flexx292 | 19.02.2013 15:07 | Habe alles so gemacht. Eine Datei ist im Anhang die andere ist zu groß.
Ich schreibe sie jetzt einfach mal hier rein. Wenn du sie anderst haben willst, musst du es sagen!
OTL Logfile: Code:
OTL logfile created on: 19.02.2013 14:51:15 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = D:\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
7,92 Gb Total Physical Memory | 6,32 Gb Available Physical Memory | 79,75% Memory free
15,84 Gb Paging File | 14,07 Gb Available in Paging File | 88,84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55,90 Gb Total Space | 5,93 Gb Free Space | 10,61% Space Free | Partition Type: NTFS
Drive D: | 1464,84 Gb Total Space | 1217,05 Gb Free Space | 83,08% Space Free | Partition Type: NTFS
Drive E: | 398,05 Gb Total Space | 57,98 Gb Free Space | 14,57% Space Free | Partition Type: NTFS
Computer Name: FELIXPC | User Name: root | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.02.19 14:50:00 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Downloads\OTL.exe
PRC - [2013.02.13 11:43:50 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2013.02.13 11:43:43 | 000,565,472 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
PRC - [2013.02.13 11:43:42 | 000,385,248 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2013.02.13 11:43:42 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.12.18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.10.19 02:26:06 | 001,573,584 | ---- | M] (Ask) -- C:\Program Files (x86)\Ask.com\Updater\Updater.exe
PRC - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.09.13 20:51:56 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011.05.20 10:10:26 | 000,013,592 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011.05.20 10:10:12 | 000,284,440 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2010.05.20 15:26:30 | 000,762,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\vVX3000.exe
PRC - [2008.10.20 22:18:26 | 000,071,096 | ---- | M] () -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
========== Modules (No Company Name) ==========
MOD - [2013.02.13 12:54:44 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll
MOD - [2013.01.09 22:50:46 | 000,491,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\346a7a67978cead8e2ff52c6d80bbeb7\IAStorUtil.ni.dll
MOD - [2013.01.09 22:50:46 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\500a8ae2a5d27132d87ccac9f97b0069\IAStorCommon.ni.dll
MOD - [2013.01.09 19:54:40 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll
MOD - [2013.01.09 19:54:20 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013.01.09 19:54:13 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll
MOD - [2013.01.09 19:54:10 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013.01.09 19:54:08 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll
MOD - [2013.01.09 19:54:07 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013.01.09 19:54:04 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2011.11.01 23:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.11.01 23:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.02.23 13:11:15 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll
MOD - [2010.11.13 01:08:41 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
========== Services (SafeList) ==========
SRV - [2013.02.15 13:08:20 | 000,543,144 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013.02.13 11:43:50 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013.02.13 11:43:43 | 000,565,472 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService)
SRV - [2013.02.13 11:43:42 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013.02.08 14:04:23 | 000,251,248 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.12.18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.12.10 17:29:46 | 002,465,712 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- D:\Software\hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2012.10.10 21:23:42 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.09.13 20:51:56 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012.06.14 23:17:46 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.06.07 18:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.03.19 22:44:20 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2011.05.20 10:10:26 | 000,013,592 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2011.03.28 20:11:06 | 002,292,096 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2010.09.22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010.05.20 15:26:28 | 000,199,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft LifeCam\MSCamS64.exe -- (MSCamSvc)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.10.20 22:18:26 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.12.11 17:11:26 | 000,129,216 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.12.11 17:11:26 | 000,099,912 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.09.28 10:32:56 | 000,053,760 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012.09.24 09:58:11 | 000,027,800 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2012.08.21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012.03.19 22:32:04 | 014,745,600 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2012.03.08 17:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.17 13:45:56 | 000,188,224 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011.12.12 09:14:23 | 000,012,904 | ---- | M] (UVNC BVBA) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mv2.sys -- (mv2)
DRV:64bit: - [2011.10.15 11:48:07 | 000,291,648 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvstusb.sys -- (NvStUSB)
DRV:64bit: - [2011.08.23 20:57:24 | 000,565,352 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.08.17 11:18:00 | 000,080,384 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronXHCI.sys -- (EtronXHCI)
DRV:64bit: - [2011.08.17 11:18:00 | 000,057,088 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronHub3.sys -- (EtronHub3)
DRV:64bit: - [2011.08.02 17:38:44 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2011.05.20 09:53:44 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011.03.14 10:29:46 | 000,313,136 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mvs91xx.sys -- (mvs91xx)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.10.19 16:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010.10.15 00:28:18 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010.05.20 15:26:30 | 002,060,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VX3000.sys -- (VX3000)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2012.04.19 10:13:50 | 000,010,568 | ---- | M] () [Kernel | On_Demand | Stopped] -- D:\Software\MSI Afterburner\RTCore64.sys -- (RTCore64)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0AA6E94E-A1B2-42F7-BDBF-4F597EBAF0BD}
IE:64bit: - HKLM\..\SearchScopes\{0AA6E94E-A1B2-42F7-BDBF-4F597EBAF0BD}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://nmd.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=91ef4bec-35c9-4290-9d19-ccf8b3a10124&searchtype=ds&q={searchTerms}
IE - HKLM\..\SearchScopes\{2597ED5E-7834-4663-9B6A-D8E433E3E74C}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://nmd.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=91ef4bec-35c9-4290-9d19-ccf8b3a10124&searchtype=ds&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=91ef4bec-35c9-4290-9d19-ccf8b3a10124&searchtype=ds&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=91ef4bec-35c9-4290-9d19-ccf8b3a10124&searchtype=hp&exp=true
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=91ef4bec-35c9-4290-9d19-ccf8b3a10124&searchtype=ds&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=91ef4bec-35c9-4290-9d19-ccf8b3a10124&searchtype=ds&q={searchTerms}
IE - HKCU\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=91ef4bec-35c9-4290-9d19-ccf8b3a10124&searchtype=ds&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: helperbar@helperbar.com:1.0
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.10
FF - prefs.js..browser.startup.homepage: "hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=91ef4bec-35c9-4290-9d19-ccf8b3a10124&searchtype=hp"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..keyword.URL: "hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=91ef4bec-35c9-4290-9d19-ccf8b3a10124&searchtype=ds&q="
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: D:\Software\Java\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.110.0: C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.118.0: C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.132.0: C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.140.0: C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: D:\Software\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}: C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [2013.01.16 22:02:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.20 18:33:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.12.12 09:08:21 | 000,000,000 | ---D | M]
[2011.12.12 09:07:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\root\AppData\Roaming\mozilla\Extensions
[2013.01.31 19:14:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\o89oo871.default\extensions
[2012.07.14 14:47:07 | 000,000,000 | ---D | M] (Facemoods) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\o89oo871.default\extensions\ffxtlbr@Facemoods.com
[2013.01.31 19:14:29 | 000,000,000 | ---D | M] ("Snap.Do ") -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\o89oo871.default\extensions\helperbar@helperbar.com
[2013.01.31 19:14:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\o89oo871.default\extensions\staged
[2012.11.03 18:08:44 | 000,000,000 | ---D | M] (Avira SearchFree Toolbar plus Web Protection) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\o89oo871.default\extensions\toolbar@ask.com
[2012.10.19 02:23:34 | 000,002,333 | ---- | M] () -- C:\Users\root\AppData\Roaming\mozilla\firefox\profiles\o89oo871.default\searchplugins\askcom.xml
[2013.01.31 19:14:30 | 000,002,399 | ---- | M] () -- C:\Users\root\AppData\Roaming\mozilla\firefox\profiles\o89oo871.default\searchplugins\Web Search.xml
[2012.06.20 18:33:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
File not found (No name found) -- C:\USERS\ROOT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\O89OO871.DEFAULT\EXTENSIONS\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
[2012.06.14 23:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.14 23:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.14 23:46:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.14 23:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.14 23:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.14 23:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.14 23:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Software\Java\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Software\Java\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {64182481-4F71-486b-A045-B233BD0DA8FC} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Inbox Toolbar) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~2\INBOXT~1\Inbox.dll (Inbox.com, Inc.)
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (&Inbox Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\PROGRA~2\INBOXT~1\Inbox.dll (Inbox.com, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" File not found
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] D:\Software\hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKCU..\Run: [Browser Infrastructure Helper] C:\Users\root\AppData\Local\Smartbar\Application\SnapDo.exe (Smartbar)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [Steam] D:\Steam\Steam.exe (Valve Corporation)
O4:64bit: - HKLM..\RunOnce: [*WerKernelReporting] C:\Windows\SysNative\WerFault.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] D:\Software\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\root\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\root\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\root\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\root\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000019 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.9.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = haggenmueller.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{32581B75-5003-4EED-BB76-904C0DFCF5D4}: NameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{91ACD172-5EF9-411F-85D2-BCB8BC563EB9}: DhcpNameServer = 10.74.210.210 10.74.210.211
O18:64bit: - Protocol\Handler\inbox - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~2\INBOXT~1\Inbox.dll (Inbox.com, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2ef0aac8-2347-11e1-99bf-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{2ef0aac8-2347-11e1-99bf-806e6f6e6963}\Shell\AutoRun\command - "" = F:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
MsConfig:64bit - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
MsConfig:64bit - State: "services" - Reg Error: Key error.
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013.02.15 11:33:23 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\Malwarebytes
[2013.02.15 11:33:11 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.02.15 11:33:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.02.15 11:33:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.02.15 11:32:33 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Local\Programs
[2013.01.31 19:14:22 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Local\Smartbar
[2013.01.30 22:30:35 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\Image-Line
[2013.01.30 22:22:08 | 001,431,552 | ---- | C] (Propellerhead Software AB) -- C:\Windows\SysWow64\rewire.dll
[2013.01.30 22:22:08 | 000,000,000 | ---D | C] -- C:\Users\root\Documents\Image-Line
[2013.01.30 22:22:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
[2013.01.30 22:22:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Outsim
[2013.01.30 22:22:00 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
[2013.01.30 21:20:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Image-Line
[2013.01.24 16:18:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013.01.24 16:18:40 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013.01.24 16:18:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2013.01.24 16:18:40 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013.01.24 16:18:40 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013.01.20 22:23:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.02.19 14:35:28 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.02.19 14:35:28 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.02.19 14:34:42 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.02.19 14:34:42 | 000,654,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.02.19 14:34:42 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.02.19 14:34:42 | 000,130,022 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.02.19 14:34:42 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.02.19 14:28:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.02.19 14:28:13 | 2082,295,807 | -HS- | M] () -- C:\hiberfil.sys
[2013.02.18 23:04:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.02.18 22:01:30 | 000,291,088 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.02.18 22:01:30 | 000,291,088 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.02.17 22:54:49 | 000,291,088 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.02.13 12:53:33 | 000,326,648 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.01.30 22:22:08 | 000,000,661 | ---- | M] () -- C:\Users\Public\Desktop\FL Studio 10.lnk
[2013.01.29 17:48:20 | 000,000,669 | ---- | M] () -- C:\Users\Public\Desktop\Tony Hawk's Underground 2.lnk
[2013.01.24 16:18:45 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.01.30 22:22:08 | 000,000,661 | ---- | C] () -- C:\Users\Public\Desktop\FL Studio 10.lnk
[2012.12.16 12:58:03 | 000,000,283 | ---- | C] () -- C:\Windows\thug2.ini
[2012.10.25 21:29:25 | 000,017,408 | ---- | C] () -- C:\Users\root\AppData\Local\WebpageIcons.db
[2012.03.19 22:31:16 | 000,963,912 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2012.03.19 22:31:16 | 000,261,208 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2012.03.19 22:25:58 | 000,058,880 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012.03.19 21:21:14 | 013,212,672 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2012.01.23 17:57:33 | 000,291,088 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.01.23 17:57:32 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011.09.19 14:03:40 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\rtvcvfw32.dll
[2011.09.13 09:38:37 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2011.12.12 09:20:23 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Canneverbe_Limited
[2013.01.16 22:03:25 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\DVDVideoSoft
[2012.07.12 13:57:11 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\DVDVideoSoftIEHelpers
[2013.01.16 18:56:51 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\HandBrake
[2013.01.30 22:30:35 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Image-Line
[2013.01.30 22:22:08 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\OpenCandy
[2012.01.23 17:26:14 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Origin
[2012.09.13 13:00:15 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\PunkBuster
[2011.12.12 09:08:23 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Thunderbird
[2012.07.11 16:20:46 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\TuneUp Software
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2012.05.09 13:01:16 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2011.10.31 14:01:34 | 000,000,000 | -HSD | M] -- C:\Boot
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2011.12.10 17:30:17 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2011.10.31 13:53:32 | 000,000,000 | ---D | M] -- C:\Driver
[2011.10.31 13:53:58 | 000,000,000 | ---D | M] -- C:\Inst
[2012.06.10 14:40:42 | 000,000,000 | ---D | M] -- C:\Intel
[2012.03.13 20:55:54 | 000,000,000 | ---D | M] -- C:\NVIDIA
[2009.07.14 04:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2013.01.24 16:18:40 | 000,000,000 | R--D | M] -- C:\Program Files
[2013.02.18 00:24:00 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2013.02.17 23:32:20 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2011.12.10 17:30:17 | 000,000,000 | -HSD | M] -- C:\Programme
[2012.02.07 22:51:51 | 000,000,000 | ---D | M] -- C:\PSFONTS
[2011.12.10 17:30:17 | 000,000,000 | -HSD | M] -- C:\Recovery
[2013.02.19 14:52:00 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2013.01.14 16:49:15 | 000,000,000 | ---D | M] -- C:\Temp
[2012.10.14 16:13:22 | 000,000,000 | ---D | M] -- C:\tmp
[2012.05.01 13:55:39 | 000,000,000 | R--D | M] -- C:\Users
[2013.01.25 16:48:38 | 000,000,000 | ---D | M] -- C:\Windows
< %PROGRAMFILES%\*.exe >
< %LOCALAPPDATA%\*.exe >
< %systemroot%\*. /mp /s >
< C:\Windows\system32\*.tsp >
[2009.07.14 02:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2009.07.14 02:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2009.07.14 02:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2009.07.14 02:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2010.11.21 04:23:55 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.04.10 15:46:36 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
< MD5 for: AGP440.SYS >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: EXPLORER.EXE >
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 04:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 04:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: IASTOR.SYS >
[2011.05.20 09:53:44 | 000,557,848 | ---- | M] (Intel Corporation) MD5=2FDAEC4B02729C48C0FD1B0B4695995B -- C:\Windows\SysNative\drivers\iaStor.sys
[2011.05.20 09:53:44 | 000,557,848 | ---- | M] (Intel Corporation) MD5=2FDAEC4B02729C48C0FD1B0B4695995B -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_e6913aab23ea9a9c\iaStor.sys
< MD5 for: IASTORV.SYS >
[2010.11.21 04:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.21 04:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2010.11.21 04:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.21 04:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.21 04:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.21 04:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.21 04:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.21 04:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2010.11.21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: USER32.DLL >
[2010.11.21 04:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.21 04:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2010.11.21 04:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.21 04:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
< MD5 for: USERINIT.EXE >
[2010.11.21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010.11.21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %USERPROFILE%\*.* >
[2013.02.19 14:51:25 | 001,048,576 | -HS- | M] () -- C:\Users\root\ntuser.dat
[2013.02.19 14:51:25 | 000,262,144 | -HS- | M] () -- C:\Users\root\ntuser.dat.LOG1
[2011.12.10 17:30:18 | 000,000,000 | -HS- | M] () -- C:\Users\root\ntuser.dat.LOG2
[2011.12.10 17:53:44 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2011.12.10 17:53:44 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2011.12.10 17:53:44 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2012.05.25 19:20:06 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{0dd20b7f-a696-11e1-ad81-50e5495bdd3a}.TM.blf
[2012.05.25 19:20:06 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{0dd20b7f-a696-11e1-ad81-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.05.25 19:20:06 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{0dd20b7f-a696-11e1-ad81-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.08.27 17:37:38 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{11de429c-f064-11e1-b97d-50e5495bdd3a}.TM.blf
[2012.08.27 17:37:38 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{11de429c-f064-11e1-b97d-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.08.27 17:37:38 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{11de429c-f064-11e1-b97d-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.01.23 17:15:38 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{15947d11-45dc-11e1-b93c-50e5495bdd3a}.TM.blf
[2012.01.23 17:15:38 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{15947d11-45dc-11e1-b93c-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.01.23 17:15:38 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{15947d11-45dc-11e1-b93c-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.07.14 22:15:54 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{1f0cde1b-cde4-11e1-adb7-50e5495bdd3a}.TM.blf
[2012.07.14 22:15:54 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{1f0cde1b-cde4-11e1-adb7-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.07.14 22:15:54 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{1f0cde1b-cde4-11e1-adb7-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2013.01.29 16:22:13 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{21ecba7a-6a26-11e2-8c38-50e5495bdd3a}.TM.blf
[2013.01.29 16:22:13 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{21ecba7a-6a26-11e2-8c38-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2013.01.29 16:22:13 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{21ecba7a-6a26-11e2-8c38-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.06.14 20:46:07 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{2dd36a01-b659-11e1-ae15-50e5495bdd3a}.TM.blf
[2012.06.14 20:46:07 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{2dd36a01-b659-11e1-ae15-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.06.14 20:46:07 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{2dd36a01-b659-11e1-ae15-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.09.06 18:21:41 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{2f13cd9e-f829-11e1-ae49-50e5495bdd3a}.TM.blf
[2012.09.06 18:21:41 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{2f13cd9e-f829-11e1-ae49-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.09.06 18:21:41 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{2f13cd9e-f829-11e1-ae49-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.06.19 16:42:40 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{3f3a215b-ba25-11e1-b942-50e5495bdd3a}.TM.blf
[2012.06.19 16:42:40 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{3f3a215b-ba25-11e1-b942-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.06.19 16:42:40 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{3f3a215b-ba25-11e1-b942-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.06.10 14:25:16 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{499fdeb5-b2ee-11e1-bb70-50e5495bdd3a}.TM.blf
[2012.06.10 14:25:16 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{499fdeb5-b2ee-11e1-bb70-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.06.10 14:25:16 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{499fdeb5-b2ee-11e1-bb70-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.08.19 14:43:27 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{4ec4eee5-ea03-11e1-b956-50e5495bdd3a}.TM.blf
[2012.08.19 14:43:27 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{4ec4eee5-ea03-11e1-b956-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.08.19 14:43:27 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{4ec4eee5-ea03-11e1-b956-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.12.08 16:48:52 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{512e2c09-4147-11e2-8c69-50e5495bdd3a}.TM.blf
[2012.12.08 16:48:52 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{512e2c09-4147-11e2-8c69-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.12.08 16:48:52 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{512e2c09-4147-11e2-8c69-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.09.14 19:46:13 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{5355b98f-fe82-11e1-b898-50e5495bdd3a}.TM.blf
[2012.09.14 19:46:13 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{5355b98f-fe82-11e1-b898-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.09.14 19:46:13 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{5355b98f-fe82-11e1-b898-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.07.02 22:35:11 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{53e371a9-c483-11e1-b9d6-50e5495bdd3a}.TM.blf
[2012.07.02 22:35:11 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{53e371a9-c483-11e1-b9d6-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.07.02 22:35:11 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{53e371a9-c483-11e1-b9d6-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2013.01.12 20:59:35 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{55a5b1a4-5cbe-11e2-8bd7-50e5495bdd3a}.TM.blf
[2013.01.12 20:59:35 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{55a5b1a4-5cbe-11e2-8bd7-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2013.01.12 20:59:35 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{55a5b1a4-5cbe-11e2-8bd7-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.02.06 17:20:09 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{5f07237a-50dc-11e1-ad55-50e5495bdd3a}.TM.blf
[2012.02.06 17:20:09 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{5f07237a-50dc-11e1-ad55-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.02.06 17:20:09 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{5f07237a-50dc-11e1-ad55-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.12.05 16:24:30 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{652a2188-3eec-11e2-8a9a-50e5495bdd3a}.TM.blf
[2012.12.05 16:24:30 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{652a2188-3eec-11e2-8a9a-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.12.05 16:24:30 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{652a2188-3eec-11e2-8a9a-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.02.07 22:21:19 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{68228b98-51cf-11e1-b8dd-50e5495bdd3a}.TM.blf
[2012.02.07 22:21:19 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{68228b98-51cf-11e1-b8dd-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.02.07 22:21:19 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{68228b98-51cf-11e1-b8dd-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.06.26 21:32:16 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{71232910-bfcd-11e1-ba33-ae603e4bd60d}.TM.blf
[2012.06.26 21:32:16 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{71232910-bfcd-11e1-ba33-ae603e4bd60d}.TMContainer00000000000000000001.regtrans-ms
[2012.06.26 21:32:16 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{71232910-bfcd-11e1-ba33-ae603e4bd60d}.TMContainer00000000000000000002.regtrans-ms
[2013.01.27 13:29:51 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{725de122-67b6-11e2-8ba6-50e5495bdd3a}.TM.blf
[2013.01.27 13:29:51 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{725de122-67b6-11e2-8ba6-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2013.01.27 13:29:51 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{725de122-67b6-11e2-8ba6-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2013.02.11 14:48:55 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{7b9aaf23-7440-11e2-8c47-50e5495bdd3a}.TM.blf
[2013.02.11 14:48:55 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{7b9aaf23-7440-11e2-8c47-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2013.02.11 14:48:55 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{7b9aaf23-7440-11e2-8c47-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.10.07 18:17:57 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{7f3cb495-10a1-11e2-adee-50e5495bdd3a}.TM.blf
[2012.10.07 18:17:57 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{7f3cb495-10a1-11e2-adee-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.10.07 18:17:57 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{7f3cb495-10a1-11e2-adee-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2013.02.15 11:32:32 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{7f89427a-775a-11e2-8c4c-50e5495bdd3a}.TM.blf
[2013.02.15 11:32:32 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{7f89427a-775a-11e2-8c4c-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2013.02.15 11:32:32 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{7f89427a-775a-11e2-8c4c-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.03.13 20:52:54 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{838a34f8-6d41-11e1-ba54-50e5495bdd3a}.TM.blf
[2012.03.13 20:52:54 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{838a34f8-6d41-11e1-ba54-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.03.13 20:52:54 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{838a34f8-6d41-11e1-ba54-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.08.03 12:52:19 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{8b825992-dd60-11e1-b970-50e5495bdd3a}.TM.blf
[2012.08.03 12:52:19 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{8b825992-dd60-11e1-b970-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.08.03 12:52:19 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{8b825992-dd60-11e1-b970-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.11.18 19:00:00 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{97225093-3196-11e2-add5-50e5495bdd3a}.TM.blf
[2012.11.18 19:00:00 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{97225093-3196-11e2-add5-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.11.18 19:00:00 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{97225093-3196-11e2-add5-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2013.01.30 21:20:22 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{994b4884-6b11-11e2-8c52-50e5495bdd3a}.TM.blf
[2013.01.30 21:20:22 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{994b4884-6b11-11e2-8c52-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2013.01.30 21:20:22 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{994b4884-6b11-11e2-8c52-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.08.09 19:52:34 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{a10ced06-e252-11e1-979a-50e5495bdd3a}.TM.blf
[2012.08.09 19:52:34 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{a10ced06-e252-11e1-979a-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.08.09 19:52:34 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{a10ced06-e252-11e1-979a-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.02.20 16:15:37 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{a4dae628-5bca-11e1-b924-50e5495bdd3a}.TM.blf
[2012.02.20 16:15:37 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{a4dae628-5bca-11e1-b924-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.02.20 16:15:37 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{a4dae628-5bca-11e1-b924-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.06.26 15:28:56 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{b4b06f6a-bf9a-11e1-af1b-50e5495bdd3a}.TM.blf
[2012.06.26 15:28:56 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{b4b06f6a-bf9a-11e1-af1b-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.06.26 15:28:56 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{b4b06f6a-bf9a-11e1-af1b-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2013.01.14 16:00:01 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{d13b6602-5e58-11e2-b93f-50e5495bdd3a}.TM.blf
[2013.01.14 16:00:01 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{d13b6602-5e58-11e2-b93f-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2013.01.14 16:00:01 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{d13b6602-5e58-11e2-b93f-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.12.23 23:23:08 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{d2880228-4d3e-11e2-a1cf-50e5495bdd3a}.TM.blf
[2012.12.23 23:23:08 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{d2880228-4d3e-11e2-a1cf-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.12.23 23:23:08 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{d2880228-4d3e-11e2-a1cf-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.11.25 19:00:01 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{d3a261a8-36f2-11e2-b8a3-50e5495bdd3a}.TM.blf
[2012.11.25 19:00:01 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{d3a261a8-36f2-11e2-b8a3-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.11.25 19:00:01 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{d3a261a8-36f2-11e2-b8a3-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.09.04 21:06:19 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{d88e7e21-f6c6-11e1-b8a3-50e5495bdd3a}.TM.blf
[2012.09.04 21:06:19 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{d88e7e21-f6c6-11e1-b8a3-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.09.04 21:06:19 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{d88e7e21-f6c6-11e1-b8a3-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2013.01.11 21:32:48 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{dd8faaf9-5c2d-11e2-8b8e-50e5495bdd3a}.TM.blf
[2013.01.11 21:32:48 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{dd8faaf9-5c2d-11e2-8b8e-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2013.01.11 21:32:48 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{dd8faaf9-5c2d-11e2-8b8e-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.09.23 08:45:26 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{e7deac90-0551-11e2-b907-50e5495bdd3a}.TM.blf
[2012.09.23 08:45:26 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{e7deac90-0551-11e2-b907-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.09.23 08:45:26 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{e7deac90-0551-11e2-b907-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.05.08 16:53:30 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{ee5c8428-991c-11e1-9711-50e5495bdd3a}.TM.blf
[2012.05.08 16:53:30 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{ee5c8428-991c-11e1-9711-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.05.08 16:53:30 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{ee5c8428-991c-11e1-9711-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2011.12.26 23:34:51 | 000,065,536 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{f00f561b-2fd2-11e1-a28e-50e5495bdd3a}.TM.blf
[2011.12.26 23:34:51 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{f00f561b-2fd2-11e1-a28e-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2011.12.26 23:34:51 | 000,524,288 | -HS- | M] () -- C:\Users\root\NTUSER.DAT{f00f561b-2fd2-11e1-a28e-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.10.20 19:11:15 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{f07562fc-1aba-11e2-8c0e-edbf65af1e73}.TM.blf
[2012.10.20 19:11:15 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{f07562fc-1aba-11e2-8c0e-edbf65af1e73}.TMContainer00000000000000000001.regtrans-ms
[2012.10.20 19:11:15 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{f07562fc-1aba-11e2-8c0e-edbf65af1e73}.TMContainer00000000000000000002.regtrans-ms
[2012.11.03 16:30:53 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{f0e1231a-25b9-11e2-b7c3-50e5495bdd3a}.TM.blf
[2012.11.03 16:30:53 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{f0e1231a-25b9-11e2-b7c3-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.11.03 16:30:53 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{f0e1231a-25b9-11e2-b7c3-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2013.01.09 15:16:36 | 000,065,536 | -HS- | M] () -- C:\Users\root\ntuser.dat{ffd5cd7a-5a63-11e2-b88e-50e5495bdd3a}.TM.blf
[2013.01.09 15:16:36 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{ffd5cd7a-5a63-11e2-b88e-50e5495bdd3a}.TMContainer00000000000000000001.regtrans-ms
[2013.01.09 15:16:36 | 000,524,288 | -HS- | M] () -- C:\Users\root\ntuser.dat{ffd5cd7a-5a63-11e2-b88e-50e5495bdd3a}.TMContainer00000000000000000002.regtrans-ms
[2011.12.10 17:30:18 | 000,000,020 | -HS- | M] () -- C:\Users\root\ntuser.ini
< %USERPROFILE%\Local Settings\Temp\*.exe >
< %USERPROFILE%\Local Settings\Temp\*.dll >
< %USERPROFILE%\Application Data\*.exe >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
< >
< End of report > --- --- --- |