Ich habe nun alles eingestellt wie beschrieben,-trotzdem fängt der Text nicht mit "ThreadingModel" = Free an
Meinst du vieleicht ein Vollscan?OTL Logfile: Code:
OTL logfile created on: 08.02.2013 19:23:31 - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Romano\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,99 Gb Total Physical Memory | 2,31 Gb Available Physical Memory | 57,96% Memory free
7,98 Gb Paging File | 6,45 Gb Available in Paging File | 80,78% Paging File free
Paging file location(s): b:\pagefile.sys 4087 4087c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 358,91 Gb Total Space | 285,54 Gb Free Space | 79,56% Space Free | Partition Type: NTFS
Drive D: | 398,72 Gb Total Space | 270,25 Gb Free Space | 67,78% Space Free | Partition Type: NTFS
Drive E: | 100,00 Mb Total Space | 70,25 Mb Free Space | 70,25% Space Free | Partition Type: NTFS
Drive F: | 15,71 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: ROMANO-PC | User Name: Romano | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.02.08 18:00:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Romano\Downloads\OTL(1).exe
PRC - [2012.12.18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.11.30 03:06:58 | 001,263,512 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2012.10.10 21:23:42 | 001,258,856 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.08.18 18:03:20 | 000,143,928 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\ccSvcHst.exe
PRC - [2012.05.10 15:30:40 | 000,018,432 | ---- | M] () -- C:\Users\Romano\AppData\LocalLow\SumatraPDF\IE\SumatraPDFUpdater.exe
PRC - [2011.08.19 08:26:50 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
========== Modules (No Company Name) ==========
MOD - [2012.11.30 03:07:48 | 000,100,248 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2012.11.30 03:06:58 | 001,263,512 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2012.05.30 07:51:08 | 000,699,280 | R--- | M] () -- C:\PROGRAM FILES (X86)\NORTON 360\ENGINE\20.1.0.24\wincfi39.dll
MOD - [2009.03.26 14:46:42 | 000,148,480 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL
MOD - [2009.03.17 11:39:46 | 000,148,992 | ---- | M] () -- C:\Windows\SysWOW64\OemSpiE.dll
MOD - [2009.02.06 18:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL
========== Services (SafeList) ==========
SRV - [2012.12.18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.10.10 21:23:42 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.08.18 18:03:20 | 000,143,928 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\ccSvcHst.exe -- (N360)
SRV - [2012.05.10 15:30:40 | 000,018,432 | ---- | M] () [Auto | Running] -- C:\Users\Romano\AppData\LocalLow\SumatraPDF\IE\SumatraPDFUpdater.exe -- (SumatraPDFUpdater)
SRV - [2011.08.19 08:26:50 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2010.11.20 03:21:38 | 000,351,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.02.04 00:38:36 | 000,095,896 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP2\RpcAgentSrv.exe -- (SandraAgentSrv)
========== Driver Services (SafeList) ==========
DRV:64bit: - File not found [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys -- (AODDriver4.01)
DRV:64bit: - [2013.02.08 13:18:45 | 000,177,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2012.08.10 18:26:44 | 000,776,352 | R--- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\N360x64\1401000.018\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2012.08.07 22:18:20 | 001,132,192 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymEFA64.sys -- (SymEFA)
DRV:64bit: - [2012.08.06 18:24:46 | 000,168,096 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\1401000.018\ccSetx64.sys -- (ccSet_N360)
DRV:64bit: - [2012.07.27 20:25:32 | 000,493,216 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymDS64.sys -- (SymDS)
DRV:64bit: - [2012.07.27 20:05:22 | 000,224,416 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\1401000.018\Ironx64.sys -- (SymIRON)
DRV:64bit: - [2012.07.22 18:34:24 | 000,432,800 | R--- | M] (Symantec Corporation) [Kernel | System | Unknown] -- C:\Windows\SysNative\drivers\N360x64\1401000.018\symnets.sys -- (SymNetS)
DRV:64bit: - [2012.05.24 22:36:56 | 000,037,496 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\1401000.018\srtspx64.sys -- (SRTSPX)
DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.12.19 13:45:22 | 000,146,736 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV:64bit: - [2011.12.16 00:00:09 | 000,132,704 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fltsrv.sys -- (fltsrv)
DRV:64bit: - [2011.11.10 03:12:44 | 000,325,632 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011.10.17 18:40:50 | 000,093,712 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011.08.15 14:51:40 | 000,079,232 | ---- | M] (Fengtao Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dvdfab.sys -- (dvdfab)
DRV:64bit: - [2011.07.08 00:21:28 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011.07.06 11:44:00 | 000,034,288 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2011.04.05 16:35:20 | 000,253,528 | ---- | M] (Sunbelt Software, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SbFw.sys -- (SbFw)
DRV:64bit: - [2011.04.05 16:35:20 | 000,094,296 | ---- | M] (Sunbelt Software, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\sbtis.sys -- (SbTis)
DRV:64bit: - [2011.04.05 16:35:20 | 000,060,504 | ---- | M] (Sunbelt Software, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sbhips.sys -- (sbhips)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.02.08 08:14:20 | 000,084,568 | ---- | M] (Sunbelt Software, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SbFwIm.sys -- (SBFWIMCLMP)
DRV:64bit: - [2011.02.08 08:14:20 | 000,084,568 | ---- | M] (Sunbelt Software, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SbFwIm.sys -- (SBFWIMCL)
DRV:64bit: - [2010.11.20 04:33:36 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 02:07:06 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.05.14 23:02:14 | 006,465,760 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:64bit: - [2010.05.14 23:00:52 | 000,329,952 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2010.05.14 23:00:28 | 000,271,712 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvpopf64.sys -- (lvpopf64)
DRV:64bit: - [2010.03.04 20:43:00 | 000,346,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.08.23 17:55:32 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.13 22:59:33 | 005,020,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009.07.13 22:59:33 | 005,020,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.06.04 03:22:40 | 000,639,512 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\t3.sys -- (t3)
DRV - [2012.12.25 01:00:00 | 002,084,000 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20121225.003\ex64.sys -- (NAVEX15)
DRV - [2012.12.25 01:00:00 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2012.12.25 01:00:00 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys -- (EraserUtilDrv11220)
DRV - [2012.12.25 01:00:00 | 000,126,112 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20121225.003\eng64.sys -- (NAVENG)
DRV - [2012.08.10 18:34:04 | 000,512,672 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20120811.001\IDSVia64.sys -- (IDSVia64)
DRV - [2012.08.10 18:28:34 | 001,385,120 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20120815.002\BHDrvx64.sys -- (BHDrvx64)
DRV - [2010.07.01 18:11:24 | 000,012,352 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Programme\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2009.08.07 22:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP2\WNt500x64\sandra.sys -- (SANDRA)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2000.03.29 15:17:42 | 000,005,824 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\ASUSHWIO.SYS -- (Asushwio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2801948
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.claro-search.com/?affID=118660&tt=0313_4&babsrc=HP_ss&mntrId=60cf961f000000000000d02788140cf1
IE - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 5D 1F 5F ED 43 F4 CD 01 [binary data]
IE - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://www.claro-search.com/?q={searchTerms}&affID=118660&tt=0313_4&babsrc=SP_ss&mntrId=60cf961f000000000000d02788140cf1
IE - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2801948
IE - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/ig"
FF - prefs.js..extensions.enabledAddons: nosquint@urandom.ca:2.1.6
FF - prefs.js..extensions.enabledAddons: ich@maltegoetz.de:1.4.3
FF - prefs.js..extensions.enabledAddons: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:5.1.1
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.11.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.0-git-20120328-0404: C:\Program Files\VideoLAN\VLC\npvlc.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.11.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files (x86)\Magic Video Converter\codec\real\browser\plugins\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files (x86)\Magic Video Converter\codec\real\browser\plugins\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\ [2013.02.08 13:20:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\ [2013.02.08 13:20:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.22 23:58:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.01.11 12:00:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.22 23:58:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.01.11 12:00:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.22 23:58:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.01.11 12:00:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.22 23:58:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.01.11 12:00:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.22 23:58:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.01.11 12:00:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.22 23:58:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.01.11 12:00:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.11.22 23:58:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2013.01.11 12:00:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\addlyrics@addlyrics.net: C:\Users\Romano\AppData\Local\AddLyrics\FF\
[2012.08.01 16:24:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Romano\AppData\Roaming\mozilla\Extensions
[2011.08.24 23:45:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Romano\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013.01.20 20:50:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Romano\AppData\Roaming\mozilla\Firefox\Profiles\2gtd40tb.default\extensions
[2012.12.27 15:45:39 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\Romano\AppData\Roaming\mozilla\Firefox\Profiles\2gtd40tb.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2012.09.25 21:47:40 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Romano\AppData\Roaming\mozilla\Firefox\Profiles\2gtd40tb.default\extensions\ich@maltegoetz.de
[2013.01.20 20:50:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Romano\AppData\Roaming\mozilla\Firefox\Profiles\9hro88k3.default\extensions
[2012.08.01 16:33:08 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Romano\AppData\Roaming\mozilla\Firefox\Profiles\9hro88k3.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012.09.23 11:55:21 | 000,113,112 | ---- | M] () (No name found) -- C:\Users\Romano\AppData\Roaming\mozilla\firefox\profiles\2gtd40tb.default\extensions\nosquint@urandom.ca.xpi
[2013.02.01 13:32:27 | 000,111,083 | ---- | M] () (No name found) -- C:\Users\Romano\AppData\Roaming\mozilla\firefox\profiles\2gtd40tb.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
[2013.02.01 12:36:46 | 000,817,973 | ---- | M] () (No name found) -- C:\Users\Romano\AppData\Roaming\mozilla\firefox\profiles\2gtd40tb.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.01.20 20:31:46 | 000,001,300 | ---- | M] () -- C:\Users\Romano\AppData\Roaming\mozilla\firefox\profiles\2gtd40tb.default\searchplugins\claro.xml
[2013.01.08 15:16:42 | 000,003,224 | ---- | M] () -- C:\Users\Romano\AppData\Roaming\mozilla\firefox\profiles\2gtd40tb.default\searchplugins\webde-suche.xml
[2012.09.23 11:44:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.09.23 11:44:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions\ffxtlbr@babylon.com
[2012.06.14 23:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.14 23:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.01.20 20:31:35 | 000,006,520 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012.06.14 23:46:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.14 23:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.14 23:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.14 23:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.14 23:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage:
CHR - Extension: No name found = C:\Users\Romano\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: No name found = C:\Users\Romano\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: No name found = C:\Users\Romano\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: No name found = C:\Users\Romano\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibgfbdggapddbjjbopabhlhianklajie\1.0.5_0\
CHR - Extension: No name found = C:\Users\Romano\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\
CHR - Extension: No name found = C:\Users\Romano\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: No name found = C:\Users\Romano\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
CHR - Extension: No name found = C:\Users\Romano\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {326E768D-4182-46FD-9C16-1449A49795F4} - No CLSID value found.
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\IPS\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SumatraPDF) - {EA58BBDF-F45C-4F28-8E52-CD5AA70D2C1E} - C:\Users\Romano\AppData\LocalLow\SumatraPDF\IE\SumatraPDF.dll (Krzysztof Kowalczyk)
O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\coIEPlg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [ROC_ROC_NT] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT File not found
O4 - HKLM..\Run: [SPIRunE] C:\Windows\SysWow64\SpiRunE.dll (Creative Technology Ltd.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1110905163-2029797133-1185949680-1008..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1110905163-2029797133-1185949680-1008..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-1110905163-2029797133-1185949680-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.11.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F6ACFEF-17AC-4A13-9AA4-742E3430E787}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk /p \??\L:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.02.08 13:49:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.02.08 13:49:16 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.02.08 13:49:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.02.08 13:48:38 | 000,000,000 | ---D | C] -- C:\Users\Romano\AppData\Local\Programs
[2013.02.08 13:30:33 | 000,000,000 | ---D | C] -- C:\Windows\LastGood
[2013.02.08 13:18:45 | 000,177,312 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013.02.08 13:18:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2013.02.08 13:18:45 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2013.02.08 13:17:50 | 000,432,800 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1401000.018\symnets.sys
[2013.02.08 13:17:50 | 000,023,448 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymELAM.sys
[2013.02.08 13:17:49 | 001,132,192 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymEFA64.sys
[2013.02.08 13:17:49 | 000,493,216 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymDS64.sys
[2013.02.08 13:17:49 | 000,037,496 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1401000.018\srtspx64.sys
[2013.02.08 13:17:48 | 000,776,352 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1401000.018\srtsp64.sys
[2013.02.08 13:17:48 | 000,224,416 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1401000.018\Ironx64.sys
[2013.02.08 13:17:48 | 000,168,096 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1401000.018\ccSetx64.sys
[2013.02.08 13:17:30 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\N360x64
[2013.02.08 13:17:30 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\N360x64\1401000.018
[2013.02.08 13:17:29 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2013.02.08 13:17:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton 360
[2013.02.04 20:14:52 | 000,000,000 | ---D | C] -- C:\Users\Romano\Documents\Scanned Documents
[2013.02.04 20:14:52 | 000,000,000 | ---D | C] -- C:\Users\Romano\Documents\Fax
[2013.01.26 20:55:05 | 000,000,000 | -H-D | C] -- C:\Users\Romano\Documents\Freemake_do_not_remove_this_folder634948305053694030
[2013.01.22 12:44:07 | 000,000,000 | ---D | C] -- C:\Users\Romano\AppData\Local\NPE
[2013.01.20 20:50:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Fat32Formatter1.1EN
[2013.01.20 20:31:46 | 000,000,000 | ---D | C] -- C:\Users\Romano\AppData\Roaming\Claro LTD
[2013.01.20 20:04:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer
[2013.01.18 17:04:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller
[2013.01.17 19:05:22 | 000,000,000 | -H-D | C] -- C:\Users\Romano\Documents\Freemake_do_not_remove_this_folder634940463221574373
[2013.01.14 19:50:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013.01.14 16:18:16 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012.10.27 07:17:30 | 002,174,976 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Program Files (x86)\Common Files\atimpenc.dll
[11 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[10 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.02.08 18:42:01 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.02.08 14:52:09 | 000,037,619 | ---- | M] () -- C:\Windows\Q-Dir.ini
[2013.02.08 13:49:18 | 000,001,117 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.02.08 13:30:22 | 001,996,111 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\Cat.DB
[2013.02.08 13:24:57 | 000,023,152 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.02.08 13:24:57 | 000,023,152 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.02.08 13:18:45 | 000,177,312 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013.02.08 13:18:45 | 000,007,466 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013.02.08 13:18:45 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013.02.08 13:17:21 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.02.08 13:17:20 | 000,001,084 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2013.02.08 13:17:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.02.08 13:17:00 | 3214,745,600 | -HS- | M] () -- C:\hiberfil.sys
[2013.02.03 21:00:07 | 000,009,622 | ---- | M] () -- C:\Users\Romano\Documents\Ihre Unterstützungsbekundung ist eingegangen! - Online-Sammelsystem.pdf
[2013.02.03 20:33:17 | 000,007,597 | ---- | M] () -- C:\Users\Romano\AppData\Local\resmon.resmoncfg
[2013.01.30 16:52:48 | 000,051,212 | ---- | M] () -- C:\Users\Romano\Documents\proprietär – Wikipedia.pdf
[2013.01.30 10:26:29 | 000,014,253 | ---- | M] () -- C:\Users\Romano\Documents\JOBBÖRSE - Stellenangebot.pdf
[2013.01.22 14:27:00 | 001,613,340 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.01.22 14:27:00 | 000,696,832 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.01.22 14:27:00 | 000,652,150 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.01.22 14:27:00 | 000,148,128 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.01.22 14:27:00 | 000,121,082 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.01.22 11:58:07 | 000,001,619 | ---- | M] () -- C:\Users\Romano\Desktop\DivX Movies.lnk
[2013.01.18 13:08:59 | 000,501,612 | ---- | M] () -- C:\Users\Romano\Documents\Kauf erfolgreich.pdf
[2013.01.17 22:13:11 | 000,651,237 | ---- | M] () -- C:\Users\Romano\Documents\Beim Kopieren wird mir immer der Dateizugriff verweigert.pdf
[2013.01.17 17:10:44 | 000,000,680 | RHS- | M] () -- C:\Users\Romano\ntuser.pol
[11 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[10 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.02.08 13:49:18 | 000,001,117 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.02.08 13:30:01 | 000,074,272 | ---- | C] () -- C:\Windows\SysNative\RtNicProp64.dll
[2013.02.08 13:18:49 | 001,996,111 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\Cat.DB
[2013.02.08 13:18:46 | 000,007,466 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013.02.08 13:18:46 | 000,000,855 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013.02.08 13:17:30 | 000,009,670 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymELAM64.cat
[2013.02.08 13:17:30 | 000,008,942 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymVTcer.dat
[2013.02.08 13:17:30 | 000,007,611 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\ccSetx64.cat
[2013.02.08 13:17:30 | 000,007,605 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\srtspx64.cat
[2013.02.08 13:17:30 | 000,007,603 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymEFA64.cat
[2013.02.08 13:17:30 | 000,007,601 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\symnet64.cat
[2013.02.08 13:17:30 | 000,007,601 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\srtsp64.cat
[2013.02.08 13:17:30 | 000,007,597 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymDS64.cat
[2013.02.08 13:17:30 | 000,007,593 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\iron.cat
[2013.02.08 13:17:30 | 000,003,434 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymEFA.inf
[2013.02.08 13:17:30 | 000,002,851 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymDS.inf
[2013.02.08 13:17:30 | 000,001,440 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\SymNet.inf
[2013.02.08 13:17:30 | 000,001,436 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\srtsp64.inf
[2013.02.08 13:17:30 | 000,001,418 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\srtspx64.inf
[2013.02.08 13:17:30 | 000,000,996 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\symELAM.inf
[2013.02.08 13:17:30 | 000,000,854 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\ccSetx64.inf
[2013.02.08 13:17:30 | 000,000,767 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\Iron.inf
[2013.02.08 13:17:30 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1401000.018\isolate.ini
[2013.02.03 21:00:06 | 000,009,622 | ---- | C] () -- C:\Users\Romano\Documents\Ihre Unterstützungsbekundung ist eingegangen! - Online-Sammelsystem.pdf
[2013.01.30 16:52:46 | 000,051,212 | ---- | C] () -- C:\Users\Romano\Documents\proprietär – Wikipedia.pdf
[2013.01.18 13:08:57 | 000,501,612 | ---- | C] () -- C:\Users\Romano\Documents\Kauf erfolgreich.pdf
[2013.01.17 22:13:05 | 000,651,237 | ---- | C] () -- C:\Users\Romano\Documents\Beim Kopieren wird mir immer der Dateizugriff verweigert.pdf
[2013.01.17 17:10:44 | 000,000,680 | RHS- | C] () -- C:\Users\Romano\ntuser.pol
[2012.12.28 23:28:29 | 000,001,483 | ---- | C] () -- C:\Users\Romano\AppData\Local\recently-used.xbel
[2012.12.28 21:07:49 | 000,000,022 | ---- | C] () -- C:\Users\Romano\AppData\Local\kodakpcd.ini
[2012.12.27 09:16:20 | 001,589,618 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.11.22 20:54:37 | 000,004,923 | ---- | C] () -- C:\ProgramData\drctchbl.xvi
[2012.11.22 20:53:29 | 000,004,948 | ---- | C] () -- C:\ProgramData\xqkcebzs.dik
[2012.10.27 12:13:11 | 000,000,047 | ---- | C] () -- C:\Windows\wininit.ini
[2012.10.01 06:17:22 | 000,039,904 | ---- | C] () -- C:\Windows\SysWow64\dischandler.exe
[2012.09.29 23:47:28 | 000,000,178 | ---- | C] () -- C:\Windows\SysWow64\Formats.ini
[2012.09.25 06:30:54 | 003,915,776 | ---- | C] () -- C:\Windows\SysWow64\ffmpeg.dll
[2012.09.25 06:30:04 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012.09.25 06:29:20 | 000,271,360 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll
[2012.09.25 06:29:00 | 000,157,184 | ---- | C] () -- C:\Windows\SysWow64\ff_unrar.dll
[2012.09.25 06:29:00 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\ff_libmad.dll
[2012.09.25 06:29:00 | 000,099,840 | ---- | C] () -- C:\Windows\SysWow64\ff_wmv9.dll
[2012.09.25 06:28:58 | 001,525,760 | ---- | C] () -- C:\Windows\SysWow64\ff_samplerate.dll
[2012.09.25 06:28:58 | 000,211,968 | ---- | C] () -- C:\Windows\SysWow64\ff_libdts.dll
[2012.09.25 06:28:58 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\ff_liba52.dll
[2012.07.19 19:56:08 | 000,172,544 | ---- | C] () -- C:\Windows\SysWow64\libbluray.dll
[2012.07.19 19:56:02 | 006,894,331 | ---- | C] () -- C:\Windows\SysWow64\avcodec-lav-54.dll
[2012.07.19 19:56:02 | 001,111,581 | ---- | C] () -- C:\Windows\SysWow64\avformat-lav-54.dll
[2012.07.19 19:56:02 | 000,401,685 | ---- | C] () -- C:\Windows\SysWow64\swscale-lav-2.dll
[2012.07.19 19:56:02 | 000,232,895 | ---- | C] () -- C:\Windows\SysWow64\avutil-lav-51.dll
[2012.07.19 19:56:02 | 000,162,743 | ---- | C] () -- C:\Windows\SysWow64\avfilter-lav-3.dll
[2012.07.19 19:56:02 | 000,101,820 | ---- | C] () -- C:\Windows\SysWow64\avresample-lav-0.dll
[2012.06.17 22:15:04 | 000,198,144 | ---- | C] () -- C:\Windows\SysWow64\spdif_test.exe
[2012.06.17 22:14:58 | 000,097,792 | ---- | C] () -- C:\Windows\SysWow64\ac3config.exe
[2012.06.17 22:14:42 | 001,021,440 | ---- | C] () -- C:\Windows\SysWow64\ac3filter_intl.dll
[2012.06.02 22:12:25 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2012.05.27 22:12:24 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\machinist2.dll
[2012.05.25 14:06:38 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
[2012.05.12 23:42:16 | 001,272,320 | ---- | C] () -- C:\Windows\SysWow64\avcodec-53.dll
[2012.05.12 23:42:16 | 000,146,432 | ---- | C] () -- C:\Windows\SysWow64\avutil-51.dll
[2012.04.23 01:20:57 | 000,172,032 | ---- | C] ( ) -- C:\Windows\SysWow64\ASILOCK.DLL
[2012.04.22 21:29:29 | 000,000,393 | ---- | C] () -- C:\Users\Romano\AppData\Local\HamsterVideoConverterSettings.cfg
[2012.03.06 16:49:11 | 000,000,029 | ---- | C] () -- C:\Windows\DEBUGSM.INI
[2012.03.06 15:55:09 | 000,111,932 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
[2012.03.06 15:55:09 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
[2012.03.06 15:55:09 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
[2012.03.06 15:55:09 | 000,026,154 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
[2012.03.06 15:55:09 | 000,024,903 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
[2012.03.06 15:55:09 | 000,021,390 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
[2012.03.06 15:55:09 | 000,020,148 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
[2012.03.06 15:55:09 | 000,011,811 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
[2012.03.06 15:55:09 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
[2012.03.06 15:55:09 | 000,001,146 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_DU.dat
[2012.03.06 15:55:09 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2012.03.06 15:55:09 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2012.03.06 15:55:09 | 000,001,136 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2012.03.06 15:55:09 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2012.03.06 15:55:09 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2012.03.06 15:55:09 | 000,001,120 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_IT.dat
[2012.03.06 15:55:09 | 000,001,107 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_GE.dat
[2012.03.06 15:55:09 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2012.03.06 15:55:09 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini
[2012.03.06 15:03:15 | 000,000,025 | ---- | C] () -- C:\Windows\CDEC66SeriesEuro.ini
[2012.03.01 16:57:10 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2012.03.01 16:52:40 | 002,117,678 | ---- | C] () -- C:\Program Files (x86)\7_Fade.scr
[2012.03.01 16:46:07 | 000,033,443 | ---- | C] () -- C:\Windows\fire-un.exe
[2012.02.09 17:36:36 | 000,000,000 | ---- | C] () -- C:\Windows\PestPatrol5.INI
[2012.02.08 21:53:57 | 011,329,536 | ---- | C] () -- C:\Users\Romano\AppData\Roaming\Sandra.mdb
[2012.02.02 19:48:29 | 000,000,043 | ---- | C] () -- C:\Windows\gswin32.ini
[2011.12.16 02:23:20 | 000,000,058 | ---- | C] () -- C:\Windows\SysWow64\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2011.12.16 02:23:20 | 000,000,058 | ---- | C] () -- C:\Users\Romano\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2011.12.15 16:22:33 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll
[2011.12.11 02:29:34 | 000,000,659 | ---- | C] () -- C:\Windows\cdplayer.ini
[2011.12.11 02:29:16 | 000,001,492 | ---- | C] () -- C:\ProgramData\ss.ini
[2011.12.11 00:43:17 | 000,000,206 | ---- | C] () -- C:\Users\Romano\AppData\Roaming\burnaware.ini
[2011.12.07 20:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\Lagarith.dll
[2011.11.22 17:41:06 | 000,000,029 | ---- | C] () -- C:\Windows\sfbm.INI
[2011.11.22 16:34:39 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2011.11.22 16:34:39 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2011.11.22 16:34:38 | 000,001,436 | ---- | C] () -- C:\Windows\CfgHPSp.ini
[2011.11.22 16:34:38 | 000,001,434 | ---- | C] () -- C:\Windows\Cfg05Sp.ini
[2011.11.22 16:34:38 | 000,001,434 | ---- | C] () -- C:\Windows\Cfg04Sp.ini
[2011.11.22 16:34:38 | 000,001,091 | ---- | C] () -- C:\Windows\Cfg03Sp.ini
[2011.11.22 16:34:38 | 000,001,091 | ---- | C] () -- C:\Windows\Cfg02Sp.ini
[2011.11.22 16:34:38 | 000,000,932 | ---- | C] () -- C:\Windows\CfgHPHp.ini
[2011.11.22 16:34:38 | 000,000,932 | ---- | C] () -- C:\Windows\CfgHPDO.ini
[2011.11.22 16:34:38 | 000,000,932 | ---- | C] () -- C:\Windows\Cfg05DO.ini
[2011.11.22 16:34:38 | 000,000,932 | ---- | C] () -- C:\Windows\Cfg04DO.ini
[2011.11.22 16:34:38 | 000,000,930 | ---- | C] () -- C:\Windows\Cfg05Hp.ini
[2011.11.22 16:34:38 | 000,000,930 | ---- | C] () -- C:\Windows\Cfg04Hp.ini
[2011.11.22 16:34:38 | 000,000,725 | ---- | C] () -- C:\Windows\Cfg03Hp.ini
[2011.11.22 16:34:38 | 000,000,725 | ---- | C] () -- C:\Windows\Cfg03DO.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\CfgHPRMi.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\CfgHPRLI.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\CfgHPFMi.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\CfgHPDI.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg05RMi.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg05RLI.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg05FMi.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg05DI.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg04RMi.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg04RLI.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg04FMi.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg04DI.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg03RMi.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg03RLI.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg03FMi.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg03DI.ini
[2011.11.22 16:34:38 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg02RMi.ini
[2011.11.22 16:34:37 | 000,148,992 | ---- | C] () -- C:\Windows\SysWow64\OemSpiE.dll
[2011.11.22 16:34:37 | 000,001,000 | ---- | C] () -- C:\Windows\Cfg01Sp.ini
[2011.11.22 16:34:37 | 000,000,818 | ---- | C] () -- C:\Windows\Cfg01APR.ini
[2011.11.22 16:34:37 | 000,000,725 | ---- | C] () -- C:\Windows\Cfg02Hp.ini
[2011.11.22 16:34:37 | 000,000,725 | ---- | C] () -- C:\Windows\Cfg02DO.ini
[2011.11.22 16:34:37 | 000,000,725 | ---- | C] () -- C:\Windows\Cfg01Hp.ini
[2011.11.22 16:34:37 | 000,000,725 | ---- | C] () -- C:\Windows\Cfg01DO.ini
[2011.11.22 16:34:37 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg02RLI.ini
[2011.11.22 16:34:37 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg02FMi.ini
[2011.11.22 16:34:37 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg02DI.ini
[2011.11.22 16:34:37 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg01Mic.ini
[2011.11.22 16:34:37 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg01LI.ini
[2011.11.22 16:34:37 | 000,000,453 | ---- | C] () -- C:\Windows\Cfg01DI.ini
[2011.11.22 14:55:09 | 000,200,704 | ---- | C] () -- C:\Windows\SysWow64\HsMgr.exe
[2011.11.10 03:36:06 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2011.11.10 03:36:06 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011.11.09 22:39:44 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011.11.09 22:39:32 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011.11.08 17:53:53 | 000,002,641 | ---- | C] () -- C:\Windows\cmudax3.ini
[2011.11.08 17:53:53 | 000,002,123 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.cfg
[2011.11.08 17:53:53 | 000,000,103 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.imi
[2011.11.06 02:20:22 | 000,098,304 | ---- | C] () -- C:\Windows\SysWow64\redmonnt.dll
[2011.11.01 00:00:10 | 000,037,619 | ---- | C] () -- C:\Windows\Q-Dir.ini
[2011.10.31 16:41:24 | 000,007,680 | ---- | C] () -- C:\Users\Romano\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.10.24 19:08:06 | 000,007,597 | ---- | C] () -- C:\Users\Romano\AppData\Local\resmon.resmoncfg
[2011.09.27 14:45:40 | 000,825,072 | ---- | C] () -- C:\Users\Romano\AppData\Local\census.cache
[2011.09.27 14:45:31 | 000,107,898 | ---- | C] () -- C:\Users\Romano\AppData\Local\ars.cache
[2011.09.27 14:35:56 | 000,000,036 | ---- | C] () -- C:\Users\Romano\AppData\Local\housecall.guid.cache
[2011.09.22 15:53:28 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.09.08 15:00:52 | 000,150,528 | ---- | C] () -- C:\Windows\SysWow64\mkx.dll
[2011.09.08 15:00:48 | 000,142,336 | ---- | C] () -- C:\Windows\SysWow64\mp4.dll
[2011.09.08 15:00:42 | 000,123,392 | ---- | C] () -- C:\Windows\SysWow64\ogm.dll
[2011.09.08 15:00:38 | 000,249,856 | ---- | C] () -- C:\Windows\SysWow64\dxr.dll
[2011.09.08 15:00:34 | 000,113,152 | ---- | C] () -- C:\Windows\SysWow64\dsmux.exe
[2011.09.08 15:00:24 | 000,154,624 | ---- | C] () -- C:\Windows\SysWow64\ts.dll
[2011.09.08 15:00:10 | 000,137,728 | ---- | C] () -- C:\Windows\SysWow64\mkv2vfr.exe
[2011.09.08 15:00:06 | 000,358,400 | ---- | C] () -- C:\Windows\SysWow64\gdsmux.exe
[2011.09.08 14:59:54 | 000,080,384 | ---- | C] () -- C:\Windows\SysWow64\mkzlib.dll
[2011.09.08 14:59:52 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\mkunicode.dll
[2011.08.26 23:11:07 | 000,000,000 | ---- | C] () -- C:\Windows\Alienware Screensaver - Vista.ini
[2011.03.03 12:39:56 | 000,109,568 | ---- | C] () -- C:\Windows\SysWow64\avi.dll
[2011.03.03 12:38:10 | 000,097,792 | ---- | C] () -- C:\Windows\SysWow64\avs.dll
[2011.03.03 12:37:50 | 000,093,184 | ---- | C] () -- C:\Windows\SysWow64\avss.dll
[2011.02.11 11:26:20 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\OptimFROG.dll
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 03:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.01.19 19:40:43 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\OpenOffice.org
[2013.01.18 23:26:40 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Q-Dir
[2013.01.19 01:17:15 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Thunderbird
[2012.04.23 12:48:12 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Ad-Aware Antivirus
[2012.04.22 00:00:45 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\AnvSoft
[2011.12.10 22:30:15 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Ashampoo
[2011.11.22 16:04:16 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\ASUS
[2011.12.16 01:46:41 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\AutoScreenShotMaker
[2012.02.09 20:53:48 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\AVG2012
[2012.04.26 22:13:32 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\avidemux
[2011.11.08 20:52:17 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Babylon
[2011.11.26 20:43:31 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\biu software
[2012.11.28 17:18:52 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Broad Intelligence
[2011.08.25 20:33:17 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Canneverbe Limited
[2012.07.30 14:37:09 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\CD Art Display
[2013.01.20 20:31:46 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Claro LTD
[2011.10.12 20:30:14 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Cocoon Software
[2011.12.10 20:13:39 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\DeepBurner
[2011.12.16 02:23:20 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\DonationCoder
[2012.11.23 00:20:48 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Dr. DivX 2.0 OSS
[2012.08.22 20:22:11 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\DVDVideoSoft
[2012.03.06 17:06:07 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\EPSON
[2011.09.09 23:07:28 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\eSobi
[2011.10.12 23:47:15 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\FileCommander
[2012.04.22 00:26:14 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Free Audio Editor
[2011.12.10 21:03:39 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\FreeBurner
[2012.02.14 16:52:50 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\FreePDF
[2012.11.22 23:49:26 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\FreeVideoConverter
[2012.02.18 16:59:37 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\GetRightToGo
[2012.04.02 16:49:51 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\gtk-2.0
[2012.03.13 14:42:31 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\inkscape
[2011.09.26 18:53:19 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Leadertech
[2011.11.04 13:52:16 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\LibreOffice
[2012.02.25 16:51:36 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Lingo4u
[2011.12.11 01:27:51 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\NCH Swift Sound
[2011.09.12 13:30:02 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Nullsoft
[2011.12.15 16:22:30 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\OCS
[2011.08.25 10:43:28 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\OpenOffice.org
[2012.02.08 18:14:43 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Opera
[2012.02.09 18:12:46 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Panda Security
[2011.12.08 19:19:53 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\PhotoFiltre
[2011.12.16 02:32:04 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\picpick
[2012.06.17 13:44:01 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Q-Dir
[2012.07.17 14:43:50 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Scribus
[2011.12.16 02:17:37 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\SimpleScreenshot
[2011.08.27 12:10:44 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Skinux
[2011.09.20 11:35:52 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Softland
[2011.08.24 23:45:22 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Thunderbird
[2011.11.12 13:58:34 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Tific
[2012.11.28 18:58:25 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\WinFF
[2012.11.22 22:19:31 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\Xilisoft
[2012.04.21 21:54:55 | 000,000,000 | ---D | M] -- C:\Users\Romano\AppData\Roaming\XMedia Recode
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:98353363
< End of report > --- --- --- |