Code:
OTL Extras logfile created on: 14.02.2013 17:22:08 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\*****\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
5,61 Gb Total Physical Memory | 3,62 Gb Available Physical Memory | 64,63% Memory free
11,21 Gb Paging File | 8,93 Gb Available in Paging File | 79,67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297,99 Gb Total Space | 126,73 Gb Free Space | 42,53% Space Free | Partition Type: NTFS
Drive Z: | 82,98 Mb Total Space | 38,64 Mb Free Space | 46,57% Space Free | Partition Type: NTFS
Computer Name: ******** | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-830199503-3038931148-3267462750-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01E3CCBF-3FB9-4409-862F-07BDB1AA9628}" = lport=rpc | protocol=6 | dir=in | app=c:\program files\sisoftware\sisoftware sandra lite 2012.sp5a\wnt500x64\rpcsandrasrv.exe |
"{04A75E48-1535-41EA-8451-CBDEDA35E92F}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{08804E0B-AAD4-4F4B-9201-F51E71C7BDFC}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
"{153225E6-5F2E-4B1B-BFF6-F818002B7EC3}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{1B39C33B-260C-43B8-84CF-8267B23592EF}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{1D0BC636-EB39-44F6-B0FF-9AFFD1E16114}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2A3C10F8-DCF6-4372-A553-C2CD8FC1FB6E}" = lport=445 | protocol=6 | dir=in | app=system |
"{2F4D0F7C-FBB8-4172-9821-AFABB012D0E3}" = rport=445 | protocol=6 | dir=out | app=system |
"{3398B788-7E9B-430C-80E9-93C0B4B4A347}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{359E2146-3163-4970-85FA-C59F967FC7C4}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
"{369F9ADE-50BE-4829-9AC6-F60DE058F1A7}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{3765E0A7-5620-41FC-AB45-8696F32F1EB1}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{380E3080-B290-4690-899E-1CEE67AA92A9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{3FB5E170-C484-482C-B9AE-B38EB6B81747}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4D9527DC-A9C8-4694-9821-8FA351656EE5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{520DB9E2-77A1-4BC4-A81C-BEAB8A3320D2}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
"{56877B28-7827-4EFF-AF6A-737735A75ED3}" = rport=139 | protocol=6 | dir=out | app=system |
"{5AABFCA0-85B7-4A70-A5EA-49F0894A908F}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5E94CEC6-6EE9-494B-B519-64D0866B9B3C}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{6895C39F-3160-4621-9AFB-DA01922A90B0}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{7584E4EF-EC90-4626-924A-926BB7A3FB10}" = lport=139 | protocol=6 | dir=in | app=system |
"{7AC167D0-8767-4D38-8773-C5F36723D200}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{7B20C2FA-C3FF-4480-8691-46BE53C6AE17}" = rport=138 | protocol=17 | dir=out | app=system |
"{8419DA14-AC0C-4CD1-9717-173447B7054C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8E606FFE-2C12-48C7-AE1A-8426E68C1ED5}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{997B6632-848D-450B-8F96-A81317B7187A}" = lport=138 | protocol=17 | dir=in | app=system |
"{A75167E0-A056-4AF4-8CDE-9015A1A549A6}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{A79D175B-91CB-42C4-B92F-25B5434AEEBF}" = lport=10243 | protocol=6 | dir=in | app=system |
"{B0C96D42-47DC-4BCE-A2ED-C78C535B36E3}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B3EACAAB-E1C2-4139-9A43-93A2A5BBCD89}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BD996BA9-B8AC-4CDE-BB85-B7D322E90FCD}" = lport=rpc | protocol=6 | dir=in | app=c:\program files\sisoftware\sisoftware sandra lite 2012.sp5a\rpcagentsrv.exe |
"{C0EC2A78-DE1E-49EC-A4DB-3CE143B0886F}" = lport=137 | protocol=17 | dir=in | app=system |
"{C7FFF57D-7B05-4412-B42A-C2D5D5318FE8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CE56AE1B-055B-46C8-9426-820D5E6C007E}" = rport=137 | protocol=17 | dir=out | app=system |
"{E0329FFB-EAB3-494E-8FA3-D8C294F435A9}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E698FE32-11E5-44D4-9724-B1962D04CD51}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{E7A57DAE-8625-40B0-92C8-F3D8E1791416}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EADF1D63-2485-4B75-9774-F2C7B5B9CD66}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{EB73B3D1-A389-443D-A503-81C962A39464}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
"{ED5EC927-1559-43F7-88E9-27BEA9E7DBF6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{EDD81481-9A9F-42A2-9721-BA1BFC8E94BF}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EFF026D7-B5B5-4243-AFF1-ADEF37D93BEE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F30C74E6-4BD0-4068-B8A0-AFBAEBEF4C92}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00D1A32E-E4E1-4D56-8911-81162080B0CD}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{016CC9C1-29D9-4CB9-B9E7-81271EBE2669}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{02AED970-C57C-49FC-8E02-A62C04A6387D}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{06272F1E-8BBE-45FC-B0D6-67E7C2979DAE}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{10B655C2-9D1E-4850-ADBA-48B094DDB333}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{11B7BD93-A8BB-41E6-98F7-1B7F0AB0EAE7}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{129F9872-7B7D-4B8E-BFA8-FFFFC0FA2C44}" = protocol=6 | dir=in | app=c:\programdata\kodak\installer\setup.exe |
"{1472BC71-EEB0-4FAC-B0D9-4435594D3B1C}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\kodak.statistics.exe |
"{1AC93D93-61A1-41FF-9DC7-6E5726829EF9}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{1EEED19B-A595-4998-87E2-87E23B49555B}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{21EBFA0E-C08A-4631-B1E7-9E3A0F6787E5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{26B875CE-511E-4D13-B17F-6027894982EC}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{29F53337-9CEA-4C7C-8C17-35B48C7004E4}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\networkprinterdiscovery.exe |
"{30395A3A-A94C-43E3-8623-2E4ACED28B6C}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{31FC7D40-8058-44B3-91A5-C3731C91F947}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\aiohomecenter.exe |
"{3224269F-7B23-4F01-B3E3-3A7DE236BE4F}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{37A01806-8D2A-4E76-A9D1-9EC20F765567}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3E494CF8-ADF2-4DB5-87CD-5F2F68C5DBFC}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3F3F2945-4457-4F35-8262-697C513AB4D5}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{43768D21-28C7-40FF-886C-8536FD23C52E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{4C37DF14-F329-4780-A47A-C84EA182F07B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2\justcause2.exe |
"{53BD0E90-975F-4680-B3BB-BC4AA5EC4C20}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{54519B0F-D865-4E61-91A4-0E361EAE88FC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5A9AA93D-DB1F-4680-A1F8-15C5835E394D}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{632E0E37-602D-4587-B265-95BAEA58463F}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\aiohomecenter.exe |
"{69FAE27C-68F5-48E4-9A1F-D79BD60EDE45}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{6C2CC2A6-10D5-43C1-BE89-CB05031514C7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{710B9AD2-02C6-4CCE-B032-BCF360FC16D2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7639E7BA-D335-4807-86B0-8DDB68C4EF5E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7670EC77-509A-4842-88D2-8F58FEFEE832}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{767F2B41-FDF6-47C7-873A-D0212782F782}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{78AD89E7-5F7E-4E51-B7F1-485639211A7C}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{79E0C3B8-5D7D-410A-A693-0209293D9C49}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2\justcause2.exe |
"{7BE19AE0-1C57-43F2-80CD-EB3D25E47141}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7F4C3BC4-729A-4BF1-9A60-7F169C7E7200}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\networkprinterdiscovery.exe |
"{8869E106-6A4C-4AA9-968D-7661AD9FFC39}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{897659E5-7CD4-42CC-A2DA-84EFE54DF32A}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{8FE601BD-189C-4E4B-8955-DC191BBB204C}" = protocol=1 | dir=in | name=sisoftware deployment agent service (icmp-in) |
"{9400A339-468F-4C89-A1E7-A1F4357B5787}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{94A32C34-88CB-436D-A292-5E2BA21AF491}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{98273B4E-1AF1-46D2-8C09-7ED71F680E2D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{9DA72641-B166-48EC-A4F0-E98664E819B9}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\firmware\kodakaioupdater.exe |
"{A177C15E-3770-4B4E-A9A2-9D6A20D9FB54}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{A18B3813-AA78-4EAA-84B5-EDE92AAD5CFA}" = protocol=17 | dir=in | app=c:\users\*****\downloads\utorrent.exe |
"{A29784DA-5AB3-4DB7-B006-7555F1CCAE9E}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{AAA9BD73-1ABE-4CC8-9723-98F1DF954642}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{AE94C606-D1A1-4CDB-8E94-A556A00A96B2}" = protocol=17 | dir=in | app=c:\programdata\kodak\installer\setup.exe |
"{B23A1B4C-49A3-428E-B0DC-FEEBE8CAD7B1}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\kodak.statistics.exe |
"{B602B93E-6BFD-4721-9575-11CEE7219025}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{BCFD3201-AC7B-4470-847D-76C97DD5CB36}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C3743B09-0B3A-496E-A19C-D7571C0F5A5C}" = protocol=6 | dir=out | app=system |
"{C486D0DC-7E04-42FD-9AA3-F9110E5B20A8}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) |
"{C7FFA64B-286B-4816-BC91-1868BADEFF96}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CB38137D-4AD9-4B6F-994B-5968E3A00D8A}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CBA86CCB-7047-4481-ADEE-CBE1A6893339}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{CD8C56F0-72EA-4037-AE17-E86459042D98}" = protocol=17 | dir=in | app=c:\fm13\fussball manager 13\manager13.exe |
"{CDCAC5C7-F6D7-4BAD-94F8-FB8EB1A7133E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{D13E5B64-4715-4BE0-AF3F-35291E164F34}" = protocol=6 | dir=in | app=c:\fm13\fussball manager 13\manager13.exe |
"{DD837881-126F-4AE1-9855-D59D3AC56DDD}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{DDF29D3C-E330-4C6D-8F9B-B6E63813C53D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E1B9CE8D-0F01-4621-9C14-64E0CB74982E}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{E4B06DCB-E537-417F-948D-1BB9A3C9291A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E6031F44-B53A-4A23-B80C-793217F89B06}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\firmware\kodakaioupdater.exe |
"{EEFE1E07-F612-468D-9E85-278FB1DE4F67}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F3100253-0738-42F2-A7D3-7B6DC8F93611}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{F32FB6E4-EEA8-4C64-8723-2E01A1973A4C}" = protocol=6 | dir=in | app=c:\users\*****\downloads\utorrent.exe |
"{F9818710-ED96-4DE6-B97C-43FB7B8185EB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FD01369B-1478-4448-A5C8-E8D1D7A7E5EC}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"TCP Query User{166C2EF0-56F3-4477-8D50-A532BFF088D6}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{2A938A5B-142C-4418-988B-86FA3F1009AC}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"TCP Query User{2E07B278-D21E-40B3-854D-ADE57E8BA46E}C:\program files\realvnc\vnc viewer\vncviewer.exe" = protocol=6 | dir=in | app=c:\program files\realvnc\vnc viewer\vncviewer.exe |
"TCP Query User{4029268D-E60B-4478-B337-DC5AD9A1DE65}C:\program files (x86)\polareditoctagon10x8\polaredit1018.exe" = protocol=6 | dir=in | app=c:\program files (x86)\polareditoctagon10x8\polaredit1018.exe |
"TCP Query User{76214B9B-0654-491B-B864-16CAFB10FD8C}C:\program files (x86)\steam\steamapps\neoforce_v2\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\neoforce_v2\counter-strike source\hl2.exe |
"TCP Query User{78E90940-E41E-4923-8D5B-96A63C46B31D}C:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tmnationsforever\tmforever.exe |
"TCP Query User{821E7292-EFAB-47F2-BE83-F06416BB8071}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{DDB6C9E4-7BC2-43C8-B34A-B410383388E9}C:\program files (x86)\atari\test drive unlimited\testdriveunlimited.exe" = protocol=6 | dir=in | app=c:\program files (x86)\atari\test drive unlimited\testdriveunlimited.exe |
"UDP Query User{399E60CF-C2E2-4EE7-AF61-13F5AE182212}C:\program files (x86)\polareditoctagon10x8\polaredit1018.exe" = protocol=17 | dir=in | app=c:\program files (x86)\polareditoctagon10x8\polaredit1018.exe |
"UDP Query User{473F5B3F-335D-4C00-8FA0-C00AF8F80615}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{5E6C2938-299D-408D-85E6-A15BCE4FC33A}C:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tmnationsforever\tmforever.exe |
"UDP Query User{824E55CB-C924-4C49-A0FE-144CC9C22C51}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{9FDED4A4-8ED4-4702-AA8F-A77E9E3E8DB5}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"UDP Query User{A99D7E1D-30DF-4BB4-8E92-791D956A7993}C:\program files (x86)\atari\test drive unlimited\testdriveunlimited.exe" = protocol=17 | dir=in | app=c:\program files (x86)\atari\test drive unlimited\testdriveunlimited.exe |
"UDP Query User{BFB0ED04-CDD2-4097-B278-2F311EF32330}C:\program files (x86)\steam\steamapps\neoforce_v2\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\neoforce_v2\counter-strike source\hl2.exe |
"UDP Query User{FABCBE9A-51AD-422D-9B91-BB6F86A3F193}C:\program files\realvnc\vnc viewer\vncviewer.exe" = protocol=17 | dir=in | app=c:\program files\realvnc\vnc viewer\vncviewer.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt
"{0C70221E-BCEB-AABD-7E4F-65476125BF9F}" = ccc-utility64
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{22D8AE6F-3C6B-47E8-8F04-629F23DBE978}" = iTunes
"{26A24AE4-039D-4CA4-87B4-2F86417007FF}" = Java 7 Update 7 (64-bit)
"{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}" = Kodak AIO Printer
"{28A43593-43C6-30BF-BB23-E9AE543766FB}" = AMD Fuel
"{2CD600E3-55E9-47B3-9611-6FE0ECC04BF9}" = BrazosTweaker
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5749CDC2-06FA-BFCC-C584-562082F50165}" = AMD Accelerated Video Transcoding
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{624C7F0A-89B2-4C49-9CAB-9D69613EC95A}" = Microsoft IntelliPoint 8.2
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile-Gerätecenter
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7660521A-062D-41F5-AA5E-CBA0E0511131}" = Treiber-Studio 2013
"{783DD6D9-3A93-94A3-6B1F-3F534EF09419}" = AMD AVIVO64 Codecs
"{8219EDCB-CE5A-4348-B056-AAC0FE4E99D0}" = Microsoft IntelliType Pro 8.2
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{82D8994C-8DC1-A68C-E966-AF915C9FE8B5}" = AMD Drag and Drop Transcoding
"{833F5E6D-6E01-11D1-978E-6DFBCEF72570}" = AMD Steady Video Plug-In
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BE9D5B90-787F-F132-876D-3C75ED5DD17A}" = AMD Media Foundation Decoders
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2396}_is1" = SiSoftware Sandra Lite 2012.SP5a
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{DDDCCFAD-2BCF-4F98-60F1-2D9262E09839}" = AMD Catalyst Install Manager
"{E9EED4AE-682B-4501-9574-D09A21717599}_is1" = AMD Quick Stream
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"Elantech" = ETDWare PS/2-X64 8.0.5.0_WHQL
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2
"Microsoft IntelliType Pro 8.2" = Microsoft IntelliType Pro 8.2
"RealVNCViewer_is1" = VNC Viewer 5.0.3
"Totalcmd64" = Total Commander 64-bit (Remove or Repair)
"VLC media player" = VLC media player 2.0.5
"WinRAR archiver" = WinRAR 4.20 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{0472F2C0-6BA4-03DF-07C8-ADDC8E9CC819}" = CCC Help Thai
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06E098A3-81EF-8426-0233-C00F2E52EC40}" = CCC Help Greek
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{09EAF3A0-6EFA-4482-91F5-CAAF4704E7C2}" = CCC Help French
"{0B8D7199-3AD8-2948-55DE-6100AB07DB6F}" = CCC Help Portuguese
"{1235083F-52F9-44CC-9DF5-F9B7802BB9B7}" = ISO Recorder
"{19ADFF5E-D5F5-4132-8D9B-AF07057057C3}" = Angry Birds Collection
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21287F5D-6703-2BBA-F54D-CE6F28332AAB}" = CCC Help Turkish
"{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9
"{2A3A4BD6-6CE0-4E2A-80D2-1D0FF6ACBFBA}" = LG United Mobile Driver
"{2D7088E8-5509-2477-E6D2-3116B8ECD46E}" = AMD VISION Engine Control Center
"{376348C2-E372-48BC-A138-E896757BD86A}" = aioscnnr
"{38717452-B781-2802-F496-F5C8886AA16D}" = CCC Help Norwegian
"{3A40E4DD-D87B-F5B0-4FCE-1C34EA749AB1}" = CCC Help English
"{3D6A3DE8-26F3-7E28-257E-B56244CE978E}" = CCC Help Chinese Traditional
"{40F95BFE-36CF-481F-B7D9-8D8F2F3369F9}" = TSDoctor
"{46EDCFA5-7EDB-46A9-B093-1C6237470CEC}" = 3DMark 11
"{48E5D832-56EF-D41E-ED72-255DE5AA983C}" = CCC Help Korean
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B35F00C-E63D-40DC-9839-DF15A33EAC46}" = Grand Theft Auto Vice City
"{4C1998B1-6C82-AFD1-4D8E-0C46042FA679}" = CCC Help Japanese
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{4D75C9EF-26C4-BA8D-4AA6-D12187CAAF3C}" = CCC Help Chinese Standard
"{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1" = Data Lifeguard Diagnostic for Windows 1.24
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{56805EA7-6FC2-2D47-5E97-5B5B529DD2F0}" = Catalyst Control Center Localization All
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{59E4543A-D49D-4489-B445-473D763C79AF}" = Microsoft Games for Windows - LIVE Redistributable
"{5AE46073-8D1C-8C9B-CF59-A50B229C69A5}" = Catalyst Control Center InstallProxy
"{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}" = NVIDIA PhysX
"{668C378C-6D35-1FED-9D8C-A9973AAB847E}" = CCC Help Finnish
"{678A9813-B5F3-7AC9-B630-8AF64034A8F8}" = CCC Help Czech
"{690F5BA3-5DEB-42CD-962B-F687EE59FAA7}" = Windows Live Essentials
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser und SDK
"{71972D00-4596-11E2-B6EA-B8AC6F97B88E}" = Google Earth Plug-in
"{73B44BD5-3659-88B9-5169-0C0E262CBA42}" = CCC Help Danish
"{74CCD315-40BF-0D42-E291-2136725F0921}" = CCC Help Hungarian
"{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7AA2C7DA-ECDD-46CC-9716-313B0EA050EB}_is1" = PolarEditOctagon 10x8 v 0.7.2.8
"{7D916FA5-DAE9-4A25-B089-655C70EAF607}" = Qualcomm Atheros WiFi Driver Installation
"{80AF0300-866F-400F-A350-D53E3C3E34E0}" = FUSSBALL MANAGER 13
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8394355C-ACC9-D7A4-9DC0-9BC7C54E2A1A}" = Catalyst Control Center Graphics Previews Common
"{86F4F32B-77C7-4951-B33C-05D41A8190C1}" = Microsoft RichCopy 4.0
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{8F311E92-C29F-4DF9-8259-B739A1831669}_is1" = SUPER © v2012.build.54 (Nov 18, 2012) Version v2012.build.54
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{9017CEAF-BE5A-4F73-8A0E-C87E26971E55}" = TomTom HOME
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v4.0
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{AE364ACC-B9DF-466B-B4EA-AEECD0CD581E}" = Windows Live Messenger
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B4C94CD6-9A8C-9F8C-F9B8-861704BC917D}" = CCC Help German
"{B727564C-47D3-473A-AC9E-F4BE7B1BD5D3}" = Windows Live UX Platform Language Pack
"{BE94C681-68E2-4561-8ABC-8D2E799168B4}" = essentials
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{BFBCF96F-7361-486A-965C-54B17AC35421}" = ocr
"{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
"{C11E1583-3056-99A7-A8AF-9C84720B615E}" = CCC Help Spanish
"{C1FDB9CE-77EC-4F7B-8AC9-5E18277101F3}" = Multiecuscan
"{C37A0BC1-52EE-4F97-8223-5CA9FC0357B0}" = Test Drive Unlimited
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{CC2422C9-F7B5-4175-B295-5EC2283AA674}" = Command & Conquer™ 3: Kanes Rache
"{CC6A1270-2C4F-87A5-7C3E-3419EF6C54B4}" = CCC Help Italian
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{D12FCFF9-13E2-B599-8703-FF5975AA8AA0}" = CCC Help Russian
"{D71C27AF-6C35-4F85-B60F-1237BD3B469A}" = BlueStacks
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DBE5DACF-BC0A-5932-62FD-C0348EA880C4}" = CCC Help Polish
"{DDA3C325-47B2-4730-9672-BF3771C08799}_is1" = XMedia Recode Version 3.1.2.5
"{DDEDAF6C-488E-4CDA-8276-1CCF5F3C5C32}" = Command & Conquer 3
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK All-in-One Software
"{E1203F8C-FF34-4968-A4A5-B4F1F8533DAB}" = Photo Common
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EF53BFAB-4C10-40DB-A82D-9B07111715C6}" = aioscnnr
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2235E5E-7881-4293-9B6F-04B2609FBFF0}" = Windows Live Messenger
"{F37A70E0-9D34-A9EB-183A-8B5516759631}" = CCC Help Swedish
"{F47D8BFA-EFEA-16BF-A4DD-4490F81F5D60}" = CCC Help Dutch
"{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}" = ASUS Live Update
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"5513-1208-7298-9440" = JDownloader 0.9
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ArtMoney SE_is1" = ArtMoney SE v7.39.1
"Ashampoo Burning Studio 2012_is1" = Ashampoo Burning Studio 2012 v.10.0.15
"Audacity_is1" = Audacity 2.0.2
"Audiograbber" = Audiograbber 1.83 SE
"Audiograbber-Lame" = Audiograbber MP3-Plugin (64 bit)
"Avira AntiVir Desktop" = Avira Free Antivirus
"AviSynth" = AviSynth 2.5
"Bridge Constructor1.0" = Bridge Constructor
"Buy Script Maker für CSS" = Buy Script Maker für CSS 0.601
"Cool Edit 2000" = Cool Edit 2000
"DAEMON Tools Pro" = DAEMON Tools Pro
"DivX Setup" = DivX-Setup
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"DVBViewer Pro_is1" = DVBViewer Pro
"DVDFab 8 Qt_is1" = DVDFab 8.2.0.0 (03/08/2012) Qt
"DVDx 4.0" = DVDx 4.0
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.50
"FileZilla Client" = FileZilla Client 3.6.0.2
"Foxit Reader_is1" = Foxit Reader
"Fraps" = Fraps (remove only)
"Free Download Manager_is1" = Free Download Manager 3.9
"Game Booster_is1" = Game Booster 3
"HaaliMkx" = Haali Media Splitter
"iBackupBot for iTunes" = iBackupBot for iTunes 3.6.2
"Indeo® Software" = Indeo® Software
"MegaTrainer eXperience_is1" = MegaTrainer eXperience V1.1.6.0
"Mozilla Firefox 18.0.2 (x86 de)" = Mozilla Firefox 18.0.2 (x86 de)
"Mozilla Thunderbird 17.0.2 (x86 de)" = Mozilla Thunderbird 17.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"PrintProjects" = PrintProjects
"PS3 Media Server" = PS3 Media Server
"Reason5_is1" = Reason 5.0
"Revo Uninstaller" = Revo Uninstaller 1.94
"Sniper Ghost Warrior - Gold Edition_is1" = Sniper Ghost Warrior - Gold Edition
"Steam App 211" = Source SDK
"Steam App 240" = Counter-Strike: Source
"Steam App 8190" = Just Cause 2
"Sync Blocker 10.6 Release 1_is1" = Sync Blocker 10.6 Release 1
"TeamViewer 8" = TeamViewer 8
"TechPowerUp GPU-Z" = TechPowerUp GPU-Z
"TmNationsForever_is1" = TmNationsForever
"UltraISO_is1" = UltraISO Premium V9.52
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.4
"VobSub" = VobSub v2.23 (Remove Only)
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials
"winscp3_is1" = WinSCP 5.1.2
"Xilisoft DVD Ripper Ultimate" = Xilisoft DVD Ripper Ultimate
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
"YTdetect" = Yahoo! Detect
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-830199503-3038931148-3267462750-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Erkennungs-Plug-in
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 13.02.2013 22:33:52 | Computer Name = ******** | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: saxbkhbf.exe, Version: 0.0.0.0, Zeitstempel:
0x50f898d7 Name des fehlerhaften Moduls: saxbkhbf.exe, Version: 0.0.0.0, Zeitstempel:
0x50f898d7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00022efc ID des fehlerhaften Prozesses:
0x103c Startzeit der fehlerhaften Anwendung: 0x01ce0a5ba6b87e4e Pfad der fehlerhaften
Anwendung: C:\Users\*****\AppData\Local\Temp\mzujlndzzllt\saxbkhbf.exe Pfad des
fehlerhaften Moduls: C:\Users\*****\AppData\Local\Temp\mzujlndzzllt\saxbkhbf.exe
Berichtskennung:
f7b1e296-764e-11e2-9c73-ce5dd7c5c55c
Error - 14.02.2013 01:36:38 | Computer Name = ******** | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: saxbkhbf.exe, Version: 0.0.0.0, Zeitstempel:
0x50f898d7 Name des fehlerhaften Moduls: saxbkhbf.exe, Version: 0.0.0.0, Zeitstempel:
0x50f898d7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00022efc ID des fehlerhaften Prozesses:
0x17e0 Startzeit der fehlerhaften Anwendung: 0x01ce0a753d090b15 Pfad der fehlerhaften
Anwendung: C:\Users\*****\AppData\Local\Temp\mzujlndzzllt\saxbkhbf.exe Pfad des
fehlerhaften Moduls: C:\Users\*****\AppData\Local\Temp\mzujlndzzllt\saxbkhbf.exe
Berichtskennung:
7ffb4230-7668-11e2-9c73-ce5dd7c5c55c
Error - 14.02.2013 01:47:08 | Computer Name = ******** | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: saxbkhbf.exe, Version: 0.0.0.0, Zeitstempel:
0x50f898d7 Name des fehlerhaften Moduls: saxbkhbf.exe, Version: 0.0.0.0, Zeitstempel:
0x50f898d7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00022efc ID des fehlerhaften Prozesses:
0x107c Startzeit der fehlerhaften Anwendung: 0x01ce0a76b4ce0363 Pfad der fehlerhaften
Anwendung: C:\Users\*****\AppData\Local\Temp\mzujlndzzllt\saxbkhbf.exe Pfad des
fehlerhaften Moduls: C:\Users\*****\AppData\Local\Temp\mzujlndzzllt\saxbkhbf.exe
Berichtskennung:
f77e91ec-7669-11e2-9c73-ce5dd7c5c55c
Error - 14.02.2013 08:54:15 | Computer Name = ******** | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Name des fehlerhaften Moduls: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00022efc ID des fehlerhaften
Prozesses: 0x7a0 Startzeit der fehlerhaften Anwendung: 0x01ce0ab25f80d347 Pfad der
fehlerhaften Anwendung: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Pfad
des fehlerhaften Moduls: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Berichtskennung:
a264c21f-76a5-11e2-945c-ed827a6cc14e
Error - 14.02.2013 10:51:11 | Computer Name = *****-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Name des fehlerhaften Moduls: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00022efc ID des fehlerhaften
Prozesses: 0x528 Startzeit der fehlerhaften Anwendung: 0x01ce0ac2b5f5ca06 Pfad der
fehlerhaften Anwendung: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Pfad
des fehlerhaften Moduls: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Berichtskennung:
f836c205-76b5-11e2-945c-ed827a6cc14e
Error - 14.02.2013 11:01:19 | Computer Name = *****-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Name des fehlerhaften Moduls: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00022efc ID des fehlerhaften
Prozesses: 0xf1c Startzeit der fehlerhaften Anwendung: 0x01ce0ac420c9d010 Pfad der
fehlerhaften Anwendung: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Pfad
des fehlerhaften Moduls: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Berichtskennung:
629dfc6e-76b7-11e2-945c-ed827a6cc14e
Error - 14.02.2013 11:16:47 | Computer Name = *****-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Name des fehlerhaften Moduls: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00022efc ID des fehlerhaften
Prozesses: 0x1248 Startzeit der fehlerhaften Anwendung: 0x01ce0ac6497018e7 Pfad der
fehlerhaften Anwendung: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Pfad
des fehlerhaften Moduls: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Berichtskennung:
8bbfd62b-76b9-11e2-945c-ed827a6cc14e
Error - 14.02.2013 11:19:15 | Computer Name = *****-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Name des fehlerhaften Moduls: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00022efc ID des fehlerhaften
Prozesses: 0x6f8 Startzeit der fehlerhaften Anwendung: 0x01ce0ac6a18f4bd0 Pfad der
fehlerhaften Anwendung: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Pfad
des fehlerhaften Moduls: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Berichtskennung:
e3f67142-76b9-11e2-945c-ed827a6cc14e
Error - 14.02.2013 11:22:09 | Computer Name = *****-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Name des fehlerhaften Moduls: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00022efc ID des fehlerhaften
Prozesses: 0x16b8 Startzeit der fehlerhaften Anwendung: 0x01ce0ac6fd451368 Pfad der
fehlerhaften Anwendung: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Pfad
des fehlerhaften Moduls: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Berichtskennung:
4bab7c63-76ba-11e2-945c-ed827a6cc14e
Error - 14.02.2013 11:27:23 | Computer Name = *****-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Name des fehlerhaften Moduls: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00022efc ID des fehlerhaften
Prozesses: 0x15a4 Startzeit der fehlerhaften Anwendung: 0x01ce0ac7c454ce5b Pfad der
fehlerhaften Anwendung: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Pfad
des fehlerhaften Moduls: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Berichtskennung:
06d4c369-76bb-11e2-945c-ed827a6cc14e
Error - 14.02.2013 11:32:07 | Computer Name = *****-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Name des fehlerhaften Moduls: ouqrqxrisu.exe, Version: 0.0.0.0,
Zeitstempel: 0x50f898d7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00022efc ID des fehlerhaften
Prozesses: 0xa34 Startzeit der fehlerhaften Anwendung: 0x01ce0ac86e5f4b47 Pfad der
fehlerhaften Anwendung: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Pfad
des fehlerhaften Moduls: C:\Users\*****\AppData\Local\Temp\ihmcmstdpp\ouqrqxrisu.exe
Berichtskennung:
b01e1317-76bb-11e2-945c-ed827a6cc14e
[ Media Center Events ]
Error - 20.09.2012 01:58:08 | Computer Name = *****-PC | Source = MCUpdate | ID = 0
Description = 07:58:08 - Fehler beim Herstellen der Internetverbindung. 07:58:08
- Serververbindung konnte nicht hergestellt werden..
Error - 20.09.2012 01:58:18 | Computer Name = *****-PC | Source = MCUpdate | ID = 0
Description = 07:58:14 - Fehler beim Herstellen der Internetverbindung. 07:58:14
- Serververbindung konnte nicht hergestellt werden..
Error - 24.09.2012 00:40:43 | Computer Name = *****-PC | Source = MCUpdate | ID = 0
Description = 06:40:43 - Fehler beim Herstellen der Internetverbindung. 06:40:43
- Serververbindung konnte nicht hergestellt werden..
Error - 24.09.2012 00:41:21 | Computer Name = *****-PC | Source = MCUpdate | ID = 0
Description = 06:41:15 - Fehler beim Herstellen der Internetverbindung. 06:41:15
- Serververbindung konnte nicht hergestellt werden..
[ System Events ]
Error - 01.11.2012 01:41:12 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
beendet: %%1064
Error - 01.11.2012 09:24:51 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "ASInsHelp" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error - 01.11.2012 09:25:02 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
beendet: %%1064
Error - 01.11.2012 17:36:07 | Computer Name = *****-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR4 gefunden.
Error - 02.11.2012 12:22:31 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "ASInsHelp" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error - 02.11.2012 12:22:43 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
beendet: %%1064
Error - 03.11.2012 01:02:41 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "ASInsHelp" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error - 03.11.2012 01:28:44 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "ASInsHelp" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error - 03.11.2012 01:30:25 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
Windows Presentation Foundation-Schriftartcache 3.0.0.0 erreicht.
Error - 03.11.2012 01:30:25 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0"
wurde aufgrund folgenden Fehlers nicht gestartet: %%1053
< End of report > Code:
OTL logfile created on: 14.02.2013 17:22:08 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\*****\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
5,61 Gb Total Physical Memory | 3,62 Gb Available Physical Memory | 64,63% Memory free
11,21 Gb Paging File | 8,93 Gb Available in Paging File | 79,67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297,99 Gb Total Space | 126,73 Gb Free Space | 42,53% Space Free | Partition Type: NTFS
Drive Z: | 82,98 Mb Total Space | 38,64 Mb Free Space | 46,57% Space Free | Partition Type: NTFS
Computer Name: *****-PC | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\*****\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\*****\AppData\Roaming\vlc\msdn.exe ()
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
PRC - C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe (Eastman Kodak Company)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files (x86)\BlueStacks\HD-FileSystem.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\BlueStacks\HD-BlockDevice.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\BlueStacks\HD-Network.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\BlueStacks\HD-Service.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Fraps\fraps.exe (Beepa P/L)
PRC - C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
PRC - C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f3c2e63623f7a64a35e3dd746b90edbc\PresentationFramework.Classic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_de_31bf3856ad364e35\PresentationFramework.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\PresentationCore.resources\3.0.0.0_de_31bf3856ad364e35\PresentationCore.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\WindowsBase.resources\3.0.0.0_de_31bf3856ad364e35\WindowsBase.resources.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AMD FUEL Service) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (TeamViewer8) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Kodak AiO Network Discovery Service) -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
SRV - (Kodak AiO Status Monitor Service) -- C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe (Eastman Kodak Company)
SRV - (Futuremark SystemInfo Service) -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (TomTomHOMEService) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (BstHdLogRotatorSvc) -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
SRV - (BstHdAndroidSvc) -- C:\Program Files (x86)\BlueStacks\HD-Service.exe (BlueStack Systems, Inc.)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (BrazosTweaker) -- C:\Programme\BrazosTweaker\BrazosTweakerService.exe ()
SRV - (AxAutoMntSrv) -- C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS)
SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (StarWindServiceAE) -- C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
SRV - (SandraAgentSrv) -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP5a\RpcAgentSrv.exe (SiSoftware)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (amd_sata) -- C:\Windows\SysNative\drivers\amd_sata.sys (Advanced Micro Devices)
DRV:64bit: - (amd_xata) -- C:\Windows\SysNative\drivers\amd_xata.sys (Advanced Micro Devices)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (RTHDMIAzAudService) -- C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (APXACC) -- C:\Windows\SysNative\drivers\appexDrv.sys (AppEx Networks Corporation)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Qualcomm Atheros Communications, Inc.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Point64) -- C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) -- C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (Rockusb) -- C:\Windows\SysNative\drivers\rockusb.sys (Fuzhou Rockchip Electronics Co,Ltd.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronics Corp.)
DRV:64bit: - (ANDModem) -- C:\Windows\SysNative\drivers\lgandmodem64.sys (LG Electronics Inc.)
DRV:64bit: - (AndDiag) -- C:\Windows\SysNative\drivers\lganddiag64.sys (LG Electronics Inc.)
DRV:64bit: - (AndGps) -- C:\Windows\SysNative\drivers\lgandgps64.sys (LG Electronics Inc.)
DRV:64bit: - (Andbus) -- C:\Windows\SysNative\drivers\lgandbus64.sys (LG Electronics Inc.)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (androidusb) -- C:\Windows\SysNative\drivers\lgandadb.sys (Google Inc)
DRV:64bit: - (ivusb) -- C:\Windows\SysNative\drivers\ivusb.sys (Initio Corporation)
DRV:64bit: - (amdiox64) -- C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (hcw95rc) -- C:\Windows\SysNative\drivers\hcw95rc.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (hcw95bda) -- C:\Windows\SysNative\drivers\hcw95bda.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (lirsgt) -- C:\Windows\SysWOW64\drivers\lirsgt.sys ()
DRV - (BstHdDrv) -- C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys (BlueStack Systems)
DRV - (WinRing0_1_2_0) -- C:\Programme\BrazosTweaker\WinRing0x64.sys (OpenLibSys.org)
DRV - (ATKWMIACPIIO) -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUS)
DRV - (SANDRA) -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP5a\WNt500x64\sandra.sys (SiSoftware)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-830199503-3038931148-3267462750-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-830199503-3038931148-3267462750-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-830199503-3038931148-3267462750-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 95 EB 78 70 5A 08 CE 01 [binary data]
IE - HKU\S-1-5-21-830199503-3038931148-3267462750-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-830199503-3038931148-3267462750-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-830199503-3038931148-3267462750-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-830199503-3038931148-3267462750-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)"
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.08.17 12:56:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.02.06 14:57:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.02.06 14:57:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013.01.25 17:22:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2012.08.15 15:21:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Extensions
[2012.06.12 16:12:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2013.02.09 19:16:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\95b9s0pc.default\extensions
[2013.01.11 16:26:41 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\95b9s0pc.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.12.13 20:28:09 | 000,000,000 | ---D | M] (Free Download Manager plugin) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\95b9s0pc.default\extensions\fdm_ffext@freedownloadmanager.org
[2013.02.05 20:40:04 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\95b9s0pc.default\extensions\ich@maltegoetz.de
[2012.08.16 05:43:51 | 000,550,833 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\DivXWebPlayer@divx.com.xpi
[2012.08.16 19:52:14 | 000,123,385 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\elemhidehelper@adblockplus.org.xpi
[2012.08.16 19:52:33 | 000,001,703 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\f6@merike.pri.ee.xpi
[2012.12.13 20:28:14 | 002,151,598 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\firebug@software.joehewitt.com.xpi
[2013.02.09 19:16:35 | 000,185,839 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\stealthyextension@gmail.com.xpi
[2012.08.16 19:52:33 | 000,004,545 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\support@easy-hideip.com.xpi
[2012.08.16 19:52:33 | 000,004,552 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\support@platinumhideip.com.xpi
[2012.08.16 19:52:33 | 000,004,526 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\support@real-hide-ip.com.xpi
[2013.01.28 17:40:08 | 000,142,907 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\unplug@compunach.xpi
[2012.08.16 19:52:33 | 000,011,510 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\youtube2mp3@mondayx.de.xpi
[2012.12.24 10:14:16 | 000,030,502 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi
[2012.12.30 11:28:47 | 000,358,225 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\{9fb7d178-155a-4318-9173-1a8eaaea7fe4}.xpi
[2013.01.31 18:20:20 | 000,817,973 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.08.16 19:52:33 | 000,026,136 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\95b9s0pc.default\extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi
[2013.02.06 14:57:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013.02.06 14:57:14 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.28 16:42:00 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012.07.14 01:45:08 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.11.20 21:04:34 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.07.14 01:45:08 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.14 01:45:08 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.14 01:45:08 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.14 01:45:07 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2012.09.24 18:05:05 | 000,000,826 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Programme\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Driver Genius] File not found
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-830199503-3038931148-3267462750-1000..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-830199503-3038931148-3267462750-1000..\Run: [AppEx Accelerator UI] C:\Program Files\AMD Quick Stream\AppexAcceleratorUI.exe (AppEx Networks Corporation)
O4 - HKU\S-1-5-21-830199503-3038931148-3267462750-1000..\Run: [Information Schema] C:\Users\*****\AppData\Roaming\vlc\msdn.exe ()
O4 - HKU\S-1-5-21-830199503-3038931148-3267462750-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\S-1-5-21-830199503-3038931148-3267462750-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8:64bit: - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O8:64bit: - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O8:64bit: - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2DEFE633-334A-461E-82B0-BA362213CF28}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6A3AEDDD-0886-427F-B7D5-E45AFF305945}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Programme\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Programme\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{4cf68b34-1169-11e2-b55c-cf2fbcbd9653}\Shell - "" = AutoRun
O33 - MountPoints2\{4cf68b34-1169-11e2-b55c-cf2fbcbd9653}\Shell\AutoRun\command - "" = E:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.02.14 03:00:54 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013.02.14 03:00:54 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013.02.14 03:00:53 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.02.14 03:00:53 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.02.14 03:00:52 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013.02.14 03:00:52 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013.02.14 03:00:51 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013.02.14 03:00:51 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013.02.14 03:00:50 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.02.14 03:00:50 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013.02.14 03:00:50 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013.02.14 03:00:50 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.02.14 03:00:47 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.02.14 03:00:47 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.02.14 03:00:47 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013.02.14 02:32:02 | 005,553,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013.02.14 02:31:59 | 003,967,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2013.02.14 02:31:58 | 003,913,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2013.02.14 02:31:56 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2013.02.14 02:31:55 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2013.02.14 02:31:55 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2013.02.14 02:31:55 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2013.02.14 02:31:55 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2013.02.14 02:31:54 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2013.02.14 02:31:51 | 000,288,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013.02.12 20:49:09 | 000,000,000 | ---D | C] -- C:\Users\*****\Documents\ProcAlyzer Dumps
[2013.02.12 20:07:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2013.02.12 20:07:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013.02.12 20:07:27 | 000,017,272 | ---- | C] (Safer Networking Limited) -- C:\Windows\SysNative\sdnclean64.exe
[2013.02.12 20:07:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2013.02.11 16:31:25 | 000,000,000 | --SD | C] -- C:\PS3
[2013.02.10 20:16:20 | 000,000,000 | ---D | C] -- C:\Users\*****\Documents\Test Drive Ferrari Racing Legends
[2013.02.09 20:10:09 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.02.09 14:30:51 | 000,000,000 | ---D | C] -- C:\Users\*****\Documents\Euro Truck Simulator 2
[2013.02.08 16:53:30 | 000,000,000 | ---D | C] -- C:\Users\*****\Documents\Command & Conquer 3 Kanes Rache
[2013.02.08 16:39:03 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2013.02.08 16:38:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2013.02.08 16:38:23 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2013.02.08 16:38:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2013.02.08 16:37:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2013.02.07 19:47:55 | 000,000,000 | ---D | C] -- C:\Multi Protocol Programming System
[2013.02.06 14:57:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.02.05 16:51:36 | 000,064,880 | ---- | C] (Fuzhou Rockchip Electronics Co,Ltd.) -- C:\Windows\SysNative\drivers\rockusb.sys
[2013.02.03 19:14:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MegaDev
[2013.02.03 19:14:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MegaDev
[2013.02.03 15:45:07 | 000,000,000 | ---D | C] -- C:\Users\*****\Documents\FUSSBALL MANAGER 13
[2013.02.03 15:42:09 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_7.dll
[2013.02.03 15:42:09 | 000,518,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_7.dll
[2013.02.03 15:42:09 | 000,077,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_5.dll
[2013.02.03 15:42:09 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_5.dll
[2013.02.03 15:42:07 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_7.dll
[2013.02.03 15:42:07 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_7.dll
[2013.02.03 15:42:06 | 002,526,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_43.dll
[2013.02.03 15:42:06 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll
[2013.02.03 15:42:05 | 001,907,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dcsx_43.dll
[2013.02.03 15:42:05 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_43.dll
[2013.02.03 15:42:04 | 000,276,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_43.dll
[2013.02.03 15:42:04 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_43.dll
[2013.02.03 15:42:03 | 000,511,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_43.dll
[2013.02.03 15:42:03 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_43.dll
[2013.02.03 15:42:01 | 002,401,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_43.dll
[2013.02.03 15:42:01 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_43.dll
[2013.02.03 15:26:48 | 000,000,000 | ---D | C] -- C:\FM13
[2013.02.03 15:14:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013.02.03 15:12:23 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Google
[2013.02.03 15:12:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2013.02.02 14:49:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft-Maus
[2013.02.02 14:49:29 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft IntelliPoint
[2013.02.01 20:46:51 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Privat
[2013.02.01 17:58:19 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Command & Conquer 3 Kanes Rache
[2013.02.01 13:32:34 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Multiecuscan
[2013.02.01 13:32:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Multiecuscan
[2013.01.29 06:55:24 | 000,078,640 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atimpc64.dll
[2013.01.29 06:55:24 | 000,078,640 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\amdpcom64.dll
[2013.01.29 06:55:20 | 000,071,912 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atimpc32.dll
[2013.01.29 06:55:20 | 000,071,912 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\amdpcom32.dll
[2013.01.29 06:55:06 | 000,139,904 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiuxp64.dll
[2013.01.29 06:55:00 | 000,118,792 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiuxpag.dll
[2013.01.29 06:54:54 | 000,113,672 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiu9p64.dll
[2013.01.29 06:54:50 | 000,092,512 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiu9pag.dll
[2013.01.29 06:54:46 | 001,150,328 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\aticfx64.dll
[2013.01.29 06:54:42 | 000,968,560 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\aticfx32.dll
[2013.01.29 06:54:34 | 008,173,928 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atidxx64.dll
[2013.01.29 06:54:28 | 007,159,384 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atidxx32.dll
[2013.01.29 06:54:18 | 004,475,192 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiumdva.dll
[2013.01.29 06:54:14 | 006,035,136 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiumdag.dll
[2013.01.29 06:54:06 | 005,035,000 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiumd6a.dll
[2013.01.29 06:54:00 | 007,038,856 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiumd64.dll
[2013.01.29 06:48:38 | 011,612,672 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\atikmdag.sys
[2013.01.29 06:39:06 | 023,581,184 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atio6axx.dll
[2013.01.29 06:27:12 | 000,163,840 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atiapfxx.exe
[2013.01.29 06:24:44 | 000,051,200 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticalrt64.dll
[2013.01.29 06:24:42 | 000,046,080 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticalrt.dll
[2013.01.29 06:24:36 | 000,044,544 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticalcl64.dll
[2013.01.29 06:24:34 | 000,044,032 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticalcl.dll
[2013.01.29 06:24:22 | 016,082,944 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticaldd64.dll
[2013.01.29 06:21:02 | 019,755,520 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWow64\atioglxx.dll
[2013.01.29 06:19:56 | 013,703,168 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticaldd.dll
[2013.01.29 06:15:54 | 000,077,312 | ---- | C] (AMD) -- C:\Windows\SysNative\coinst_12.10.17.dll
[2013.01.29 06:03:00 | 000,442,368 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atidemgy.dll
[2013.01.29 06:02:50 | 000,561,152 | ---- | C] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2013.01.29 06:01:58 | 000,240,640 | ---- | C] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2013.01.29 06:00:20 | 000,120,320 | ---- | C] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2013.01.29 06:00:00 | 000,025,600 | ---- | C] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2013.01.29 05:59:56 | 000,059,392 | ---- | C] (ATI Technologies, Inc.) -- C:\Windows\SysNative\atiedu64.dll
[2013.01.29 05:59:50 | 000,043,520 | ---- | C] (ATI Technologies, Inc.) -- C:\Windows\SysWow64\ati2edxx.dll
[2013.01.29 05:34:28 | 000,629,760 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atiadlxx.dll
[2013.01.29 05:34:16 | 000,425,984 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWow64\atiadlxy.dll
[2013.01.29 05:34:00 | 000,017,920 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atig6pxx.dll
[2013.01.29 05:33:56 | 000,014,848 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiglpxx.dll
[2013.01.29 05:33:56 | 000,014,848 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiglpxx.dll
[2013.01.29 05:33:52 | 000,044,032 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atig6txx.dll
[2013.01.29 05:33:44 | 000,034,816 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atigktxx.dll
[2013.01.29 05:33:36 | 000,576,000 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\atikmpag.sys
[2013.01.29 05:30:44 | 000,053,248 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\ati2erec.dll
[2013.01.28 23:20:40 | 000,076,288 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\OpenVideo64.dll
[2013.01.28 23:20:36 | 000,065,536 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\OpenVideo.dll
[2013.01.28 23:20:32 | 000,064,000 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\OVDecode64.dll
[2013.01.28 23:20:30 | 000,056,320 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\OVDecode.dll
[2013.01.28 23:20:20 | 029,150,208 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\amdocl64.dll
[2013.01.28 23:18:24 | 023,810,048 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\amdocl.dll
[2013.01.28 23:16:40 | 000,054,784 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2013.01.28 23:16:36 | 000,050,176 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2013.01.28 23:10:28 | 005,067,264 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\amdsc64.dll
[2013.01.28 23:10:26 | 004,083,200 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\amdsc.dll
[2013.01.28 17:01:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Publish Data
[2013.01.28 16:58:27 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Publish_Data
[2013.01.28 16:45:02 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Treiber-Studio 2013
[2013.01.28 16:45:01 | 000,000,000 | ---D | C] -- C:\Program Files\Publish Data
[2013.01.25 17:22:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2013.01.25 16:53:46 | 000,000,000 | ---D | C] -- C:\Windows\WindowsMobile
[2013.01.23 14:48:46 | 000,000,000 | ---D | C] -- C:\ProgramData\RELOADED
[2013.01.23 14:45:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CI Games
[2013.01.23 06:45:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CI Games
[2013.01.23 06:45:11 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Programs
[2013.01.21 19:06:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
[2013.01.19 11:12:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PolarEditor10x8
[2013.01.18 06:17:25 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013.01.18 06:17:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013.01.15 21:41:53 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Innovative Solutions
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.02.14 17:24:00 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.02.14 16:47:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.02.14 15:24:00 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.02.14 13:49:14 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.02.14 13:49:14 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.02.14 13:41:00 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.02.14 13:40:55 | 218,869,759 | -HS- | M] () -- C:\hiberfil.sys
[2013.02.14 03:31:15 | 004,912,920 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.02.14 03:05:51 | 001,635,332 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.02.14 03:05:51 | 000,697,082 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.02.14 03:05:51 | 000,652,360 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.02.14 03:05:51 | 000,148,346 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.02.14 03:05:51 | 000,121,292 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.02.09 21:48:14 | 000,697,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.02.09 21:48:14 | 000,074,096 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.02.09 13:25:41 | 000,196,608 | ---- | M] () -- C:\Users\*****\Documents\Aktuell.fdu
[2013.02.09 13:21:28 | 000,196,608 | ---- | M] () -- C:\Users\*****\Documents\PolarEdit 10x8 2.fdu
[2013.02.02 14:49:54 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_point64_01009.Wdf
[2013.01.29 13:30:36 | 001,590,506 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.01.29 06:55:24 | 000,078,640 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atimpc64.dll
[2013.01.29 06:55:24 | 000,078,640 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\amdpcom64.dll
[2013.01.29 06:55:20 | 000,071,912 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atimpc32.dll
[2013.01.29 06:55:20 | 000,071,912 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\amdpcom32.dll
[2013.01.29 06:55:06 | 000,139,904 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiuxp64.dll
[2013.01.29 06:55:00 | 000,118,792 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiuxpag.dll
[2013.01.29 06:54:54 | 000,113,672 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiu9p64.dll
[2013.01.29 06:54:50 | 000,092,512 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiu9pag.dll
[2013.01.29 06:54:46 | 001,150,328 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\aticfx64.dll
[2013.01.29 06:54:42 | 000,968,560 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\aticfx32.dll
[2013.01.29 06:54:34 | 008,173,928 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atidxx64.dll
[2013.01.29 06:54:28 | 007,159,384 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atidxx32.dll
[2013.01.29 06:54:18 | 004,475,192 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiumdva.dll
[2013.01.29 06:54:14 | 006,035,136 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiumdag.dll
[2013.01.29 06:54:06 | 005,035,000 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiumd6a.dll
[2013.01.29 06:54:00 | 007,038,856 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiumd64.dll
[2013.01.29 06:48:38 | 011,612,672 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\atikmdag.sys
[2013.01.29 06:39:06 | 023,581,184 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atio6axx.dll
[2013.01.29 06:28:32 | 000,340,256 | ---- | M] () -- C:\Windows\SysWow64\atiapfxx.blb
[2013.01.29 06:28:32 | 000,340,256 | ---- | M] () -- C:\Windows\SysNative\atiapfxx.blb
[2013.01.29 06:27:12 | 000,163,840 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atiapfxx.exe
[2013.01.29 06:24:44 | 000,051,200 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticalrt64.dll
[2013.01.29 06:24:42 | 000,046,080 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticalrt.dll
[2013.01.29 06:24:36 | 000,044,544 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticalcl64.dll
[2013.01.29 06:24:34 | 000,044,032 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticalcl.dll
[2013.01.29 06:24:22 | 016,082,944 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticaldd64.dll
[2013.01.29 06:21:02 | 019,755,520 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWow64\atioglxx.dll
[2013.01.29 06:19:56 | 013,703,168 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticaldd.dll
[2013.01.29 06:15:54 | 000,077,312 | ---- | M] (AMD) -- C:\Windows\SysNative\coinst_12.10.17.dll
[2013.01.29 06:03:00 | 000,442,368 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atidemgy.dll
[2013.01.29 06:02:50 | 000,561,152 | ---- | M] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2013.01.29 06:01:58 | 000,240,640 | ---- | M] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2013.01.29 06:00:20 | 000,120,320 | ---- | M] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2013.01.29 06:00:00 | 000,025,600 | ---- | M] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2013.01.29 05:59:56 | 000,059,392 | ---- | M] (ATI Technologies, Inc.) -- C:\Windows\SysNative\atiedu64.dll
[2013.01.29 05:59:50 | 000,043,520 | ---- | M] (ATI Technologies, Inc.) -- C:\Windows\SysWow64\ati2edxx.dll
[2013.01.29 05:34:28 | 000,629,760 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atiadlxx.dll
[2013.01.29 05:34:16 | 000,425,984 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWow64\atiadlxy.dll
[2013.01.29 05:34:00 | 000,017,920 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atig6pxx.dll
[2013.01.29 05:33:56 | 000,014,848 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiglpxx.dll
[2013.01.29 05:33:56 | 000,014,848 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiglpxx.dll
[2013.01.29 05:33:52 | 000,044,032 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atig6txx.dll
[2013.01.29 05:33:44 | 000,034,816 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atigktxx.dll
[2013.01.29 05:33:36 | 000,576,000 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\atikmpag.sys
[2013.01.29 05:30:44 | 000,053,248 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\ati2erec.dll
[2013.01.29 04:50:40 | 003,296,864 | ---- | M] () -- C:\Windows\SysNative\atiumd6a.cap
[2013.01.29 04:50:40 | 000,204,952 | ---- | M] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.01.29 04:50:40 | 000,204,952 | ---- | M] () -- C:\Windows\SysNative\ativvsvl.dat
[2013.01.29 04:50:40 | 000,157,144 | ---- | M] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.01.29 04:50:40 | 000,157,144 | ---- | M] () -- C:\Windows\SysNative\ativvsva.dat
[2013.01.29 04:36:10 | 003,330,608 | ---- | M] () -- C:\Windows\SysWow64\atiumdva.cap
[2013.01.28 23:20:58 | 000,222,720 | ---- | M] () -- C:\Windows\SysNative\clinfo.exe
[2013.01.28 23:20:40 | 000,076,288 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\OpenVideo64.dll
[2013.01.28 23:20:36 | 000,065,536 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\OpenVideo.dll
[2013.01.28 23:20:32 | 000,064,000 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\OVDecode64.dll
[2013.01.28 23:20:30 | 000,056,320 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\OVDecode.dll
[2013.01.28 23:20:20 | 029,150,208 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\amdocl64.dll
[2013.01.28 23:18:24 | 023,810,048 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\amdocl.dll
[2013.01.28 23:16:40 | 000,054,784 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2013.01.28 23:16:36 | 000,050,176 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2013.01.28 23:10:28 | 005,067,264 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\amdsc64.dll
[2013.01.28 23:10:26 | 004,083,200 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\amdsc.dll
[2013.01.25 16:55:18 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[2013.01.23 14:24:36 | 000,405,309 | ---- | M] () -- C:\plugin.rar
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.02.12 20:07:36 | 000,002,185 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013.02.09 13:25:41 | 000,196,608 | ---- | C] () -- C:\Users\*****\Documents\Aktuell.fdu
[2013.02.09 13:21:27 | 000,196,608 | ---- | C] () -- C:\Users\*****\Documents\PolarEdit 10x8 2.fdu
[2013.02.03 15:12:27 | 000,001,108 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.02.03 15:12:26 | 000,001,104 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.02.02 14:49:54 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_point64_01009.Wdf
[2013.01.29 06:28:32 | 000,340,256 | ---- | C] () -- C:\Windows\SysWow64\atiapfxx.blb
[2013.01.29 06:28:32 | 000,340,256 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2013.01.29 04:50:40 | 003,296,864 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap
[2013.01.29 04:50:40 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.01.29 04:50:40 | 000,204,952 | ---- | C] () -- C:\Windows\SysNative\ativvsvl.dat
[2013.01.29 04:50:40 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.01.29 04:50:40 | 000,157,144 | ---- | C] () -- C:\Windows\SysNative\ativvsva.dat
[2013.01.29 04:36:10 | 003,330,608 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap
[2013.01.28 23:20:58 | 000,222,720 | ---- | C] () -- C:\Windows\SysNative\clinfo.exe
[2013.01.28 16:43:02 | 001,590,506 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.01.25 16:55:18 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[2013.01.25 16:54:01 | 000,002,419 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mobile Device Center.lnk
[2013.01.08 16:48:57 | 000,027,783 | ---- | C] () -- C:\Users\*****\AppData\Roaming\*****3SQLite3.dll
[2013.01.07 16:27:51 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll
[2013.01.06 19:36:59 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2012.12.23 10:39:25 | 000,000,029 | ---- | C] () -- C:\Windows\wordpad.ini
[2012.12.15 18:24:33 | 000,000,600 | ---- | C] () -- C:\Users\*****\AppData\Roaming\winscp.rnd
[2012.12.06 20:35:11 | 000,018,048 | ---- | C] () -- C:\Windows\SysWow64\drivers\lirsgt.sys
[2012.12.06 20:33:15 | 000,056,320 | ---- | C] () -- C:\Windows\SysWow64\iyvu9_32.dll
[2012.11.27 00:18:46 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.11.05 21:52:43 | 000,000,078 | ---- | C] () -- C:\Windows\wininit.ini
[2012.10.26 17:05:38 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.10.26 17:05:30 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.10.03 19:35:41 | 000,000,534 | ---- | C] () -- C:\Windows\eReg.dat
[2012.10.03 13:48:16 | 000,001,574 | ---- | C] () -- C:\Windows\cdplayer.ini
[2012.10.03 13:46:11 | 000,078,085 | ---- | C] () -- C:\Windows\SysWow64\pattern.dat
[2012.10.03 13:46:05 | 000,307,200 | ---- | C] () -- C:\Windows\SysWow64\fxstudio.dll
[2012.10.03 13:46:04 | 000,282,624 | ---- | C] () -- C:\Windows\SysWow64\animation2.dll
[2012.09.15 17:31:17 | 000,092,168 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2012.08.26 18:54:01 | 000,036,892 | ---- | C] () -- C:\Windows\SysWow64\bassmod.dll
[2012.08.24 19:05:26 | 000,005,632 | ---- | C] () -- C:\Windows\SysWow64\dvttrn.dll
[2012.08.22 05:40:50 | 002,097,152 | ---- | C] () -- C:\Windows\sample5x.dat
[2012.08.20 17:05:42 | 000,000,064 | ---- | C] () -- C:\Users\*****\AppData\Roaming\Sandra.ldb
[2012.08.20 17:05:41 | 011,730,944 | ---- | C] () -- C:\Users\*****\AppData\Roaming\Sandra.mdb
[2012.08.16 18:38:56 | 000,007,605 | ---- | C] () -- C:\Users\*****\AppData\Local\resmon.resmoncfg
[2012.08.15 14:01:23 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.09.12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report > |