OTL Logfile: Code:
OTL logfile created on: 5/30/2013 4:41:22 AM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
64bit-Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 87.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 116.44 Gb Total Space | 13.55 Gb Free Space | 11.64% Space Free | Partition Type: NTFS
Drive D: | 327.83 Gb Total Space | 51.85 Gb Free Space | 15.82% Space Free | Partition Type: NTFS
Drive E: | 1.86 Gb Total Space | 0.30 Gb Free Space | 15.87% Space Free | Partition Type: FAT
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2012/09/19 08:01:14 | 001,432,400 | ---- | M] (Flexera Software, Inc.) [On_Demand] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2010/11/30 17:19:52 | 000,379,520 | ---- | M] (ASUSTeK Computer Inc.) [Auto] -- C:\Windows\System32\FBAgent.exe -- (AFBAgent)
SRV:64bit: - [2010/09/22 22:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/05/27 03:46:59 | 000,216,576 | ---- | M] (Samsung Electronics Co., Ltd.) [Auto] -- C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe -- (Samsung Network Fax Server)
SRV:64bit: - [2010/04/16 20:07:42 | 000,134,928 | ---- | M] (Intel(R) Corporation) [Auto] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost) Intel(R)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013/05/15 18:48:00 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/10 03:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/04/14 19:55:33 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/03/30 19:59:48 | 000,246,112 | ---- | M] () [Auto] -- C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe -- (Mobile Partner. RunOuc)
SRV - [2012/11/20 19:40:38 | 000,058,288 | ---- | M] (Absolute Software Corp.) [Auto] -- C:\Windows\SysWOW64\rpcnet.exe -- (rpcnet) Remote Procedure Call (RPC)
SRV - [2012/10/17 13:29:39 | 000,544,248 | ---- | M] (Cisco Systems, Inc.) [Auto] -- C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe -- (vpnagent)
SRV - [2012/01/31 04:46:56 | 000,019,232 | ---- | M] (Autodesk, Inc.) [Auto] -- C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe -- (Autodesk Content Service)
SRV - [2011/11/17 13:59:06 | 002,790,936 | ---- | M] (Sophos Limited) [Auto] -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe -- (swi_service)
SRV - [2011/11/17 13:59:05 | 002,024,984 | ---- | M] (Sophos Limited) [Auto] -- C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe -- (swi_update_64)
SRV - [2011/11/17 13:58:54 | 000,212,504 | ---- | M] (Sophos Limited) [Auto] -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe -- (SAVAdminService)
SRV - [2011/11/17 13:58:54 | 000,139,800 | ---- | M] (Sophos Limited) [Auto] -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe -- (SAVService)
SRV - [2011/10/23 09:01:10 | 000,232,472 | ---- | M] (Sophos Limited) [Auto] -- C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe -- (Sophos AutoUpdate Service)
SRV - [2011/10/18 22:28:53 | 000,150,552 | ---- | M] (Sophos Limited) [Auto] -- C:\Program Files (x86)\Sophos\Sophos Client Firewall\SCFManager.exe -- (Sophos Client Firewall Manager)
SRV - [2011/10/18 22:28:53 | 000,089,112 | ---- | M] (Sophos Limited) [Auto] -- C:\Program Files (x86)\Sophos\Sophos Client Firewall\SCFService.exe -- (Sophos Client Firewall)
SRV - [2010/12/27 09:41:59 | 001,997,416 | ---- | M] (NVIDIA Corporation) [Auto] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2010/09/29 09:08:58 | 000,200,624 | ---- | M] (Telefónica I+D) [Auto] -- C:\Program Files (x86)\o2\Mobile Connection Manager\ImpWiFiSvc.exe -- (TGCM_ImportWiFiSvc)
SRV - [2010/03/18 07:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/12/15 05:39:38 | 000,096,896 | ---- | M] (ASUS) [Auto] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
SRV - [2009/06/15 12:30:42 | 000,084,536 | ---- | M] (ASUS) [Auto] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe -- (ASLDRService)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/03/30 19:59:55 | 000,086,016 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV:64bit: - [2013/03/30 19:59:54 | 000,415,744 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbwwan.sys -- (ewusbmbb)
DRV:64bit: - [2013/03/30 19:59:54 | 000,222,464 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2013/03/30 19:59:54 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV:64bit: - [2012/10/17 13:13:36 | 000,027,048 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vpnva64.sys -- (vpnva)
DRV:64bit: - [2012/10/17 13:11:37 | 000,107,432 | R--- | M] (Cisco Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\acsock64.sys -- (acsock)
DRV:64bit: - [2011/12/02 12:37:10 | 000,348,560 | ---- | M] (EldoS Corporation) [Kernel | System] -- C:\Windows\System32\drivers\cbfs3.sys -- (cbfs3)
DRV:64bit: - [2011/10/21 04:14:54 | 000,059,256 | ---- | M] (G Data Software AG) [Kernel | On_Demand] -- C:\Windows\System32\drivers\PktIcpt.sys -- (GDPkIcpt)
DRV:64bit: - [2011/10/07 05:49:50 | 002,770,944 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\athrx.sys -- (athr)
DRV:64bit: - [2011/08/31 14:53:22 | 012,306,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/08/24 21:47:34 | 000,102,688 | ---- | M] (Sophos Limited) [Kernel | System] -- C:\Windows\System32\drivers\scfdriver.sys -- (scfdriver)
DRV:64bit: - [2011/08/24 21:47:34 | 000,055,072 | ---- | M] (Sophos Limited) [Kernel | System] -- C:\Windows\System32\drivers\scfndis.sys -- (scfndis)
DRV:64bit: - [2011/08/24 21:47:22 | 000,144,672 | ---- | M] (Sophos Limited) [File_System | System] -- C:\Windows\System32\drivers\savonaccess.sys -- (SAVOnAccess)
DRV:64bit: - [2011/08/24 21:47:22 | 000,025,608 | ---- | M] (Sophos Plc) [Kernel | Disabled] -- C:\Windows\System32\drivers\SophosBootDriver.sys -- (SophosBootDriver)
DRV:64bit: - [2011/02/18 21:07:00 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\nvpciflt.sys -- (nvpciflt)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/10/19 18:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:64bit: - [2010/10/14 12:28:15 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2010/09/23 04:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010/09/07 05:19:37 | 001,800,832 | ---- | M] (Sonix Technology Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV:64bit: - [2010/08/03 06:43:13 | 000,290,920 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:64bit: - [2010/07/01 13:11:24 | 000,012,352 | ---- | M] () [Kernel | "Start" not found.] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV:64bit: - [2010/06/22 21:31:11 | 000,333,928 | ---- | M] (Realtek ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010/04/16 20:07:28 | 000,013,832 | ---- | M] () [Kernel | Auto] -- C:\Windows\System32\drivers\TurboB.sys -- (TurboB)
DRV:64bit: - [2009/07/21 05:29:39 | 000,015,416 | ---- | M] ( ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\kbfiltr.sys -- (kbfiltr)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- C:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:35:57 | 000,056,832 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\SiSG664.sys -- (SiSGbeLH)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/02/10 21:48:19 | 000,053,816 | R--- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto] -- C:\Windows\System32\drivers\DgivEcp.sys -- (DgiVecp)
DRV:64bit: - [2008/11/11 06:09:18 | 000,011,576 | R--- | M] (Samsung Electronics) [Kernel | Auto] -- C:\Windows\System32\drivers\SSPORT.sys -- (SSPORT)
DRV:64bit: - [2008/05/23 21:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2011/09/07 04:55:04 | 000,017,536 | ---- | M] (ASUS) [Kernel | System] -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys -- (ATKWMIACPIIO)
DRV - [2009/07/02 12:36:14 | 000,015,416 | ---- | M] (ASUS) [Kernel | Auto] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)
DRV - [2009/02/06 03:05:05 | 000,011,576 | ---- | M] (Samsung Electronics) [Kernel | Auto] -- C:\Windows\SysWOW64\drivers\SSPORT.SYS -- (SSPORT)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\UpdatusUser_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
IE - HKU\UpdatusUser_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
IE - HKU\UpdatusUser_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Wong_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://asus.de.msn.com/?ocid=iehp
IE - HKU\Wong_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\Wong_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 64 54 13 6E 29 50 CE 01 [binary data]
IE - HKU\Wong_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF64_11_7_700_202.dll ()
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/07/02 09:56:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/04/14 19:55:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/05/15 16:52:23 | 000,000,000 | ---D | M]
[2013/04/14 19:55:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/04/14 19:55:05 | 000,000,000 | ---D | M] (G Data BankGuard) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{906305f7-aafc-45e9-8bbd-941950a84dad}
[2013/04/14 19:55:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}
[2013/04/14 19:55:05 | 000,000,000 | ---D | M] (QuickStores-Toolbar) -- C:\Program Files (x86)\Mozilla Firefox\extensions\quickstores@quickstores.de
[2013/04/14 19:55:34 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/07/02 09:55:42 | 000,129,144 | ---- | M] (RealPlayer) -- C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll
[2012/09/05 22:07:37 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013/03/21 11:00:52 | 000,006,468 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/09/05 22:07:37 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/05 22:07:37 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012/09/05 22:07:37 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/09/05 22:07:37 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/09/05 22:07:37 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2013/05/28 18:52:03 | 000,000,869 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 134.130.5.240 vpn-unidsl.rwth-aachen.de
O2:64bit: - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Wong\AppData\Roaming\Complitly\64\Complitly64.dll (SimplyGen)
O2:64bit: - BHO: (Virtual Storage Mount Notification) - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\System32\CbFsMntNtf3.dll (EldoS Corporation)
O2 - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Wong\AppData\Roaming\Complitly\Complitly.dll (SimplyGen)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Virtual Storage Mount Notification) - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\Wong_ON_C\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (Autodesk, Inc.)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix Technology Co., Ltd.)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (Virage Logic Corporation / Sonic Focus)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
O4 - HKU\LocalService_ON_C..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_C..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\UpdatusUser_ON_C..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKU\UpdatusUser_ON_C..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe ()
O4 - HKU\UpdatusUser_ON_C..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\UpdatusUser_ON_C..\Run: [swg] File not found
O4 - HKU\UpdatusUser_ON_C..\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\syncables.exe (syncables, LLC)
O4 - HKU\Wong_ON_C..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKU\Wong_ON_C..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe ()
O4 - HKU\Wong_ON_C..\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\syncables.exe (syncables, LLC)
O4 - HKU\Wong_ON_C..\Run: [Yontoo Desktop] C:\Users\Wong\AppData\Roaming\Yontoo\YontooDesktop.exe (Yontoo LLC)
O4:64bit: - HKLM..\RunOnce: [*Restore] C:\Windows\System32\rstrui.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_C..\RunOnce: [mctadmin] File not found
O4 - HKU\NetworkService_ON_C..\RunOnce: [mctadmin] File not found
O4 - HKU\UpdatusUser_ON_C..\RunOnce: [mctadmin] File not found
O4 - Startup: Error locating startup folders.
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\UpdatusUser_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\UpdatusUser_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\Wong_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\Wong_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.13.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\System32\nvinitx.dll (NVIDIA Corporation)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL) - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll (Sophos Limited)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Limited)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKU\Wong_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKU\Wong_ON_C Winlogon: Shell - (C:\Users\Wong\AppData\Roaming\skype.dat) - C:\Users\Wong\AppData\Roaming\skype.dat ()
O21:64bit: - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\System32\CbFsMntNtf3.dll (EldoS Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O22:64bit: - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\System32\CbFsMntNtf3.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/08/24 14:00:53 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2013/05/26 20:49:30 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/05/26 20:49:29 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/05/26 20:49:27 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013/05/26 20:49:25 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013/05/26 20:49:25 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013/05/26 20:49:24 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013/05/26 20:49:24 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/05/26 20:49:24 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013/05/26 20:49:24 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013/05/26 20:49:23 | 000,493,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2013/05/26 20:49:23 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013/05/26 20:49:23 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013/05/26 20:49:22 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/05/26 20:49:17 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2013/05/26 20:49:17 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/05/26 20:49:15 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013/05/26 20:49:14 | 002,877,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
[2013/05/25 09:34:58 | 001,054,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/05/25 09:34:57 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\elshyph.dll
[2013/05/25 09:34:57 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2013/05/25 09:34:56 | 000,719,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2013/05/25 09:34:56 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2013/05/25 09:34:56 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msls31.dll
[2013/05/25 09:34:56 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2013/05/25 09:34:56 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2013/05/25 09:34:56 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2013/05/25 09:34:56 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/05/25 09:34:55 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013/05/25 09:34:55 | 000,125,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2013/05/25 09:34:55 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2013/05/25 09:34:55 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2013/05/25 09:34:55 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/05/25 09:34:55 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2013/05/25 09:34:55 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2013/05/25 09:34:55 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imgutil.dll
[2013/05/25 09:34:55 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2013/05/25 09:34:54 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013/05/25 09:34:54 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2013/05/25 09:34:54 | 000,629,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2013/05/25 09:34:54 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2013/05/25 09:34:54 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft.dll
[2013/05/25 09:34:54 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/05/25 09:34:54 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtrans.dll
[2013/05/25 09:34:54 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2013/05/25 09:34:54 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2013/05/25 09:34:54 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2013/05/25 09:34:53 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2013/05/25 09:34:52 | 001,509,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013/05/25 09:34:52 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2013/05/25 09:34:52 | 000,905,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
[2013/05/25 09:34:52 | 000,762,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2013/05/25 09:34:52 | 000,452,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2013/05/25 09:34:52 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2013/05/25 09:34:52 | 000,281,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2013/05/25 09:34:52 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013/05/25 09:34:52 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2013/05/25 09:34:52 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
[2013/05/25 09:34:51 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2013/05/25 09:34:51 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013/05/25 09:34:51 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2013/05/25 09:34:51 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
[2013/05/25 09:34:51 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2013/05/25 09:34:51 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2013/05/25 09:34:51 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2013/05/25 09:34:51 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
[2013/05/25 09:34:51 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2013/05/25 09:34:51 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2013/05/25 09:34:51 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2013/05/25 09:34:51 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
[2013/05/25 09:34:50 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2013/05/25 09:34:50 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2013/05/25 09:34:50 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
[2013/05/25 09:34:50 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2013/05/25 09:34:50 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2013/05/15 17:07:06 | 000,265,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2013/05/15 17:07:06 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2013/05/15 17:06:37 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
[2013/05/15 17:06:37 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shdocvw.dll
[2013/05/15 17:06:34 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2013/05/15 17:06:34 | 000,111,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
[2013/05/15 17:06:17 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wwanprotdim.dll
[2013/05/12 17:33:58 | 000,000,000 | ---D | C] -- C:\Users\Wong\Documents\Gutscheine
[2013/05/07 07:01:41 | 000,000,000 | ---D | C] -- C:\Users\Wong\Documents\OneNote-Notizbücher
[2013/04/30 10:23:02 | 000,000,000 | ---D | C] -- C:\Users\Wong\Documents\DA Direkt - Kfz Versicherung
[2013/04/30 06:04:42 | 000,000,000 | ---D | C] -- C:\Users\Wong\AppData\Roaming\Canneverbe Limited
[2013/04/30 06:04:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
[2013/04/30 06:04:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDBurnerXP
========== Files - Modified Within 30 Days ==========
[2013/05/28 19:02:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/05/28 19:02:11 | 000,058,288 | ---- | M] (Absolute Software Corp.) -- C:\Windows\SysWow64\rpcnet.dll
[2013/05/28 19:01:27 | 467,480,575 | -HS- | M] () -- C:\hiberfil.sys
[2013/05/28 18:52:54 | 000,000,004 | ---- | M] () -- C:\Users\Wong\AppData\Roaming\skype.ini
[2013/05/28 18:52:03 | 000,000,869 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013/05/28 18:51:34 | 000,045,056 | ---- | M] () -- C:\Windows\System32\acovcnt.exe
[2013/05/28 18:50:55 | 000,017,920 | ---- | M] () -- C:\Windows\System32\rpcnetp.exe
[2013/05/28 18:49:55 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/28 18:49:55 | 000,000,142 | ---- | M] () -- C:\Windows\ODBC.INI
[2013/05/28 18:18:36 | 000,012,288 | ---- | M] () -- C:\Windows\System32\umstartup.etl
[2013/05/28 14:54:00 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/28 14:47:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/28 14:39:49 | 000,010,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/28 14:39:49 | 000,010,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/28 14:26:03 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2642857034-4049780713-3514487108-1001UA.job
[2013/05/27 19:32:43 | 000,001,064 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2642857034-4049780713-3514487108-1001Core.job
[2013/05/26 14:02:05 | 000,002,368 | ---- | M] () -- C:\Users\Wong\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/05/26 14:02:05 | 000,002,366 | ---- | M] () -- C:\Users\Wong\Desktop\Google Chrome.lnk
[2013/05/25 09:34:58 | 001,054,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/05/25 09:34:57 | 000,226,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\elshyph.dll
[2013/05/25 09:34:57 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2013/05/25 09:34:56 | 000,719,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2013/05/25 09:34:56 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2013/05/25 09:34:56 | 000,158,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msls31.dll
[2013/05/25 09:34:56 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2013/05/25 09:34:56 | 000,138,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2013/05/25 09:34:56 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2013/05/25 09:34:56 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/05/25 09:34:56 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2013/05/25 09:34:55 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013/05/25 09:34:55 | 000,125,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2013/05/25 09:34:55 | 000,117,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2013/05/25 09:34:55 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2013/05/25 09:34:55 | 000,073,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/05/25 09:34:55 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2013/05/25 09:34:55 | 000,038,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\imgutil.dll
[2013/05/25 09:34:55 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2013/05/25 09:34:54 | 001,441,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013/05/25 09:34:54 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2013/05/25 09:34:54 | 000,629,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2013/05/25 09:34:54 | 000,361,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2013/05/25 09:34:54 | 000,357,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft.dll
[2013/05/25 09:34:54 | 000,232,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/05/25 09:34:54 | 000,226,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtrans.dll
[2013/05/25 09:34:54 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2013/05/25 09:34:54 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2013/05/25 09:34:54 | 000,025,185 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2013/05/25 09:34:54 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2013/05/25 09:34:53 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2013/05/25 09:34:52 | 001,509,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013/05/25 09:34:52 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2013/05/25 09:34:52 | 000,905,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
[2013/05/25 09:34:52 | 000,762,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2013/05/25 09:34:52 | 000,452,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2013/05/25 09:34:52 | 000,441,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2013/05/25 09:34:52 | 000,281,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2013/05/25 09:34:52 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013/05/25 09:34:52 | 000,216,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2013/05/25 09:34:52 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
[2013/05/25 09:34:52 | 000,025,185 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2013/05/25 09:34:51 | 000,599,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2013/05/25 09:34:51 | 000,173,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013/05/25 09:34:51 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2013/05/25 09:34:51 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
[2013/05/25 09:34:51 | 000,144,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2013/05/25 09:34:51 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2013/05/25 09:34:51 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2013/05/25 09:34:51 | 000,097,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
[2013/05/25 09:34:51 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2013/05/25 09:34:51 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2013/05/25 09:34:51 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2013/05/25 09:34:51 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
[2013/05/25 09:34:50 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2013/05/25 09:34:50 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2013/05/25 09:34:50 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
[2013/05/25 09:34:50 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2013/05/25 09:34:50 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2013/05/20 18:14:47 | 000,708,510 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013/05/20 18:14:47 | 000,663,788 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/05/20 18:14:47 | 000,152,114 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013/05/20 18:14:47 | 000,125,060 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/05/16 03:17:25 | 000,517,848 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/05/15 18:47:56 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/05/15 18:47:55 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/05/15 16:52:23 | 000,002,441 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2013/05/07 07:01:41 | 000,001,358 | ---- | M] () -- C:\Users\Wong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
[2013/04/30 10:19:31 | 000,011,231 | ---- | M] () -- C:\Users\Wong\AppData\Roaming\SmarThruOptions.xml
[2013/04/30 10:17:35 | 001,737,005 | ---- | M] () -- C:\Users\Wong\Desktop\Fahrzeugbrief - Kfz Halterwechsel.pdf
[2013/04/30 06:04:33 | 000,001,905 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
========== Files Created - No Company Name ==========
[2013/05/28 05:15:47 | 000,000,004 | ---- | C] () -- C:\Users\Wong\AppData\Roaming\skype.ini
[2013/05/25 09:34:54 | 000,025,185 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2013/05/25 09:34:52 | 000,025,185 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2013/05/07 07:01:41 | 000,001,358 | ---- | C] () -- C:\Users\Wong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
[2013/04/30 10:17:35 | 001,737,005 | ---- | C] () -- C:\Users\Wong\Desktop\Fahrzeugbrief - Kfz Halterwechsel.pdf
[2013/04/30 06:04:33 | 000,001,905 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
[2012/09/19 08:02:04 | 000,000,153 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2012/09/18 10:10:13 | 000,000,017 | ---- | C] () -- C:\Users\Wong\AppData\Local\resmon.resmoncfg
[2012/08/26 20:46:25 | 001,622,066 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/05/21 03:28:41 | 000,000,142 | ---- | C] () -- C:\Windows\ODBC.INI
[2012/01/11 10:38:15 | 000,060,928 | ---- | C] () -- C:\Users\Wong\AppData\Roaming\skype.dat
[2011/12/03 10:55:28 | 000,011,231 | ---- | C] () -- C:\Users\Wong\AppData\Roaming\SmarThruOptions.xml
[2011/12/03 10:55:14 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\SvcMan.exe
[2011/12/03 10:54:38 | 000,000,136 | ---- | C] () -- C:\Windows\Readiris.ini
[2011/12/03 10:54:31 | 000,023,040 | ---- | C] () -- C:\Windows\SysWow64\irisco32.dll
[2011/12/03 10:50:51 | 000,485,240 | ---- | C] () -- C:\Windows\ssndii.exe
[2011/12/03 10:50:43 | 000,149,880 | ---- | C] () -- C:\Windows\Wiainst64.exe
[2011/08/31 14:51:16 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011/08/31 14:51:16 | 000,216,000 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011/08/31 14:46:00 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011/08/31 14:26:20 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/07/01 15:49:02 | 000,476,045 | ---- | C] () -- C:\Windows\SysWow64\sig.bin
[2011/06/10 15:03:51 | 000,252,928 | ---- | C] () -- C:\Windows\SysWow64\DShowRdpFilter.dll
[2011/04/20 05:55:57 | 000,000,024 | ---- | C] () -- C:\Windows\ATKPF.ini
[2011/03/02 10:05:27 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\acovcnt.exe
[2011/03/02 09:28:35 | 000,131,472 | ---- | C] () -- C:\ProgramData\FullRemove.exe
[2011/03/02 08:26:06 | 000,017,920 | ---- | C] () -- C:\Windows\SysWow64\rpcnetp.dll
[2011/03/02 08:24:40 | 000,017,920 | ---- | C] () -- C:\Windows\SysWow64\rpcnetp.exe
[2010/11/28 09:21:29 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2009/07/29 01:20:40 | 000,000,010 | ---- | C] () -- C:\Windows\SysWow64\ABLKSR.ini
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 18:25:04 | 000,197,632 | ---- | C] () -- C:\Windows\SysWow64\ir32_32.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/02/26 02:50:32 | 000,000,176 | ---- | C] () -- C:\Windows\explorer.exe.config
[2006/05/18 23:39:57 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini
========== LOP Check ==========
[2011/04/21 11:43:19 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Asus WebStorage
[2012/09/19 09:48:38 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Autodesk
[2012/03/18 06:53:26 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Babylon
[2013/04/30 06:04:42 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Canneverbe Limited
[2012/03/18 06:53:26 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Complitly
[2013/05/28 18:52:53 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Dropbox
[2012/05/16 19:32:25 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\DVDVideoSoft
[2012/05/16 19:31:28 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/04/21 11:42:21 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\EeeStorageUploader
[2012/09/22 06:36:45 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Freemium
[2013/03/21 10:56:36 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\GoforFiles
[2011/04/20 05:55:16 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Nuance
[2012/09/22 06:36:15 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\OpenCandy
[2012/10/17 13:09:23 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Origin
[2012/08/19 21:03:19 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Party
[2011/12/04 06:05:31 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\PlayFirst
[2012/06/20 01:54:31 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\PTC
[2011/10/10 14:24:57 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\SumatraPDF
[2013/03/28 09:38:03 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Telefónica
[2012/05/16 19:33:26 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\TuneUp Software
[2011/04/20 06:44:20 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Unigraphics Solutions
[2012/04/17 11:08:11 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Wuala
[2013/05/28 18:52:20 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Yontoo
[2011/04/20 05:55:14 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\Zeon
[2013/02/09 22:08:54 | 000,000,000 | ---D | M] -- C:\Users\Wong\AppData\Roaming\{BF347A0C-D2D3-4B9B-9A91-700B286996D7}
[2011/04/20 06:05:27 | 000,000,000 | -H-D | M] -- C:\ProgramData\.Syncables
[2011/04/20 06:05:32 | 000,000,000 | -H-D | M] -- C:\ProgramData\.syncID
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2011/04/20 05:56:09 | 000,000,000 | ---D | M] -- C:\ProgramData\ASUS
[2012/09/19 09:48:38 | 000,000,000 | ---D | M] -- C:\ProgramData\Autodesk
[2012/03/18 06:53:26 | 000,000,000 | ---D | M] -- C:\ProgramData\Babylon
[2013/04/30 06:04:42 | 000,000,000 | ---D | M] -- C:\ProgramData\Canneverbe Limited
[2012/10/23 13:56:35 | 000,000,000 | ---D | M] -- C:\ProgramData\Cisco
[2012/05/16 19:32:59 | 000,000,000 | -H-D | M] -- C:\ProgramData\Common Files
[2013/03/31 08:45:37 | 000,000,000 | ---D | M] -- C:\ProgramData\DatacardService
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2011/03/02 09:06:12 | 000,000,000 | ---D | M] -- C:\ProgramData\Downloaded Installations
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2012/05/21 03:26:37 | 000,000,000 | ---D | M] -- C:\ProgramData\G DATA
[2012/01/18 17:25:25 | 000,000,000 | ---D | M] -- C:\ProgramData\Graboid Inc
[2013/03/30 20:04:18 | 000,000,000 | ---D | M] -- C:\ProgramData\Mobile Partner
[2011/04/20 05:55:16 | 000,000,000 | ---D | M] -- C:\ProgramData\Nuance
[2011/03/02 09:28:21 | 000,000,000 | ---D | M] -- C:\ProgramData\OberonGameConsole
[2012/11/21 02:33:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Origin
[2012/03/07 06:42:55 | 000,000,000 | ---D | M] -- C:\ProgramData\P4G
[2011/09/16 03:45:27 | 000,000,000 | ---D | M] -- C:\ProgramData\Partner
[2011/12/04 06:05:31 | 000,000,000 | ---D | M] -- C:\ProgramData\PlayFirst
[2011/03/02 09:06:18 | 000,000,000 | ---D | M] -- C:\ProgramData\ScanSoft
[2011/12/20 14:22:10 | 000,000,000 | ---D | M] -- C:\ProgramData\SecTaskMan
[2013/02/22 16:16:16 | 000,000,000 | ---D | M] -- C:\ProgramData\Sophos
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2013/03/21 11:00:43 | 000,000,000 | ---D | M] -- C:\ProgramData\Tarma Installer
[2011/12/04 06:11:10 | 000,000,000 | ---D | M] -- C:\ProgramData\Temp
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2012/05/16 19:34:13 | 000,000,000 | ---D | M] -- C:\ProgramData\TuneUp Software
[2012/05/16 19:32:59 | 000,000,000 | -HSD | M] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2013/01/29 08:27:04 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:41099CE9
@Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:3E7393FC
< End of report > --- --- --- |