autolyrics@man-soft.net"="C:\Program Files\AutoLyrics\FF\"
[HKEY_USERS\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers]
"C:\Program Files\AutoLyrics\AutoLyricsUpdater.exe"="RunAsAdmin"
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\hitlistlyrics.com]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\lyrics-finden.com]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\nellyslyrics.com]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\hitlistlyrics.com]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\lyrics-finden.com]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\nellyslyrics.com]
-= EOF =- Code:
# AdwCleaner v2.112 - Datei am 20/04/2013 um 00:05:32 erstellt
# Aktualisiert am 10/02/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : Armin01 - ARMIN01-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Armin01\AppData\Local\Temp\OCS\Downloads\705f49176579a643660bff5ff6ae3956\ee8e33e956b0dc98c57df72e892819c6\adwcleaner_2.112.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
***** [Registrierungsdatenbank] *****
***** [Internet Browser] *****
-\\ Internet Explorer v9.0.8112.16476
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v20.0.1 (en-US)
Datei : C:\Users\Armin01\AppData\Roaming\Mozilla\Firefox\Profiles\c9lop5zk.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\Gina01\AppData\Roaming\Mozilla\Firefox\Profiles\e03fy42t.default\prefs.js
[OK] Die Datei ist sauber.
-\\ Google Chrome v26.0.1410.64
Datei : C:\Users\Armin01\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
*************************
AdwCleaner[R1].txt - [10192 octets] - [10/04/2013 23:55:22]
AdwCleaner[R2].txt - [1414 octets] - [11/04/2013 00:16:13]
AdwCleaner[R3].txt - [1534 octets] - [11/04/2013 13:15:39]
AdwCleaner[R4].txt - [1606 octets] - [19/04/2013 16:40:05]
AdwCleaner[S1].txt - [10356 octets] - [10/04/2013 23:56:56]
AdwCleaner[S2].txt - [1476 octets] - [11/04/2013 00:16:49]
AdwCleaner[S3].txt - [1596 octets] - [11/04/2013 13:16:21]
AdwCleaner[S4].txt - [1668 octets] - [19/04/2013 16:42:06]
AdwCleaner[S5].txt - [1728 octets] - [19/04/2013 16:49:25]
AdwCleaner[S6].txt - [1659 octets] - [20/04/2013 00:05:32]
########## EOF - C:\AdwCleaner[S6].txt - [1719 octets] ########## Code:
OTL logfile created on: 20.04.2013 00:11:59 - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Armin01\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 0,97 Gb Available Physical Memory | 48,71% Memory free
4,23 Gb Paging File | 3,10 Gb Available in Paging File | 73,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 303,84 Gb Total Space | 3,56 Gb Free Space | 1,17% Space Free | Partition Type: NTFS
Drive D: | 149,91 Gb Total Space | 142,06 Gb Free Space | 94,77% Space Free | Partition Type: NTFS
Drive F: | 589,80 Gb Total Space | 17,79 Gb Free Space | 3,02% Space Free | Partition Type: NTFS
Drive G: | 589,63 Gb Total Space | 524,91 Gb Free Space | 89,02% Space Free | Partition Type: NTFS
Drive H: | 683,59 Gb Total Space | 655,38 Gb Free Space | 95,87% Space Free | Partition Type: NTFS
Computer Name: ARMIN01-PC | User Name: Armin01 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.04.19 22:52:38 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Armin01\Desktop\OTL.exe
PRC - [2013.04.19 17:31:27 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\Programme\Real\RealPlayer\Update\realsched.exe
PRC - [2013.03.06 02:21:50 | 000,039,056 | ---- | M] () -- C:\Programme\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2012.12.21 12:00:52 | 000,031,744 | ---- | M] () -- C:\Programme\SoftwareUpdater\UpdaterService.exe
PRC - [2012.12.14 06:33:18 | 000,024,064 | ---- | M] () -- C:\Programme\OpenVPN Technologies\PrivateTunnel\core\capiws.exe
PRC - [2012.11.27 22:12:44 | 000,479,840 | ---- | M] (Sony Corporation) -- C:\Programme\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
PRC - [2012.11.27 22:08:28 | 000,739,936 | ---- | M] (Sony Corporation) -- C:\Programme\Sony\PlayMemories Home\PMBVolumeWatcher.exe
PRC - [2012.08.08 19:16:16 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.04.24 02:11:55 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.03.23 14:25:24 | 000,087,040 | ---- | M] () -- C:\Programme\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2010.09.13 15:56:02 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmplayer.exe
PRC - [2010.09.03 22:04:00 | 000,664,896 | ---- | M] () -- C:\Programme\Motorola\MotoHelper\MotoHelperAgent.exe
PRC - [2010.09.03 18:54:40 | 000,202,048 | ---- | M] () -- C:\Programme\Motorola\MotoHelper\MotoHelperService.exe
PRC - [2010.08.02 16:09:30 | 000,328,192 | ---- | M] (Dawicontrol GmbH) -- C:\Programme\Dawicontrol GmbH\Dawicontrol RAID Monitor\RAIDservice.exe
PRC - [2010.05.27 05:40:30 | 000,087,336 | ---- | M] (Nero AG) -- C:\Programme\Motorola Media Link\NServiceEntry.exe
PRC - [2010.02.03 06:17:28 | 000,372,736 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2010.02.03 06:16:58 | 000,172,032 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2009.10.17 17:21:26 | 000,878,592 | ---- | M] (Speed-Soft) -- C:\Programme\Time-Sync\TimeSyncServiceClient.exe
PRC - [2009.08.18 12:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009.08.18 12:29:22 | 000,183,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009.06.15 13:29:54 | 000,906,968 | ---- | M] (Acronis) -- C:\Programme\Acronis\TrueImageHome\TimounterMonitor.exe
PRC - [2009.06.15 13:27:16 | 001,352,584 | ---- | M] (Acronis) -- C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe
PRC - [2009.06.15 11:55:18 | 000,136,472 | ---- | M] (Acronis) -- C:\Programme\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2009.06.15 11:55:14 | 000,431,384 | ---- | M] (Acronis) -- C:\Programme\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008.01.29 17:38:32 | 000,583,048 | ---- | M] (Symantec Corporation) -- C:\Programme\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2008.01.19 00:38:40 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Defender\MSASCui.exe
PRC - [2008.01.19 00:33:40 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2008.01.19 00:33:40 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
PRC - [2007.10.01 11:53:50 | 004,702,208 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007.07.25 16:30:40 | 001,728,512 | ---- | M] () -- C:\Programme\Silicon Image\57xx SteelVine\SteelVineManager.exe
PRC - [2007.07.25 16:28:04 | 001,282,048 | ---- | M] () -- C:\Programme\Silicon Image\57xx SteelVine\SteelVine.exe
PRC - [2007.06.04 16:20:38 | 000,065,536 | ---- | M] () -- c:\Programme\Fujitsu Siemens Computers\FSCLounge\FSCWBaseUpdaterService\2\FSCWBaseUpdaterService.exe
PRC - [2007.05.03 10:43:06 | 002,759,872 | ---- | M] (Software602) -- C:\Programme\Software602\Print2PDF\PrnPack.exe
PRC - [2006.12.08 11:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe
========== Modules (No Company Name) ==========
MOD - [2013.02.13 04:43:20 | 011,820,544 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\421cb77e6a4c21f94e3c5ddf766de23b\System.Web.ni.dll
MOD - [2013.02.13 04:40:15 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e64304962098e90f0d3f4c33c1b080a6\System.Windows.Forms.ni.dll
MOD - [2013.01.10 04:34:38 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b5df40c22ab563a816103629e2ca99d4\System.Runtime.Remoting.ni.dll
MOD - [2013.01.10 04:34:19 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\004bc6615f9c06df5c98859d35149fe6\System.Configuration.ni.dll
MOD - [2013.01.10 04:34:15 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll
MOD - [2013.01.10 04:33:52 | 001,593,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\78157a494dc9a7e52be8840decfcd9cc\System.Drawing.ni.dll
MOD - [2013.01.10 04:33:00 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll
MOD - [2013.01.10 04:32:51 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll
MOD - [2011.06.24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.09.03 22:04:00 | 000,664,896 | ---- | M] () -- C:\Programme\Motorola\MotoHelper\MotoHelperAgent.exe
MOD - [2010.03.22 22:14:37 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HydraVision.Wizard\2.0.3685.42407__90ba9c70f846762e\CLI.Aspect.HydraVision.Wizard.dll
MOD - [2010.03.22 22:14:37 | 000,241,664 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MultiDesk.HydraVision.Dashboard\2.0.3685.42406__90ba9c70f846762e\CLI.Aspect.MultiDesk.HydraVision.Dashboard.dll
MOD - [2010.03.22 22:14:37 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MDProp.HydraVision.Dashboard\2.0.3685.42404__90ba9c70f846762e\CLI.Aspect.MDProp.HydraVision.Dashboard.dll
MOD - [2010.03.22 22:14:37 | 000,163,840 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeskMan.HydraVision.Dashboard\2.0.3685.42403__90ba9c70f846762e\CLI.Aspect.DeskMan.HydraVision.Dashboard.dll
MOD - [2010.03.22 22:14:37 | 000,147,456 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Grid.HydraVision.Dashboard\2.0.3685.42397__90ba9c70f846762e\CLI.Aspect.Grid.HydraVision.Dashboard.dll
MOD - [2010.03.22 22:14:37 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Grid.HydraVision.Runtime\2.0.3685.42397__90ba9c70f846762e\CLI.Aspect.Grid.HydraVision.Runtime.dll
MOD - [2010.03.22 22:14:37 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeskMan.HydraVision.Runtime\2.0.3685.42403__90ba9c70f846762e\CLI.Aspect.DeskMan.HydraVision.Runtime.dll
MOD - [2010.03.22 22:14:37 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MultiDesk.HydraVision.Runtime\2.0.3685.42405__90ba9c70f846762e\CLI.Aspect.MultiDesk.HydraVision.Runtime.dll
MOD - [2010.03.22 22:14:37 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MDProp.HydraVision.Runtime\2.0.3685.42404__90ba9c70f846762e\CLI.Aspect.MDProp.HydraVision.Runtime.dll
MOD - [2010.03.22 22:14:37 | 000,012,800 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeskMan.HydraVision.Shared\2.0.3685.42402__90ba9c70f846762e\CLI.Aspect.DeskMan.HydraVision.Shared.dll
MOD - [2010.03.22 22:14:37 | 000,010,240 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MDProp.HydraVision.Shared\2.0.3685.42403__90ba9c70f846762e\CLI.Aspect.MDProp.HydraVision.Shared.dll
MOD - [2010.03.22 22:14:37 | 000,010,240 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Grid.HydraVision.Shared\2.0.3685.42396__90ba9c70f846762e\CLI.Aspect.Grid.HydraVision.Shared.dll
MOD - [2010.03.22 22:14:37 | 000,009,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MultiDesk.HydraVision.Shared\2.0.3685.42405__90ba9c70f846762e\CLI.Aspect.MultiDesk.HydraVision.Shared.dll
MOD - [2010.03.22 22:14:36 | 001,708,032 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager2.Graphics.Wizard\2.0.3685.42422__90ba9c70f846762e\CLI.Aspect.DisplaysManager2.Graphics.Wizard.dll
MOD - [2010.03.22 22:14:36 | 000,380,928 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3685.42249__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:36 | 000,204,800 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3685.42279__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2010.03.22 22:14:36 | 000,077,824 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3685.42353__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:36 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3685.42310__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:36 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3685.42271__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2010.03.22 22:14:36 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3685.42263__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:36 | 000,011,776 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.HydraVision.Runtime\2.0.3685.42396__90ba9c70f846762e\CLI.Caste.HydraVision.Runtime.dll
MOD - [2010.03.22 22:14:36 | 000,008,704 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.HydraVision.Shared\2.0.3685.42395__90ba9c70f846762e\CLI.Caste.HydraVision.Shared.dll
MOD - [2010.03.22 22:14:36 | 000,007,680 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.HydraVision.Wizard\2.0.3685.42400__90ba9c70f846762e\CLI.Caste.HydraVision.Wizard.dll
MOD - [2010.03.22 22:14:36 | 000,007,680 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.HydraVision.Dashboard\2.0.3685.42396__90ba9c70f846762e\CLI.Caste.HydraVision.Dashboard.dll
MOD - [2010.03.22 22:14:35 | 000,491,520 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3685.42379__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2010.03.22 22:14:35 | 000,356,352 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3685.42331__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:35 | 000,094,208 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3685.42332__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2010.03.22 22:14:35 | 000,073,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3685.42261__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:35 | 000,065,536 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3685.42380__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:35 | 000,065,536 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3685.42330__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:35 | 000,065,536 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3685.42324__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:35 | 000,013,312 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Runtime\2.0.3685.42422__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:32 | 000,651,264 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Dashboard\2.0.3685.42394__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:32 | 000,077,824 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Runtime\2.0.3685.42394__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:31 | 001,302,528 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager2.Graphics.Dashboard\2.0.3685.42418__90ba9c70f846762e\CLI.Aspect.DisplaysManager2.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:31 | 000,827,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3685.42313__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:31 | 000,573,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3685.42280__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:31 | 000,409,600 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3685.42344__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2010.03.22 22:14:31 | 000,397,312 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3685.42311__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:31 | 000,372,736 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3685.42305__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:31 | 000,270,336 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:31 | 000,196,608 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3685.42279__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:31 | 000,098,304 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3685.42312__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:31 | 000,094,208 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3685.42320__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2010.03.22 22:14:31 | 000,065,536 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3685.42310__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:31 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3685.42312__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:31 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3685.42319__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:31 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3685.42284__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:31 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3685.42321__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2010.03.22 22:14:31 | 000,008,192 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3685.42241__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2010.03.22 22:14:31 | 000,007,168 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3685.42236__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2010.03.22 22:14:31 | 000,006,144 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3685.42244__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll
MOD - [2010.03.22 22:14:31 | 000,005,632 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3685.42244__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2010.03.22 22:14:30 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2010.03.22 22:14:30 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3685.42235__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2010.03.22 22:14:30 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0703\2.0.2651.18802__90ba9c70f846762e\DEM.Graphics.I0703.dll
MOD - [2010.03.22 22:14:30 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll
MOD - [2010.03.22 22:14:30 | 000,015,360 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3685.42236__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2010.03.22 22:14:30 | 000,007,168 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2010.03.22 22:14:30 | 000,006,656 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3685.42247__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2010.03.22 22:14:30 | 000,006,656 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3685.42377__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2010.03.22 22:14:30 | 000,005,632 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3685.42240__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2010.03.22 22:14:30 | 000,005,632 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3685.42387__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll
MOD - [2010.03.22 22:14:30 | 000,005,632 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3685.42248__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2010.03.22 22:14:29 | 000,151,552 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3685.42239__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2010.03.22 22:14:29 | 000,098,304 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3685.42237__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2010.03.22 22:14:29 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Shared\2.0.3685.42393__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Shared.dll
MOD - [2010.03.22 22:14:29 | 000,057,344 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3685.42330__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2010.03.22 22:14:29 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3685.42378__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2010.03.22 22:14:29 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3685.42371__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2010.03.22 22:14:29 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3685.42238__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2010.03.22 22:14:29 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3685.42238__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2010.03.22 22:14:29 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2010.03.22 22:14:29 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3685.42270__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2010.03.22 22:14:29 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3685.42261__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2010.03.22 22:14:29 | 000,009,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Shared\2.0.3685.42379__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Shared.dll
MOD - [2010.03.22 22:14:29 | 000,007,680 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3685.42238__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2010.03.22 22:14:29 | 000,005,632 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3685.42243__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,741,376 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Implementation\2.0.3685.42415__90ba9c70f846762e\ResourceManagement.Foundation.Implementation.dll
MOD - [2010.03.22 22:14:28 | 000,065,536 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3685.42352__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3685.42300__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3685.42276__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3685.42310__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3685.42261__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3685.42387__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2010.03.22 22:14:28 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3685.42323__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3685.42262__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3685.42262__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3685.42275__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3685.42319__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3685.42248__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2010.03.22 22:14:28 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.3685.42237__90ba9c70f846762e\APM.Foundation.dll
MOD - [2010.03.22 22:14:28 | 000,007,168 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3685.42245__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
MOD - [2010.03.22 22:14:28 | 000,006,144 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3685.42243__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2010.03.22 22:14:27 | 000,577,536 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3685.42364__90ba9c70f846762e\CLI.Component.Systemtray.dll
MOD - [2010.03.22 22:14:27 | 000,405,504 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3685.42270__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2010.03.22 22:14:27 | 000,106,496 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3685.42372__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2010.03.22 22:14:27 | 000,065,536 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3685.42369__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2010.03.22 22:14:27 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3685.42246__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2010.03.22 22:14:27 | 000,057,344 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3685.42247__90ba9c70f846762e\CLI.Component.SkinFactory.dll
MOD - [2010.03.22 22:14:27 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3685.42245__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2010.03.22 22:14:27 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3685.42241__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2010.03.22 22:14:27 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3685.42239__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2010.03.22 22:14:27 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3685.42240__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2010.03.22 22:14:27 | 000,011,776 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3685.42269__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2010.03.22 22:14:27 | 000,007,168 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3685.42246__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll
MOD - [2010.03.22 22:14:26 | 001,220,608 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3685.42256__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2010.03.22 22:14:26 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3685.42254__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2010.03.22 22:14:26 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2010.03.22 22:14:26 | 000,019,456 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3685.42371__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2010.03.22 22:14:26 | 000,010,240 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3685.42255__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2010.03.22 22:14:26 | 000,008,704 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3685.42277__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2010.03.22 22:14:25 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\APM.Server\2.0.3685.42242__90ba9c70f846762e\APM.Server.dll
MOD - [2010.03.22 22:14:25 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.3685.42244__90ba9c70f846762e\AEM.Server.dll
MOD - [2010.03.15 12:28:22 | 000,141,824 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2010.02.03 05:22:36 | 000,023,040 | ---- | M] () -- C:\Windows\System32\atitmpxx.dll
MOD - [2009.11.24 14:36:36 | 000,016,384 | R--- | M] () -- C:\Programme\ATI Technologies\ATI.ACE\Branding\Branding.dll
MOD - [2009.06.15 13:09:54 | 001,336,600 | ---- | M] () -- C:\Programme\Acronis\TrueImageHome\fox.dll
MOD - [2009.03.30 06:42:11 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2007.07.25 16:30:40 | 001,728,512 | ---- | M] () -- C:\Programme\Silicon Image\57xx SteelVine\SteelVineManager.exe
MOD - [2007.03.01 15:48:24 | 000,475,136 | ---- | M] () -- C:\Programme\Common Files\BCL Technologies\easyPDF 5\bepprint.dll
MOD - [2006.09.08 14:44:38 | 002,224,128 | ---- | M] () -- C:\Programme\Silicon Image\57xx SteelVine\Qt3Support4.dll
MOD - [2006.09.08 14:41:30 | 000,249,856 | ---- | M] () -- C:\Programme\Silicon Image\57xx SteelVine\QtNetwork4.dll
MOD - [2006.09.08 14:41:10 | 000,409,600 | ---- | M] () -- C:\Programme\Silicon Image\57xx SteelVine\QtSql4.dll
MOD - [2006.09.08 14:40:54 | 003,969,024 | ---- | M] () -- C:\Programme\Silicon Image\57xx SteelVine\QtGui4.dll
MOD - [2006.09.08 14:32:58 | 000,204,800 | ---- | M] () -- C:\Programme\Silicon Image\57xx SteelVine\QtXml4.dll
MOD - [2006.09.08 14:32:50 | 001,720,320 | ---- | M] () -- C:\Programme\Silicon Image\57xx SteelVine\QtCore4.dll
MOD - [2005.01.26 13:37:30 | 000,061,440 | ---- | M] () -- C:\Programme\Common Files\soft602\W5_STRSN.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService)
SRV - [2013.04.19 17:32:29 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.04.12 08:19:51 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013.03.06 02:21:50 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Programme\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2012.12.21 12:00:52 | 000,031,744 | ---- | M] () [Auto | Running] -- C:\Programme\SoftwareUpdater\UpdaterService.exe -- (SrvUpdater)
SRV - [2012.12.14 06:33:18 | 000,024,064 | ---- | M] () [Auto | Running] -- C:\Programme\OpenVPN Technologies\PrivateTunnel\core\capiws.exe -- (OpenVPNAccessClient)
SRV - [2012.11.27 22:12:44 | 000,479,840 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2012.09.20 14:28:48 | 030,785,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.03.23 14:25:24 | 000,087,040 | ---- | M] () [Auto | Running] -- C:\Programme\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2010.09.03 18:54:40 | 000,202,048 | ---- | M] () [Auto | Running] -- C:\Programme\Motorola\MotoHelper\MotoHelperService.exe -- (MotoHelper)
SRV - [2010.08.02 16:09:30 | 000,328,192 | ---- | M] (Dawicontrol GmbH) [Auto | Running] -- C:\Programme\Dawicontrol GmbH\Dawicontrol RAID Monitor\RAIDservice.exe -- (DcRaidMoSrv)
SRV - [2010.05.27 05:40:30 | 000,087,336 | ---- | M] (Nero AG) [Auto | Running] -- C:\Programme\Motorola Media Link\NServiceEntry.exe -- (DeviceMonitorService)
SRV - [2010.02.03 06:16:58 | 000,172,032 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2010.01.09 22:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.09 22:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
SRV - [2009.10.17 17:21:26 | 000,878,592 | ---- | M] (Speed-Soft) [Auto | Running] -- C:\Programme\Time-Sync\TimeSyncServiceClient.exe -- (ServiceTimeSyncClient)
SRV - [2009.08.18 12:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009.06.15 11:55:14 | 000,431,384 | ---- | M] (Acronis) [Auto | Running] -- C:\Programme\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2008.01.29 17:38:32 | 000,583,048 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe -- (LiveUpdate Notice Service)
SRV - [2008.01.19 00:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.01.19 00:33:40 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2007.07.25 16:28:04 | 001,282,048 | ---- | M] () [Auto | Running] -- C:\Programme\Silicon Image\57xx SteelVine\SteelVine.exe -- (57xx SteelVine Manager)
SRV - [2007.06.04 16:20:38 | 000,065,536 | ---- | M] () [Auto | Running] -- c:\Programme\Fujitsu Siemens Computers\FSCLounge\FSCWBaseUpdaterService\2\FSCWBaseUpdaterService.exe -- (FSCLBaseUpdaterService)
SRV - [2007.03.01 15:50:36 | 000,151,552 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Common Files\BCL Technologies\easyPDF 5\bepldr.exe -- (bepldr)
SRV - [2006.12.08 11:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\usbVM31b.sys -- (ZSMC301b)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\motusbdevice.sys -- (motusbdevice)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Motousbnet.sys -- (Motousbnet)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\motccgp.sys -- (motccgp)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Armin01\AppData\Local\Temp\cpuz130\cpuz_x32.sys -- (cpuz130)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.07.15 11:48:16 | 000,026,112 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tapoas.sys -- (tapoas)
DRV - [2012.04.27 10:20:04 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.04.25 00:32:27 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.04.16 21:17:40 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011.03.18 18:08:54 | 000,025,240 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\Windows\System32\speedfan.sys -- (speedfan)
DRV - [2010.06.23 11:23:44 | 000,023,040 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\htcnprot.sys -- (htcnprot)
DRV - [2010.06.23 10:21:32 | 000,259,176 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2010.06.18 15:09:48 | 000,023,936 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motmodem.sys -- (motmodem)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.02.03 06:54:34 | 005,313,536 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2010.02.03 06:54:34 | 005,313,536 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atipmdag.sys -- (amdkmdag)
DRV - [2010.02.03 05:23:42 | 000,150,016 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2010.01.28 16:33:28 | 000,097,792 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2009.11.15 14:20:32 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\Windows\System32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2009.11.15 14:20:31 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\timntr.sys -- (timounter)
DRV - [2009.11.15 14:20:21 | 000,132,480 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\snapman.sys -- (snapman)
DRV - [2009.11.15 14:20:15 | 000,368,480 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\tdrpman.sys -- (tdrpman)
DRV - [2009.06.10 01:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2009.01.29 17:18:00 | 000,008,320 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motccgpfl.sys -- (motccgpfl)
DRV - [2009.01.29 17:11:20 | 000,006,016 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motfilt.sys -- (BTCFilterService)
DRV - [2008.11.07 07:12:00 | 000,064,480 | ---- | M] (Juniper Networks) [Kernel | System | Running] -- C:\Windows\System32\drivers\NEOFLTR_620_13687.sys -- (NEOFLTR_620_13687)
DRV - [2008.01.18 23:15:00 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2007.11.02 15:51:30 | 000,006,400 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motswch.sys -- (MotoSwitchService)
DRV - [2007.09.04 23:41:04 | 000,039,408 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Programme\CyberLink\PowerDVD\000.fcl -- ({95808DC4-FA4A-4C74-92FE-5B863F82066B})
DRV - [2007.07.02 17:37:10 | 000,131,616 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvrd32.sys -- (nvrd32)
DRV - [2007.07.02 17:37:08 | 000,110,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32)
DRV - [2007.06.13 23:47:12 | 000,048,256 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\jraid.sys -- (JRAID)
DRV - [2007.01.23 14:36:46 | 000,299,776 | ---- | M] (Hauppauge Computer Works, Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hcw88tse.sys -- (HCW88TSE)
DRV - [2007.01.23 14:25:30 | 000,207,872 | ---- | M] (Hauppauge Computer Works, Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hcw88bda.sys -- (HCW88BDA)
DRV - [2007.01.23 14:25:14 | 000,011,904 | ---- | M] (Hauppauge Computer Works, Inc) [Kernel | System | Running] -- C:\Windows\System32\drivers\hcw88aud.sys -- (HCW88AUD)
DRV - [1996.04.03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-306692126-4049508593-1777269419-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-306692126-4049508593-1777269419-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-306692126-4049508593-1777269419-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-306692126-4049508593-1777269419-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F0 56 51 3D 23 E2 CD 01 [binary data]
IE - HKU\S-1-5-21-306692126-4049508593-1777269419-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-306692126-4049508593-1777269419-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-306692126-4049508593-1777269419-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-306692126-4049508593-1777269419-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-306692126-4049508593-1777269419-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "hxxp://www.osterholzer.de/"
FF - prefs.js..extensions.enabledAddons: brief%40mozdev.org:1.6.2
FF - prefs.js..extensions.enabledAddons: optout%40google.com:1.5
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.14
FF - prefs.js..extensions.enabledAddons: %7B966762eb-7132-4081-ac70-20d20161ad96%7D:4.3
FF - prefs.js..extensions.enabledAddons: https-everywhere%40eff.org:3.1.4
FF - prefs.js..extensions.enabledAddons: %7BDDC359D1-844A-42a7-9AA1-88A850A938A8%7D:2.0.16
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0033-ABCDEFFEDCBA%7D:6.0.33
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0035-ABCDEFFEDCBA%7D:6.0.35
FF - prefs.js..extensions.enabledAddons: %7BDAC3F861-B30D-40dd-9166-F4E75327FAC7%7D:1.3.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..extensions.enabledItems: brief@mozdev.org:1.5.4
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: https-everywhere@eff.org:0.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.no_proxies_on: ",192.168.0.0/16"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Old_C\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\Armin01\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.11.24 11:31:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DAC3F861-B30D-40dd-9166-F4E75327FAC7}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013.04.19 17:33:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 08:19:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.04.19 17:41:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\Old_D\Programme\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\Old_D\Programme\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.04.03 14:10:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.04.19 17:41:25 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.11.24 11:31:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 08:19:53 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.04.19 17:41:25 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Components: C:\Old_D\Programme\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Plugins: C:\Old_D\Programme\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.04.03 14:10:38 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.04.19 17:41:25 | 000,000,000 | ---D | M]
[2010.09.15 13:29:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Armin01\AppData\Roaming\mozilla\Extensions
[2010.09.15 13:29:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Armin01\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013.04.08 23:26:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Armin01\AppData\Roaming\mozilla\Firefox\Profiles\c9lop5zk.default\extensions
[2010.04.28 03:39:45 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Armin01\AppData\Roaming\mozilla\Firefox\Profiles\c9lop5zk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013.02.24 10:42:39 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Armin01\AppData\Roaming\mozilla\Firefox\Profiles\c9lop5zk.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.09.18 18:58:02 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Armin01\AppData\Roaming\mozilla\Firefox\Profiles\c9lop5zk.default\extensions\foxmarks@kei.com
[2013.03.09 10:48:13 | 000,000,000 | ---D | M] (HTTPS-Everywhere) -- C:\Users\Armin01\AppData\Roaming\mozilla\Firefox\Profiles\c9lop5zk.default\extensions\https-everywhere@eff.org
[2012.08.01 09:23:42 | 000,242,942 | ---- | M] () (No name found) -- C:\Users\Armin01\AppData\Roaming\mozilla\firefox\profiles\c9lop5zk.default\extensions\brief@mozdev.org.xpi
[2012.03.01 01:04:31 | 000,008,363 | ---- | M] () (No name found) -- C:\Users\Armin01\AppData\Roaming\mozilla\firefox\profiles\c9lop5zk.default\extensions\optout@google.com.xpi
[2013.03.07 08:59:45 | 000,093,464 | ---- | M] () (No name found) -- C:\Users\Armin01\AppData\Roaming\mozilla\firefox\profiles\c9lop5zk.default\extensions\{966762eb-7132-4081-ac70-20d20161ad96}.xpi
[2013.04.08 23:26:00 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Armin01\AppData\Roaming\mozilla\firefox\profiles\c9lop5zk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.04.05 08:08:55 | 000,714,654 | ---- | M] () (No name found) -- C:\Users\Armin01\AppData\Roaming\mozilla\firefox\profiles\c9lop5zk.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2013.04.12 08:19:40 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.04.12 08:19:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013.04.12 08:19:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013.04.12 08:19:40 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013.04.12 08:19:40 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013.04.19 17:33:24 | 000,000,000 | ---D | M] (RealDownloader) -- C:\PROGRAMDATA\REALNETWORKS\REALDOWNLOADER\BROWSERPLUGINS\FIREFOX\EXT
[2013.04.12 08:19:52 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007.08.29 23:47:44 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\mozilla firefox\plugins\npbittorrent.dll
[2012.09.28 21:39:06 | 000,031,872 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
[2013.04.19 17:31:47 | 000,124,504 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2008.11.05 01:40:37 | 000,221,184 | ---- | M] (CNN) -- C:\Program Files\mozilla firefox\plugins\NPTURNMED.dll
[2013.01.10 23:55:23 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013.02.20 18:55:54 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = https://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&aq=t&q={searchTerms}&ie=utf-8&oe=utf-8&aq=t&channel=fflb&q={searchTerms}&ie=utf-8&oe=utf-8&aq=t&channel=rcs
CHR - default_search_provider: suggest_url = https://www.google.com/complete/search?q={searchTerms}
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00C2\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
CHR - plugin: Microsoft Lync 2010 Meeting Join Plug-in (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin8.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Turner Media Plugin 1.0.0.10 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Old_C\Programme\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U35 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.350.10 (Enabled) = C:\Windows\system32\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Armin01\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Move Media Player 7 (Enabled) = C:\Users\Armin01\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Users\Armin01\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\Armin01\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock = C:\Users\Armin01\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.61_0\
CHR - Extension: RealDownloader = C:\Users\Armin01\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: Google Mail = C:\Users\Armin01\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: Auto Lyrics = C:\Users\Armin01\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkcdkfohdadbjmlfejhncigcbfkiaamf\1.110_0\
O1 HOSTS File: ([2009.09.24 21:16:22 | 000,335,252 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 11489 more lines...
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [57xxSteelVine] C:\Programme\Silicon Image\57xx SteelVine\SteelVineManager.exe ()
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Programme\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Programme\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [PrintPack dispatcher] C:\Program Files\Software602\Print2PDF\PrnPack.exe (Software602)
O4 - HKLM..\Run: [recinfo585] c:\RecInfo\RecInfo.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-306692126-4049508593-1777269419-1000..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-306692126-4049508593-1777269419-1000..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Armin01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Armin01\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Armin01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\Armin01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qlock.lnk = C:\Programme\Qlock\qlock.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\S-1-5-21-306692126-4049508593-1777269419-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Lync-Add-On - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync-Add-On - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: Print2PDF - {5B7027AD-AA6D-40df-8F56-9560F277D2A5} - C:\Windows\System32\Print602.dll (Software602 a.s.)
O9 - Extra 'Tools' menuitem : Print2PDF - {5B7027AD-AA6D-40df-8F56-9560F277D2A5} - C:\Windows\System32\Print602.dll (Software602 a.s.)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Programme\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Programme\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3E5F3D3E-D50B-4569-932D-D24621F5992E}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O30 - LSA: Authentication Packages - (relog_ap) - C:\Windows\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{99628d33-a8f5-11de-8251-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{99628d33-a8f5-11de-8251-806e6f6e6963}\Shell\AutoRun\command - "" = E:\start.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.04.20 00:08:40 | 000,000,000 | ---D | C] -- C:\Users\Armin01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
[2013.04.19 22:52:36 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Armin01\Desktop\OTL.exe
[2013.04.19 21:39:19 | 000,000,000 | ---D | C] -- C:\Users\Armin01\Desktop\GMER
[2013.04.19 21:39:12 | 000,000,000 | ---D | C] -- C:\Users\Armin01\Desktop\OTL
[2013.04.19 21:37:03 | 000,000,000 | ---D | C] -- C:\Users\Armin01\Desktop\Defogger
[2013.04.19 17:41:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2013.04.19 17:33:23 | 000,000,000 | ---D | C] -- C:\Program Files\RealNetworks
[2013.04.19 17:32:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2013.04.19 17:17:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013.04.19 17:09:08 | 000,000,000 | ---D | C] -- C:\Users\Armin01\AppData\Roaming\Oracle
[2013.04.19 16:37:35 | 000,000,000 | ---D | C] -- C:\Users\Armin01\Desktop\clickcomp
[2013.04.12 08:19:38 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.04.11 00:25:17 | 000,000,000 | ---D | C] -- C:\Users\Armin01\AppData\Roaming\Malwarebytes
[2013.04.11 00:25:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.04.11 00:25:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.04.11 00:25:00 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.04.11 00:24:59 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.04.10 23:54:01 | 000,592,736 | ---- | C] (www.download-sponsor.de) -- C:\Users\Armin01\Desktop\adwcleaner_2.112.exe.exe
[2013.04.03 14:10:38 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2013.03.22 07:43:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2010.03.03 20:14:02 | 012,378,640 | ---- | C] (JonDos GmbH) -- C:\ProgramData\JonDoFox.paf.exe
========== Files - Modified Within 30 Days ==========
[2013.04.20 00:14:11 | 000,628,524 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.04.20 00:14:11 | 000,595,818 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.04.20 00:14:11 | 000,126,074 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.04.20 00:14:11 | 000,103,892 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.04.20 00:08:45 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.04.20 00:08:03 | 000,227,328 | ---- | M] () -- C:\Windows\System32\SV_SQL3_Events.db
[2013.04.20 00:07:56 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.04.20 00:07:56 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.04.20 00:07:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.04.20 00:07:42 | 2146,754,560 | -HS- | M] () -- C:\hiberfil.sys
[2013.04.20 00:02:45 | 000,001,151 | ---- | M] () -- C:\Users\Armin01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
[2013.04.19 23:56:21 | 000,139,264 | ---- | M] () -- C:\Users\Armin01\Desktop\SystemLook.exe
[2013.04.19 23:53:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.04.19 23:43:00 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.04.19 23:25:44 | 000,053,248 | ---- | M] () -- C:\Users\Armin01\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.04.19 22:52:38 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Armin01\Desktop\OTL.exe
[2013.04.19 21:42:46 | 000,000,000 | ---- | M] () -- C:\Users\Armin01\defogger_reenable
[2013.04.19 17:41:25 | 000,001,898 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2013.04.19 17:33:39 | 000,000,937 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2013.04.19 17:31:32 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2013.04.11 00:25:02 | 000,000,912 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.04.10 23:54:02 | 000,592,736 | ---- | M] (www.download-sponsor.de) -- C:\Users\Armin01\Desktop\adwcleaner_2.112.exe.exe
[2013.04.10 15:51:55 | 000,397,720 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.04.10 15:01:28 | 000,230,048 | ---- | M] () -- C:\Users\Armin01\Documents\cc_20130410_150058.reg
[2013.04.10 13:43:46 | 000,001,977 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013.04.09 20:40:21 | 000,000,352 | ---- | M] () -- C:\Users\Armin01\openvpn-connect.json
[2013.04.08 23:01:49 | 000,000,862 | ---- | M] () -- C:\Windows\System32\InstallUtil.InstallLog
[2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.03.29 13:03:41 | 000,000,959 | ---- | M] () -- C:\Users\Armin01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.03.29 13:03:30 | 000,000,931 | ---- | M] () -- C:\Users\Armin01\Desktop\Dropbox.lnk
[2013.03.27 13:34:53 | 000,000,810 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
========== Files Created - No Company Name ==========
[2013.04.19 23:56:19 | 000,139,264 | ---- | C] () -- C:\Users\Armin01\Desktop\SystemLook.exe
[2013.04.19 21:42:46 | 000,000,000 | ---- | C] () -- C:\Users\Armin01\defogger_reenable
[2013.04.19 17:41:25 | 000,001,898 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2013.04.19 17:41:25 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2013.04.19 17:33:39 | 000,000,937 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2013.04.11 00:25:02 | 000,000,912 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.04.10 15:01:12 | 000,230,048 | ---- | C] () -- C:\Users\Armin01\Documents\cc_20130410_150058.reg
[2013.04.09 20:40:21 | 000,000,352 | ---- | C] () -- C:\Users\Armin01\openvpn-connect.json
[2013.04.07 13:40:09 | 000,000,862 | ---- | C] () -- C:\Windows\System32\InstallUtil.InstallLog
[2013.01.03 22:38:28 | 000,000,256 | ---- | C] () -- C:\Users\Armin01\AppData\Roaming\wklnhst.dat
[2011.11.26 08:05:58 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011.11.26 07:32:26 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011.11.26 07:32:26 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.11.24 12:50:49 | 000,069,851 | ---- | C] () -- C:\Windows\hpqins13.dat.temp
[2011.11.24 11:23:20 | 000,266,091 | ---- | C] () -- C:\Windows\hpwins22.dat
[2011.11.24 11:23:20 | 000,002,850 | ---- | C] () -- C:\Windows\hpwmdl22.dat
[2011.11.13 22:19:50 | 000,266,541 | ---- | C] () -- C:\Windows\hpwins22.dat.temp
[2011.02.09 19:26:17 | 000,000,640 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010.07.25 15:40:48 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010.04.21 08:56:21 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.04.08 08:20:19 | 000,000,080 | ---- | C] () -- C:\Users\Armin01\AppData\Local\X-Plane Installer.prf
[2010.03.20 20:36:26 | 000,000,680 | ---- | C] () -- C:\Users\Armin01\AppData\Local\d3d9caps.dat
[2009.12.27 20:47:33 | 000,022,328 | ---- | C] () -- C:\Users\Armin01\AppData\Roaming\PnkBstrK.sys
[2009.09.26 23:09:25 | 000,053,248 | ---- | C] () -- C:\Users\Armin01\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.03.23 01:27:05 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Amazon
[2010.01.02 17:41:17 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\ASCOMP Software
[2010.03.07 02:10:46 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Avery
[2011.12.25 02:27:08 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Blender Foundation
[2009.12.29 15:24:24 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Canon
[2011.11.28 02:44:25 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\ChessBase
[2009.11.15 18:12:00 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\concept design
[2013.04.20 00:10:33 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Dropbox
[2009.09.27 01:31:11 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Foxit
[2010.04.19 22:09:33 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Foxit Software
[2011.10.01 20:56:21 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Geogrid
[2012.04.15 22:12:36 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\HTC
[2011.03.11 13:45:27 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2009.11.15 18:18:18 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\JLC's Software
[2009.12.24 13:37:24 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Juniper Networks
[2013.02.13 12:50:55 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\KeePass
[2010.06.26 20:18:44 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\motorola
[2011.05.11 14:50:23 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\MusicBee
[2013.04.19 17:09:08 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Oracle
[2011.12.04 14:49:07 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Outlook
[2013.04.02 16:45:50 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\PrivateTunnel
[2009.12.31 17:00:31 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Qlock
[2012.05.22 21:12:06 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Samsung
[2013.01.03 22:38:30 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Template
[2010.09.15 13:29:27 | 000,000,000 | ---D | M] -- C:\Users\Armin01\AppData\Roaming\Thunderbird
[2012.04.22 14:01:31 | 000,000,000 | ---D | M] -- C:\Users\Besucher\AppData\Roaming\HTC
[2012.04.22 12:59:04 | 000,000,000 | ---D | M] -- C:\Users\Gina01\AppData\Roaming\HTC
[2012.04.09 16:01:47 | 000,000,000 | ---D | M] -- C:\Users\Gina01\AppData\Roaming\Thunderbird
========== Purity Check ==========
< End of report > |