Das ist ja eine neverending story .>
schonmal vielen Dank
Ich hab übrigens immernoch dieses "debugger" deaktiviert, von dieser einen Software. Dort stand ja man solle es erst wieder aktivieren, wenn jemand sagt, dass man es aktivieren soll :> Code:
OTL logfile created on: 22.10.2012 16:52:07 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\cali\Pictures\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,50 Gb Total Physical Memory | 2,40 Gb Available Physical Memory | 68,58% Memory free
7,00 Gb Paging File | 5,70 Gb Available in Paging File | 81,51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 93,91 Gb Total Space | 20,91 Gb Free Space | 22,27% Space Free | Partition Type: NTFS
Drive D: | 931,51 Gb Total Space | 29,12 Gb Free Space | 3,13% Space Free | Partition Type: NTFS
Drive E: | 92,38 Gb Total Space | 15,78 Gb Free Space | 17,08% Space Free | Partition Type: FAT32
Drive F: | 303,76 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
Computer Name: CALIPCI | User Name: cali | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.10.22 16:49:03 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\cali\Pictures\Desktop\OTL.exe
PRC - [2012.10.18 19:48:38 | 001,591,768 | ---- | M] (Bitdefender) -- C:\Programme\Bitdefender\Bitdefender 2013\bdagent.exe
PRC - [2012.10.02 21:29:14 | 000,864,616 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2012.10.02 21:28:55 | 001,820,520 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe
PRC - [2012.09.26 20:29:52 | 001,285,888 | ---- | M] (Bitdefender) -- C:\Programme\Bitdefender\Bitdefender 2013\vsserv.exe
PRC - [2012.09.04 12:15:28 | 000,615,440 | ---- | M] () -- C:\Programme\EslWire\service\WireHelperSvc.exe
PRC - [2012.07.03 12:04:45 | 000,055,544 | ---- | M] (Bitdefender) -- C:\Programme\Bitdefender\Bitdefender 2013\updatesrv.exe
PRC - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2011.11.23 12:27:04 | 001,052,472 | ---- | M] (COMODO) -- C:\Programme\Comodo\COMODO GeekBuddy\CLPSLS.exe
PRC - [2011.10.07 11:40:42 | 001,387,288 | ---- | M] (Logitech, Inc.) -- C:\Programme\Logitech\SetPointP\SetPoint.exe
PRC - [2011.09.29 12:16:26 | 000,101,144 | ---- | M] (Logitech Inc.) -- C:\Programme\Logitech Gaming Software\LCore.exe
PRC - [2011.09.27 21:05:24 | 000,149,784 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
PRC - [2011.03.28 21:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011.03.28 21:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.07.12 14:39:24 | 000,053,248 | ---- | M] () -- C:\Programme\D-Link\DWA-125 revA\ANIWConnService.exe
PRC - [2009.10.07 02:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Programme\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2007.09.02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.exe
========== Modules (No Company Name) ==========
MOD - [2012.04.27 16:08:08 | 000,092,600 | ---- | M] () -- C:\Programme\Bitdefender\Bitdefender 2013\bdmetrics.dll
MOD - [2012.04.25 12:24:09 | 000,202,032 | ---- | M] () -- C:\Programme\Bitdefender\Bitdefender 2013\txmlutil.dll
MOD - [2011.11.08 03:27:22 | 000,026,112 | ---- | M] () -- C:\Programme\Logitech Gaming Software\plugins\PnpGamePanelDevices-8.12.049\PnpGamePanelDevices.dll
MOD - [2011.11.08 03:27:20 | 000,070,656 | ---- | M] () -- C:\Programme\Logitech Gaming Software\plugins\SimInput-8.12.068\SimInput.dll
MOD - [2011.11.08 03:27:18 | 000,467,456 | ---- | M] () -- C:\Programme\Logitech Gaming Software\plugins\MainUI-8.12.179\MainUI.dll
MOD - [2011.11.08 03:27:12 | 000,206,336 | ---- | M] () -- C:\Programme\Logitech Gaming Software\plugins\G19Device-8.12.147\G19Device.dll
MOD - [2011.11.08 03:27:09 | 000,189,952 | ---- | M] () -- C:\Programme\Logitech Gaming Software\plugins\G13Device-8.12.155\G13Device.dll
MOD - [2011.11.08 03:27:08 | 000,086,016 | ---- | M] () -- C:\Programme\Logitech Gaming Software\plugins\DevMgr-8.12.077\DevMgr.dll
MOD - [2011.11.08 03:27:07 | 000,090,112 | ---- | M] () -- C:\Programme\Logitech Gaming Software\plugins\DevBusHid-8.12.078\DevBusHid.dll
MOD - [2011.11.08 03:27:07 | 000,088,064 | ---- | M] () -- C:\Programme\Logitech Gaming Software\plugins\DevBusBulk-8.12.076\DevBusBulk.dll
MOD - [2011.10.07 11:41:16 | 000,879,896 | ---- | M] () -- C:\Programme\Logitech\SetPointP\Macros\MacroCore.dll
MOD - [2011.05.22 19:21:36 | 000,093,696 | ---- | M] () -- C:\Programme\FileZilla FTP Client\fzshellext.dll
MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.10.20 16:45:26 | 008,801,120 | ---- | M] () -- C:\Programme\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2010.03.25 00:34:52 | 000,035,840 | ---- | M] () -- C:\Programme\DAEMON Tools Pro\cryptapi.dll
MOD - [2010.03.15 12:28:22 | 000,141,824 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2009.01.18 15:50:02 | 000,417,792 | ---- | M] () -- C:\Programme\Adobe\Reader 9.0\Reader\AdobeXMP.dll
MOD - [2007.11.16 16:02:18 | 000,479,232 | R--- | M] () -- C:\Programme\Adobe\Reader 9.0\Reader\ccme_base.dll
MOD - [2007.11.16 16:02:18 | 000,401,408 | R--- | M] () -- C:\Programme\Adobe\Reader 9.0\Reader\cryptocme2.dll
MOD - [2007.09.02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.exe
MOD - [2007.09.02 14:57:36 | 000,069,632 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.dll
MOD - [2007.04.05 02:59:56 | 000,007,680 | ---- | M] () -- C:\Programme\DAEMON Tools Pro\Plugins\Images\bw5mount.dll
========== Services (SafeList) ==========
SRV - [2012.10.16 20:14:47 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.10.09 16:29:45 | 000,008,704 | ---- | M] (Hi-Rez Studios) [Auto | Stopped] -- D:\games\smite\HiPatchService.exe -- (HiPatchService)
SRV - [2012.09.26 20:29:52 | 001,285,888 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe -- (VSSERV)
SRV - [2012.09.11 11:16:32 | 000,059,152 | ---- | M] (Bitdefender) [Disabled | Stopped] -- C:\Programme\Bitdefender\Bitdefender 2013\bdparentalservice.exe -- (BdDesktopParental)
SRV - [2012.09.08 00:34:29 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.09.04 12:15:28 | 000,615,440 | ---- | M] () [Auto | Running] -- C:\Programme\EslWire\service\WireHelperSvc.exe -- (EslWireHelper)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.07.03 12:04:45 | 000,055,544 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe -- (UPDATESRV)
SRV - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2011.11.23 12:27:04 | 001,052,472 | ---- | M] (COMODO) [Auto | Running] -- C:\Programme\Comodo\COMODO GeekBuddy\CLPSLS.exe -- (CLPSLS)
SRV - [2011.09.27 21:03:28 | 000,295,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2011.06.12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2011.03.28 21:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011.03.24 14:10:59 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010.07.12 14:39:24 | 000,053,248 | ---- | M] () [Auto | Running] -- C:\Programme\D-Link\DWA-125 revA\ANIWConnService.exe -- (D_Link_DWA-125_WPS)
SRV - [2010.03.24 16:57:22 | 000,435,016 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Programme\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2010.02.19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Programme\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010.01.09 22:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.09 22:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
SRV - [2009.12.08 20:26:15 | 003,616,768 | ---- | M] (Native Instruments GmbH) [Auto | Stopped] -- C:\Programme\Common Files\Native Instruments\Hardware\NIHardwareService.exe -- (NIHardwareService)
SRV - [2009.10.30 16:05:48 | 001,021,256 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Programme\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2009.10.30 16:01:00 | 000,030,024 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2009.10.07 02:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Programme\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.12.14 12:46:28 | 000,047,624 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\GIGABYTE\GEST\GSvr.exe -- (GEST Service)
SRV - [2007.02.05 10:11:18 | 000,075,320 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\AVLib\SSScsiSV.exe -- (SSScsiSV)
SRV - [2007.02.05 10:11:16 | 000,112,184 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\AVLib\SsBeSvc.exe -- (SonicStage Back-End Service)
SRV - [2006.12.14 02:21:20 | 000,045,056 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV)
SRV - [2006.12.14 02:02:08 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV)
SRV - [2006.12.14 01:46:16 | 000,057,344 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
========== Driver Services (SafeList) ==========
DRV - File not found [File_System | On_Demand | Stopped] -- C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys -- (WinRing0_1_2_0)
DRV - File not found [File_System | Boot | Stopped] -- system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys -- (Lavasoft Kernexplorer)
DRV - [2012.10.03 00:20:00 | 010,837,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012.09.04 12:15:22 | 000,836,496 | ---- | M] (<Turtle Entertainment>) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ESLWireACD.sys -- (ESLWireAC)
DRV - [2012.08.29 18:24:08 | 000,161,312 | ---- | M] (BitDefender LLC) [File_System | Boot | Running] -- C:\Windows\System32\drivers\gzflt.sys -- (gzflt)
DRV - [2012.08.23 17:07:27 | 000,066,392 | ---- | M] (BitDefender SRL) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\bdsandbox.sys -- (BDSandBox)
DRV - [2012.08.12 13:34:54 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2012.07.12 17:12:20 | 000,132,600 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- C:\Programme\Bitdefender\Bitdefender 2013\bdselfpr.sys -- (bdselfpr)
DRV - [2012.07.06 15:13:12 | 000,077,192 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- c:\Programme\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys -- (BdfNdisf)
DRV - [2012.07.02 15:21:35 | 000,343,456 | ---- | M] (BitDefender S.R.L.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\trufos.sys -- (trufos)
DRV - [2012.06.13 14:00:26 | 000,473,248 | ---- | M] (BitDefender) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\avckf.sys -- (avckf)
DRV - [2012.06.13 14:00:22 | 000,617,984 | ---- | M] (BitDefender) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avc3.sys -- (avc3)
DRV - [2011.11.25 14:59:40 | 000,240,184 | ---- | M] (BitDefender) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\avchv.sys -- (avchv)
DRV - [2011.11.14 20:16:27 | 000,090,704 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- C:\Programme\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys -- (bdfwfpf)
DRV - [2011.11.08 03:27:20 | 000,019,720 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV - [2011.11.08 03:27:20 | 000,014,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LGVirHid.sys -- (LGVirHid)
DRV - [2011.11.08 03:27:08 | 000,041,880 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LGSHidFilt.Sys -- (LGSHidFilt)
DRV - [2011.09.02 08:31:20 | 000,041,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2011.04.28 14:20:26 | 001,228,864 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Dnetr28u.sys -- (netr28u)
DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010.11.05 02:29:35 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\etdrv.sys -- (etdrv)
DRV - [2010.10.13 13:19:54 | 000,024,504 | ---- | M] (Turtle Entertainment GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ESLvnic.sys -- (ESLvnic1)
DRV - [2010.09.16 12:39:16 | 001,505,280 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cmudaxp.sys -- (cmudaxp)
DRV - [2010.05.29 07:58:30 | 000,012,800 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\anodlwf.sys -- (anodlwf)
DRV - [2010.03.24 17:08:38 | 000,722,416 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2010.03.13 13:58:52 | 000,087,536 | ---- | M] (CyberLink Corp.) [2010/03/24 15:11:53] [Kernel | Auto | Running] -- C:\Programme\CyberLink\PowerDVD10\NavFilter\000.fcl -- ({1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC})
DRV - [2009.11.10 13:55:32 | 000,028,560 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2009.11.10 13:55:08 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2009.10.14 08:24:44 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Programme\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2009.10.07 02:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009.07.14 00:02:52 | 000,043,008 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2009.05.12 16:53:04 | 000,016,896 | ---- | M] (Danish Wireless Design A/S) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\FlashUsb.sys -- (FlashUSB)
DRV - [2009.05.01 00:56:30 | 000,495,768 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LV561AV.SYS -- (PID_0928)
DRV - [2008.11.11 14:42:00 | 000,024,832 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2008.11.11 14:41:00 | 000,019,968 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2008.11.11 14:41:00 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2007.10.11 12:10:52 | 000,030,008 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ET5Drv.sys -- (ET5Drv)
DRV - [2007.09.29 07:30:52 | 000,065,024 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\jraid.sys -- (JRAID)
DRV - [2007.06.29 14:47:34 | 000,034,304 | ---- | M] (AMD, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AmdLLD.sys -- (AmdLLD)
DRV - [2007.06.02 15:59:42 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Programme\PeerGuardian2\pgfilter.sys -- (pgfilter)
DRV - [2007.04.11 17:23:48 | 000,045,440 | ---- | M] (Razer USA Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\UsbFltr.sys -- (TarFltr)
DRV - [2005.03.09 21:50:16 | 000,033,792 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\libusb0.sys -- (libusb0)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2144295801-1104322103-669315532-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2144295801-1104322103-669315532-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-2144295801-1104322103-669315532-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-2144295801-1104322103-669315532-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CC 2D 39 34 EC CA CA 01 [binary data]
IE - HKU\S-1-5-21-2144295801-1104322103-669315532-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-2144295801-1104322103-669315532-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2144295801-1104322103-669315532-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2144295801-1104322103-669315532-1008\..\SearchScopes,DefaultScope =
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de"
FF - prefs.js..extensions.enabledAddons: {cc5cc7f7-8645-49b2-862f-f6e8116dfc44}:0.6.81
FF - prefs.js..extensions.enabledAddons: ich@maltegoetz.de:1.4.3
FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.10
FF - prefs.js..extensions.enabledAddons: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.119
FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.5.9rc2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {cc5cc7f7-8645-49b2-862f-f6e8116dfc44}:0.6.81
FF - prefs.js..extensions.enabledItems: {3160baf9-cf68-48ec-9076-faed7ce49467}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 3
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: battlefieldplay4free@ea.com:1.0.53.2
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.0.3
FF - prefs.js..extensions.enabledItems: {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.265.2
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll ()
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\cali\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1002170-0-npoctoshape.dll (Octoshape ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.18 18:37:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.18 18:37:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\bdThunderbird@bitdefender.com: C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2012.10.18 19:17:35 | 000,000,000 | ---D | M]
[2010.03.24 02:53:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\cali\AppData\Roaming\mozilla\Extensions
[2012.10.22 16:35:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\cali\AppData\Roaming\mozilla\Firefox\Profiles\bpwct85r.default\extensions
[2012.09.15 21:28:18 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\cali\AppData\Roaming\mozilla\Firefox\Profiles\bpwct85r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011.04.10 18:29:39 | 000,000,000 | ---D | M] (Dict) -- C:\Users\cali\AppData\Roaming\mozilla\Firefox\Profiles\bpwct85r.default\extensions\{cc5cc7f7-8645-49b2-862f-f6e8116dfc44}
[2012.10.16 06:06:10 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Users\cali\AppData\Roaming\mozilla\Firefox\Profiles\bpwct85r.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012.09.20 22:55:49 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\cali\AppData\Roaming\mozilla\Firefox\Profiles\bpwct85r.default\extensions\firefox@ghostery.com
[2012.09.15 21:28:16 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\cali\AppData\Roaming\mozilla\Firefox\Profiles\bpwct85r.default\extensions\ich@maltegoetz.de
[2012.02.10 16:30:02 | 000,000,000 | ---D | M] (Cooliris) -- C:\Users\cali\AppData\Roaming\mozilla\Firefox\Profiles\bpwct85r.default\extensions\piclens@cooliris.com
[2011.09.02 18:54:26 | 000,011,510 | ---- | M] () (No name found) -- C:\Users\cali\AppData\Roaming\mozilla\firefox\profiles\bpwct85r.default\extensions\youtube2mp3@mondayx.de.xpi
[2012.10.21 17:28:14 | 000,529,958 | ---- | M] () (No name found) -- C:\Users\cali\AppData\Roaming\mozilla\firefox\profiles\bpwct85r.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2010.04.02 20:15:12 | 000,000,687 | ---- | M] () -- C:\Users\cali\AppData\Roaming\mozilla\firefox\profiles\bpwct85r.default\searchplugins\icq-search.xml
[2010.09.09 22:48:02 | 000,000,950 | ---- | M] () -- C:\Users\cali\AppData\Roaming\mozilla\firefox\profiles\bpwct85r.default\searchplugins\icqplugin-4.xml
[2010.09.16 21:48:40 | 000,000,950 | ---- | M] () -- C:\Users\cali\AppData\Roaming\mozilla\firefox\profiles\bpwct85r.default\searchplugins\icqplugin-5.xml
[2010.10.21 12:16:54 | 000,000,950 | ---- | M] () -- C:\Users\cali\AppData\Roaming\mozilla\firefox\profiles\bpwct85r.default\searchplugins\icqplugin-6.xml
[2010.10.28 13:47:58 | 000,000,950 | ---- | M] () -- C:\Users\cali\AppData\Roaming\mozilla\firefox\profiles\bpwct85r.default\searchplugins\icqplugin-7.xml
[2010.11.06 02:09:41 | 000,000,950 | ---- | M] () -- C:\Users\cali\AppData\Roaming\mozilla\firefox\profiles\bpwct85r.default\searchplugins\icqplugin-8.xml
[2011.03.02 22:27:57 | 000,000,950 | ---- | M] () -- C:\Users\cali\AppData\Roaming\mozilla\firefox\profiles\bpwct85r.default\searchplugins\icqplugin-9.xml
[2012.10.16 20:14:42 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.10.16 20:14:42 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.10.16 20:14:47 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.12.09 19:23:32 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012.02.14 11:35:59 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.30 11:45:41 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.02.14 11:35:59 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.14 11:35:59 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.14 11:35:59 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.14 11:35:59 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\cali\AppData\Local\Google\Chrome\Application\22.0.1229.92\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\cali\AppData\Local\Google\Chrome\Application\22.0.1229.92\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\cali\AppData\Local\Google\Chrome\Application\22.0.1229.92\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: getPlusPlus for Adobe 16263 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\cali\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\cali\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1002170-0-npoctoshape.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Windows\system32\TVUAx\npTVUAx.dll
CHR - Extension: YouTube = C:\Users\cali\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\cali\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Psykopaint = C:\Users\cali\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil\0.0.0.10_0\
CHR - Extension: Psykopaint = C:\Users\cali\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil\0.0.0.10_0\.bak
CHR - Extension: Google Mail = C:\Users\cali\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKU\S-1-5-21-2144295801-1104322103-669315532-1000\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [Bdagent] C:\Programme\Bitdefender\Bitdefender 2013\bdagent.exe (Bitdefender)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4 - HKU\S-1-5-21-2144295801-1104322103-669315532-1000..\Run: [ESL Wire] C:\Program Files\EslWire\wire.exe (Turtle Entertainment GmbH)
O4 - HKU\S-1-5-21-2144295801-1104322103-669315532-1000..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2144295801-1104322103-669315532-1008..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 153
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-2144295801-1104322103-669315532-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 153
O7 - HKU\S-1-5-21-2144295801-1104322103-669315532-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-2144295801-1104322103-669315532-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~4\Office14\ONBttnIE.dll/105 File not found
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{871F438F-D35E-4976-9403-4F7C07FD2AE3}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008.02.23 12:34:14 | 000,003,104 | R--- | M] () - D:\autoexec.cfg -- [ NTFS ]
O32 - AutoRun File - [2011.09.01 09:43:05 | 000,533,824 | R--- | M] (MediaChance) - F:\autorun.exe -- [ UDF ]
O32 - AutoRun File - [2011.09.01 09:35:29 | 000,000,047 | R--- | M] () - F:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2011.09.01 09:35:29 | 000,389,554 | R--- | M] () - F:\autorun.mbd -- [ UDF ]
O33 - MountPoints2\{09c0362f-36dd-11df-8d79-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{09c0362f-36dd-11df-8d79-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Run.exe
O33 - MountPoints2\{8811e49d-3757-11df-a7d6-002401320ac8}\Shell - "" = AutoRun
O33 - MountPoints2\{8811e49d-3757-11df-a7d6-002401320ac8}\Shell\AutoRun\command - "" = G:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: UxTuneUp - C:\Windows\System32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
MsConfig - StartUpReg: bdinstaller - hkey= - key= - C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\setuplauncher.exe (Bitdefender)
MsConfig - StartUpReg: Tarantula - hkey= - key= - File not found
MsConfig - StartUpReg: TrojanScanner - hkey= - key= - File not found
MsConfig - State: "startup" - 2
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: CLPSLS - C:\Programme\Comodo\COMODO GeekBuddy\CLPSLS.exe (COMODO)
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: CLPSLS - C:\Programme\Comodo\COMODO GeekBuddy\CLPSLS.exe (COMODO)
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: vsmon - Service
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {A6F332B3-9277-5775-57C8-B83B0EB0A418} - Browser Customizations
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {D8E53E4D-A790-C27F-6EBD-1779E98F73CF} - Microsoft Windows Media Player 12.0
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS hxxp://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.I420 - C:\Windows\System32\LVCodec2.dll (Logitech Inc.)
Drivers32: vidc.tscc - C:\Windows\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012.10.22 16:49:01 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\cali\Pictures\Desktop\OTL.exe
[2012.10.20 03:30:46 | 000,000,000 | ---D | C] -- C:\Users\cali\AppData\Local\bdch
[2012.10.20 03:30:41 | 000,000,000 | ---D | C] -- C:\ProgramData\bdch
[2012.10.20 01:19:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.10.18 23:47:18 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.10.18 23:46:39 | 002,322,184 | ---- | C] (ESET) -- C:\Users\cali\Pictures\Desktop\esetsmartinstaller_enu.exe
[2012.10.18 19:48:48 | 000,072,704 | ---- | C] (BitDefender) -- C:\Windows\System32\drivers\bdvedisk.sys
[2012.10.18 19:17:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2013
[2012.10.18 19:17:42 | 000,000,000 | ---D | C] -- C:\ProgramData\BDLogging
[2012.10.18 19:17:33 | 000,077,192 | ---- | C] (BitDefender LLC) -- C:\Windows\System32\drivers\BdfNdisf6.sys
[2012.10.18 19:17:33 | 000,066,392 | ---- | C] (BitDefender SRL) -- C:\Windows\System32\drivers\bdsandbox.sys
[2012.10.18 19:17:20 | 000,240,184 | ---- | C] (BitDefender) -- C:\Windows\System32\drivers\avchv.sys
[2012.10.18 19:17:19 | 000,473,248 | ---- | C] (BitDefender) -- C:\Windows\System32\drivers\avckf.sys
[2012.10.18 19:17:18 | 000,617,984 | ---- | C] (BitDefender) -- C:\Windows\System32\drivers\avc3.sys
[2012.10.18 19:16:39 | 000,000,000 | ---D | C] -- C:\Users\cali\AppData\Roaming\Bitdefender
[2012.10.18 19:16:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Bitdefender
[2012.10.18 19:14:32 | 000,161,312 | ---- | C] (BitDefender LLC) -- C:\Windows\System32\drivers\gzflt.sys
[2012.10.18 19:14:19 | 000,343,456 | ---- | C] (BitDefender S.R.L.) -- C:\Windows\System32\drivers\trufos.sys
[2012.10.18 19:14:19 | 000,000,000 | ---D | C] -- C:\Program Files\Bitdefender
[2012.10.18 18:57:37 | 000,061,248 | ---- | C] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2012.10.18 18:57:12 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2012.10.18 07:30:23 | 000,159,608 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe.bfde.deleteme
[2012.10.16 20:14:41 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012.10.16 18:04:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.10.16 18:03:53 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.10.16 17:45:32 | 000,000,000 | ---D | C] -- C:\Users\cali\AppData\Roaming\DriverCure
[2012.10.16 17:45:31 | 000,000,000 | ---D | C] -- C:\Users\cali\AppData\Roaming\SpeedyPC Software
[2012.10.16 17:35:49 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedyPC Software
[2012.10.16 06:22:24 | 000,159,608 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe.a966.deleteme
[2012.10.16 06:08:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Bitdefender
[2012.10.16 06:06:38 | 000,000,000 | ---D | C] -- C:\Users\cali\AppData\Roaming\QuickScan
[2012.10.13 15:13:17 | 000,000,000 | ---D | C] -- C:\Users\cali\Pictures\Desktop\wg party
[2012.10.11 17:32:56 | 000,000,000 | ---D | C] -- C:\Users\cali\Pictures\Desktop\hyper
[2012.10.11 17:31:35 | 000,000,000 | ---D | C] -- C:\Users\cali\Pictures\Desktop\nookie
[2012.10.10 23:34:28 | 000,000,000 | ---D | C] -- C:\Users\cali\AppData\Roaming\AMPSoft
[2012.10.10 17:54:59 | 000,000,000 | ---D | C] -- C:\Users\cali\Pictures\Desktop\leine hertz
[2012.10.10 04:58:53 | 000,000,000 | ---D | C] -- C:\Users\cali\Desktop
[2012.10.10 04:58:45 | 000,000,000 | ---D | C] -- C:\Users\cali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AMP Font Viewer
[2012.10.10 04:58:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMP Font Viewer
[2012.10.10 04:58:34 | 000,000,000 | ---D | C] -- C:\Program Files\AMP Font Viewer
[2012.10.10 01:36:46 | 000,000,000 | ---D | C] -- C:\Users\cali\Pictures\Desktop\Neuer Ordner
[2012.10.09 06:31:07 | 000,000,000 | ---D | C] -- C:\Program Files\Emsisoft Anti-Malware
[2012.10.09 06:31:07 | 000,000,000 | ---D | C] -- C:\Users\cali\Documents\Anti-Malware
[2012.10.09 06:25:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Solidshield
[2012.10.09 06:16:21 | 000,000,000 | ---D | C] -- C:\Users\cali\AppData\Local\Comodo
[2012.10.02 16:51:17 | 000,000,000 | ---D | C] -- C:\Users\cali\Pictures\Desktop\flyer_gfx_versuche
[2012.09.29 22:35:50 | 000,000,000 | ---D | C] -- C:\Users\cali\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.09.24 21:04:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
[2012.09.24 21:04:42 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2012.09.24 21:04:42 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2012.09.24 21:04:42 | 000,000,000 | ---D | C] -- C:\Program Files\ffdshow
[2012.09.24 06:17:00 | 000,000,000 | ---D | C] -- C:\Users\cali\Pictures\Desktop\medialink-1
[2012.09.24 06:15:42 | 000,000,000 | ---D | C] -- C:\Users\cali\Pictures\Desktop\medialink
[8 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[6 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.10.22 16:49:03 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\cali\Pictures\Desktop\OTL.exe
[2012.10.22 16:45:50 | 000,016,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.22 16:45:50 | 000,016,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.22 16:44:28 | 000,709,992 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.10.22 16:44:28 | 000,663,610 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.10.22 16:44:28 | 000,153,524 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.10.22 16:44:28 | 000,125,740 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.10.22 16:38:09 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.22 16:37:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.22 16:37:07 | 2817,384,448 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.22 15:51:00 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.21 20:20:23 | 000,538,941 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\adwcleaner.exe
[2012.10.20 01:19:10 | 000,001,024 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012.10.18 23:47:34 | 002,322,184 | ---- | M] (ESET) -- C:\Users\cali\Pictures\Desktop\esetsmartinstaller_enu.exe
[2012.10.18 20:55:08 | 000,009,617 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\config.cfg
[2012.10.18 19:48:48 | 000,072,704 | ---- | M] (BitDefender) -- C:\Windows\System32\drivers\bdvedisk.sys
[2012.10.18 19:32:40 | 000,000,215 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\valve.rc
[2012.10.18 19:18:55 | 000,505,557 | ---- | M] () -- C:\ProgramData\1350580437.bdinstall.bin
[2012.10.18 19:18:42 | 000,000,385 | ---- | M] () -- C:\Windows\System32\user_gensett.xml
[2012.10.18 19:18:08 | 000,253,404 | -H-- | M] () -- C:\bdr-ld01
[2012.10.18 19:18:08 | 000,009,216 | -H-- | M] () -- C:\bdr-ld01.mbr
[2012.10.18 19:18:08 | 000,000,308 | -H-- | M] () -- C:\bdr-cf01
[2012.10.18 19:17:52 | 000,002,122 | ---- | M] () -- C:\Users\Public\Desktop\Bitdefender Internet Security 2013.lnk
[2012.10.18 19:17:52 | 000,002,074 | ---- | M] () -- C:\Users\Public\Desktop\Bitdefender Safepay.lnk
[2012.10.18 19:17:51 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_avchv_01009.Wdf
[2012.10.18 18:49:05 | 000,000,064 | ---- | M] () -- C:\Windows\System32\rp_stats.dat
[2012.10.18 18:49:05 | 000,000,044 | ---- | M] () -- C:\Windows\System32\rp_rules.dat
[2012.10.18 07:30:19 | 000,159,608 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe.bfde.deleteme
[2012.10.17 20:12:25 | 000,329,638 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\autumn_by_imperioli-d4gibjl.jpg
[2012.10.17 20:11:40 | 000,363,236 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\fafdcafec45f0c80becbdd5b02cb9faa-d2dvclx.jpg
[2012.10.17 17:43:44 | 000,109,680 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\Brandon-Schaefer-SpaceBalls-550x733.jpg
[2012.10.16 20:09:25 | 000,019,915 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\Gmer.zip
[2012.10.16 20:04:31 | 000,041,966 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\OTL+Extras.zip
[2012.10.16 19:12:48 | 000,302,592 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\d1riohdk.exe
[2012.10.16 18:49:12 | 000,000,020 | ---- | M] () -- C:\Users\cali\defogger_reenable
[2012.10.16 18:10:48 | 000,648,294 | ---- | M] () -- C:\Users\cali\Documents\cc_20121016_180919.reg
[2012.10.16 18:04:02 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.10.16 06:22:20 | 000,159,608 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe.a966.deleteme
[2012.10.14 23:33:01 | 000,000,932 | ---- | M] () -- C:\Users\Public\Desktop\ESL Wire.lnk
[2012.10.14 16:49:49 | 006,222,520 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.10.13 16:53:17 | 000,522,991 | ---- | M] () -- C:\VirtualDJ Local Database v6.xml
[2012.10.12 23:08:10 | 000,059,737 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\wgparty.m3u
[2012.10.11 23:40:37 | 000,403,309 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\duude.jpg
[2012.10.11 23:40:21 | 000,403,309 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\dude.jpg
[2012.10.11 00:24:53 | 002,134,065 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\CamelFrdsdsdsdankfurt.jpg
[2012.10.10 23:42:04 | 000,096,107 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\851199.jpg
[2012.10.10 21:18:46 | 000,059,801 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\pink moons.m3u
[2012.10.10 20:46:54 | 000,581,208 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\outtake.mp3
[2012.10.10 20:24:03 | 135,003,632 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\2012_1110_23-00_pink_moon.mp3
[2012.10.09 22:15:20 | 000,126,159 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\cali_owl.png
[2012.10.08 21:44:56 | 001,389,137 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\logo.rar
[2012.10.08 19:20:36 | 004,776,519 | ---- | M] () -- C:\Users\cali\Pictures\Desktop\cafeglocksee.m3u
[2012.10.03 00:20:00 | 000,012,865 | ---- | M] () -- C:\Windows\System32\nvinfo.pb
[2012.09.29 16:15:41 | 000,000,049 | ---- | M] () -- C:\Windows\NeroDigital.ini
[8 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[6 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.10.21 20:20:13 | 000,538,941 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\adwcleaner.exe
[2012.10.20 01:19:10 | 000,001,024 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012.10.18 20:57:22 | 000,009,617 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\config.cfg
[2012.10.18 20:57:22 | 000,000,837 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\autoexec.cfg
[2012.10.18 19:18:55 | 000,505,557 | ---- | C] () -- C:\ProgramData\1350580437.bdinstall.bin
[2012.10.18 19:18:42 | 000,000,385 | ---- | C] () -- C:\Windows\System32\user_gensett.xml
[2012.10.18 19:18:08 | 000,000,308 | -H-- | C] () -- C:\bdr-cf01
[2012.10.18 19:17:52 | 000,002,122 | ---- | C] () -- C:\Users\Public\Desktop\Bitdefender Internet Security 2013.lnk
[2012.10.18 19:17:52 | 000,002,074 | ---- | C] () -- C:\Users\Public\Desktop\Bitdefender Safepay.lnk
[2012.10.18 19:17:51 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_avchv_01009.Wdf
[2012.10.18 19:16:27 | 035,188,281 | -H-- | C] () -- C:\bdr-im01.gz
[2012.10.18 19:16:27 | 002,294,848 | -H-- | C] () -- C:\bdr-bz01
[2012.10.18 19:16:27 | 000,253,404 | -H-- | C] () -- C:\bdr-ld01
[2012.10.18 19:16:27 | 000,009,216 | -H-- | C] () -- C:\bdr-ld01.mbr
[2012.10.17 20:12:22 | 000,329,638 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\autumn_by_imperioli-d4gibjl.jpg
[2012.10.17 20:11:35 | 000,363,236 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\fafdcafec45f0c80becbdd5b02cb9faa-d2dvclx.jpg
[2012.10.17 17:43:39 | 000,109,680 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\Brandon-Schaefer-SpaceBalls-550x733.jpg
[2012.10.16 20:09:25 | 000,019,915 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\Gmer.zip
[2012.10.16 20:04:31 | 000,041,966 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\OTL+Extras.zip
[2012.10.16 19:12:47 | 000,302,592 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\d1riohdk.exe
[2012.10.16 18:48:53 | 000,000,020 | ---- | C] () -- C:\Users\cali\defogger_reenable
[2012.10.16 18:09:24 | 000,648,294 | ---- | C] () -- C:\Users\cali\Documents\cc_20121016_180919.reg
[2012.10.16 18:04:02 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.10.12 23:08:10 | 000,059,737 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\wgparty.m3u
[2012.10.11 23:40:36 | 000,403,309 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\duude.jpg
[2012.10.11 22:32:12 | 000,403,309 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\dude.jpg
[2012.10.11 02:51:06 | 000,000,215 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\valve.rc
[2012.10.11 02:50:50 | 000,003,924 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\autoexec111111.cfg.cfg
[2012.10.11 02:50:31 | 000,000,103 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\autoexec2222222222222.cfg
[2012.10.11 00:24:50 | 002,134,065 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\CamelFrdsdsdsdankfurt.jpg
[2012.10.10 23:41:55 | 000,096,107 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\851199.jpg
[2012.10.10 21:18:46 | 000,059,801 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\pink moons.m3u
[2012.10.10 20:46:52 | 000,581,208 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\outtake.mp3
[2012.10.10 20:19:40 | 135,003,632 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\2012_1110_23-00_pink_moon.mp3
[2012.10.09 22:15:19 | 000,126,159 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\cali_owl.png
[2012.10.08 21:44:55 | 001,389,137 | ---- | C] () -- C:\Users\cali\Pictures\Desktop\logo.rar
[2012.10.04 20:44:30 | 000,000,932 | ---- | C] () -- C:\Users\Public\Desktop\ESL Wire.lnk
[2012.09.24 21:04:43 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2012.08.30 10:40:14 | 000,429,416 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
[2012.08.21 22:29:10 | 000,000,253 | ---- | C] () -- C:\Users\cali\AppData\Roaming\ANICONFIG_{871F438F-D35E-4976-9403-4F7C07FD2AE3}.ini
[2012.08.21 21:36:46 | 000,000,253 | ---- | C] () -- C:\Users\cali\AppData\Roaming\ANICONFIG_{0AA8CA46-7BBF-4E47-8B8E-1F33935F7F3D}.ini
[2012.08.21 20:11:02 | 000,000,253 | ---- | C] () -- C:\Users\cali\AppData\Roaming\ANICONFIG_{44F76163-2AA8-48C9-88DE-249DFCC1DED2}.ini
[2012.08.21 20:02:47 | 000,012,800 | ---- | C] () -- C:\Windows\System32\drivers\anodlwf.sys
[2012.08.21 20:02:46 | 000,014,119 | ---- | C] () -- C:\Windows\System32\RaCoInst.dat
[2012.07.24 13:50:37 | 000,265,120 | ---- | C] () -- C:\Program Files\Common Files\WireHelpSvc.exe
[2012.04.08 18:51:13 | 000,000,132 | ---- | C] () -- C:\Users\cali\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
[2012.04.08 18:43:08 | 000,001,456 | ---- | C] () -- C:\Users\cali\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011.12.28 00:30:24 | 000,000,000 | ---- | C] () -- C:\Users\cali\AppData\Local\{C433B468-92C5-4996-A02F-C05E05AF3F68}
[2011.10.16 22:23:17 | 000,000,680 | RHS- | C] () -- C:\Users\cali\ntuser.pol
[2011.09.25 23:30:37 | 000,010,240 | ---- | C] () -- C:\Users\cali\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.08.06 20:44:21 | 000,000,092 | ---- | C] () -- C:\Users\cali\AppData\Local\fusioncache.dat
[2011.07.26 15:56:47 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2011.07.12 16:43:39 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2011.05.15 17:40:54 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011.05.07 21:42:31 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat
[2011.05.07 21:42:31 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat
[2011.04.13 16:07:35 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011.04.13 16:06:19 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011.02.15 21:52:34 | 000,033,792 | ---- | C] () -- C:\Windows\System32\drivers\libusb0.sys
[2011.02.09 18:36:55 | 000,082,289 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2010.12.22 13:55:38 | 000,000,032 | ---- | C] () -- C:\Windows\Menu.INI
[2010.11.22 21:30:33 | 000,008,192 | ---- | C] () -- C:\Windows\System32\CNMVS5u.DLL
[2010.11.18 15:23:29 | 000,053,248 | ---- | C] () -- C:\Windows\System32\CommonDL.dll
[2010.11.18 15:23:29 | 000,002,413 | ---- | C] () -- C:\Windows\System32\lgAxconfig.ini
[2010.11.05 02:29:28 | 000,024,944 | ---- | C] () -- C:\Windows\System32\drivers\GVTDrv.sys
[2010.04.21 20:56:23 | 000,138,056 | ---- | C] () -- C:\Users\cali\AppData\Roaming\PnkBstrK.sys
========== ZeroAccess Check ==========
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011.08.13 18:16:36 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Ableton
[2012.10.10 23:34:28 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\AMPSoft
[2010.03.24 02:47:06 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\ASUS
[2012.01.22 01:42:14 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\BigHugeEngine
[2012.10.18 19:16:39 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Bitdefender
[2012.09.29 22:35:50 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010.03.24 03:02:04 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\CheckPoint
[2012.04.08 18:52:25 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\com.adobe.DC3Module.AdobeADC
[2010.03.24 14:24:26 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\DAEMON Tools Lite
[2010.03.25 00:35:47 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\DAEMON Tools Pro
[2012.10.16 17:45:32 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\DriverCure
[2012.04.10 01:06:05 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Dropbox
[2012.10.16 18:07:57 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\FileZilla
[2011.01.31 15:18:15 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\GetRightToGo
[2012.10.22 02:42:37 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\ICQ
[2011.01.22 20:37:46 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\IrfanView
[2010.06.11 17:51:47 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\KORG
[2010.03.24 14:32:26 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Leadertech
[2010.11.18 15:40:12 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\LG Electronics
[2012.09.03 13:26:14 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\MA Lighting Technologies
[2010.12.29 20:52:40 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\mkvtoolnix
[2012.10.12 18:46:20 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Mumble
[2011.01.19 18:38:13 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Nicalis
[2010.06.12 19:28:45 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Octoshape
[2011.04.12 17:13:52 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\OfficeRecovery
[2011.09.30 18:01:43 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Origin
[2012.09.10 23:57:08 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Plane9
[2011.03.24 00:50:16 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Publish Providers
[2010.10.25 18:50:11 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Quest3D
[2012.10.18 17:49:44 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\QuickScan
[2010.10.25 18:50:10 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Roaming
[2012.09.20 01:52:20 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\RotMG.Production
[2011.03.24 00:50:11 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Sony
[2012.10.16 17:45:31 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\SpeedyPC Software
[2012.03.19 23:17:26 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\SplitMediaLabs
[2012.03.14 18:30:03 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Spotify
[2012.02.07 18:49:02 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012.09.04 01:41:21 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Steinberg
[2011.08.04 23:07:26 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Stellarium
[2012.10.18 05:51:24 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\TS3Client
[2012.05.04 16:36:42 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\ts3overlay
[2010.03.24 16:57:13 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\TuneUp Software
[2012.10.19 18:27:42 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\uTorrent
[2010.05.27 15:09:19 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Warsow 0.5
[2011.07.09 15:25:56 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Warsow 0.6
[2011.11.19 10:28:33 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\WordToPDF
========== Purity Check ==========
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2011.08.13 18:16:36 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Ableton
[2012.04.08 18:52:12 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Adobe
[2012.02.07 18:49:03 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Adobe Mini Bridge CS5.1
[2012.10.10 23:34:28 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\AMPSoft
[2011.12.19 13:51:58 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Apple Computer
[2010.03.24 02:47:06 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\ASUS
[2012.01.22 01:42:14 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\BigHugeEngine
[2012.10.18 19:16:39 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Bitdefender
[2012.09.29 22:35:50 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010.03.24 03:02:04 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\CheckPoint
[2012.04.08 18:52:25 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\com.adobe.DC3Module.AdobeADC
[2011.03.17 22:01:00 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\CyberLink
[2010.03.24 14:24:26 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\DAEMON Tools Lite
[2010.03.25 00:35:47 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\DAEMON Tools Pro
[2010.05.01 21:59:21 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\DivX
[2010.09.17 16:54:04 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Download Manager
[2012.10.16 17:45:32 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\DriverCure
[2012.04.10 01:06:05 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Dropbox
[2011.10.01 14:32:38 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\dvdcss
[2012.10.16 18:07:57 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\FileZilla
[2011.01.31 15:18:15 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\GetRightToGo
[2012.10.22 02:42:37 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\ICQ
[2010.03.24 02:44:09 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Identities
[2011.01.22 20:37:46 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\IrfanView
[2010.06.11 17:51:47 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\KORG
[2010.03.24 14:32:26 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Leadertech
[2010.11.18 15:40:12 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\LG Electronics
[2010.03.24 14:31:28 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Logishrd
[2010.03.24 14:32:33 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Logitech
[2012.09.03 13:26:14 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\MA Lighting Technologies
[2010.03.24 03:30:20 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Macromedia
[2012.03.27 17:36:28 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Malwarebytes
[2009.07.14 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Media Center Programs
[2012.10.21 01:02:00 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Media Player Classic
[2012.07.13 22:03:09 | 000,000,000 | --SD | M] -- C:\Users\cali\AppData\Roaming\Microsoft
[2010.12.29 20:52:40 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\mkvtoolnix
[2010.11.10 12:24:54 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Mozilla
[2012.10.12 18:46:20 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Mumble
[2010.07.23 00:35:16 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Nero
[2011.01.19 18:38:13 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Nicalis
[2011.10.12 13:40:09 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\NVIDIA
[2010.06.12 19:28:45 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Octoshape
[2011.04.12 17:13:52 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\OfficeRecovery
[2011.09.30 18:01:43 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Origin
[2012.09.10 23:57:08 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Plane9
[2011.03.24 00:50:16 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Publish Providers
[2010.10.25 18:50:11 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Quest3D
[2012.10.18 17:49:44 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\QuickScan
[2010.10.25 18:50:10 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Roaming
[2012.09.20 01:52:20 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\RotMG.Production
[2010.03.24 03:59:20 | 000,000,000 | RH-D | M] -- C:\Users\cali\AppData\Roaming\SecuROM
[2012.10.22 16:51:13 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Skype
[2011.07.01 21:32:33 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\skypePM
[2011.03.24 00:50:11 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Sony
[2010.04.25 15:42:19 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Sony Corporation
[2012.10.16 17:45:31 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\SpeedyPC Software
[2012.03.19 23:17:26 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\SplitMediaLabs
[2012.03.14 18:30:03 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Spotify
[2012.02.07 18:49:02 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012.09.04 01:41:21 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Steinberg
[2011.08.04 23:07:26 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Stellarium
[2011.02.19 00:15:42 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\teamspeak2
[2012.10.18 05:51:24 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\TS3Client
[2012.05.04 16:36:42 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\ts3overlay
[2010.03.24 16:57:13 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\TuneUp Software
[2012.10.19 18:27:42 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\uTorrent
[2012.10.16 18:08:00 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Ventrilo
[2012.10.20 02:56:16 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\vlc
[2010.05.27 15:09:19 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Warsow 0.5
[2011.07.09 15:25:56 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Warsow 0.6
[2012.10.17 07:10:42 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\Winamp
[2010.03.24 15:53:09 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\WinRAR
[2011.11.19 10:28:33 | 000,000,000 | ---D | M] -- C:\Users\cali\AppData\Roaming\WordToPDF
< %APPDATA%\*.exe /s >
[2012.02.15 01:03:14 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Users\cali\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2012.02.15 01:03:44 | 000,174,752 | ---- | M] (Dropbox, Inc.) -- C:\Users\cali\AppData\Roaming\Dropbox\bin\Uninstall.exe
[2010.03.24 14:32:26 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\cali\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2010.06.10 21:36:25 | 000,040,960 | R--- | M] (InstallShield Software Corp.) -- C:\Users\cali\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
[2010.06.10 21:36:25 | 000,040,960 | R--- | M] (InstallShield Software Corp.) -- C:\Users\cali\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
[2010.06.10 21:36:25 | 000,008,854 | R--- | M] () -- C:\Users\cali\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\Uninstall_Project64__9559F7CA5E344237A2D9D856464AD727.exe
[2011.06.28 17:10:42 | 000,010,134 | R--- | M] () -- C:\Users\cali\AppData\Roaming\Microsoft\Installer\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}\ARPPRODUCTICON.exe
[2012.02.06 14:07:28 | 000,425,984 | ---- | M] () -- C:\Users\cali\AppData\Roaming\Mozilla\Firefox\Profiles\bpwct85r.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
[2012.02.06 14:07:28 | 000,545,792 | ---- | M] () -- C:\Users\cali\AppData\Roaming\Mozilla\Firefox\Profiles\bpwct85r.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
[2009.01.08 15:44:06 | 000,070,936 | ---- | M] (Octoshape ApS) -- C:\Users\cali\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
[2012.03.14 18:10:58 | 004,011,184 | ---- | M] (Spotify Ltd) -- C:\Users\cali\AppData\Roaming\Spotify\spotify.exe
[2009.02.03 10:09:38 | 000,068,096 | ---- | M] (Igor Pavlov) -- C:\Users\cali\AppData\Roaming\uTorrent\7z.exe
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
< MD5 for: IASTORV.SYS >
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\drivers\iaStorV.sys
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys
[2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
[2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\drivers\nvstor.sys
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
< MD5 for: USER32.DLL >
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll
[2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
< MD5 for: USERINIT.EXE >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
< MD5 for: WININIT.EXE >
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
< MD5 for: WINLOGON.EXE >
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2012.08.29 18:24:08 | 000,161,312 | ---- | M] (BitDefender LLC) Unable to obtain MD5 -- C:\Windows\system32\drivers\gzflt.sys
< %systemroot%\System32\config\*.sav >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[6 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< >
[2009.07.14 06:53:46 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.07.14 06:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2011.06.28 15:49:11 | 000,001,090 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2011.06.28 15:49:13 | 000,001,094 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
========== Alternate Data Streams ==========
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:CB0AACC9
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:A8ADE5D8
@Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:ADF211B1
< End of report > |