karlshagen | 22.02.2013 14:43 | Code:
OTL logfile created on: 22.02.2013 14:28:05 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\15G22J0290K0EU2Y\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,75 Gb Total Physical Memory | 0,86 Gb Available Physical Memory | 49,05% Memory free
6,12 Gb Paging File | 5,03 Gb Available in Paging File | 82,15% Paging File free
Paging file location(s): c:\pagefile.sys 2686 2686d:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 98,59 Gb Total Space | 55,79 Gb Free Space | 56,59% Space Free | Partition Type: NTFS
Drive D: | 191,46 Gb Total Space | 121,75 Gb Free Space | 63,59% Space Free | Partition Type: NTFS
Drive I: | 3,78 Gb Total Space | 3,60 Gb Free Space | 95,21% Space Free | Partition Type: FAT
Drive J: | 537,11 Gb Total Space | 2,07 Gb Free Space | 0,38% Space Free | Partition Type: NTFS
Drive K: | 390,63 Gb Total Space | 122,90 Gb Free Space | 31,46% Space Free | Partition Type: NTFS
Drive L: | 298,05 Mb Total Space | 7,75 Mb Free Space | 2,60% Space Free | Partition Type: NTFS
Drive M: | 194,00 Mb Total Space | 124,86 Mb Free Space | 64,36% Space Free | Partition Type: NTFS
Drive O: | 209,87 Gb Total Space | 174,23 Gb Free Space | 83,02% Space Free | Partition Type: NTFS
Drive U: | 488,28 Gb Total Space | 472,89 Gb Free Space | 96,85% Space Free | Partition Type: NTFS
Computer Name: BIBA | User Name: 15G22J0290K0EU2Y | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\15G22J0290K0EU2Y\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\ProgramData\MobileBrServ\mbbService.exe ()
PRC - C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\IdeaCom\TSC\IdcSrv.exe (IdeaCom Technology Inc.)
PRC - C:\Program Files\IdeaCom\TSC\ETSCSERVICE.exe (IdeaCom Technology Inc.)
PRC - C:\Program Files\ASUS\Eee Manager\EMMessageParser.exe (ASUSTeK)
PRC - C:\Program Files\ASUS\Eee Manager\EeeManager.exe (ASUSTeK)
PRC - C:\Program Files\ASUS\Message Controller\AsMessageController.exe (ASUSTeK)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7366a39c36523a084bc11c230929ff92\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\01c6cb58745f397c9b7ccf3ab7bfc9cd\System.EnterpriseServices.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\536d704e93ffec9b54e4a0312fb5b996\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\dd20416f723ee13ffb4173ec1afc4ec4\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\SqliteShared\1.0.3524.15966__0d0f4b69e50e559b\SqliteShared.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data.SQLite\1.0.60.0__db937bc2d44ff139\System.Data.SQLite.dll ()
MOD - C:\Program Files\ASUS\Asus WebStorage\EcaremeDLL.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Program Files\ASUS\Message Controller\AsACPINotify.dll ()
MOD - C:\Program Files\ASUS\Message Controller\AsRemoteControlHooker.dll ()
MOD - C:\Program Files\ASUS\Eee Manager\ImageMgr.dll ()
MOD - C:\Program Files\ASUS\Message Controller\AsKeyboardHooker.dll ()
MOD - C:\Program Files\ASUS\Eee Manager\MessageParser\AsMultiLang.dll ()
MOD - C:\Program Files\ASUS\Eee Manager\AsMultiLang.dll ()
========== Services (SafeList) ==========
SRV - (Guard.Mail.ru) -- File not found
SRV - (Dnscache) -- %SystemRoot%\System32\pouae2gyp.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (NisSrv) -- C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Mobile Broadband HL Service) -- C:\ProgramData\MobileBrServ\mbbService.exe ()
SRV - (Update-Service) -- C:\Windows\System32\UpdSvc.dll (Joosoft.com GmbH)
SRV - (NAUpdate) -- C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
SRV - (IdcSrv) -- C:\Program Files\IdeaCom\TSC\IdcSrv.exe (IdeaCom Technology Inc.)
SRV - (ETSCSERVICE) -- C:\Program Files\IdeaCom\TSC\ETSCSERVICE.exe (IdeaCom Technology Inc.)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (iwaozptt) -- File not found
DRV - (ivtpxjih) -- File not found
DRV - (islxmqgh) -- File not found
DRV - (hwdatacard) -- system32\DRIVERS\ewusbmdm.sys File not found
DRV - (cooonihv) -- File not found
DRV - (aqyj3d4q) -- File not found
DRV - (NisDrv) -- C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (sptd) -- C:\Windows\System32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (nvsmu) -- C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (nvamacpi) -- C:\Windows\System32\drivers\nvamacpi.sys (NVIDIA Corporation)
DRV - (epmntdrv) -- C:\Windows\System32\epmntdrv.sys ()
DRV - (EuGdiDrv) -- C:\Windows\System32\EuGdiDrv.sys ()
DRV - (NBVol) -- C:\Windows\System32\drivers\NBVol.sys (Nero AG)
DRV - (NBVolUp) -- C:\Windows\System32\drivers\NBVolUp.sys (Nero AG)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (IdcFltr) -- C:\Windows\System32\drivers\idcfltr.sys (IdeaCom Technology Inc.)
DRV - (AmUStor) -- C:\Windows\System32\drivers\AmUStor.sys (Alcor Micro, Corp.)
DRV - (AsIO) -- C:\Windows\System32\drivers\AsIO.sys ()
DRV - (enecir) -- C:\Windows\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (enecirhid) -- C:\Windows\System32\drivers\enecirhid.sys (ENE TECHNOLOGY INC.)
DRV - (enecirhidma) -- C:\Windows\System32\drivers\enecirhidma.sys (ENE TECHNOLOGY INC.)
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (s1029unic) -- C:\Windows\System32\drivers\s1029unic.sys (MCCI Corporation)
DRV - (s1029mdm) -- C:\Windows\System32\drivers\s1029mdm.sys (MCCI Corporation)
DRV - (s1029bus) -- C:\Windows\System32\drivers\s1029bus.sys (MCCI Corporation)
DRV - (s1029mdfl) -- C:\Windows\System32\drivers\s1029mdfl.sys (MCCI Corporation)
DRV - (s1029mgmt) -- C:\Windows\System32\drivers\s1029mgmt.sys (MCCI Corporation)
DRV - (s1029obex) -- C:\Windows\System32\drivers\s1029obex.sys (MCCI Corporation)
DRV - (s1029nd5) -- C:\Windows\System32\drivers\s1029nd5.sys (MCCI Corporation)
DRV - (ASInsHelp) -- C:\Windows\System32\drivers\AsInsHelp32.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = D:\Downloads
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com/
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\..\SearchScopes,DefaultScope = {36377DD7-B3EB-42f5-986F-680BAF59BA9D}
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\..\SearchScopes\{36377DD7-B3EB-42f5-986F-680BAF59BA9D}: "URL" = hxxp://start.gamesagogo.iplay.com/searchresultsredirect.aspx?o=chrome&q={searchTerms}
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo!"
FF - prefs.js..browser.search.selectedEngine: "Yahoo!"
FF - prefs.js..browser.startup.homepage: "hxxp://office-manager/Account/LogOn"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~1\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: D:\Program Files\VLC\npvlc.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\15G22J0290K0EU2Y\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}: C:\Program Files\RelevantKnowledge\firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.02.20 23:21:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.01.12 08:43:15 | 000,000,000 | ---D | M]
[2012.08.28 19:40:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\mozilla\Extensions
[2012.12.28 09:57:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\mozilla\Firefox\Profiles\pz396p4t.default\extensions
[2012.12.10 18:04:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2012.12.10 18:04:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013.02.20 23:21:56 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.01.18 21:02:20 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.29 11:27:41 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.01.18 21:02:20 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.01.18 21:02:20 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.01.18 21:02:19 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.01.18 21:02:19 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
[2012.12.22 17:18:38 | 000,000,786 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Yahooober14387457.xml
Hosts file not found
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\..\Toolbar\WebBrowser: (no name) - {990AF1C2-5A27-4460-8149-ECC6BC122AF3} - No CLSID value found.
O3 - HKU\S-1-5-21-1998982368-3054312690-3844566786-1000\..\Toolbar\WebBrowser: (no name) - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - No CLSID value found.
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NBAgent] C:\Program Files\Nero\Nero 11\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [PrivitizeVPN] C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe (OOO Industry)
O4 - HKLM..\Run: [StartCal.exe] C:\Program Files\IdeaCom\TSC\StartCal.exe (IdeaCom Technology Inc.)
O4 - HKU\.DEFAULT..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe ()
O4 - HKU\S-1-5-18..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8 - Extra context menu item: An OneNote s&enden - res://D:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://D:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\system32\UDDIjdlcn.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{577a8c28-8370-4d95-a804-69548d509e85}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{716FB368-5896-4B52-8AF2-C05A3D46DE1D}: DhcpNameServer = 10.1.1.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7862A30D-58BD-4301-9854-D68DEF14A18E}: DhcpNameServer = 10.1.1.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{d4817425-ae18-4a77-9d08-71acc98bd32c}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{f759e9d5-c984-4da0-b5a0-a2d9df02b1ff}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\IdcNotify: DllName - (idcnotify.dll) - C:\Windows\System32\idcnotify.dll ()
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{1550962e-d83e-11e1-a9ca-0025d37d7501}\Shell - "" = AutoRun
O33 - MountPoints2\{1550962e-d83e-11e1-a9ca-0025d37d7501}\Shell\AutoRun\command - "" = F:\start.exe
O33 - MountPoints2\{28e63b4b-bb23-11e1-a36b-90e6ba5b36a3}\Shell - "" = AutoRun
O33 - MountPoints2\{28e63b4b-bb23-11e1-a36b-90e6ba5b36a3}\Shell\AutoRun\command - "" = F:\Startme.exe
O33 - MountPoints2\{698150b1-deaa-11df-971b-90e6ba5b36a3}\Shell - "" = AutoRun
O33 - MountPoints2\{698150b1-deaa-11df-971b-90e6ba5b36a3}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{698150b9-deaa-11df-971b-90e6ba5b36a3}\Shell - "" = AutoRun
O33 - MountPoints2\{698150b9-deaa-11df-971b-90e6ba5b36a3}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{9cdf9d38-bcff-11e1-b74e-90e6ba5b36a3}\Shell - "" = AutoRun
O33 - MountPoints2\{9cdf9d38-bcff-11e1-b74e-90e6ba5b36a3}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.02.22 12:56:53 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\15G22J0290K0EU2Y\Desktop\OTL.exe
[2013.02.20 12:40:44 | 000,000,000 | ---D | C] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\Malwarebytes
[2013.02.20 12:39:24 | 000,000,000 | ---D | C] -- C:\Users\15G22J0290K0EU2Y\AppData\Local\Programs
[2013.02.17 14:09:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013.02.17 14:09:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2013.02.15 16:42:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2013.02.15 16:42:51 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2013.02.15 13:53:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.02.13 15:47:39 | 000,000,000 | ---D | C] -- C:\Users\15G22J0290K0EU2Y\Desktop\Scan
[2013.02.11 17:08:00 | 000,000,000 | ---D | C] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\TuneUp Software
[2013.02.11 16:48:28 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2013.02.11 16:48:27 | 000,000,000 | ---D | C] -- C:\Users\15G22J0290K0EU2Y\AppData\Local\MFAData
[2013.02.11 16:48:27 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2013.02.11 16:48:27 | 000,000,000 | ---D | C] -- C:\Users\15G22J0290K0EU2Y\AppData\Local\Avg2013
[2013.02.07 17:44:16 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2013.02.05 15:38:22 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2012.05.08 10:11:07 | 001,638,400 | ---- | C] (LIGHTNING UK!) -- C:\Users\15G22J0290K0EU2Y\AppData\Local\ImgBurn.exe
[2011.12.08 23:02:17 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 30 Days ==========
[2013.02.22 14:21:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.02.22 13:55:01 | 000,001,118 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.02.22 13:40:22 | 000,001,041 | ---- | M] () -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\vso_ts_preview.xml
[2013.02.22 12:57:11 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\15G22J0290K0EU2Y\Desktop\OTL.exe
[2013.02.22 12:07:05 | 000,000,972 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1998982368-3054312690-3844566786-1000UA.job
[2013.02.22 10:49:11 | 000,039,424 | ---- | M] () -- C:\Users\15G22J0290K0EU2Y\Desktop\Kea New Zealand - Karlen 36985161 Booking Cancelled.msg
[2013.02.22 09:11:53 | 000,018,736 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.02.22 09:11:53 | 000,018,736 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.02.22 09:07:01 | 000,000,950 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1998982368-3054312690-3844566786-1000Core.job
[2013.02.22 09:06:54 | 000,000,266 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
[2013.02.22 09:06:18 | 000,000,431 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2013.02.22 09:06:05 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.02.22 09:05:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.02.22 09:05:39 | 1408,638,976 | -HS- | M] () -- C:\hiberfil.sys
[2013.02.21 15:41:02 | 004,381,412 | ---- | M] () -- C:\Users\15G22J0290K0EU2Y\Desktop\Samsung 3d Fernseher.pdf
[2013.02.21 08:12:06 | 000,409,984 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.02.18 18:24:56 | 000,033,792 | ---- | M] () -- C:\Users\15G22J0290K0EU2Y\Desktop\Türkman.msg
[2013.02.18 15:34:10 | 000,616,498 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.02.18 15:34:10 | 000,580,736 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.02.18 15:34:10 | 000,122,242 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.02.18 15:34:10 | 000,098,632 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.02.17 14:09:51 | 000,002,505 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2013.02.16 20:45:08 | 000,327,680 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2013.02.16 02:30:31 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2013.02.11 16:41:42 | 000,007,625 | ---- | M] () -- C:\Users\15G22J0290K0EU2Y\AppData\Local\Resmon.ResmonCfg
[2013.02.09 20:56:03 | 000,084,992 | ---- | M] () -- C:\Users\15G22J0290K0EU2Y\Desktop\20% Off Easy Change.msg
[2013.02.09 18:57:42 | 000,555,429 | ---- | M] () -- C:\Users\15G22J0290K0EU2Y\Desktop\QuoteDetail6BerthSTPremierUnitedCampervansNZ1302093898STW.pdf
[2013.01.30 16:53:03 | 000,000,973 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
========== Files Created - No Company Name ==========
[2013.02.22 10:49:10 | 000,039,424 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\Desktop\Kea New Zealand - Karlen 36985161 Booking Cancelled.msg
[2013.02.21 15:40:58 | 004,381,412 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\Desktop\Samsung 3d Fernseher.pdf
[2013.02.21 08:11:45 | 000,409,984 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.02.18 18:24:54 | 000,033,792 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\Desktop\Türkman.msg
[2013.02.11 16:41:42 | 000,007,625 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\AppData\Local\Resmon.ResmonCfg
[2013.02.09 20:56:02 | 000,084,992 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\Desktop\20% Off Easy Change.msg
[2013.02.09 18:57:42 | 000,555,429 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\Desktop\QuoteDetail6BerthSTPremierUnitedCampervansNZ1302093898STW.pdf
[2012.12.07 21:19:13 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
[2012.12.07 21:19:12 | 002,469,760 | ---- | C] () -- C:\Windows\System32\BootMan.exe
[2012.12.07 21:19:11 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
[2012.12.07 21:19:10 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
[2012.12.07 21:19:10 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
[2012.10.27 18:13:50 | 000,003,584 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.08.27 15:17:26 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2012.07.02 22:59:09 | 000,283,097 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2012.07.02 19:28:06 | 000,112,640 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2012.06.16 15:52:46 | 000,000,130 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\default.rss
[2012.06.09 18:21:56 | 000,178,688 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2012.06.08 00:59:27 | 000,002,272 | ---- | C] () -- C:\Windows\System32\ASOROSet.bin
[2012.06.08 00:54:38 | 000,032,256 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2012.05.30 10:52:20 | 004,305,920 | ---- | C] () -- C:\Windows\System32\x264vfw.dll
[2012.05.21 17:28:58 | 000,155,648 | ---- | C] () -- C:\Windows\System32\mlc.dll
[2012.02.22 12:05:36 | 015,495,729 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\SMRBackup250.dat
[2011.12.08 23:02:17 | 000,087,608 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\inst.exe
[2011.12.08 23:02:17 | 000,007,887 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\pcouffin.cat
[2011.12.08 23:02:17 | 000,001,144 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\pcouffin.inf
[2011.12.08 22:20:53 | 000,001,041 | ---- | C] () -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\vso_ts_preview.xml
[2011.12.08 20:25:00 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2011.12.08 17:03:53 | 000,000,050 | ---- | C] () -- C:\Windows\System32\bridf08b.dat
[2011.12.07 22:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\lagarith.dll
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.08.28 19:37:12 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\Asus WebStorage
[2013.01.12 23:11:05 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\DAEMON Tools Lite
[2012.07.03 17:59:26 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\DVDVideoSoft
[2012.07.03 17:44:29 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.05.07 13:25:37 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\elsterformular
[2012.12.21 09:12:47 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\ImgBurn
[2012.12.22 17:18:39 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\Oberon Media
[2011.11.28 21:18:31 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\PhotoFiltre
[2012.06.20 23:07:33 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\Sony
[2012.06.20 23:08:20 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\Sony Setup
[2012.06.08 00:59:47 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\systweak
[2013.02.03 14:32:52 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\TeamViewer
[2013.02.11 17:08:00 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\TuneUp Software
[2012.07.06 08:44:00 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\Uniblue
[2012.12.22 17:18:32 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\VisicomToolBar
[2013.02.22 13:40:21 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\Vso
[2012.07.05 21:42:20 | 000,000,000 | ---D | M] -- C:\Users\15G22J0290K0EU2Y\AppData\Roaming\Win7codecs
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Telephony\Providers >
"ProviderID0" = 1
"ProviderID1" = 2
"ProviderID2" = 3
"ProviderID3" = 4
"NextProviderID" = 7
"ProviderFileName0" = unimdm.tsp -- [2010.11.20 13:16:53 | 000,281,088 | ---- | M] (Microsoft Corporation)
"ProviderFileName1" = kmddsp.tsp -- [2009.07.14 02:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation)
"ProviderFileName2" = ndptsp.tsp -- [2009.07.14 02:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation)
"ProviderFileName3" = hidphone.tsp -- [2009.07.14 02:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation)
"NumProviders" = 5
"ProviderID4" = 6
"ProviderFilename4" = MICBx19zz.tsp
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Parameters >
"ServiceDll" = %SystemRoot%\System32\pouae2gyp.dll
"ServiceDllUnloadOnStop" = 1
"extension" = %SystemRoot%\System32\dnsext.dll -- [2009.07.14 02:15:12 | 000,006,656 | ---- | M] (Microsoft Corporation)
"CacheHashTableBucketSize" = 1
"CacheHashTableSize" = 180
"MaxCacheEntryTtlLimit" = 65280
"MaxSOACacheEntryTtlLimit" = 301
"EnablePlainTextPassword" = 0
"EnableSecuritySignature" = 1
"OtherDomains" = [binary data]
"RequireSecuritySignature" = 0
"ServiceMain" = SetAccessPolicy
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Parameters\DnsCache]
< HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost >
"RPCSS" = RpcEptMapperRpcSs [binary data]
"defragsvc" = defragsvc [binary data] -- [2009.07.14 02:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation)
"LocalSystemNetworkRestricted" = UxSmsWdiSystemHostNetmantrkwks [Binary data over 200 bytes]
"LocalService" = nsiWdiServiceHostw32timeEventSy [Binary data over 200 bytes]
"netsvcs" = AeLookupSvcCertPropSvcSCPolicySv [Binary data over 200 bytes]
"WerSvcGroup" = wersvc [binary data] -- [2009.07.14 02:16:18 | 000,065,024 | ---- | M] (Microsoft Corporation)
"LocalServiceNoNetwork" = DPSPLABFEmpssvcWwanSvc [binary data]
"termsvcs" = TermService [binary data]
"swprv" = swprv [binary data] -- [2009.07.14 02:16:15 | 000,313,856 | ---- | M] (Microsoft Corporation)
"LocalServiceNetworkRestricted" = DHCPeventlogAudioSrvBthHFSrvLm [Binary data over 200 bytes]
"LocalServicePeerNet" = PNRPSvcp2pimsvcp2psvcPnrpAutoReg [binary data]
"NetworkServiceAndNoImpersonation" = KtmRm [binary data]
"regsvc" = RemoteRegistry [binary data]
"LocalServiceAndNoImpersonation" = SSDPSRVupnphostSCardSvrTBSFont [Binary data over 200 bytes]
"DcomLaunch" = PowerPlugPlayDcomLaunch [binary data]
"NetworkServiceNetworkRestricted" = PolicyAgent [binary data]
"NetworkService" = CryptSvcDHCPTermServiceDNSCache [Binary data over 200 bytes]
"sdrsvc" = sdrsvc [binary data] -- [2010.11.20 13:21:06 | 000,125,952 | ---- | M] (Microsoft Corporation)
"WbioSvcGroup" = WbioSrvc [binary data] -- [2009.07.14 02:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation)
"imgsvc" = StiSvc [binary data]
"wcssvc" = WcsPlugInService [binary data] -- [2009.07.14 02:16:18 | 000,032,768 | ---- | M] (Microsoft Corporation)
"AxInstSVGroup" = AxInstSV [binary data] -- [2010.11.20 13:18:06 | 000,088,064 | ---- | M] (Microsoft Corporation)
"secsvcs" = WinDefend [binary data]
"bthsvcs" = bthserv [binary data] -- [2009.07.14 02:15:00 | 000,064,512 | ---- | M] (Microsoft Corporation)
"Update-Service-Installer-Service" = Update-Service-Installer-Service [binary data]
"Update-Service" = Update-Service [binary data]
"GPSvcGroup" = GPSvc [binary data] -- [2010.11.20 13:19:09 | 000,593,408 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\AxInstSVGroup]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\defragsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\GPSvcGroup]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalService]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalServiceAndNoImpersonation]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalServiceNetworkRestricted]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalServiceNoNetwork]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalSystemNetworkRestricted]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\netsvcs]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\NetworkService]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\NetworkServiceRemoteDesktopHyperVAgent]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\NetworkServiceRemoteDesktopPublishing]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\SDRSVC]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\swprv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\termsvcs]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\wcssvc]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\wercplsupport]
< HKEY_LOCAL_MACHINE\SOFTWARE\Joosoft.com >
[HKEY_LOCAL_MACHINE\SOFTWARE\Joosoft.com\UpdateClient]
< %SystemRoot%\system32\*.tsp >
[2009.07.14 02:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2009.07.14 02:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2009.07.14 02:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2009.07.14 02:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2010.11.20 13:16:53 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
< C:\Windows\system32\*.dll /360 >
[2012.08.23 12:15:57 | 000,269,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\aaclient.dll
[2012.03.08 10:47:00 | 000,176,736 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\system32\AERTACap.dll
[2012.03.08 10:47:34 | 000,095,840 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\system32\AERTARen.dll
[2012.11.30 05:45:14 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
[2012.11.30 05:45:14 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
[2012.11.30 05:45:14 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
[2012.11.30 05:45:14 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
[2012.11.30 05:45:14 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.11.30 05:45:14 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
[2012.11.30 05:45:14 | 000,005,120 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
[2012.11.30 05:45:14 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
[2012.11.30 05:45:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
[2012.11.30 05:45:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
[2012.11.30 05:45:15 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
[2012.11.30 05:45:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 05:45:15 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
[2012.11.30 05:45:15 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
[2012.11.30 05:45:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
[2012.11.30 05:45:15 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
[2012.11.30 05:45:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.11.30 05:45:15 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.11.30 05:45:15 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
[2012.11.30 05:45:15 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
[2012.11.30 05:45:15 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.11.30 05:45:15 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
[2012.11.30 05:45:15 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
[2012.11.30 05:45:15 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.11.30 03:38:59 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
[2012.11.30 03:38:59 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
[2012.11.30 03:38:59 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
[2012.11.30 03:38:59 | 000,006,144 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
[2012.12.16 15:13:28 | 000,295,424 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\system32\atmfd.dll
[2012.12.16 15:13:20 | 000,034,304 | ---- | M] (Adobe Systems) -- C:\Windows\system32\atmlib.dll
[2012.07.04 22:14:34 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\browcli.dll
[2012.07.04 22:14:34 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\browser.dll
[2012.12.04 01:12:16 | 001,534,464 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\BrWia09b.dll
[2012.06.06 06:03:06 | 000,805,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\cdosys.dll
[2012.06.02 05:36:29 | 001,159,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\crypt32.dll
[2012.06.02 05:36:29 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\cryptnet.dll
[2012.06.02 05:36:29 | 000,140,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\cryptsvc.dll
[2012.08.02 17:57:20 | 000,490,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\d3d10level9.dll
[2012.12.10 16:07:27 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\system32\deployJava1.dll
[2012.10.09 18:40:31 | 000,193,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dhcpcore6.dll
[2012.10.09 18:40:31 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dhcpcsvc6.dll
[2012.11.02 06:11:31 | 000,376,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dpnet.dll
[2012.03.03 06:31:19 | 001,077,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\DWrite.dll
[2012.07.02 19:28:06 | 000,112,640 | ---- | M] () -- C:\Windows\system32\ff_vfw.dll
[2012.04.10 13:40:00 | 002,193,472 | ---- | M] (Fortemedia Corporation) -- C:\Windows\system32\FMAPO.dll
[2012.12.07 13:20:43 | 002,576,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\gameux.dll
[2013.01.08 23:09:18 | 009,738,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieframe.dll
[2013.01.08 22:56:51 | 001,796,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iertutil.dll
[2013.01.08 22:53:13 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieui.dll
[2012.03.01 06:33:23 | 000,159,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\imagehlp.dll
[2012.10.03 17:40:35 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iphlpsvc.dll
[2012.06.25 15:12:07 | 000,744,960 | ---- | M] (Intel Corporation) -- C:\Windows\system32\IR41_32.DLL
[2013.01.08 22:58:43 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\jscript.dll
[2013.01.08 23:11:21 | 001,800,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\jscript9.dll
[2013.01.08 23:00:14 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\jsproxy.dll
[2012.08.11 00:56:14 | 000,542,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kerberos.dll
[2012.11.30 05:47:44 | 000,868,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kernel32.dll
[2012.11.30 05:47:45 | 000,293,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\KernelBase.dll
[2012.05.14 05:33:42 | 000,769,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\localspl.dll
[2012.08.24 17:56:48 | 001,039,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\lsasrv.dll
[2012.04.03 17:41:58 | 000,709,976 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\system32\MaxxAudioAPOShell.dll
[2012.04.03 17:41:54 | 001,185,112 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\system32\MaxxAudioRealtek2.dll
[2012.05.21 17:28:58 | 000,155,648 | ---- | M] () -- C:\Windows\system32\mlc.dll
[2013.01.08 22:57:49 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msfeeds.dll
[2013.01.08 23:23:25 | 012,321,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mshtml.dll
[2013.01.08 22:56:37 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mshtmled.dll
[2012.04.07 12:26:29 | 002,342,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msi.dll
[2012.08.23 14:47:20 | 000,046,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\MsRdpWebAccess.dll
[2012.08.23 09:19:01 | 004,916,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mstscax.dll
[2012.06.06 06:05:52 | 001,236,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msxml3.dll
[2012.11.01 05:47:54 | 001,389,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msxml6.dll
[2012.11.20 05:51:09 | 000,220,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ncrypt.dll
[2012.10.03 17:42:23 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ncsi.dll
[2012.07.04 22:16:56 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\netapi32.dll
[2012.10.03 17:42:24 | 000,175,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\netcorehc.dll
[2012.10.03 17:42:24 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\netevent.dll
[2012.06.22 15:32:30 | 000,405,144 | ---- | M] (Newtonsoft) -- C:\Windows\system32\Newtonsoft.Json.Net20.dll
[2012.10.03 17:42:26 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\nlaapi.dll
[2012.10.03 17:42:26 | 000,242,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\nlasvc.dll
[2012.12.10 16:07:27 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\system32\npDeployJava1.dll
[2012.10.10 20:14:44 | 002,428,776 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvapi.dll
[2012.10.10 20:14:46 | 017,559,912 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvcompiler.dll
[2012.10.02 20:28:53 | 003,965,288 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvcpl.dll
[2012.10.10 20:14:42 | 007,697,768 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvcuda.dll
[2012.10.10 20:15:04 | 001,867,112 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvcuvenc.dll
[2012.10.10 20:15:00 | 002,574,696 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvcuvid.dll
[2012.10.10 20:14:16 | 015,309,160 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvd3dum.dll
[2012.10.10 20:14:22 | 001,009,512 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvdispco32.dll
[2012.10.10 20:14:50 | 000,888,168 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvdispgenco32.dll
[2012.03.01 00:59:00 | 000,881,984 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvgenco32.dll
[2012.10.02 20:29:41 | 000,108,392 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvmctray.dll
[2012.10.10 20:14:22 | 019,906,920 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvoglv32.dll
[2012.10.10 20:14:16 | 006,127,464 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvopencl.dll
[2012.10.02 20:29:41 | 000,062,312 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvshext.dll
[2012.10.02 20:29:22 | 002,853,224 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvsvc.dll
[2012.10.02 20:29:41 | 002,557,288 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvsvcr.dll
[2012.10.10 20:14:50 | 012,501,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvwgf2um.dll
[2012.03.01 00:59:00 | 000,061,248 | ---- | M] (Khronos Group) -- C:\Windows\system32\OpenCL.dll
[2012.05.01 05:44:12 | 000,164,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\profsvc.dll
[2012.05.04 10:59:54 | 000,514,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\qdvd.dll
[2012.04.26 05:45:54 | 000,129,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpcorekmts.dll
[2012.08.23 11:08:49 | 002,739,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpcorets.dll
[2012.08.23 12:12:17 | 000,192,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpendp_winip.dll
[2012.08.23 14:52:25 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\RdpGroupPolicyExtension.dll
[2012.08.23 15:48:14 | 000,221,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpudd.dll
[2012.04.26 05:45:55 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpwsx.dll
[2012.05.09 14:57:36 | 003,166,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\system32\RtkAPO.dll
[2012.05.29 15:34:44 | 000,637,584 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\system32\RtkApoApi.dll
[2012.05.31 17:08:16 | 000,087,696 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\system32\RtkCoInstII.dll
[2012.05.09 14:57:36 | 002,415,720 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\system32\RtkPgExt.dll
[2012.08.24 17:57:40 | 000,247,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\schannel.dll
[2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\shell32.dll
[2012.05.05 08:46:52 | 000,400,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\srcore.dll
[2012.09.25 23:47:43 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\synceng.dll
[2012.08.23 14:18:14 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\tsgqec.dll
[2012.08.23 14:32:59 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\TsUsbGDCoInstaller.dll
[2012.08.23 15:10:04 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
[2012.11.09 05:42:49 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\tzres.dll
[2012.06.09 18:21:56 | 000,178,688 | ---- | M] () -- C:\Windows\system32\unrar.dll
[2013.01.08 23:01:48 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\url.dll
[2013.01.08 23:03:57 | 001,103,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\urlmon.dll
[2012.11.22 05:45:03 | 000,626,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\usp10.dll
[2013.01.08 22:58:29 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\vbscript.dll
[2012.06.22 22:28:30 | 001,282,048 | ---- | M] (xy-VSFilter Team) -- C:\Windows\system32\VSFilter.dll
[2012.07.26 03:46:47 | 000,009,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Wdfres.dll
[2012.11.09 05:43:04 | 000,492,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\win32spl.dll
[2013.01.08 23:03:20 | 001,129,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wininet.dll
[2013.01.04 05:50:52 | 000,169,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\winsrv.dll
[2012.08.24 17:57:48 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wintrust.dll
[2012.08.23 14:46:20 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wksprtPS.dll
[2012.03.01 06:29:16 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wmi.dll
[2012.12.07 13:26:17 | 000,308,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Wpc.dll
[2012.06.02 23:19:23 | 000,577,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuapi.dll
[2012.06.02 23:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuaueng.dll
[2012.06.02 23:12:32 | 002,422,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wucltux.dll
[2012.07.26 04:20:40 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\WUDFCoinstaller.dll
[2012.07.26 04:20:40 | 000,172,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\WUDFPlatform.dll
[2012.07.26 04:20:40 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\WUDFSvc.dll
[2012.07.26 04:20:40 | 000,613,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\WUDFx.dll
[2012.06.02 23:12:13 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wudriver.dll
[2012.06.02 23:19:32 | 000,035,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wups.dll
[2012.06.02 23:19:33 | 000,045,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wups2.dll
[2012.06.02 14:19:42 | 000,171,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuwebv.dll
[2012.05.30 10:52:20 | 004,305,920 | ---- | M] () -- C:\Windows\system32\x264vfw.dll
[2009.07.14 05:53:46 | 000,032,640 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.07.14 05:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2012.01.25 17:20:32 | 000,001,114 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.01.25 17:20:34 | 000,001,118 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.04.02 09:33:05 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.06.07 14:44:12 | 000,000,266 | ---- | C] () -- C:\Windows\Tasks\AutoKMS.job
[2012.07.30 08:02:36 | 000,000,950 | ---- | C] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1998982368-3054312690-3844566786-1000Core.job
[2012.07.30 08:02:37 | 000,000,972 | ---- | C] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1998982368-3054312690-3844566786-1000UA.job
< C:\Windows\SysNative\*.dll /360 >
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 192 bytes -> C:\ProgramData\TEMP:CB0AACC9
< End of report > Ist das jetzt richtig. |