| Bassmaker |  29.04.2011 20:29 |        Punkt 4: 
OTL-Log:    Code:  
 OTL logfile created on: 29.04.2011 21:23:41 - Run 1 
OTL by OldTimer - Version 3.2.22.3     Folder = F:\! Downloads ! 
64bit- An unknown product  (Version = 6.1.7600) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.7600.16385) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 67,00% Memory free 
8,00 Gb Paging File | 7,00 Gb Available in Paging File | 82,00% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 465,76 Gb Total Space | 294,99 Gb Free Space | 63,34% Space Free | Partition Type: NTFS 
Drive D: | 298,09 Gb Total Space | 93,30 Gb Free Space | 31,30% Space Free | Partition Type: NTFS 
Drive F: | 149,05 Gb Total Space | 79,39 Gb Free Space | 53,27% Space Free | Partition Type: NTFS 
Drive G: | 824,35 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS 
Drive J: | 6,67 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS 
Drive K: | 14,92 Gb Total Space | 12,70 Gb Free Space | 85,18% Space Free | Partition Type: FAT32 
  
Computer Name: MICHAEL-PC | User Name: Michael | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans 
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Processes (SafeList) ========== 
  
PRC - F:\! Downloads !\OTL.exe (OldTimer Tools) 
PRC - C:\Users\Michael\AppData\Local\Apps\2.0\N837HV3P.X1W\EWEARXCT.C0M\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe (AVM Berlin) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) 
PRC - C:\Program Files (x86)\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) 
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.) 
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira GmbH) 
PRC - C:\Windows\SysWOW64\PnkBstrA.exe () 
PRC - C:\Program Files (x86)\lg_fwupdate\fwupdate.exe (BitLeader) 
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe (Avira GmbH) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) 
PRC - C:\Windows\SysWOW64\dgdersvc.exe (Devguru Co., Ltd.) 
PRC - C:\Programme\Logitech\GamePanel Software\Applets\LCDMedia.exe (Logitech Inc.) 
PRC - C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe () 
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG) 
PRC - C:\Program Files (x86)\MySpace\Toolbar\1.0.72.0_1\MSTBCoreContainer.exe (MySpace) 
PRC - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE () 
PRC - C:\Program Files (x86)\Free Download Manager\fdm.exe (FreeDownloadManager.ORG) 
PRC - C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe (Razer Inc.) 
  
   ========== Modules (SafeList) ========== 
  
MOD - F:\! Downloads !\OTL.exe (OldTimer Tools) 
MOD - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchrome10browserrecordhelper.dll (RealNetworks, Inc.) 
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation) 
MOD - C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4926_none_508ed732bcbc0e5a\msvcr90.dll (Microsoft Corporation) 
MOD - C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4926_none_508ed732bcbc0e5a\msvcp90.dll (Microsoft Corporation) 
  
   ========== Win32 Services (SafeList) ========== 
  
SRV:64bit: - (OODefragAgent) -- C:\Program Files\OO Software\Defrag\oodag.exe (O&O Software GmbH) 
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) 
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) 
SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira GmbH) 
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe () 
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) 
SRV - (AntiVirFirewallService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe (Avira GmbH) 
SRV - (AntiVirMailService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH) 
SRV - (dgdersvc) -- C:\Windows\SysWOW64\dgdersvc.exe (Devguru Co., Ltd.) 
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) 
SRV - (CLKMSVC10_9EC60124) -- C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe (CyberLink) 
SRV - (KiesAllShare) -- C:\Program Files (x86)\Samsung\Kies\WiselinkPro\WiselinkPro.exe () 
SRV - (NAUpdate) -- C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG) 
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) 
SRV - (HPSLPSVC) -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.) 
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) 
SRV - (IJPLMSVC) -- C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE () 
SRV - (HerculesDJControlMP3) -- C:\Programme\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE () 
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation) 
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) 
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) 
DRV:64bit: - (avmaudio) -- C:\Windows\SysNative\drivers\avmaudio.sys (AVM Berlin) 
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) 
DRV:64bit: - (avfwot) -- C:\Windows\SysNative\drivers\avfwot.sys (Avira GmbH) 
DRV:64bit: - (netr28ux) -- C:\Windows\SysNative\drivers\netr28ux.sys (Ralink Technology Corp.) 
DRV:64bit: - (Btcsrusb) -- C:\Windows\SysNative\drivers\btcusb.sys (IVT Corporation.) 
DRV:64bit: - (HDJCtrl) -- C:\Windows\SysNative\drivers\HDJCtrl.sys (© Guillemot R&D, 2010. All rights reserved.) 
DRV:64bit: - (HDJMidi) -- C:\Windows\SysNative\drivers\HDJMidi.sys (© Guillemot R&D, 2010. All rights reserved.) 
DRV:64bit: - (TFsExDisk) -- C:\Windows\SysNative\drivers\TFsExDisk.sys (Teruten Inc) 
DRV:64bit: - (dgderdrv) -- C:\Windows\SysNative\drivers\dgderdrv.sys (Devguru Co., Ltd) 
DRV:64bit: - (ss_bmdm) -- C:\Windows\SysNative\drivers\ss_bmdm.sys (MCCI Corporation) 
DRV:64bit: - (ss_bserd) -- C:\Windows\SysNative\drivers\ss_bserd.sys (MCCI Corporation) 
DRV:64bit: - (ss_bbus) SAMSUNG USB Mobile Device (WDM) -- C:\Windows\SysNative\drivers\ss_bbus.sys (MCCI) 
DRV:64bit: - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) -- C:\Windows\SysNative\drivers\ss_bmdfl.sys (MCCI Corporation) 
DRV:64bit: - (danewFltr) -- C:\Windows\SysNative\drivers\danew.sys (Razer (Asia-Pacific) Pte Ltd) 
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH) 
DRV:64bit: - (avfwim) -- C:\Windows\SysNative\drivers\avfwim.sys (Avira GmbH) 
DRV:64bit: - (vhidmini) -- C:\Windows\SysNative\drivers\vHidDev.sys (Windows (R) Win 7 DDK provider) 
DRV:64bit: - (LGVirHid) -- C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.) 
DRV:64bit: - (LGBusEnum) -- C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.) 
DRV:64bit: - (HTCAND64) -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation) 
DRV:64bit: - (Pd71HiFiWdm.sys) -- C:\Windows\SysNative\drivers\Pd71HiFiWdm.sys () 
DRV:64bit: - (Pd71HiFi.sys) -- C:\Windows\SysNative\drivers\Pd71HiFi.sys () 
DRV:64bit: - (CYUSB) -- C:\Windows\SysNative\drivers\CYUSB.sys (Cypress Semiconductor) 
DRV:64bit: - (VClone) -- C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG) 
DRV:64bit: - (NVNET) -- C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation) 
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) 
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) 
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) 
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) 
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation) 
DRV:64bit: - (SynUSB64) -- C:\Windows\SysNative\drivers\synusb64.sys (Steinberg Media Technologies GmbH) 
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof () 
DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation) 
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) 
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) 
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) 
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) 
DRV:64bit: - (FWLANUSB) -- C:\Windows\SysNative\drivers\fwlanusb.sys (AVM GmbH) 
DRV:64bit: - (avmeject) -- C:\Windows\SysNative\drivers\avmeject.sys (AVM Berlin) 
DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.) 
DRV:64bit: - (Envy24HFS) -- C:\Windows\SysNative\drivers\Envy24HF.sys (VIA - IC Ensemble, Inc.) 
DRV - (avfwot) -- C:\Windows\SysWOW64\drivers\avfwot.sys (Avira GmbH) 
DRV - (dgderdrv) -- C:\Windows\SysWOW64\drivers\dgderdrv.sys (Devguru Co., Ltd) 
DRV - (TFsExDisk) -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys (Teruten Inc) 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
  
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 19 3A F3 28 B4 EC CB 01  [binary data] 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = fritz.box 
   ========== FireFox ========== 
  
FF - prefs.js..browser.search.defaultenginename: "ICQ Search" 
FF - prefs.js..browser.search.selectedEngine: "Google" 
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/ig" 
FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.3.4 
FF - prefs.js..extensions.enabledItems: myspacefftb@myspace.com:1.0.72.0 
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6 
FF - prefs.js..extensions.enabledItems: {79c50f9a-2ffe-4ee0-8a37-fae4f5dacd4f}:4.7.8 
FF - prefs.js..extensions.enabledItems: {097d3191-e6fa-4728-9826-b533d755359d}:0.7.13 
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 
FF - prefs.js..extensions.enabledItems: battlefieldheroespatcher@ea.com:5.0.31.0 
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.3 
FF - prefs.js..network.proxy.backup.ftp: "41.234.205.125" 
FF - prefs.js..network.proxy.backup.ftp_port: 80 
FF - prefs.js..network.proxy.backup.gopher: "41.234.205.125" 
FF - prefs.js..network.proxy.backup.gopher_port: 80 
FF - prefs.js..network.proxy.backup.socks: "41.234.205.125" 
FF - prefs.js..network.proxy.backup.socks_port: 80 
FF - prefs.js..network.proxy.backup.ssl: "41.234.205.125" 
FF - prefs.js..network.proxy.backup.ssl_port: 80 
FF - prefs.js..network.proxy.ftp: "81.25.168.238" 
FF - prefs.js..network.proxy.ftp_port: 3128 
FF - prefs.js..network.proxy.gopher: "81.25.168.238" 
FF - prefs.js..network.proxy.gopher_port: 3128 
FF - prefs.js..network.proxy.http: "81.25.168.238" 
FF - prefs.js..network.proxy.http_port: 3128 
FF - prefs.js..network.proxy.share_proxy_settings: true 
FF - prefs.js..network.proxy.socks: "81.25.168.238" 
FF - prefs.js..network.proxy.socks_port: 3128 
FF - prefs.js..network.proxy.ssl: "81.25.168.238" 
FF - prefs.js..network.proxy.ssl_port: 3128 
FF - prefs.js..network.proxy.type: 0 
  
  
FF - HKLM\software\mozilla\Firefox\Extensions\\myspacefftb@myspace.com: C:\Program Files (x86)\MySpace\Toolbar\1.0.72.0_1\ [2010.12.11 21:24:35 | 000,000,000 | ---D | M] 
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.01.02 00:00:56 | 000,000,000 | ---D | M] 
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.04.28 21:12:16 | 000,000,000 | ---D | M] 
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.04.16 19:36:05 | 000,000,000 | ---D | M] 
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.04.28 21:12:16 | 000,000,000 | ---D | M] 
  
[2010.07.29 21:16:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michael\AppData\Roaming\Mozilla\Extensions 
[2011.04.28 21:25:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kp8tx8fq.default\extensions 
[2011.03.17 21:04:01 | 000,000,000 | ---D | M] (All-in-One Sidebar) -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kp8tx8fq.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d} 
[2011.04.28 21:12:15 | 000,000,000 | ---D | M] (Googlebar Lite) -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kp8tx8fq.default\extensions\{79c50f9a-2ffe-4ee0-8a37-fae4f5dacd4f} 
[2011.04.07 08:36:06 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kp8tx8fq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} 
[2010.08.27 14:51:58 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kp8tx8fq.default\extensions\battlefieldheroespatcher@ea.com 
[2011.04.28 20:05:08 | 000,000,947 | ---- | M] () -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kp8tx8fq.default\searchplugins\icqplugin.xml 
[2010.12.11 21:24:42 | 000,002,138 | ---- | M] () -- C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kp8tx8fq.default\searchplugins\MySpace.xml 
[2011.04.28 21:25:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions 
[2010.07.30 22:50:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} 
[2010.08.08 22:23:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} 
[2010.10.17 16:07:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} 
[2011.03.01 10:25:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} 
[2010.07.30 22:59:10 | 000,000,000 | ---D | M] (Free Download Manager plugin) -- C:\PROGRAM FILES (X86)\FREE DOWNLOAD MANAGER\FIREFOX\EXTENSION 
[2010.12.11 21:24:35 | 000,000,000 | ---D | M] (MySpace Toolbar for Windows) -- C:\PROGRAM FILES (X86)\MYSPACE\TOOLBAR\1.0.72.0_1 
[2011.04.28 21:12:16 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT 
[2011.03.01 10:25:29 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll 
[2010.09.09 14:29:17 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml 
[2010.09.09 14:29:17 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml 
[2010.09.09 14:29:17 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml 
[2010.09.09 14:29:17 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml 
[2010.09.09 14:29:17 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml 
  
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts 
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) 
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) 
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll () 
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) 
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) 
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.) 
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.) 
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.) 
O4:64bit: - HKLM..\Run: [Pd71HiFiPan.exe] C:\Windows\SysNative\Pd71HiFiPan.exe () 
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation) 
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) 
O4 - HKLM..\Run: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe () 
O4 - HKLM..\Run: [LGODDFU] C:\Program Files (x86)\lg_fwupdate\fwupdate.exe (BitLeader) 
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.) 
O4 - HKCU..\Run: [AVMUSBFernanschluss] C:\Users\Michael\AppData\Local\Apps\2.0\N837HV3P.X1W\EWEARXCT.C0M\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\AVMAutoStart.exe (AVM Berlin) 
O4 - HKCU..\Run: [Free Download Manager] C:\Program Files (x86)\Free Download Manager\fdm.exe (FreeDownloadManager.ORG) 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00  [binary data] 
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1 
O8:64bit: - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlall.htm () 
O8:64bit: - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlselected.htm () 
O8:64bit: - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dllink.htm () 
O8:64bit: - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm () 
O8 - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlall.htm () 
O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlselected.htm () 
O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dllink.htm () 
O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm () 
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) 
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) 
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) 
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) 
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH) 
O13 - gopher Prefix: missing 
O13 - gopher Prefix: missing 
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet) 
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet) 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) 
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found 
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found 
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. 
O32 - HKLM CDRom: AutoRun - 1 
O32 - AutoRun File - [2010.10.04 03:27:16 | 000,000,000 | ---D | M] - G:\autorun -- [ CDFS ] 
O32 - AutoRun File - [2010.09.20 09:59:24 | 000,000,062 | R--- | M] () - G:\autorun.inf -- [ CDFS ] 
O32 - AutoRun File - [2008.05.06 14:26:23 | 000,000,309 | R--- | M] () - J:\autorun.inf -- [ CDFS ] 
O33 - MountPoints2\{0bfd3757-2e33-11e0-bf06-858107958f8e}\Shell - "" = AutoRun 
O33 - MountPoints2\{0bfd3757-2e33-11e0-bf06-858107958f8e}\Shell\AutoRun\command - "" = H:\AutoRun.exe 
O33 - MountPoints2\{284fa2c0-2e38-11e0-b1a2-001f1fbb893e}\Shell - "" = AutoRun 
O33 - MountPoints2\{284fa2c0-2e38-11e0-b1a2-001f1fbb893e}\Shell\AutoRun\command - "" = H:\AutoRun.exe 
O33 - MountPoints2\{284fa2c4-2e38-11e0-b1a2-001f1fbb893e}\Shell - "" = AutoRun 
O33 - MountPoints2\{284fa2c4-2e38-11e0-b1a2-001f1fbb893e}\Shell\AutoRun\command - "" = H:\AutoRun.exe 
O33 - MountPoints2\{284fa2cf-2e38-11e0-b1a2-001f1fbb893e}\Shell - "" = AutoRun 
O33 - MountPoints2\{284fa2cf-2e38-11e0-b1a2-001f1fbb893e}\Shell\AutoRun\command - "" = H:\AutoRun.exe 
O33 - MountPoints2\{284fa2d4-2e38-11e0-b1a2-001f1fbb893e}\Shell - "" = AutoRun 
O33 - MountPoints2\{284fa2d4-2e38-11e0-b1a2-001f1fbb893e}\Shell\AutoRun\command - "" = H:\AutoRun.exe 
O33 - MountPoints2\{597a5f53-dee8-11df-a359-bc0543005acd}\Shell - "" = AutoRun 
O33 - MountPoints2\{597a5f53-dee8-11df-a359-bc0543005acd}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a 
O33 - MountPoints2\{5a8ea0cc-2331-11e0-a69b-806e6f6e6963}\Shell - "" = AutoRun 
O33 - MountPoints2\{5a8ea0cc-2331-11e0-a69b-806e6f6e6963}\Shell\AutoRun\command - "" = G:\cdstart.exe -- [2010.10.04 03:14:24 | 001,419,984 | R--- | M] () 
O33 - MountPoints2\{75a10736-9fe5-11df-a511-001c4af45f9b}\Shell - "" = AutoRun 
O33 - MountPoints2\{75a10736-9fe5-11df-a511-001c4af45f9b}\Shell\AutoRun\command - "" = I:\AutoRun.exe 
O33 - MountPoints2\{75a1073e-9fe5-11df-a511-001c4af45f9b}\Shell - "" = AutoRun 
O33 - MountPoints2\{75a1073e-9fe5-11df-a511-001c4af45f9b}\Shell\AutoRun\command - "" = H:\AutoRun.exe 
O33 - MountPoints2\{ba0297ec-b473-11df-a306-0015833034c0}\Shell - "" = AutoRun 
O33 - MountPoints2\{ba0297ec-b473-11df-a306-0015833034c0}\Shell\AutoRun\command - "" = I:\cdstart.exe 
O33 - MountPoints2\{fe813ccf-9b3f-11df-b72b-001d92765e47}\Shell - "" = AutoRun 
O33 - MountPoints2\{fe813ccf-9b3f-11df-b72b-001d92765e47}\Shell\AutoRun\command - "" = J:\pushinst.exe 
O33 - MountPoints2\{fe813d33-9b3f-11df-b72b-001c4af45f9b}\Shell - "" = AutoRun 
O33 - MountPoints2\{fe813d33-9b3f-11df-b72b-001c4af45f9b}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -- [2007.10.23 09:45:39 | 001,336,632 | R--- | M] () 
O33 - MountPoints2\H\Shell - "" = AutoRun 
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a 
O33 - MountPoints2\J\Shell - "" = AutoRun 
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\LaunchU3.exe -- [2007.10.23 09:45:39 | 001,336,632 | R--- | M] () 
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found 
O34 - HKLM BootExecute: (OODBS) -  File not found 
O35:64bit: - HKLM\..comfile [open] -- "%1" %* 
O35:64bit: - HKLM\..exefile [open] -- "%1" %* 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O35 - HKCU\..exefile [open] -- "%1" %* 
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* 
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* 
O37 - HKLM\...com [@ = comfile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
O37 - HKCU\...exe [@ = exefile] -- "%1" %* 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2011.04.29 20:26:27 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\Malwarebytes 
[2011.04.29 20:26:19 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 
[2011.04.29 20:26:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware 
[2011.04.29 20:26:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes 
[2011.04.29 20:26:15 | 000,024,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys 
[2011.04.29 20:26:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware 
[2011.04.28 20:17:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Grisoft 
[2011.04.28 19:16:03 | 002,870,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe 
[2011.04.28 19:16:02 | 002,614,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe 
[2011.04.28 19:15:42 | 002,566,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\esent.dll 
[2011.04.28 19:15:41 | 001,686,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\esent.dll 
[2011.04.28 19:15:41 | 000,187,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storport.sys 
[2011.04.28 19:15:41 | 000,107,904 | ---- | C] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\amdsata.sys 
[2011.04.28 19:15:41 | 000,027,008 | ---- | C] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\amdxata.sys 
[2011.04.28 19:15:40 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fsutil.exe 
[2011.04.28 19:15:40 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fsutil.exe 
[2011.04.28 07:58:40 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll 
[2011.04.28 07:58:39 | 000,662,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll 
[2011.04.28 07:53:15 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prevhost.exe 
[2011.04.28 07:53:15 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prevhost.exe 
[2011.04.27 23:19:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Tools Security 
[2011.04.27 22:46:35 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools 
[2011.04.23 20:50:36 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee 
[2011.04.16 19:36:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared 
[2011.04.16 19:36:05 | 000,198,848 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll 
[2011.04.16 19:35:53 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll 
[2011.04.16 19:35:53 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll 
[2011.04.16 19:35:52 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll 
[2011.04.16 19:35:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real 
[2011.04.16 19:35:49 | 000,499,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp71.dll 
[2011.04.16 07:34:44 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll 
[2011.04.16 07:34:44 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll 
[2011.04.16 07:34:43 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll 
[2011.04.16 07:34:43 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll 
[2011.04.16 07:34:43 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll 
[2011.04.16 07:34:43 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll 
[2011.04.16 07:34:43 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll 
[2011.04.16 07:34:43 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll 
[2011.04.16 07:34:43 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll 
[2011.04.16 07:34:43 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll 
[2011.04.16 07:34:43 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe 
[2011.04.16 07:34:43 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe 
[2011.04.16 07:34:42 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec 
[2011.04.16 07:34:42 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec 
[2011.04.15 20:40:41 | 000,476,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll 
[2011.04.15 20:40:41 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll 
[2011.04.15 20:40:34 | 000,852,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll 
[2011.04.15 20:40:33 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll 
[2011.04.15 20:40:33 | 000,612,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll 
[2011.04.15 20:40:21 | 001,359,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42u.dll 
[2011.04.15 20:40:20 | 001,395,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42.dll 
[2011.04.15 20:40:20 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42u.dll 
[2011.04.15 20:40:20 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42.dll 
[2011.04.15 20:40:16 | 000,367,104 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll 
[2011.04.15 20:40:16 | 000,294,912 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll 
[2011.04.15 20:40:16 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll 
[2011.04.15 20:40:16 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll 
[2011.04.15 20:37:31 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll 
[2011.04.15 20:37:31 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnscacheugc.exe 
[2011.04.15 20:37:31 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dnscacheugc.exe 
[2011.04.15 20:09:23 | 000,640,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi 
[2011.04.15 20:09:23 | 000,603,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe 
[2011.04.15 20:09:23 | 000,518,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe 
[2011.04.15 20:09:22 | 000,556,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi 
[2011.04.15 20:09:22 | 000,020,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdusb.dll 
[2011.04.15 20:09:22 | 000,019,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kd1394.dll 
[2011.04.15 20:09:22 | 000,017,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdcom.dll 
[2011.04.15 20:09:14 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSCOVER.exe 
[2011.04.09 22:28:14 | 000,000,000 | ---D | C] -- C:\Users\Michael\AppData\Roaming\NeroDigital(TM) 
[2011.04.09 20:35:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nero 
[2011.04.09 20:35:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 
[2011.04.09 20:35:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nero 
[2011.04.08 21:32:56 | 000,000,000 | ---D | C] -- C:\ProgramData\LightScribe 
[2011.04.08 19:43:41 | 000,000,000 | ---D | C] -- C:\Users\Michael\Documents\NeroVision 
[2010.08.10 18:43:08 | 005,811,712 | ---- | C] (reFX) -- C:\Program Files (x86)\Nexus.dll 
[2 C:\Users\Michael\*.tmp files -> C:\Users\Michael\*.tmp -> ] 
   ========== Files - Modified Within 30 Days ========== 
  
[2011.04.29 21:26:32 | 001,507,106 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI 
[2011.04.29 21:26:32 | 000,657,438 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat 
[2011.04.29 21:26:32 | 000,618,714 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat 
[2011.04.29 21:26:32 | 000,130,810 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat 
[2011.04.29 21:26:32 | 000,107,034 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat 
[2011.04.29 21:20:34 | 000,000,372 | ---- | M] () -- C:\Windows\lgfwup.ini 
[2011.04.29 21:20:23 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job 
[2011.04.29 21:20:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat 
[2011.04.29 21:20:17 | 3220,566,016 | -HS- | M] () -- C:\hiberfil.sys 
[2011.04.29 21:20:17 | 000,441,496 | ---- | M] () -- C:\Windows\SysNative\oodbs.lor 
[2011.04.29 21:02:01 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job 
[2011.04.29 20:26:19 | 000,001,119 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk 
[2011.04.29 20:02:42 | 000,014,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
[2011.04.29 20:02:42 | 000,014,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
[2011.04.28 20:55:05 | 000,004,284 | -HS- | M] () -- C:\Users\Michael\AppData\Local\s1pni65073 
[2011.04.28 20:55:05 | 000,004,284 | -HS- | M] () -- C:\ProgramData\s1pni65073 
[2011.04.28 08:03:39 | 001,373,878 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB 
[2011.04.27 13:59:20 | 000,270,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr 
[2011.04.27 13:59:20 | 000,270,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe 
[2011.04.24 23:04:04 | 000,002,020 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk 
[2011.04.16 19:36:05 | 000,198,848 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll 
[2011.04.16 19:35:53 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll 
[2011.04.16 19:35:53 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll 
[2011.04.16 19:35:52 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll 
[2011.04.16 19:35:49 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp71.dll 
[2011.04.16 07:26:38 | 000,442,920 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT 
[2011.04.09 22:33:04 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini 
[2011.04.09 20:39:29 | 000,002,923 | ---- | M] () -- C:\Users\Public\Desktop\Nero StartSmart 10.lnk 
[2 C:\Users\Michael\*.tmp files -> C:\Users\Michael\*.tmp -> ] 
   ========== Files Created - No Company Name ========== 
  
[2011.04.29 20:26:19 | 000,001,119 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk 
[2011.04.27 23:20:15 | 001,373,878 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB 
[2011.04.27 22:09:21 | 000,004,284 | -HS- | C] () -- C:\Users\Michael\AppData\Local\s1pni65073 
[2011.04.27 22:09:21 | 000,004,284 | -HS- | C] () -- C:\ProgramData\s1pni65073 
[2011.04.09 20:39:29 | 000,002,923 | ---- | C] () -- C:\Users\Public\Desktop\Nero StartSmart 10.lnk 
[2011.03.26 10:58:13 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini 
[2011.03.13 22:01:49 | 002,255,360 | ---- | C] () -- C:\Windows\SysWow64\libavcodec.dll 
[2011.03.13 22:01:49 | 000,395,776 | ---- | C] () -- C:\Windows\SysWow64\libmplayer.dll 
[2011.03.13 22:01:49 | 000,262,144 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll 
[2011.03.13 22:01:49 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll 
[2011.03.13 21:47:48 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll 
[2011.03.13 21:47:29 | 000,033,019 | ---- | C] () -- C:\Windows\SysWow64\CoreAAC-uninstall.exe 
[2011.02.03 23:12:47 | 000,000,042 | ---- | C] () -- C:\Windows\oodjobd.INI 
[2011.01.18 21:13:42 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini 
[2011.01.18 20:45:00 | 000,000,372 | ---- | C] () -- C:\Windows\lgfwup.ini 
[2011.01.16 00:47:15 | 000,000,156 | ---- | C] () -- C:\Users\Michael\AppData\Roaming\burnaware.ini 
[2011.01.02 00:00:35 | 000,023,731 | ---- | C] () -- C:\Windows\hpqins15.dat.temp 
[2011.01.01 19:47:06 | 000,266,058 | ---- | C] () -- C:\Windows\hpwins23.dat 
[2010.12.24 17:19:44 | 000,023,731 | ---- | C] () -- C:\Windows\hpqins15.dat 
[2010.09.26 21:37:30 | 000,002,604 | ---- | C] () -- C:\Windows\cdplayer.ini 
[2010.09.12 16:12:37 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe 
[2010.09.03 19:57:37 | 001,499,556 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI 
[2010.08.29 15:32:26 | 000,270,904 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe 
[2010.08.29 15:32:25 | 002,427,248 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_heroes.exe 
[2010.08.29 15:32:25 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe 
[2010.08.14 22:09:30 | 000,008,704 | ---- | C] () -- C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 
[2010.08.10 21:39:50 | 000,000,037 | ---- | C] () -- C:\Windows\SWFConverter.INI 
[2010.08.01 14:15:41 | 000,000,051 | ---- | C] () -- C:\Windows\SysWow64\SYNSOPOS.exe.cfg 
[2010.07.29 22:20:34 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\SYNSOPOS.exe 
[2010.07.29 21:16:06 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat 
[2010.06.30 16:01:38 | 000,749,568 | ---- | C] () -- C:\Windows\SysWow64\spk.dll 
[2010.05.07 07:54:16 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll 
[2010.05.07 07:54:16 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll 
[2010.05.07 07:54:16 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll 
[2010.05.07 07:54:16 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll 
[2009.11.06 11:17:18 | 000,001,843 | ---- | C] () -- C:\Windows\hpwmdl23.dat 
[2009.10.29 17:16:32 | 000,103,008 | ---- | C] () -- C:\Windows\SysWow64\Pd71HiFiAsio32.dll 
[2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat 
[2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT 
[2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat 
[2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin 
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll 
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll 
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat 
[2002.09.18 01:45:00 | 000,119,808 | ---- | C] () -- C:\Windows\lsb_un20.exe 
   ========== Alternate Data Streams ========== 
  
@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:DFC5A2B2 
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:64217CD0 
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84   
< End of report >      |