rupertbayern | 01.02.2013 18:09 | Code:
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Datenbank Version: v2013.02.01.06
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Rupert Niko :: HOME-PC [Administrator]
01.02.2013 15:41:56
mbam-log-2013-02-01 (15-41-56).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 511189
Laufzeit: 1 Stunde(n), 51 Minute(n), 41 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 1
D:\SoftonicDownloader_fuer_comic-life.exe (PUP.OfferBundler.ST) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) OTL
OTL Logfile: Code:
OTL logfile created on: 01.02.2013 17:59:10 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rupert Niko\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 1,74 Gb Available Physical Memory | 58,03% Memory free
6,00 Gb Paging File | 4,34 Gb Available in Paging File | 72,44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 178,66 Gb Free Space | 39,18% Space Free | Partition Type: NTFS
Drive D: | 732,42 Gb Total Space | 132,62 Gb Free Space | 18,11% Space Free | Partition Type: NTFS
Drive E: | 199,09 Gb Total Space | 28,22 Gb Free Space | 14,18% Space Free | Partition Type: NTFS
Drive F: | 69,71 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive M: | 5,23 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: HOME-PC | User Name: Rupert Niko | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Rupert Niko\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Xfire\Xfire.exe (Xfire Inc.)
PRC - C:\Programme\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Programme\LOLReplay\LOLRecorder.exe (LOL Replay)
PRC - C:\Programme\MOUSE Editor\MouseEditor.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab)
PRC - C:\Programme\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
========== Modules (No Company Name) ==========
MOD - C:\Users\Rupert Niko\AppData\Local\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\Rupert Niko\AppData\Local\Google\Chrome\Application\24.0.1312.56\pdf.dll ()
MOD - C:\Users\Rupert Niko\AppData\Local\Google\Chrome\Application\24.0.1312.56\libglesv2.dll ()
MOD - C:\Users\Rupert Niko\AppData\Local\Google\Chrome\Application\24.0.1312.56\libegl.dll ()
MOD - C:\Users\Rupert Niko\AppData\Local\Google\Chrome\Application\24.0.1312.56\ffmpegsumo.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\77dfcfed5fd5f67d0d3edc545935bb21\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\865d2bf19a7af7fab8660a42d92550fe\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Programme\LOLReplay\LOLUtils.dll ()
MOD - C:\Programme\MOUSE Editor\MouseEditor.exe ()
MOD - C:\Programme\MOUSE Editor\Data\MouseEditor\Forms\ScreenCapture\ScreenCapture.dll ()
MOD - C:\Programme\MOUSE Editor\dll\DLL_Wheel4D.dll ()
MOD - C:\Programme\MOUSE Editor\dll\DLL_AnalyzeGesturesInRight.dll ()
MOD - C:\Programme\MOUSE Editor\Data\MouseEditor\Forms\TrayIconWebAdvertisement\TrayIconWebAdvertisement.dll ()
MOD - C:\Programme\MOUSE Editor\dll\DLL_MouseDeviceManager.dll ()
MOD - C:\Programme\MOUSE Editor\Data\MouseEditor\Forms\OSD_Text\OSD_Text.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Programme\MOUSE Editor\dll\DLL_AnalyzeGesturesInOne.dll ()
MOD - C:\Programme\Kaspersky Lab\Kaspersky PURE\QtGui4.dll ()
MOD - C:\Programme\Kaspersky Lab\Kaspersky PURE\QtCore4.dll ()
MOD - C:\Programme\Kaspersky Lab\Kaspersky PURE\localization_manager.dll ()
MOD - C:\Programme\MOUSE Editor\dll\DLL_ZoomControl.dll ()
MOD - C:\Programme\MOUSE Editor\dll\DLL_ScrollbarControl.dll ()
MOD - C:\Programme\Kaspersky Lab\Kaspersky PURE\dblite.dll ()
========== Services (SafeList) ==========
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (AVP) -- C:\Programme\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab)
SRV - (CSObjectsSrv) -- C:\Programme\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (odserv) -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (KLIF) -- C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbGD) -- C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (dmvsc) -- C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (CSCrySec) -- C:\Windows\System32\drivers\CSCrySec.sys (Infowatch)
DRV - (CSVirtualDiskDrv) -- C:\Windows\System32\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV - (KLBG) -- C:\Windows\System32\drivers\klbg.sys (Kaspersky Lab)
DRV - (klmouflt) -- C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (KLIM6) -- C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab)
DRV - (kl1) -- C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab)
DRV - (Serial) -- C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (smserial) -- C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (CXAVSAUD) -- C:\Windows\System32\drivers\pvavsaud.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 80 15 01 25 EF E9 CD 01 [binary data]
IE - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\..\SearchScopes\{C32DDE2A-14EF-4427-8670-799FED10A61F}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=7B981B49-C767-4317-B9C0-D130A6E5F9B2&apn_sauid=805414D4-AC6A-49E7-B46B-A16E65F909F4
IE - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Rupert Niko\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Rupert Niko\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky PURE\THBExt [2013.01.03 20:42:00 | 000,000,000 | ---D | M]
========== Chrome ==========
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Rupert Niko\AppData\Local\Google\Chrome\Application\24.0.1312.56\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Rupert Niko\AppData\Local\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Rupert Niko\AppData\Local\Google\Chrome\Application\24.0.1312.56\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Rupert Niko\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: Click to activate/deactivate ProxTube = C:\Users\Rupert Niko\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.0_0\
CHR - Extension: Google Drive = C:\Users\Rupert Niko\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: WOT = C:\Users\Rupert Niko\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.8_0\
CHR - Extension: YouTube = C:\Users\Rupert Niko\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\Rupert Niko\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AdBlock = C:\Users\Rupert Niko\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.56_0\
CHR - Extension: Reddit Enhancement Suite = C:\Users\Rupert Niko\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.1.5_0\
CHR - Extension: Google Mail = C:\Users\Rupert Niko\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programme\Kaspersky Lab\Kaspersky PURE\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab)
O4 - HKU\S-1-5-21-497382121-3916464205-3174431237-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-497382121-3916464205-3174431237-1000..\Run: [OscarEditor] C:\Program Files\MOUSE Editor\MouseEditor.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Rupert Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Programme\Xfire\Xfire.exe (Xfire Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Programme\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Programme\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Programme\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-497382121-3916464205-3174431237-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2FACA56B-6A1B-4488-A49A-310824028276}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Programme\Kaspersky Lab\Kaspersky PURE\kloehk.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Programme\Kaspersky Lab\Kaspersky PURE\mzvkbd3.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011.10.10 14:54:08 | 002,290,144 | R--- | M] () - M:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2011.10.09 15:23:34 | 000,000,047 | R--- | M] () - M:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2011.10.09 15:23:34 | 000,224,630 | R--- | M] () - M:\autorun.ico -- [ CDFS ]
O33 - MountPoints2\{801d6ee5-5756-11e2-bb29-001a926c2bd3}\Shell - "" = AutoRun
O33 - MountPoints2\{801d6ee5-5756-11e2-bb29-001a926c2bd3}\Shell\AutoRun\command - "" = M:\Autorun.exe -- [2011.10.10 14:54:08 | 002,290,144 | R--- | M] ()
O33 - MountPoints2\{d39d85ac-6a50-11e2-a9cd-001a926c2bd3}\Shell - "" = AutoRun
O33 - MountPoints2\{d39d85ac-6a50-11e2-a9cd-001a926c2bd3}\Shell\AutoRun\command - "" = L:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.02.01 15:39:29 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Malwarebytes
[2013.02.01 15:39:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.02.01 15:39:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.02.01 15:39:17 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.02.01 15:39:17 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.02.01 15:39:11 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\Programs
[2013.01.30 19:50:43 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Download Manager
[2013.01.18 15:23:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Application Compatibility Toolkit
[2013.01.18 15:22:55 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Application Compatibility Toolkit
[2013.01.15 19:31:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mouse Software
[2013.01.14 14:50:23 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013.01.14 14:50:23 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013.01.14 14:50:23 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013.01.09 17:05:26 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\APN
[2013.01.09 17:05:25 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com
[2013.01.09 17:05:22 | 000,000,000 | ---D | C] -- C:\Firefox
[2013.01.09 16:54:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Ask
[2013.01.09 16:54:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2013.01.09 16:54:13 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\.minecraft
[2013.01.09 16:54:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013.01.09 16:53:45 | 000,859,072 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2013.01.09 16:53:45 | 000,779,704 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2013.01.09 16:53:11 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013.01.09 16:43:07 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013.01.09 16:42:30 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2013.01.09 16:42:30 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2013.01.09 16:42:29 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013.01.09 16:42:29 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013.01.09 16:42:29 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013.01.09 16:42:29 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013.01.09 16:42:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013.01.09 16:42:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013.01.09 16:42:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013.01.09 16:42:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013.01.09 16:42:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013.01.09 16:42:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013.01.09 16:42:17 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\System32\fpb.rs
[2013.01.09 16:42:17 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\System32\oflc-nz.rs
[2013.01.09 16:42:17 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\System32\pegibbfc.rs
[2013.01.09 16:42:17 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\System32\csrr.rs
[2013.01.09 16:42:17 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\System32\cob-au.rs
[2013.01.09 16:42:17 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\System32\usk.rs
[2013.01.09 16:42:17 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\System32\grb.rs
[2013.01.09 16:42:17 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\System32\djctq.rs
[2013.01.09 16:42:16 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2013.01.09 16:42:16 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wpc.dll
[2013.01.09 16:42:16 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\System32\cero.rs
[2013.01.09 16:42:16 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\System32\esrb.rs
[2013.01.09 16:42:16 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\System32\oflc.rs
[2013.01.09 16:42:16 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi-pt.rs
[2013.01.09 16:42:16 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi-fi.rs
[2013.01.09 16:42:16 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi.rs
[2013.01.09 16:42:08 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2013.01.09 16:42:07 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
[2013.01.06 18:04:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
[2013.01.06 18:04:16 | 000,000,000 | ---D | C] -- C:\Program Files\Lavalys
[2013.01.06 05:20:08 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\ANNO 2070
[2013.01.06 03:24:03 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2013.01.06 03:21:22 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\Diagnostics
[2013.01.06 03:11:24 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Ubisoft
[2013.01.06 03:01:23 | 000,000,000 | ---D | C] -- C:\Program Files\Ubisoft
[2013.01.06 03:01:10 | 000,000,000 | RH-D | C] -- C:\Users\Rupert Niko\AppData\Roaming\SecuROM
[2013.01.06 02:58:43 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll
[2013.01.06 02:58:43 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll
[2013.01.06 02:58:43 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll
[2013.01.06 02:58:43 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll
[2013.01.06 02:58:42 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll
[2013.01.06 02:58:42 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll
[2013.01.06 02:58:42 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll
[2013.01.06 02:58:42 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll
[2013.01.06 02:58:41 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll
[2013.01.06 02:58:41 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll
[2013.01.06 02:58:41 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll
[2013.01.06 02:58:40 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2013.01.06 02:58:40 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll
[2013.01.06 02:58:39 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2013.01.06 02:58:39 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2013.01.06 02:58:39 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2013.01.06 02:58:38 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2013.01.06 02:58:38 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_41.dll
[2013.01.06 02:58:38 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2013.01.06 02:58:38 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_41.dll
[2013.01.06 02:58:38 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2013.01.06 02:58:37 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll
[2013.01.06 02:58:37 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll
[2013.01.06 02:58:37 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2013.01.06 02:58:36 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2013.01.06 02:58:36 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2013.01.06 02:58:36 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll
[2013.01.06 02:58:36 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll
[2013.01.06 02:58:35 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2013.01.06 02:58:35 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2013.01.06 02:58:35 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2013.01.06 02:58:34 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2013.01.06 02:58:34 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2013.01.06 02:58:32 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2013.01.06 02:31:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2013.01.06 02:30:02 | 000,242,240 | ---- | C] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2013.01.06 02:29:57 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\DAEMON Tools Lite
[2013.01.06 02:18:14 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2013.01.06 00:58:20 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\FalloutNV
[2013.01.06 00:56:31 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\SCE
[2013.01.06 00:30:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013.01.06 00:19:41 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2013.01.06 00:18:41 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2013.01.06 00:18:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2013.01.06 00:16:18 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2013.01.05 23:55:04 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\Microsoft Help
[2013.01.05 23:54:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2013.01.05 23:36:57 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2013.01.05 23:13:07 | 000,000,000 | ---D | C] -- C:\Program Files\SEGA
[2013.01.05 22:04:24 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\vlc
[2013.01.05 20:44:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows - LIVE
[2013.01.05 20:40:43 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games for Windows - LIVE
[2013.01.05 20:03:10 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\Fallout3
[2013.01.05 19:31:39 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\InstallShield Installation Information
[2013.01.05 19:30:34 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll
[2013.01.05 19:30:34 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll
[2013.01.05 19:30:33 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll
[2013.01.05 19:30:32 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll
[2013.01.05 19:30:32 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll
[2013.01.05 19:30:31 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll
[2013.01.05 19:30:30 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll
[2013.01.05 19:30:28 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll
[2013.01.05 19:30:26 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll
[2013.01.05 19:30:26 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll
[2013.01.05 19:30:26 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll
[2013.01.05 19:30:26 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll
[2013.01.05 19:30:26 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll
[2013.01.05 19:30:23 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_10.dll
[2013.01.05 19:30:19 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_36.dll
[2013.01.05 19:30:19 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_36.dll
[2013.01.05 19:30:17 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_36.dll
[2013.01.05 19:30:13 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_9.dll
[2013.01.05 19:30:12 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll
[2013.01.05 19:30:12 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll
[2013.01.05 19:30:11 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_35.dll
[2013.01.05 19:30:08 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll
[2013.01.05 19:30:08 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll
[2013.01.05 19:30:08 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll
[2013.01.05 19:30:08 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_2.dll
[2013.01.05 19:30:07 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll
[2013.01.05 19:30:06 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll
[2013.01.05 19:30:00 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll
[2013.01.05 19:29:56 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll
[2013.01.05 19:29:56 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll
[2013.01.05 19:29:55 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll
[2013.01.05 19:29:50 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll
[2013.01.05 19:29:50 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll
[2013.01.05 19:29:49 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll
[2013.01.05 19:29:48 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll
[2013.01.05 19:29:47 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll
[2013.01.05 19:29:47 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll
[2013.01.05 19:29:46 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_1.dll
[2013.01.05 19:29:44 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_1.dll
[2013.01.05 19:29:07 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll
[2013.01.05 19:29:00 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_0.dll
[2013.01.05 19:29:00 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_0.dll
[2013.01.05 19:28:59 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_29.dll
[2013.01.05 19:28:58 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2013.01.05 19:28:56 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_27.dll
[2013.01.05 19:28:55 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_26.dll
[2013.01.05 19:28:54 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll
[2013.01.05 19:28:53 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_24.dll
[2013.01.05 19:24:11 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll
[2013.01.05 19:24:11 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll
[2013.01.05 19:24:10 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll
[2013.01.05 19:23:55 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll
[2013.01.05 19:21:48 | 000,000,000 | ---D | C] -- C:\Windows\System32\xlive
[2013.01.05 19:18:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2013.01.05 19:14:30 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2013.01.05 18:50:59 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\OpenOffice.org
[2013.01.05 18:50:14 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4.1
[2013.01.05 18:48:31 | 000,000,000 | ---D | C] -- C:\Program Files\OpenOffice.org 3
[2013.01.05 03:30:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2013.01.05 03:29:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013.01.05 03:29:00 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2013.01.05 03:26:09 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\ElevatedDiagnostics
[2013.01.05 03:24:04 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
[2013.01.05 03:24:03 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\rdpvideominiport.sys
[2013.01.05 03:24:00 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
[2013.01.05 03:24:00 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RdpGroupPolicyExtension.dll
[2013.01.05 03:23:58 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\TsUsbFlt.sys
[2013.01.05 03:23:58 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\TsUsbGD.sys
[2013.01.05 03:23:51 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsRdpWebAccess.dll
[2013.01.05 03:23:51 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsgqec.dll
[2013.01.05 03:23:51 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbGDCoInstaller.dll
[2013.01.05 03:23:51 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprtPS.dll
[2013.01.05 03:23:50 | 002,739,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll
[2013.01.05 03:23:50 | 000,317,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprt.exe
[2013.01.05 03:23:50 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll
[2013.01.05 03:23:50 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpudd.dll
[2013.01.05 03:23:50 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpendp_winip.dll
[2013.01.05 03:23:50 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSWbPrxy.exe
[2013.01.05 03:22:36 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2013.01.05 03:22:35 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2013.01.05 02:13:13 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.01.05 02:13:11 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.01.05 02:13:11 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.01.05 02:13:10 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.01.05 02:13:10 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.01.05 02:13:09 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.01.05 02:13:09 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.01.05 02:13:07 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.01.05 01:25:41 | 000,148,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\storport.sys
[2013.01.05 01:25:41 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fsutil.exe
[2013.01.05 01:25:07 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbport.sys
[2013.01.05 01:25:07 | 000,005,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbd.sys
[2013.01.05 00:51:15 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2013.01.05 00:47:01 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\Apple Computer
[2013.01.05 00:30:44 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2013.01.05 00:30:44 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2013.01.05 00:30:44 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2013.01.04 23:26:44 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Apple Computer
[2013.01.04 23:06:41 | 000,047,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\WdfLdr.sys
[2013.01.04 23:06:41 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wdfres.dll
[2013.01.04 23:04:44 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFPlatform.dll
[2013.01.04 23:04:41 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFx.dll
[2013.01.04 23:04:41 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFCoinstaller.dll
[2013.01.04 22:49:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013.01.04 22:48:19 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013.01.04 22:48:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2013.01.04 22:48:18 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013.01.04 22:45:23 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\Apple
[2013.01.04 22:45:15 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2013.01.04 22:42:05 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2013.01.04 22:38:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2013.01.04 22:38:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2013.01.04 22:07:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam
[2013.01.04 21:18:33 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2013.01.04 21:18:33 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013.01.04 21:18:27 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2013.01.04 21:18:27 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2013.01.04 21:18:27 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2013.01.04 21:18:27 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013.01.04 21:18:27 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2013.01.04 21:18:27 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2013.01.04 21:18:27 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2013.01.04 21:18:27 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2013.01.04 21:18:17 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2013.01.04 21:18:17 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2013.01.04 21:18:17 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2013.01.04 21:18:17 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2013.01.04 21:18:17 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2013.01.04 21:18:17 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2013.01.04 21:18:17 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013.01.04 21:18:17 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013.01.04 21:18:17 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013.01.04 21:18:16 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2013.01.04 21:18:15 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2013.01.04 21:18:14 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2013.01.04 21:18:13 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2013.01.04 21:18:12 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2013.01.04 21:18:12 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2013.01.04 21:18:12 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2013.01.04 21:18:12 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2013.01.04 21:18:12 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2013.01.04 21:18:12 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2013.01.04 20:31:54 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browserchoice.exe
[2013.01.04 18:27:46 | 000,232,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2013.01.04 03:47:53 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Desktop\Call of duty 4
[2013.01.04 03:40:13 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\RNDISMP.sys
[2013.01.04 03:39:19 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnet.dll
[2013.01.04 03:39:17 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prevhost.exe
[2013.01.04 03:38:42 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2013.01.04 03:38:12 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2013.01.04 03:38:12 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2013.01.04 03:38:09 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl
[2013.01.04 03:38:04 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OxpsConverter.exe
[2013.01.04 03:37:46 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3r.dll
[2013.01.04 03:37:21 | 000,240,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2013.01.04 03:37:21 | 000,187,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2013.01.04 03:37:21 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcorehc.dll
[2013.01.04 03:37:21 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncsi.dll
[2013.01.04 03:37:20 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netevent.dll
[2013.01.04 03:37:12 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\WinRAR
[2013.01.04 03:37:12 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013.01.04 03:37:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013.01.04 03:37:11 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2013.01.04 03:37:11 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2013.01.04 03:37:10 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2013.01.04 03:37:10 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2013.01.04 03:37:10 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2013.01.04 03:37:10 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2013.01.04 03:37:09 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2013.01.04 03:37:07 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll
[2013.01.04 03:37:03 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2013.01.04 03:37:02 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSCOVER.exe
[2013.01.04 03:36:59 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
[2013.01.04 03:36:58 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2013.01.04 03:36:57 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll
[2013.01.04 03:36:55 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2013.01.04 03:36:52 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2013.01.04 03:36:52 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2013.01.04 03:36:52 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2013.01.04 03:36:50 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2013.01.04 03:36:41 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2013.01.04 03:36:31 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2013.01.04 03:36:16 | 002,616,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2013.01.04 03:35:52 | 003,968,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2013.01.04 03:35:52 | 003,914,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013.01.04 03:35:47 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2013.01.04 03:35:44 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll
[2013.01.04 03:35:44 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2013.01.04 03:35:42 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcjt32.dll
[2013.01.04 03:35:42 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbctrac.dll
[2013.01.04 03:35:42 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccp32.dll
[2013.01.04 03:35:42 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccu32.dll
[2013.01.04 03:35:42 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccr32.dll
[2013.01.04 03:35:41 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2013.01.04 03:35:37 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2013.01.04 03:35:37 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2013.01.04 03:35:37 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2013.01.04 03:35:31 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll
[2013.01.04 03:35:27 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2013.01.04 03:35:25 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcore6.dll
[2013.01.04 03:35:25 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc6.dll
[2013.01.04 03:35:09 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2013.01.04 03:35:09 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2013.01.04 03:35:02 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\poqexec.exe
[2013.01.04 03:35:02 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys
[2013.01.04 03:34:54 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2013.01.04 03:34:18 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2013.01.04 03:19:35 | 000,219,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2013.01.04 02:54:50 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\PunkBuster
[2013.01.04 02:50:48 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Desktop\inYourFace
[2013.01.04 01:47:25 | 000,000,000 | ---D | C] -- C:\Program Files\GUILD WARS
[2013.01.04 01:43:31 | 000,000,000 | ---D | C] -- C:\Program Files\fallout3
[2013.01.04 01:36:44 | 000,000,000 | ---D | C] -- C:\Program Files\Fallout New Vegas2
[2013.01.04 01:27:23 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Xfire
[2013.01.04 01:26:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire
[2013.01.04 01:26:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Xfire
[2013.01.04 01:19:21 | 000,000,000 | ---D | C] -- C:\Program Files\COD4
[2013.01.04 01:15:00 | 000,000,000 | ---D | C] -- C:\Program Files\VideoConverter
[2013.01.04 01:14:52 | 000,000,000 | ---D | C] -- C:\Program Files\TrackMania
[2013.01.04 01:14:51 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2013.01.04 01:14:36 | 000,000,000 | ---D | C] -- C:\Program Files\Xfire
[2013.01.03 22:13:41 | 000,000,000 | ---D | C] -- C:\Program Files\LOLReplay
[2013.01.03 21:47:34 | 000,000,000 | ---D | C] -- C:\Program Files\Tomb Raider - Anniversary
[2013.01.03 21:47:31 | 000,000,000 | ---D | C] -- C:\Program Files\TCX Converter
[2013.01.03 21:47:31 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2013.01.03 21:47:28 | 000,000,000 | ---D | C] -- C:\Program Files\Skype
[2013.01.03 21:47:10 | 000,000,000 | ---D | C] -- C:\Program Files\Sandisk
[2013.01.03 21:46:53 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
[2013.01.03 21:46:53 | 000,000,000 | ---D | C] -- C:\Program Files\Origin Games
[2013.01.03 21:46:38 | 000,000,000 | ---D | C] -- C:\Program Files\Origin
[2013.01.03 21:46:29 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
[2013.01.03 21:46:18 | 000,000,000 | ---D | C] -- C:\Program Files\Notepad++
[2013.01.03 21:45:16 | 000,000,000 | ---D | C] -- C:\Program Files\Nero
[2013.01.03 21:45:02 | 000,000,000 | ---D | C] -- C:\Program Files\MOUSE Editor
[2013.01.03 21:43:14 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2013.01.03 21:31:38 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013.01.03 21:31:12 | 000,000,000 | ---D | C] -- C:\Program Files\Mass Effect 2
[2013.01.03 21:25:55 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\LolClient
[2013.01.03 21:25:53 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Macromedia
[2013.01.03 21:25:50 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Adobe
[2013.01.03 21:25:21 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\Google
[2013.01.03 21:23:15 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Desktop\Neuer Ordner
[2013.01.03 21:21:07 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2013.01.03 21:21:07 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2013.01.03 21:21:07 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2013.01.03 21:21:07 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2013.01.03 21:21:07 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2013.01.03 21:19:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2013.01.03 21:19:34 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2013.01.03 21:19:00 | 000,000,000 | ---D | C] -- C:\Program Files\Mass Effect
[2013.01.03 21:17:21 | 000,000,000 | ---D | C] -- C:\Program Files\LucasArts
[2013.01.03 21:14:56 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013.01.03 21:14:13 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2013.01.03 21:14:08 | 000,000,000 | ---D | C] -- C:\Program Files\Garmin
[2013.01.03 21:14:08 | 000,000,000 | ---D | C] -- C:\Program Files\Freemium
[2013.01.03 21:14:06 | 000,000,000 | ---D | C] -- C:\Program Files\Free Video Joiner
[2013.01.03 21:13:55 | 000,000,000 | ---D | C] -- C:\Program Files\Free Video Converter
[2013.01.03 21:09:58 | 000,000,000 | ---D | C] -- C:\Program Files\EA Sports
[2013.01.03 21:09:55 | 000,000,000 | ---D | C] -- C:\Program Files\Defraggler
[2013.01.03 21:09:54 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013.01.03 21:06:43 | 000,000,000 | ---D | C] -- C:\Program Files\Bethesda Softworks
[2013.01.03 21:06:19 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2013.01.03 21:01:47 | 000,000,000 | ---D | C] -- C:\Program Files\Alldj_DVD_Ripper_Platium
[2013.01.03 20:42:26 | 000,088,632 | ---- | C] (Infowatch) -- C:\Windows\System32\drivers\CSCrySec.sys
[2013.01.03 20:42:26 | 000,039,352 | ---- | C] (Infowatch) -- C:\Windows\System32\drivers\CSVirtualDiskDrv.sys
[2013.01.03 20:42:26 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2013.01.03 20:41:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InfoWatch
[2013.01.03 20:41:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky PURE
[2013.01.03 20:41:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2013.01.03 20:41:44 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
[2013.01.03 20:41:34 | 000,311,312 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys
[2013.01.03 20:40:33 | 777,027,962 | ---- | C] (Epic Games ) -- C:\Users\Rupert Niko\Documents\ut3betademo_4p.exe
[2013.01.03 20:40:28 | 133,437,288 | ---- | C] (Caligari ) -- C:\Users\Rupert Niko\Documents\tS76.exe
[2013.01.03 20:40:18 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Xfire
[2013.01.03 20:39:55 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Wolf
[2013.01.03 20:39:55 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Video Converter
[2013.01.03 20:39:52 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2013.01.03 20:39:24 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\TubeBox!
[2013.01.03 20:38:13 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\TubeBox
[2013.01.03 20:38:13 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Tomb Raider - Legend
[2013.01.03 20:38:11 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Saves
[2013.01.03 20:38:05 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Sansa Media Converter
[2013.01.03 20:38:04 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Documents\Notes
[2013.01.03 20:38:04 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\NWT
[2013.01.03 20:38:02 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\NeroVision
[2013.01.03 20:38:02 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Nero Recode
[2013.01.03 20:36:50 | 000,000,000 | --SD | C] -- C:\Users\Rupert Niko\Documents\My DocsToGo
[2013.01.03 20:36:50 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\My Games
[2013.01.03 20:36:50 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Mein Garmin
[2013.01.03 20:36:50 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\MAGIX_Music_Maker_17
[2013.01.03 20:36:50 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\MAGIX Downloads
[2013.01.03 20:36:38 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\LOLReplay
[2013.01.03 20:36:38 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Jack Keane
[2013.01.03 20:36:38 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\iTSfv
[2013.01.03 20:36:38 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\ICQ
[2013.01.03 20:36:38 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\GUILD WARS
[2013.01.03 20:36:37 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\gmka
[2013.01.03 20:36:37 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Eidos
[2013.01.03 20:36:37 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\DVDVideoSoft
[2013.01.03 20:36:37 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\DVDFab Passkey
[2013.01.03 20:36:37 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\DVDFab
[2013.01.03 20:36:37 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Comic Life
[2013.01.03 20:36:37 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Borland Studio Projects
[2013.01.03 20:36:32 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\BioWare
[2013.01.03 20:36:31 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Documents\Bildlenoten
[2013.01.03 20:36:25 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Battlefield 2142
[2013.01.03 20:36:21 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Battlefield 2
[2013.01.03 20:36:21 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Audible
[2013.01.03 20:36:21 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Applications
[2013.01.03 20:36:21 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\AnyDVDHD
[2013.01.03 20:36:19 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\alles mögliches
[2013.01.03 20:36:19 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\Alcohol 120%
[2013.01.03 20:36:18 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\Documents\4A Games
[2013.01.03 20:34:16 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll
[2013.01.03 20:34:07 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\MigWiz
[2013.01.03 20:30:41 | 002,422,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2013.01.03 20:30:41 | 000,045,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2013.01.03 20:30:36 | 000,577,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2013.01.03 20:30:36 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2013.01.03 20:30:36 | 000,035,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2013.01.03 20:30:15 | 000,171,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2013.01.03 20:30:15 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2013.01.03 20:29:56 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013.01.03 20:29:56 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Searches
[2013.01.03 20:29:56 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013.01.03 20:29:49 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Identities
[2013.01.03 20:29:47 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Contacts
[2013.01.03 20:29:43 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\VirtualStore
[2013.01.03 20:29:42 | 000,000,000 | --SD | C] -- C:\Users\Rupert Niko\AppData\Roaming\Microsoft
[2013.01.03 20:29:42 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Videos
[2013.01.03 20:29:42 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Saved Games
[2013.01.03 20:29:42 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Pictures
[2013.01.03 20:29:42 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Music
[2013.01.03 20:29:42 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013.01.03 20:29:42 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Links
[2013.01.03 20:29:42 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Favorites
[2013.01.03 20:29:42 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Downloads
[2013.01.03 20:29:42 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Documents
[2013.01.03 20:29:42 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\Desktop
[2013.01.03 20:29:42 | 000,000,000 | R--D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Vorlagen
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\AppData\Local\Verlauf
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\AppData\Local\Temporary Internet Files
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Startmenü
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\SendTo
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Recent
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Netzwerkumgebung
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Lokale Einstellungen
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Documents\Eigene Videos
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Documents\Eigene Musik
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Eigene Dateien
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Documents\Eigene Bilder
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Druckumgebung
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Cookies
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\AppData\Local\Anwendungsdaten
[2013.01.03 20:29:42 | 000,000,000 | -HSD | C] -- C:\Users\Rupert Niko\Anwendungsdaten
[2013.01.03 20:29:42 | 000,000,000 | -H-D | C] -- C:\Users\Rupert Niko\AppData
[2013.01.03 20:29:42 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\Temp
[2013.01.03 20:29:42 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Local\Microsoft
[2013.01.03 20:29:42 | 000,000,000 | ---D | C] -- C:\Users\Rupert Niko\AppData\Roaming\Media Center Programs
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\Recovery
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\Programme
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2013.01.03 20:29:29 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2013.01.03 20:17:38 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2013.01.03 20:15:31 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2013.01.03 20:14:42 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2013.01.03 20:13:53 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2013.01.03 20:13:38 | 000,000,000 | -HSD | C] -- C:\Boot
========== Files - Modified Within 30 Days ==========
[2013.02.01 17:56:28 | 000,021,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.02.01 17:56:28 | 000,021,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.02.01 17:48:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.02.01 17:48:54 | 2414,731,264 | -HS- | M] () -- C:\hiberfil.sys
[2013.02.01 17:36:00 | 000,001,144 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-497382121-3916464205-3174431237-1000UA.job
[2013.02.01 15:39:19 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.01.30 20:02:09 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.01.30 20:02:09 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.01.30 20:02:09 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.01.30 20:02:09 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.01.30 19:52:22 | 340,508,784 | ---- | M] () -- C:\Users\Rupert Niko\Documents\X16-69412.exe.dlm
[2013.01.30 19:51:03 | 000,000,585 | ---- | M] () -- C:\Users\Rupert Niko\Desktop\Start Download Manager.html
[2013.01.26 12:44:27 | 000,002,393 | ---- | M] () -- C:\Users\Rupert Niko\Desktop\Google Chrome.lnk
[2013.01.25 06:23:38 | 000,042,880 | ---- | M] () -- C:\Windows\System32\xfcodec.dll
[2013.01.21 19:00:28 | 000,076,343 | ---- | M] () -- C:\Users\Rupert Niko\Desktop\urbans gfs.odt
[2013.01.17 20:33:47 | 000,139,832 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2013.01.17 20:33:41 | 000,281,768 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2013.01.17 20:25:37 | 000,281,768 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2013.01.17 01:28:58 | 000,232,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2013.01.15 19:31:33 | 000,002,737 | ---- | M] () -- C:\Users\Public\Desktop\Mouse Editor.lnk
[2013.01.14 14:48:28 | 000,001,046 | ---- | M] () -- C:\Users\Rupert Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk
[2013.01.12 03:30:20 | 000,094,112 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013.01.12 03:26:16 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013.01.12 03:24:49 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013.01.09 18:24:59 | 000,438,336 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.01.09 16:53:16 | 000,859,072 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2013.01.09 16:53:16 | 000,779,704 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2013.01.08 00:35:07 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-497382121-3916464205-3174431237-1000Core.job
[2013.01.06 18:04:17 | 000,001,072 | ---- | M] () -- C:\Users\Rupert Niko\Desktop\EVEREST Home Edition.lnk
[2013.01.06 02:30:02 | 000,242,240 | ---- | M] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2013.01.05 18:50:14 | 000,001,130 | ---- | M] () -- C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk
[2013.01.05 18:39:28 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013.01.05 18:36:01 | 152,249,762 | ---- | M] () -- C:\Program Files\Apache_OpenOffice_incubating_3.4.1_Win_x86_install_de.exe
[2013.01.05 18:31:25 | 016,381,530 | ---- | M] () -- C:\Users\Rupert Niko\Documents\Sportzusammenfassung-1.rtf
[2013.01.05 03:29:06 | 000,001,815 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013.01.04 22:49:05 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013.01.04 21:18:33 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2013.01.04 21:18:33 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013.01.04 21:18:27 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2013.01.04 21:18:27 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2013.01.04 21:18:27 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2013.01.04 21:18:27 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013.01.04 21:18:27 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2013.01.04 21:18:27 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2013.01.04 21:18:27 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2013.01.04 21:18:27 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2013.01.04 21:18:17 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2013.01.04 21:18:17 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2013.01.04 21:18:17 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2013.01.04 21:18:17 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2013.01.04 21:18:17 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2013.01.04 21:18:17 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2013.01.04 21:18:17 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013.01.04 21:18:17 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013.01.04 21:18:17 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2013.01.04 21:18:17 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013.01.04 21:18:16 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2013.01.04 21:18:15 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2013.01.04 21:18:14 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2013.01.04 21:18:13 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2013.01.04 21:18:12 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2013.01.04 21:18:12 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2013.01.04 21:18:12 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2013.01.04 21:18:12 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2013.01.04 21:18:12 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2013.01.04 21:18:12 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2013.01.04 01:26:28 | 000,000,929 | ---- | M] () -- C:\Users\Public\Desktop\Xfire.lnk
[2013.01.03 22:13:42 | 000,001,939 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\LOLRecorder.lnk
[2013.01.03 22:13:42 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\LOL Recorder.lnk
[2013.01.03 21:21:07 | 000,000,805 | ---- | M] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
[2013.01.03 21:07:02 | 000,116,189 | ---- | M] () -- C:\Windows\System32\drivers\klin.dat
[2013.01.03 21:07:02 | 000,098,168 | ---- | M] () -- C:\Windows\System32\drivers\klick.dat
[2013.01.03 20:41:34 | 000,311,312 | ---- | M] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys
[2013.01.03 20:19:14 | 000,055,513 | ---- | M] () -- C:\Windows\System32\license.rtf
[2013.01.03 20:18:33 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013.01.03 20:17:29 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2013.01.03 20:17:29 | 000,000,000 | ---- | M] () -- C:\Windows\System32\atiicdxx.dat
[2013.01.03 20:13:40 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
========== Files Created - No Company Name ==========
[2013.02.01 15:39:19 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.01.30 19:51:02 | 340,508,784 | ---- | C] () -- C:\Users\Rupert Niko\Documents\X16-69412.exe.dlm
[2013.01.30 19:50:57 | 000,000,585 | ---- | C] () -- C:\Users\Rupert Niko\Desktop\Start Download Manager.html
[2013.01.25 06:23:38 | 000,042,880 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2013.01.21 18:29:38 | 000,076,343 | ---- | C] () -- C:\Users\Rupert Niko\Desktop\urbans gfs.odt
[2013.01.15 19:31:32 | 000,002,737 | ---- | C] () -- C:\Users\Public\Desktop\Mouse Editor.lnk
[2013.01.14 14:48:28 | 000,001,046 | ---- | C] () -- C:\Users\Rupert Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk
[2013.01.06 18:04:17 | 000,001,072 | ---- | C] () -- C:\Users\Rupert Niko\Desktop\EVEREST Home Edition.lnk
[2013.01.06 13:22:05 | 000,139,832 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2013.01.06 00:54:07 | 000,281,768 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2013.01.06 00:54:07 | 000,281,768 | ---- | C] () -- C:\Windows\System32\PnkBstrB.ex0
[2013.01.06 00:53:46 | 000,281,768 | ---- | C] () -- C:\Windows\System32\PnkBstrB.xtr
[2013.01.06 00:53:40 | 000,076,888 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2013.01.06 00:29:45 | 002,900,505 | ---- | C] () -- C:\Users\Rupert Niko\Desktop\L1060940.JPG
[2013.01.05 18:50:14 | 000,001,130 | ---- | C] () -- C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk
[2013.01.05 18:39:28 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013.01.05 18:34:06 | 152,249,762 | ---- | C] () -- C:\Program Files\Apache_OpenOffice_incubating_3.4.1_Win_x86_install_de.exe
[2013.01.05 18:31:25 | 016,381,530 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Sportzusammenfassung-1.rtf
[2013.01.05 03:29:06 | 000,001,815 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013.01.04 23:06:59 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013.01.04 23:04:40 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013.01.04 22:49:05 | 000,001,753 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013.01.04 22:45:15 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013.01.04 21:18:17 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2013.01.04 01:26:28 | 000,000,929 | ---- | C] () -- C:\Users\Public\Desktop\Xfire.lnk
[2013.01.03 22:13:42 | 000,001,939 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\LOLRecorder.lnk
[2013.01.03 22:13:42 | 000,001,859 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LOL Recorder.lnk
[2013.01.03 22:13:42 | 000,001,847 | ---- | C] () -- C:\Users\Public\Desktop\LOL Recorder.lnk
[2013.01.03 21:32:06 | 000,002,393 | ---- | C] () -- C:\Users\Rupert Niko\Desktop\Google Chrome.lnk
[2013.01.03 21:25:25 | 000,001,144 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-497382121-3916464205-3174431237-1000UA.job
[2013.01.03 21:25:23 | 000,001,092 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-497382121-3916464205-3174431237-1000Core.job
[2013.01.03 21:21:07 | 000,000,805 | ---- | C] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
[2013.01.03 20:42:42 | 000,116,189 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2013.01.03 20:42:42 | 000,098,168 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2013.01.03 20:41:02 | 001,313,792 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Viana364.exe
[2013.01.03 20:41:00 | 028,032,080 | ---- | C] () -- C:\Users\Rupert Niko\Documents\UT3Demo.exe
[2013.01.03 20:40:33 | 003,196,451 | ---- | C] () -- C:\Users\Rupert Niko\Documents\unitag_flyer_2011.pdf
[2013.01.03 20:40:33 | 000,000,816 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Universal Soldier.tbc
[2013.01.03 20:40:28 | 003,320,642 | ---- | C] () -- C:\Users\Rupert Niko\Documents\test2011-08-28T15_4.tcx
[2013.01.03 20:40:28 | 000,962,586 | ---- | C] () -- C:\Users\Rupert Niko\Documents\PAPA25.09.2011 17_05_24_history.tcx
[2013.01.03 20:40:28 | 000,392,520 | ---- | C] () -- C:\Users\Rupert Niko\Documents\portal.jpg
[2013.01.03 20:40:28 | 000,063,135 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Rupertbayern.zip
[2013.01.03 20:40:28 | 000,009,592 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Track.gdb
[2013.01.03 20:40:28 | 000,000,914 | ---- | C] () -- C:\Users\Rupert Niko\Documents\shyvana.LRI
[2013.01.03 20:40:28 | 000,000,824 | ---- | C] () -- C:\Users\Rupert Niko\Documents\The Fighters.tbc
[2013.01.03 20:40:28 | 000,000,704 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Pulp Fiction Englisch.tbc
[2013.01.03 20:40:28 | 000,000,445 | ---- | C] () -- C:\Users\Rupert Niko\Documents\poppydominion.LRI
[2013.01.03 20:40:28 | 000,000,444 | ---- | C] () -- C:\Users\Rupert Niko\Documents\TEst2.o
[2013.01.03 20:40:28 | 000,000,173 | ---- | C] () -- C:\Users\Rupert Niko\Documents\test3.c
[2013.01.03 20:40:28 | 000,000,151 | ---- | C] () -- C:\Users\Rupert Niko\Documents\test.cpp
[2013.01.03 20:40:28 | 000,000,082 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Test.c
[2013.01.03 20:40:28 | 000,000,018 | ---- | C] () -- C:\Users\Rupert Niko\Documents\TEst2.cpp
[2013.01.03 20:40:27 | 004,158,021 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Papa3.7.11.tcx
[2013.01.03 20:40:27 | 000,972,427 | ---- | C] () -- C:\Users\Rupert Niko\Documents\PAPA18.09.2011 16_48_32_history.tcx
[2013.01.03 20:40:27 | 000,781,354 | ---- | C] () -- C:\Users\Rupert Niko\Documents\PAPA08.10.2011 17_55_06_history.tcx
[2013.01.03 20:40:27 | 000,678,948 | ---- | C] () -- C:\Users\Rupert Niko\Documents\PAPA03.10.2011 17_35_53_history.tcx
[2013.01.03 20:40:26 | 000,566,293 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Coalesced.ini
[2013.01.03 20:40:26 | 000,392,520 | ---- | C] () -- C:\Users\Rupert Niko\Documents\cod4frag.jpg
[2013.01.03 20:40:26 | 000,046,883 | ---- | C] () -- C:\Users\Rupert Niko\Documents\MassEffectKonfigurationsbericht2011-06-22.xml
[2013.01.03 20:40:26 | 000,001,260 | ---- | C] () -- C:\Users\Rupert Niko\Documents\fluch der Karibik.tbc
[2013.01.03 20:40:26 | 000,000,824 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Hallo.dev
[2013.01.03 20:40:26 | 000,000,767 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Makefile.win
[2013.01.03 20:40:26 | 000,000,740 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Bad Boys 2.tbc
[2013.01.03 20:40:26 | 000,000,663 | ---- | C] () -- C:\Users\Rupert Niko\Documents\ashe.LRI
[2013.01.03 20:40:26 | 000,000,480 | ---- | C] () -- C:\Users\Rupert Niko\Documents\nocturne.LRI
[2013.01.03 20:40:26 | 000,000,410 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Cloverfield.tbc
[2013.01.03 20:40:26 | 000,000,145 | ---- | C] () -- C:\Users\Rupert Niko\Documents\main.c
[2013.01.03 20:40:23 | 113,740,808 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Antigone.comicdoc
[2013.01.03 20:40:23 | 003,521,733 | ---- | C] () -- C:\Users\Rupert Niko\Documents\2011-05-08T16_3gekürzt.tcx
[2013.01.03 20:40:23 | 002,673,660 | ---- | C] () -- C:\Users\Rupert Niko\Documents\30.07.2011 10_49_47_history.tcx
[2013.01.03 20:40:23 | 002,044,018 | ---- | C] () -- C:\Users\Rupert Niko\Documents\31.05.2011 18_34_53_history.tcx
[2013.01.03 20:40:23 | 000,845,114 | ---- | C] () -- C:\Users\Rupert Niko\Documents\29.12.2010 15_39_59_history.tcx
[2013.01.03 20:40:23 | 000,701,219 | ---- | C] () -- C:\Users\Rupert Niko\Documents\29.10.2011 16_03_17_history.tcx
[2013.01.03 20:40:23 | 000,605,250 | ---- | C] () -- C:\Users\Rupert Niko\Documents\31.12.2010 16_19_48_history.tcx
[2013.01.03 20:40:23 | 000,490,585 | ---- | C] () -- C:\Users\Rupert Niko\Documents\28.12.2011 14_04_38_history.tcx
[2013.01.03 20:40:23 | 000,462,778 | ---- | C] () -- C:\Users\Rupert Niko\Documents\28.09.2011 19_22_56_history.tcx
[2013.01.03 20:40:23 | 000,291,214 | ---- | C] () -- C:\Users\Rupert Niko\Documents\31.01.2012 18_38_34_history.tcx
[2013.01.03 20:40:23 | 000,001,636 | ---- | C] () -- C:\Users\Rupert Niko\Documents\30.04.2011 16_03_13_history.tcx
[2013.01.03 20:40:23 | 000,001,635 | ---- | C] () -- C:\Users\Rupert Niko\Documents\29.03.2011 18_32_14_history.tcx
[2013.01.03 20:40:23 | 000,000,696 | ---- | C] () -- C:\Users\Rupert Niko\Documents\ahri.LRI
[2013.01.03 20:40:22 | 004,355,627 | ---- | C] () -- C:\Users\Rupert Niko\Documents\28.08.2011PAPA 17_45_24_history.tcx
[2013.01.03 20:40:22 | 003,284,207 | ---- | C] () -- C:\Users\Rupert Niko\Documents\28.05.2011 16_05_35_history.tcx
[2013.01.03 20:40:22 | 002,444,266 | ---- | C] () -- C:\Users\Rupert Niko\Documents\26.07.2011 18_32_19_history.tcx
[2013.01.03 20:40:22 | 001,985,698 | ---- | C] () -- C:\Users\Rupert Niko\Documents\27.08.2011 16_02_07_history.tcx
[2013.01.03 20:40:22 | 001,982,930 | ---- | C] () -- C:\Users\Rupert Niko\Documents\28.06.2011 18_33_59_history.tcx
[2013.01.03 20:40:22 | 000,829,996 | ---- | C] () -- C:\Users\Rupert Niko\Documents\27.12.2010 10_08_13_history.tcx
[2013.01.03 20:40:22 | 000,685,240 | ---- | C] () -- C:\Users\Rupert Niko\Documents\26.12.2010 11_43_35_history.tcx
[2013.01.03 20:40:22 | 000,685,240 | ---- | C] () -- C:\Users\Rupert Niko\Documents\26.12.2010 11_43_35_history.gpx
[2013.01.03 20:40:22 | 000,608,859 | ---- | C] () -- C:\Users\Rupert Niko\Documents\27.02.2011 17_17_09_history.tcx
[2013.01.03 20:40:22 | 000,506,432 | ---- | C] () -- C:\Users\Rupert Niko\Documents\25.01.2011 18_32_01_history.tcx
[2013.01.03 20:40:22 | 000,483,793 | ---- | C] () -- C:\Users\Rupert Niko\Documents\24.03.2011 18_49_52_history.tcx
[2013.01.03 20:40:22 | 000,441,524 | ---- | C] () -- C:\Users\Rupert Niko\Documents\23.02.2011 19_40_08_history.tcx
[2013.01.03 20:40:22 | 000,298,864 | ---- | C] () -- C:\Users\Rupert Niko\Documents\22.09.2011 18_23_57_history.tcx
[2013.01.03 20:40:22 | 000,293,049 | ---- | C] () -- C:\Users\Rupert Niko\Documents\24.09.2011 16_01_25_history.tcx
[2013.01.03 20:40:22 | 000,243,820 | ---- | C] () -- C:\Users\Rupert Niko\Documents\22.09.2011 16_48_25_history.tcx
[2013.01.03 20:40:22 | 000,040,865 | ---- | C] () -- C:\Users\Rupert Niko\Documents\22.09.2011 18_18_03_history.tcx
[2013.01.03 20:40:22 | 000,001,636 | ---- | C] () -- C:\Users\Rupert Niko\Documents\23.04.2011 16_03_15_history.tcx
[2013.01.03 20:40:22 | 000,001,634 | ---- | C] () -- C:\Users\Rupert Niko\Documents\27.03.2011 15_33_10_history.tcx
[2013.01.03 20:40:22 | 000,001,634 | ---- | C] () -- C:\Users\Rupert Niko\Documents\26.04.2011 20_14_01_history.tcx
[2013.01.03 20:40:21 | 003,916,358 | ---- | C] () -- C:\Users\Rupert Niko\Documents\16.07.2011 16_02_46_history.tcx
[2013.01.03 20:40:21 | 003,654,376 | ---- | C] () -- C:\Users\Rupert Niko\Documents\15.05.2011 18_35_43_history.tcx
[2013.01.03 20:40:21 | 003,449,196 | ---- | C] () -- C:\Users\Rupert Niko\Documents\22.05.2011 09_00_00_history.tcx
[2013.01.03 20:40:21 | 002,990,898 | ---- | C] () -- C:\Users\Rupert Niko\Documents\13.08.2011 19_22_42_history.tcx
[2013.01.03 20:40:21 | 002,479,692 | ---- | C] () -- C:\Users\Rupert Niko\Documents\16.02.2011 19_31_39_history.tcx
[2013.01.03 20:40:21 | 002,160,295 | ---- | C] () -- C:\Users\Rupert Niko\Documents\17.05.2011 18_37_03_history.tcx
[2013.01.03 20:40:21 | 002,135,009 | ---- | C] () -- C:\Users\Rupert Niko\Documents\21.07.2011 16_14_20_history.tcx
[2013.01.03 20:40:21 | 001,264,119 | ---- | C] () -- C:\Users\Rupert Niko\Documents\21.05.2011 17_55_36_history.tcx
[2013.01.03 20:40:21 | 000,857,441 | ---- | C] () -- C:\Users\Rupert Niko\Documents\19.03.2011 16_02_40_history.tcx
[2013.01.03 20:40:21 | 000,704,073 | ---- | C] () -- C:\Users\Rupert Niko\Documents\19.02.2011 16_02_06_history.tcx
[2013.01.03 20:40:21 | 000,675,154 | ---- | C] () -- C:\Users\Rupert Niko\Documents\17.04.2012 19_14_39_history.tcx
[2013.01.03 20:40:21 | 000,606,423 | ---- | C] () -- C:\Users\Rupert Niko\Documents\19.01.2011 19_16_07_history.tcx
[2013.01.03 20:40:21 | 000,554,130 | ---- | C] () -- C:\Users\Rupert Niko\Documents\14.01.2011 20_29_20_history.tcx
[2013.01.03 20:40:21 | 000,546,190 | ---- | C] () -- C:\Users\Rupert Niko\Documents\13.09.2011 18_35_15_history.tcx
[2013.01.03 20:40:21 | 000,501,817 | ---- | C] () -- C:\Users\Rupert Niko\Documents\15.10.2011 16_02_42_history.tcx
[2013.01.03 20:40:21 | 000,478,098 | ---- | C] () -- C:\Users\Rupert Niko\Documents\20.12.2011 18_32_36_history.tcx
[2013.01.03 20:40:21 | 000,375,300 | ---- | C] () -- C:\Users\Rupert Niko\Documents\21.01.2012 16_24_25_history.tcx
[2013.01.03 20:40:21 | 000,366,618 | ---- | C] () -- C:\Users\Rupert Niko\Documents\22.02.2011 18_33_10_history.tcx
[2013.01.03 20:40:21 | 000,201,002 | ---- | C] () -- C:\Users\Rupert Niko\Documents\17.06.2011 19_04_44_history.tcx
[2013.01.03 20:40:21 | 000,004,291 | ---- | C] () -- C:\Users\Rupert Niko\Documents\22.04.2011 11_12_46_history.tcx
[2013.01.03 20:40:21 | 000,003,955 | ---- | C] () -- C:\Users\Rupert Niko\Documents\19.07.2011 18_32_48_history.tcx
[2013.01.03 20:40:21 | 000,001,635 | ---- | C] () -- C:\Users\Rupert Niko\Documents\17.04.2011 11_27_06_history.tcx
[2013.01.03 20:40:20 | 004,619,400 | ---- | C] () -- C:\Users\Rupert Niko\Documents\08.05.2011 18_32_04_history.tcx
[2013.01.03 20:40:20 | 004,619,400 | ---- | C] () -- C:\Users\Rupert Niko\Documents\08.05.2011 18_32_04_history (2).tcx
[2013.01.03 20:40:20 | 003,412,692 | ---- | C] () -- C:\Users\Rupert Niko\Documents\11.06.2011 16_03_45_history.tcx
[2013.01.03 20:40:20 | 003,258,528 | ---- | C] () -- C:\Users\Rupert Niko\Documents\10.07.2011 18_37_11_history.tcx
[2013.01.03 20:40:20 | 002,757,972 | ---- | C] () -- C:\Users\Rupert Niko\Documents\13.02.2011 17_43_39_history.tcx
[2013.01.03 20:40:20 | 002,708,503 | ---- | C] () -- C:\Users\Rupert Niko\Documents\11.08.2011 18_30_14_history.tcx
[2013.01.03 20:40:20 | 002,402,413 | ---- | C] () -- C:\Users\Rupert Niko\Documents\10.05.2011 18_35_43_history.tcx
[2013.01.03 20:40:20 | 002,095,238 | ---- | C] () -- C:\Users\Rupert Niko\Documents\07.06.2011 18_35_05_history.tcx
[2013.01.03 20:40:20 | 000,799,903 | ---- | C] () -- C:\Users\Rupert Niko\Documents\12.03.2011 16_02_20_history.tcx
[2013.01.03 20:40:20 | 000,701,660 | ---- | C] () -- C:\Users\Rupert Niko\Documents\05.03.2011 16_01_46_history.tcx
[2013.01.03 20:40:20 | 000,671,531 | ---- | C] () -- C:\Users\Rupert Niko\Documents\06.02.2011 15_59_33_history.tcx
[2013.01.03 20:40:20 | 000,489,352 | ---- | C] () -- C:\Users\Rupert Niko\Documents\05.05.2012 18_42_50_history.tcx
[2013.01.03 20:40:20 | 000,447,813 | ---- | C] () -- C:\Users\Rupert Niko\Documents\08.02.2011 18_31_49_history.tcx
[2013.01.03 20:40:20 | 000,416,531 | ---- | C] () -- C:\Users\Rupert Niko\Documents\11.10.2011 16_09_03_history.tcx
[2013.01.03 20:40:20 | 000,409,767 | ---- | C] () -- C:\Users\Rupert Niko\Documents\07.02.2012 18_35_28_history.tcx
[2013.01.03 20:40:20 | 000,403,541 | ---- | C] () -- C:\Users\Rupert Niko\Documents\08.03.2011 18_32_07_history.tcx
[2013.01.03 20:40:20 | 000,379,361 | ---- | C] () -- C:\Users\Rupert Niko\Documents\11.01.2011 18_33_00_history.tcx
[2013.01.03 20:40:20 | 000,374,169 | ---- | C] () -- C:\Users\Rupert Niko\Documents\04.10.2011 18_32_46_history.tcx
[2013.01.03 20:40:20 | 000,360,332 | ---- | C] () -- C:\Users\Rupert Niko\Documents\06.02.2011 12_00_01_history.tcx
[2013.01.03 20:40:20 | 000,265,195 | ---- | C] () -- C:\Users\Rupert Niko\Documents\06.01.2011 18_32_22_history.tcx
[2013.01.03 20:40:20 | 000,261,036 | ---- | C] () -- C:\Users\Rupert Niko\Documents\11.05.2012 21_19_55_history.tcx
[2013.01.03 20:40:20 | 000,001,960 | ---- | C] () -- C:\Users\Rupert Niko\Documents\10.04.2011 09_30_01_history.tcx
[2013.01.03 20:40:19 | 004,158,021 | ---- | C] () -- C:\Users\Rupert Niko\Documents\03.07.2011 18_12_18_history.tcx
[2013.01.03 20:40:19 | 003,291,041 | ---- | C] () -- C:\Users\Rupert Niko\Documents\04.06.2011 16_04_08_history.tcx
[2013.01.03 20:40:19 | 002,766,496 | ---- | C] () -- C:\Users\Rupert Niko\Documents\03.05.2011 18_34_02_history.tcx
[2013.01.03 20:40:19 | 002,563,071 | ---- | C] () -- C:\Users\Rupert Niko\Documents\02.08.2011 18_34_18_history.tcx
[2013.01.03 20:40:19 | 000,731,316 | ---- | C] () -- C:\Users\Rupert Niko\Documents\01.04.2012 18_17_02_history.tcx
[2013.01.03 20:40:19 | 000,623,151 | ---- | C] () -- C:\Users\Rupert Niko\Documents\04.02.2012 15_59_02_history.tcx
[2013.01.03 20:40:19 | 000,576,892 | ---- | C] () -- C:\Users\Rupert Niko\Documents\02.02.2011 19_25_16_history.tcx
[2013.01.03 20:40:19 | 000,557,013 | ---- | C] () -- C:\Users\Rupert Niko\Documents\03.12.2011 16_02_55_history.tcx
[2013.01.03 20:40:19 | 000,523,944 | ---- | C] () -- C:\Users\Rupert Niko\Documents\02.03.2011 19_18_39_history.tcx
[2013.01.03 20:40:19 | 000,483,239 | ---- | C] () -- C:\Users\Rupert Niko\Documents\02.01.2011 11_08_52_history.tcx
[2013.01.03 20:40:19 | 000,442,672 | ---- | C] () -- C:\Users\Rupert Niko\Documents\03.01.2012 18_34_45_history.tcx
[2013.01.03 20:40:19 | 000,441,427 | ---- | C] () -- C:\Users\Rupert Niko\Documents\01.03.2011 18_31_55_history.tcx
[2013.01.03 20:40:19 | 000,431,030 | ---- | C] () -- C:\Users\Rupert Niko\Documents\04.01.2011 18_34_53_history.tcx
[2013.01.03 20:40:19 | 000,001,634 | ---- | C] () -- C:\Users\Rupert Niko\Documents\03.04.2011 18_15_32_history.tcx
[2013.01.03 20:36:18 | 000,078,904 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Wochenaufsatz.xps
[2013.01.03 20:36:18 | 000,000,456 | ---- | C] () -- C:\Users\Rupert Niko\Documents\Xfire.lnk
[2013.01.03 20:36:18 | 000,000,000 | ---- | C] () -- C:\Users\Rupert Niko\Documents\WinRAR-Archiv (neu).rar
[2013.01.03 20:29:57 | 000,001,413 | ---- | C] () -- C:\Users\Rupert Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013.01.03 20:19:01 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2013.01.03 20:18:54 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2013.01.03 20:18:33 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013.01.03 20:17:29 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013.01.03 20:17:29 | 000,000,000 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2013.01.03 20:14:42 | 2414,731,264 | -HS- | C] () -- C:\hiberfil.sys
[2013.01.03 20:13:40 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2013.01.03 20:13:38 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2011.04.12 02:30:05 | 000,653,928 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2011.04.12 02:30:05 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2011.04.12 02:30:05 | 000,129,800 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2011.04.12 02:30:05 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013.01.09 16:54:13 | 000,000,000 | ---D | M] -- C:\Users\Rupert Niko\AppData\Roaming\.minecraft
[2013.01.06 02:50:49 | 000,000,000 | ---D | M] -- C:\Users\Rupert Niko\AppData\Roaming\DAEMON Tools Lite
[2013.01.03 21:25:55 | 000,000,000 | ---D | M] -- C:\Users\Rupert Niko\AppData\Roaming\LolClient
[2013.01.05 18:50:59 | 000,000,000 | ---D | M] -- C:\Users\Rupert Niko\AppData\Roaming\OpenOffice.org
[2013.01.06 03:11:24 | 000,000,000 | ---D | M] -- C:\Users\Rupert Niko\AppData\Roaming\Ubisoft
========== Purity Check ==========
< End of report > --- --- ---
OTL EXTRAS Logfile: Code:
OTL Extras logfile created on: 01.02.2013 17:59:10 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rupert Niko\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 1,74 Gb Available Physical Memory | 58,03% Memory free
6,00 Gb Paging File | 4,34 Gb Available in Paging File | 72,44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 178,66 Gb Free Space | 39,18% Space Free | Partition Type: NTFS
Drive D: | 732,42 Gb Total Space | 132,62 Gb Free Space | 18,11% Space Free | Partition Type: NTFS
Drive E: | 199,09 Gb Total Space | 28,22 Gb Free Space | 14,18% Space Free | Partition Type: NTFS
Drive F: | 69,71 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive M: | 5,23 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: HOME-PC | User Name: Rupert Niko | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02B32B86-FB4B-4F6C-96E0-C0185A65CC83}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{271CBEA2-552D-4B1B-9402-66383476C904}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{31DF21C9-D5FB-4286-81D8-6C9A04BFA6C2}" = rport=138 | protocol=17 | dir=out | app=system |
"{42D55EA1-E081-4C1B-8764-52465E871D53}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{43F380FD-4877-490F-A4DC-22355E5D9AE6}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{498217D6-1370-4800-BB59-D725460D64A1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{589E783F-C6F6-495E-94DC-8DC38CFB429F}" = lport=10243 | protocol=6 | dir=in | app=system |
"{5CA2CA79-37E4-4E09-A348-E338232FA420}" = rport=10243 | protocol=6 | dir=out | app=system |
"{6B0E2864-064B-4AAC-9DFE-474DAE94FDD5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7F31D7BD-D811-4624-96E0-8A8AB05EC13A}" = lport=139 | protocol=6 | dir=in | app=system |
"{8321B08F-2B6F-4B75-A941-FC5246E4E134}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8D61DBF6-5AA0-40D0-9243-EB02E334DD78}" = lport=445 | protocol=6 | dir=in | app=system |
"{94956392-F3AC-4030-BED3-E710A9F170CE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9A4239BC-C855-4F2A-B7B9-FE6F60575286}" = lport=138 | protocol=17 | dir=in | app=system |
"{9B05F722-5AAA-4380-9461-8085EF8BA93A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9BB88E02-02CC-47E4-AC94-AC08F2AABF2E}" = rport=445 | protocol=6 | dir=out | app=system |
"{9EEB1065-385F-4F33-B904-5ED832F140B3}" = rport=139 | protocol=6 | dir=out | app=system |
"{A813ABCE-E050-4C2E-9174-F38E7C658E86}" = lport=137 | protocol=17 | dir=in | app=system |
"{AFA30BBC-1DB3-4AC0-BB87-69D0A0933C2F}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B1574F00-4E1D-4C32-9C84-EBDE785A6163}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C16FAAE5-4B2D-4303-95DE-BC8CBA64EEAC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C1AB6AEF-D92E-4484-8FB6-76833BE0046C}" = rport=137 | protocol=17 | dir=out | app=system |
"{DC158116-62CB-480A-B198-4DBCC4F194C8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F4ED1ED7-78BF-4DC9-AEC5-44FAE2BBB2B2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{051ABE96-AE22-49F5-B5D3-A59A47D1C022}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{187EB4E1-ABC0-43E3-A5CF-9D1AB7828D7E}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{1E5DFA7D-CCF3-4A39-B1B2-C58D3BDFF3BF}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1F018B6B-78AF-4BC4-9E57-F72367557092}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2D189199-DE1A-4DB1-BCAE-950BBB75E3D7}" = protocol=17 | dir=in | app=d:\anno 2070 again\anno5.exe |
"{38D1CD77-6548-48A4-BEFF-B5404D26B76F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{42912EF0-2CD8-49B1-8FDF-D7C5F2B371F0}" = protocol=6 | dir=in | app=d:\anno 2070 again\initengine.exe |
"{57D5D19A-818A-4F99-AC84-011186A62DED}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5A066EF7-2E78-4D21-B55C-D117F708E032}" = protocol=17 | dir=in | app=d:\anno 2070 again\initengine.exe |
"{6D96D4D6-7FE0-468E-AA62-9C4B9BE91CC8}" = protocol=6 | dir=in | app=l:\c_users_nikolai polley\saved games\steam\steam.exe |
"{6DB3B440-2CF6-4130-83CF-7228734E4E37}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{765EF2CF-7CD7-4AD0-81FD-CDEF6098E5F2}" = protocol=6 | dir=in | app=d:\anno 2070 again\autopatcher.exe |
"{8A981916-B3ED-445A-8B76-A1BA52EF3CCC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{8E45E218-06C7-4B3F-9728-04900F332191}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{916751FF-E9A8-4009-BAA3-02A5FFBF1EE3}" = protocol=6 | dir=out | app=system |
"{9DBF3E74-558E-427B-AD74-1EFD55BE904D}" = protocol=17 | dir=in | app=l:\c_users_nikolai polley\saved games\steam\steam.exe |
"{9E8EA3CA-9E19-4AB0-9EF1-632C24FC27FA}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AAC273CF-E650-419A-99FD-18FF3AEF3E14}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AE853E18-8CCF-4F4D-A829-4853CF2E9A16}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AF14C8A5-2DBF-435C-816D-611D43A7DCD6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B91E1019-0768-4598-AD3B-42DF444C232D}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{C34FC1E2-164F-4595-8328-5723A38813FC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D067D79F-6ABD-448B-9FC8-74D29F37E644}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{D29DE4CC-7932-44BC-8FD2-19422097E3B0}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{D85CF51D-A94E-45B7-9C13-A0B31F5B53B7}" = protocol=6 | dir=in | app=d:\anno 2070 again\anno5.exe |
"{E3F0982C-95F8-4F0B-8058-B8DFB90DA3E7}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E888D2BA-73FA-4E4A-8977-6D5E069C6950}" = protocol=17 | dir=in | app=d:\anno 2070 again\autopatcher.exe |
"{EC2C1C0C-51E7-4AE0-ADE4-B603DDB46476}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F22EF893-ED71-467E-9EFF-A0CB4117B813}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FBA3CDE3-2840-43CC-A70D-7947807FFBD2}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0F5AEBB0-43F3-4571-ACE7-A7942E8AA179}" = Microsoft Application Compatibility Toolkit 5.6
"{1A59064A-12A9-469F-99F6-04BF118DBCFF}" = Kaspersky PURE
"{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 11
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{459699C3-9430-4381-964B-4248D87B49F9}" = Apple Mobile Device Support
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}" = Microsoft Games for Windows - LIVE
"{5DDB3393-E08B-447E-925F-6C00B95D0FE7}" = iCloud
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{72376EB6-0189-45B3-A4F6-823F549697C3}" = MOUSE Editor
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{86085e53-ff85-4daa-835c-50ec31c29f95}.sdb" = xfire
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B0261E53-B6F1-474A-864B-E7C3CBF468E0}" = iTunes
"{B48E264C-C8CD-4617-B0BE-46E977BAD694}" = ANNO 2070
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FD052FB9-FE90-4438-B355-15EDC89D8FB1}" = Microsoft Games for Windows - LIVE Redistributable
"DAEMON Tools Lite" = DAEMON Tools Lite
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"InstallShield_{72376EB6-0189-45B3-A4F6-823F549697C3}" = Mouse Editor
"InstallWIX_{1A59064A-12A9-469F-99F6-04BF118DBCFF}" = Kaspersky PURE
"LOLReplay" = LOLReplay
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"PROR" = Microsoft Office Professional 2007
"WinRAR archiver" = WinRAR 4.20 (32-Bit)
"Xfire" = Xfire
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-497382121-3916464205-3174431237-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"Google Chrome" = Google Chrome
"SOE-PlanetSide 2 PSG" = PlanetSide 2
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 26.01.2013 11:33:52 | Computer Name = Home-PC | Source = WinMgmt | ID = 10
Description =
Error - 26.01.2013 12:09:22 | Computer Name = Home-PC | Source = WinMgmt | ID = 10
Description =
Error - 28.01.2013 08:21:57 | Computer Name = Home-PC | Source = WinMgmt | ID = 10
Description =
Error - 29.01.2013 09:19:33 | Computer Name = Home-PC | Source = WinMgmt | ID = 10
Description =
Error - 29.01.2013 10:41:17 | Computer Name = Home-PC | Source = WinMgmt | ID = 10
Description =
Error - 29.01.2013 16:18:51 | Computer Name = Home-PC | Source = WinMgmt | ID = 10
Description =
Error - 30.01.2013 12:44:13 | Computer Name = Home-PC | Source = WinMgmt | ID = 10
Description =
Error - 31.01.2013 06:19:11 | Computer Name = Home-PC | Source = WinMgmt | ID = 10
Description =
Error - 01.02.2013 08:53:33 | Computer Name = Home-PC | Source = WinMgmt | ID = 10
Description =
Error - 01.02.2013 12:50:42 | Computer Name = Home-PC | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 29.01.2013 09:17:49 | Computer Name = Home-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?28.?01.?2013 um 15:58:09 unerwartet heruntergefahren.
Error - 29.01.2013 11:14:33 | Computer Name = Home-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = Der Speicher wurde beim letzten Leistungsübergang des Systems von
der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte
Firmware verfügbar ist.
Error - 29.01.2013 12:25:24 | Computer Name = Home-PC | Source = DCOM | ID = 10010
Description =
Error - 29.01.2013 16:17:07 | Computer Name = Home-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?29.?01.?2013 um 19:46:33 unerwartet heruntergefahren.
Error - 30.01.2013 15:11:17 | Computer Name = Home-PC | Source = Service Control Manager | ID = 7043
Description = Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements
nicht richtig heruntergefahren werden.
Error - 31.01.2013 06:17:33 | Computer Name = Home-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?30.?01.?2013 um 20:03:21 unerwartet heruntergefahren.
Error - 01.02.2013 08:51:53 | Computer Name = Home-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?31.?01.?2013 um 12:12:21 unerwartet heruntergefahren.
Error - 01.02.2013 09:29:31 | Computer Name = Home-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = Der Speicher wurde beim letzten Leistungsübergang des Systems von
der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte
Firmware verfügbar ist.
Error - 01.02.2013 10:14:41 | Computer Name = Home-PC | Source = DCOM | ID = 10010
Description =
Error - 01.02.2013 10:14:41 | Computer Name = Home-PC | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
von Dienst Netman erreicht.
< End of report > --- --- --- |