Oberoanut | 04.06.2011 16:09 | OTL Normal Log:OTL Logfile: Code:
OTL logfile created on: 03.06.2011 18:43:44 - Run 2
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Michl\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 1,95 Gb Available Physical Memory | 48,80% Memory free
12,47 Gb Paging File | 10,45 Gb Available in Paging File | 83,78% Paging File free
Paging file location(s): c:\pagefile.sys 0 0d:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 178,79 Gb Total Space | 38,61 Gb Free Space | 21,59% Space Free | Partition Type: NTFS
Drive D: | 119,30 Gb Total Space | 34,63 Gb Free Space | 29,03% Space Free | Partition Type: NTFS
Drive E: | 340,65 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: ****** | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\*****\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\PROGRA~2\Bandoo\Bandoo.exe (Bandoo Media Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Programme\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Programme\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\pdf24\pdf24.exe (Geek Software GmbH)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Common Files\MAGIX Shared\Database2\bin\FABS.exe (MAGIX AG)
========== Modules (SafeList) ==========
MOD - C:\Users\*****\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (O&O Defrag) -- C:\Windows\SysNative\oodag.exe (O&O Software GmbH)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Bandoo Coordinator) -- C:\PROGRA~2\Bandoo\Bandoo.exe (Bandoo Media Inc.)
SRV - (Akamai) -- c:\program files (x86)\common files\akamai\netsession_win_8832f4b.dll ()
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Futuremark SystemInfo Service) -- C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (Creative ALchemy AL6 Licensing Service) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (nSvcIp) -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV - (SandraAgentSrv) -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3c\RpcAgentSrv.exe (SiSoftware)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CTAudSvcService) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Shared\Database2\bin\FABS.exe (MAGIX AG)
SRV - (UPnPService) -- C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe (Magix AG)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Shared\Database2\bin\fbserver.exe (MAGIX®)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\Drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (AnyDVD) -- C:\Windows\SysNative\Drivers\AnyDVD.sys (SlySoft, Inc.)
DRV:64bit: - (btnetBUs) -- C:\Windows\SysNative\Drivers\btnetBus.sys ()
DRV:64bit: - (IvtBtBUs) -- C:\Windows\SysNative\Drivers\IvtBtBus.sys (IVT Corporation.)
DRV:64bit: - (BtHidBus) -- C:\Windows\SysNative\Drivers\BtHidBus.sys (IVT Corporation.)
DRV:64bit: - (atksgt) -- C:\Windows\SysNative\DRIVERS\atksgt.sys ()
DRV:64bit: - (lirsgt) -- C:\Windows\SysNative\DRIVERS\lirsgt.sys ()
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (VClone) -- C:\Windows\SysNative\DRIVERS\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (ha20x2k) -- C:\Windows\SysNative\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV:64bit: - (emupia) -- C:\Windows\SysNative\drivers\emupia2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctsfm2k) -- C:\Windows\SysNative\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctprxy2k) -- C:\Windows\SysNative\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV:64bit: - (ossrv) -- C:\Windows\SysNative\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV:64bit: - (ctaud2k) Creative Audio Driver (WDM) -- C:\Windows\SysNative\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctac32k) -- C:\Windows\SysNative\drivers\ctac32k.sys (Creative Technology Ltd)
DRV:64bit: - (CTEXFIFX.SYS) -- C:\Windows\SysNative\drivers\CTEXFIFX.SYS (Creative Technology Ltd.)
DRV:64bit: - (CTEXFIFX) -- C:\Windows\SysNative\drivers\CTEXFIFX.SYS (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT.SYS) -- C:\Windows\SysNative\drivers\CTHWIUT.SYS (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT) -- C:\Windows\SysNative\drivers\CTHWIUT.SYS (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT.SYS) -- C:\Windows\SysNative\drivers\CT20XUT.SYS (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT) -- C:\Windows\SysNative\drivers\CT20XUT.SYS (Creative Technology Ltd.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (MagicTune) -- C:\Windows\SysNative\drivers\MTiCtwl.sys (Samsung Electronics, Inc. )
DRV:64bit: - (PciPPorts) -- C:\Windows\SysNative\DRIVERS\PciPPorts.sys ()
DRV:64bit: - (PciSPorts) -- C:\Windows\SysNative\DRIVERS\PciSPorts.sys ()
DRV:64bit: - (ROOTMODEM) -- C:\Windows\SysNative\Drivers\RootMdm.sys (Microsoft Corporation)
DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\DRIVERS\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (Btcsrusb) -- C:\Windows\SysNative\Drivers\btcusb.sys (IVT Corporation.)
DRV:64bit: - (BlueletSCOAudio) -- C:\Windows\SysNative\DRIVERS\BlueletSCOAudio.sys (IVT Corporation.)
DRV:64bit: - (BT) -- C:\Windows\SysNative\DRIVERS\btnetdrv.sys (IVT Corporation.)
DRV:64bit: - (VcommMgr) -- C:\Windows\SysNative\Drivers\VcommMgr.sys (IVT Corporation.)
DRV:64bit: - (VComm) -- C:\Windows\SysNative\DRIVERS\VComm.sys (IVT Corporation.)
DRV:64bit: - (BlueletAudio) -- C:\Windows\SysNative\DRIVERS\blueletaudio.sys (IVT Corporation.)
DRV:64bit: - (CTEDSPSY.DLL) -- C:\Windows\SysNative\CTEDSPSY.DLL (Creative Technology Ltd)
DRV:64bit: - (CTEDSPIO.DLL) -- C:\Windows\SysNative\CTEDSPIO.DLL (Creative Technology Ltd)
DRV:64bit: - (CTERFXFX.DLL) -- C:\Windows\SysNative\CTERFXFX.DLL (Creative Technology Ltd)
DRV:64bit: - (CTEDSPFX.DLL) -- C:\Windows\SysNative\CTEDSPFX.DLL (Creative Technology Ltd)
DRV:64bit: - (CTEAPSFX.DLL) -- C:\Windows\SysNative\CTEAPSFX.DLL (Creative Technology Ltd)
DRV:64bit: - (CTSBLFX.DLL) -- C:\Windows\SysNative\CTSBLFX.DLL (Creative Technology Ltd)
DRV:64bit: - (CTAUDFX.DLL) -- C:\Windows\SysNative\CTAUDFX.DLL (Creative Technology Ltd)
DRV:64bit: - (COMMONFX.DLL) -- C:\Windows\SysNative\COMMONFX.DLL (Creative Technology Ltd)
DRV:64bit: - (ElbyCDFL) -- C:\Windows\SysNative\Drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV:64bit: - (R300) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\DRIVERS\nvm60x64.sys (NVIDIA Corporation)
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\DRIVERS\ASACPI.sys ()
DRV - (AnyDVD) -- C:\Windows\SysWOW64\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (SANDRA) -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP3c\WNt500x64\sandra.sys (SiSoftware)
DRV - (Btcsrusb) -- C:\Windows\SysWOW64\drivers\btcusb.sys (IVT Corporation.)
DRV - (BlueletSCOAudio) -- C:\Windows\SysWOW64\drivers\BlueletSCOAudio.sys (IVT Corporation.)
DRV - (BT) -- C:\Windows\SysWOW64\drivers\btnetdrv.sys (IVT Corporation.)
DRV - (BTHidMgr) -- C:\Windows\System32\Drivers\BTHidMgr.sys (IVT Corporation.)
DRV - (BTHidEnum) -- C:\Windows\System32\Drivers\vbtenum.sys (IVT Corporation.)
DRV - (VcommMgr) -- C:\Windows\SysWOW64\drivers\VCommMgr.sys (IVT Corporation.)
DRV - (VComm) -- C:\Windows\SysWOW64\drivers\VComm.sys (IVT Corporation.)
DRV - (BlueletAudio) -- C:\Windows\SysWOW64\drivers\blueletaudio.sys (IVT Corporation.)
DRV - (ElbyCDFL) -- C:\Windows\SysWOW64\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (StarOpen) -- C:\Windows\SysWow64\drivers\StarOpen.sys ()
DRV - (ElbyCDIO) -- C:\Windows\SysWOW64\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011.05.31 10:45:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.05.09 07:20:42 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.05.16 15:28:13 | 000,000,000 | ---D | M]
[2011.05.30 08:31:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michl\AppData\Roaming\mozilla\Extensions
[2009.11.15 12:31:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michl\AppData\Roaming\mozilla\Extensions\MediaCoder
[2010.02.04 12:55:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michl\AppData\Roaming\mozilla\Extensions\MediaCoder-MCEX
[2009.11.15 12:35:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michl\AppData\Roaming\mozilla\Extensions\MediaCoder-Setup-Wizard
[2011.05.30 21:37:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michl\AppData\Roaming\mozilla\Firefox\Profiles\wdxuh5yd.default\extensions
[2010.04.27 14:56:19 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Michl\AppData\Roaming\mozilla\Firefox\Profiles\wdxuh5yd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.05.21 18:31:59 | 000,000,000 | ---D | M] (XfireXO) -- C:\Users\Michl\AppData\Roaming\mozilla\Firefox\Profiles\wdxuh5yd.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
[2011.05.30 08:30:49 | 000,000,000 | ---D | M] (Searchqu Toolbar) -- C:\Users\Michl\AppData\Roaming\mozilla\Firefox\Profiles\wdxuh5yd.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2011.01.20 22:33:01 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\Michl\AppData\Roaming\mozilla\Firefox\Profiles\wdxuh5yd.default\extensions\battlefieldheroespatcher@ea.com
[2011.05.30 08:31:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.05.16 15:28:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011.05.17 12:31:27 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.05.09 07:20:40 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.02.02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.05.09 07:20:41 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.05.09 07:20:41 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.05.09 07:20:41 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.05.09 07:20:41 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.05.09 07:20:41 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.05.09 07:20:41 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2011.05.30 22:56:19 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Windows Live ID-Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Programme\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll (Conduit Ltd.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files (x86)\XfireXO\prxtbXfir.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AsioThk32Reg] C:\Windows\SysWow64\ctasio.dll (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\pdf24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab (Creative Software AutoUpdate Support Package 1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 195.58.160.194 195.58.161.122
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - File not found
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI371A~1\Datamngr\x64\datamngr.dll) - C:\PROGRA~2\WI371A~1\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI371A~1\Datamngr\x64\IEBHO.dll) - C:\PROGRA~2\WI371A~1\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (c:\PROGRA~2\WI371A~1\Datamngr\datamngr.dll) - c:\PROGRA~2\WI371A~1\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (c:\PROGRA~2\WI371A~1\Datamngr\IEBHO.dll) - c:\PROGRA~2\WI371A~1\Datamngr\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (c:\PROGRA~2\Bandoo\BndHook.dll) - c:\PROGRA~2\Bandoo\BndHook.dll (Discordia Limited)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Michl\Desktop\76341_TheWitcher2-KeyArt-02.jpg
O24 - Desktop BackupWallPaper: C:\Users\Michl\Desktop\76341_TheWitcher2-KeyArt-02.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.07.23 08:13:31 | 000,000,000 | ---D | M] - E:\AutoPlay -- [ CDFS ]
O32 - AutoRun File - [2010.07.19 01:50:37 | 002,834,432 | R--- | M] () - E:\autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2009.04.10 18:32:30 | 000,000,046 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7070D8E0-650A-46b3-B03C-9497582E6A74} - %SystemRoot%\system32\soundschemes.exe /AddRegistration
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24} - %SystemRoot%\system32\soundschemes2.exe /AddRegistration
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2F6EFCE6-10DF-49F9-9E64-9AE3775B2588} - Microsoft .NET Framework 1.1 Security Update (KB2416447)
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GammaTray.exe.lnk - C:\Programme\MagicTune Premium\GammaTray.exe - ()
MsConfig:64bit - StartUpFolder: C:^Users^Michl^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Kuma_Tray.lnk - C:\PROGRA~2\KUMAGA~1\KGSYST~1\KUMA_T~1.EXE - ()
MsConfig:64bit - StartUpFolder: C:^Users^Michl^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - - File not found
MsConfig:64bit - StartUpFolder: C:^Users^Michl^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Xfire.lnk - C:\PROGRA~2\Xfire\Xfire.exe - (Xfire Inc.)
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: AnyDVD - hkey= - key= - C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
MsConfig:64bit - StartUpReg: AppleSyncNotifier - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: AudioDrvEmulator - hkey= - key= - C:\Program Files (x86)\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
MsConfig:64bit - StartUpReg: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: CloneCDTray - hkey= - key= - C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe (SlySoft, Inc.)
MsConfig:64bit - StartUpReg: Creative MediaSource Go - hkey= - key= - C:\Program Files (x86)\Creative\MediaSource5\Go\CTCMSGoU.exe (Creative Technology Ltd)
MsConfig:64bit - StartUpReg: CTHelper - hkey= - key= - C:\Windows\SysWow64\CTHELPER.EXE (Creative Technology Ltd)
MsConfig:64bit - StartUpReg: CTxfiHlp - hkey= - key= - C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
MsConfig:64bit - StartUpReg: DATAMNGR - hkey= - key= - C:\PROGRA~2\WI371A~1\Datamngr\DATAMN~1.EXE (Discordia, LTD)
MsConfig:64bit - StartUpReg: EA Core - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: EPSON Stylus DX4400 Series - hkey= - key= - C:\Windows\SysNative\spool\DRIVERS\x64\3\E_IATICAE.EXE (SEIKO EPSON CORPORATION)
MsConfig:64bit - StartUpReg: GrooveMonitor - hkey= - key= - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg: ICQ - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: MagicTuneEngine - hkey= - key= - C:\Programme\MagicTune Premium\MagicTuneLauncher.exe ()
MsConfig:64bit - StartUpReg: NeroFilterCheck - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: NVIDIA nTune - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: OODefragTray - hkey= - key= - C:\Windows\SysNative\oodtray.exe (O&O Software GmbH)
MsConfig:64bit - StartUpReg: Pando Media Booster - hkey= - key= - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
MsConfig:64bit - StartUpReg: PC SpeedScan Pro - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: Performance Center - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: RCSystem - hkey= - key= - C:\Program Files (x86)\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
MsConfig:64bit - StartUpReg: RGSC - hkey= - key= - C:\Program Files (x86)\Steam\steamapps\common\grand theft auto iv\RGSC\RGSCLauncher.exe (Take-Two Interactive Software, Inc.)
MsConfig:64bit - StartUpReg: Skype - hkey= - key= - C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig:64bit - StartUpReg: Software Informer - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: Steam - hkey= - key= - c:\program files (x86)\steam\steam.exe (Valve Corporation)
MsConfig:64bit - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
MsConfig:64bit - StartUpReg: TkBellExe - hkey= - key= - C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
MsConfig:64bit - StartUpReg: UpdReg - hkey= - key= - C:\Windows\Updreg.EXE (Creative Technology Ltd.)
MsConfig:64bit - StartUpReg: VolPanel - hkey= - key= - C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
MsConfig:64bit - StartUpReg: Windows Defender - hkey= - key= - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011.06.03 18:40:16 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\Michl\Desktop\OTL.exe
[2011.06.03 18:38:02 | 000,589,632 | ---- | C] (AVAST Software) -- C:\Users\Michl\Desktop\aswMBR.exe
[2011.06.03 18:31:00 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Roaming\Malwarebytes
[2011.06.03 18:30:53 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011.06.03 18:30:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.06.03 18:30:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.06.03 18:30:49 | 000,025,912 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011.06.03 18:30:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.06.03 18:29:30 | 009,435,312 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Michl\Desktop\mbam-setup-1.51.0.1200.exe
[2011.06.03 17:09:04 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011.06.03 16:56:35 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011.06.03 16:52:33 | 004,112,250 | R--- | C] (Swearware) -- C:\Users\Michl\Desktop\ComboFix.exe
[2011.05.30 23:04:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2011.05.30 23:04:21 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011.05.30 22:40:27 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011.05.30 22:40:27 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011.05.30 22:40:18 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.05.30 22:40:14 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.05.30 20:49:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MonitorDriver
[2011.05.30 20:49:05 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Roaming\InstallShield
[2011.05.30 20:12:21 | 000,023,096 | ---- | C] (Samsung Electronics, Inc. ) -- C:\Windows\SysNative\drivers\MTiCtwl.sys
[2011.05.30 20:11:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Electronics Ltd
[2011.05.30 20:11:45 | 000,000,000 | ---D | C] -- C:\Programme\MagicTune Premium
[2011.05.30 20:06:43 | 000,000,000 | ---D | C] -- C:\Samsung
[2011.05.30 11:54:24 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
[2011.05.30 11:45:11 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Roaming\Bandoo
[2011.05.30 09:29:13 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Local\Ilivid Player
[2011.05.30 08:34:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandoo
[2011.05.30 08:33:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Bandoo
[2011.05.30 08:33:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bandoo
[2011.05.30 08:32:00 | 000,000,000 | -H-D | C] -- C:\ProgramData\{EF2D8223-8F3C-423E-BFA7-5E8BEEA8A6C2}
[2011.05.30 08:31:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iLivid
[2011.05.30 08:31:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iLivid
[2011.05.30 08:30:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows iLivid Toolbar
[2011.05.30 08:28:01 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Local\PackageAware
[2011.05.28 07:15:31 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2011.05.28 07:14:43 | 003,040,360 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll
[2011.05.28 07:14:43 | 000,061,544 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
[2011.05.28 07:14:38 | 006,289,512 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll
[2011.05.28 07:14:38 | 002,560,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll
[2011.05.28 07:14:38 | 000,794,216 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\easyupdatusapiu64.dll
[2011.05.28 07:14:38 | 000,117,864 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll
[2011.05.28 07:14:24 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2011.05.28 07:07:12 | 022,286,952 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2011.05.28 07:07:12 | 016,456,296 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2011.05.28 07:07:12 | 008,865,896 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2011.05.28 07:07:12 | 006,555,752 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2011.05.28 07:07:12 | 001,427,048 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvgenco642090.dll
[2011.05.28 07:07:12 | 000,067,176 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011.05.28 07:07:12 | 000,057,960 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011.05.28 07:07:11 | 018,583,144 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2011.05.28 07:07:11 | 015,223,912 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll
[2011.05.28 07:07:11 | 013,011,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2011.05.28 07:07:11 | 011,992,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2011.05.28 07:07:11 | 007,123,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2011.05.28 07:07:11 | 005,301,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2011.05.28 07:07:11 | 002,943,592 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2011.05.28 07:07:11 | 002,804,328 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2011.05.28 07:07:11 | 002,644,072 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
[2011.05.28 07:07:11 | 002,335,336 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2011.05.28 07:07:11 | 002,212,968 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2011.05.28 07:07:11 | 002,082,408 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2011.05.28 07:07:11 | 001,496,168 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6420150.dll
[2011.05.28 07:07:11 | 000,012,392 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvBridge.kmd
[2011.05.26 17:19:05 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Local\PDF24
[2011.05.26 17:17:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pdf24
[2011.05.21 18:32:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XfireXO
[2011.05.21 18:32:00 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Local\Conduit
[2011.05.21 18:31:30 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Roaming\Xfire
[2011.05.21 18:31:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Xfire
[2011.05.21 18:31:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire
[2011.05.21 18:31:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xfire
[2011.05.21 07:32:37 | 000,000,000 | ---D | C] -- C:\Users\Michl\Documents\3DMark 11
[2011.05.21 07:32:14 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Local\IsolatedStorage
[2011.05.21 07:32:06 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Local\Futuremark_Corporation
[2011.05.21 07:25:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Futuremark
[2011.05.21 07:25:51 | 000,000,000 | ---D | C] -- C:\Programme\Futuremark
[2011.05.18 21:35:16 | 000,000,000 | ---D | C] -- C:\Users\Michl\Documents\Witcher 2
[2011.05.18 21:35:16 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Local\The Witcher 2
[2011.05.17 12:33:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011.05.17 12:31:24 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2011.05.17 12:31:24 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2011.05.17 12:31:24 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2011.05.16 15:28:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2011.05.16 15:28:13 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2011.05.15 18:28:00 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011.05.15 14:41:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.05.15 14:41:26 | 000,000,000 | ---D | C] -- C:\Programme\iPod
[2011.05.15 14:41:22 | 000,000,000 | ---D | C] -- C:\Programme\iTunes
[2011.05.15 14:41:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011.05.15 14:39:45 | 000,000,000 | ---D | C] -- C:\Programme\Bonjour
[2011.05.15 14:39:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2011.05.11 23:47:38 | 000,071,680 | ---- | C] (Beepa P/L) -- C:\Windows\SysNative\frapsv64.dll
[2011.05.11 23:47:36 | 000,065,536 | ---- | C] (Beepa P/L) -- C:\Windows\SysWow64\frapsvid.dll
[2011.05.11 11:59:16 | 000,000,000 | ---D | C] -- C:\Users\Michl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kuma Games
[2011.05.11 11:58:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Akamai
[2011.05.11 11:57:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Kuma Games
[2009.06.04 00:57:38 | 000,060,928 | ---- | C] ( ) -- C:\Windows\SysWow64\a3d.dll
[2009.06.04 00:32:54 | 000,012,800 | ---- | C] ( ) -- C:\Windows\SysWow64\killapps.exe
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011.06.03 18:45:49 | 000,000,438 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{6242D63D-81AE-4DB4-A58D-CF609B1522E2}.job
[2011.06.03 18:40:17 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Michl\Desktop\OTL.exe
[2011.06.03 18:39:22 | 000,000,512 | ---- | M] () -- C:\Users\Michl\Desktop\MBR.dat
[2011.06.03 18:38:05 | 000,589,632 | ---- | M] (AVAST Software) -- C:\Users\Michl\Desktop\aswMBR.exe
[2011.06.03 18:36:41 | 000,098,565 | ---- | M] () -- C:\Users\Michl\Desktop\Malwarebyts.jpg
[2011.06.03 18:30:53 | 000,000,948 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.06.03 18:30:07 | 009,435,312 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Michl\Desktop\mbam-setup-1.51.0.1200.exe
[2011.06.03 18:25:39 | 000,005,088 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.06.03 18:25:39 | 000,005,088 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.06.03 17:56:00 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.06.03 16:56:14 | 004,112,250 | R--- | M] (Swearware) -- C:\Users\Michl\Desktop\ComboFix.exe
[2011.06.03 10:39:00 | 000,395,109 | ---- | M] () -- C:\Users\Michl\Desktop\76341_TheWitcher2-KeyArt-02.jpg
[2011.06.03 10:25:52 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2011.06.03 10:25:42 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.06.03 10:25:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.06.03 10:25:27 | 4293,451,776 | -HS- | M] () -- C:\hiberfil.sys
[2011.06.03 10:25:19 | 001,763,665 | ---- | M] () -- C:\Windows\SysNative\oodbs.lor
[2011.06.03 10:24:30 | 000,061,448 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000007-00000000-00000007-00001102-00000005-00291102}.rfx
[2011.06.03 10:24:30 | 000,061,448 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000007-00000000-00000007-00001102-00000005-00291102}.rfx
[2011.06.03 10:24:30 | 000,000,788 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000007-00000000-00000007-00001102-00000005-00291102}.rfx
[2011.06.03 10:23:01 | 000,018,453 | ---- | M] () -- C:\Users\Michl\Desktop\Combo Fix Fehler.jpg
[2011.06.02 14:27:35 | 000,104,674 | ---- | M] () -- C:\Users\Michl\Desktop\HD Auslastung.jpg
[2011.06.01 13:20:40 | 000,057,344 | ---- | M] () -- C:\Users\Michl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.06.01 07:30:31 | 000,073,116 | ---- | M] () -- C:\Users\Michl\Desktop\AVAST Container.jpg
[2011.06.01 07:20:14 | 000,000,816 | ---- | M] () -- C:\Users\Michl\Desktop\PW Logis.lnk
[2011.05.31 10:45:30 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011.05.30 23:26:35 | 000,054,981 | ---- | M] () -- C:\Users\Michl\Desktop\www.searchqu,com.jpg
[2011.05.30 22:56:19 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011.05.30 21:36:30 | 000,038,630 | ---- | M] () -- C:\Users\Michl\Desktop\Firefox.jpg
[2011.05.30 20:49:17 | 000,001,477 | ---- | M] () -- C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk
[2011.05.30 20:11:45 | 000,001,431 | ---- | M] () -- C:\Users\Public\Desktop\MagicTunePremium.lnk
[2011.05.30 11:54:24 | 000,000,524 | ---- | M] () -- C:\Users\Michl\Desktop\Fraps.lnk
[2011.05.30 08:31:59 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\iLivid Download Manager.lnk
[2011.05.29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011.05.29 09:11:20 | 000,025,912 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011.05.28 07:12:33 | 000,001,460 | ---- | M] () -- C:\Users\Michl\AppData\Local\d3d9caps64.dat
[2011.05.28 07:12:13 | 000,001,356 | ---- | M] () -- C:\Users\Michl\AppData\Local\d3d9caps.dat
[2011.05.28 07:02:53 | 000,001,100 | ---- | M] () -- C:\Users\Michl\AppData\Local\d3d8caps.dat
[2011.05.27 20:48:32 | 000,051,480 | ---- | M] () -- C:\Users\Michl\Desktop\Zwischenablage02.jpg
[2011.05.26 17:19:52 | 000,580,689 | ---- | M] () -- C:\Users\Michl\Desktop\Typenschein Peugeot 206.pdf
[2011.05.26 17:17:52 | 000,001,707 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2011.05.26 09:42:01 | 001,598,440 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.05.26 09:42:01 | 000,685,890 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.05.26 09:42:01 | 000,643,978 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.05.26 09:42:01 | 000,150,290 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.05.26 09:42:01 | 000,123,802 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.05.25 16:55:28 | 001,524,112 | ---- | M] () -- C:\Windows\SysWow64\bandoolmx.dll
[2011.05.23 18:02:19 | 000,001,788 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2011.05.23 10:55:00 | 000,408,698 | ---- | M] () -- C:\Users\Michl\Documents\UPC.pdf
[2011.05.23 10:55:00 | 000,389,945 | ---- | M] () -- C:\Users\Michl\Documents\UPC3.pdf
[2011.05.23 10:55:00 | 000,380,536 | ---- | M] () -- C:\Users\Michl\Documents\UPC 2.pdf
[2011.05.23 09:42:40 | 000,032,613 | ---- | M] () -- C:\Users\Michl\Desktop\Tastaturbelegung Witcher 2.jpg
[2011.05.23 08:25:53 | 000,000,980 | ---- | M] () -- C:\Users\Michl\Desktop\Scheidung.lnk
[2011.05.21 18:31:29 | 000,000,802 | ---- | M] () -- C:\Users\Public\Desktop\Xfire.lnk
[2011.05.21 07:25:57 | 000,001,745 | ---- | M] () -- C:\Users\Public\Desktop\3DMark 11.lnk
[2011.05.19 20:41:18 | 000,000,221 | ---- | M] () -- C:\Users\Michl\Desktop\The Witcher 2.url
[2011.05.19 19:43:25 | 004,710,557 | ---- | M] () -- C:\Users\Michl\Desktop\The Witcher 2 Manual - German.pdf
[2011.05.16 15:53:04 | 000,000,129 | ---- | M] () -- C:\Users\Michl\jagex_runescape_preferences2.dat
[2011.05.16 15:50:00 | 000,000,046 | ---- | M] () -- C:\Users\Michl\jagex_runescape_preferences.dat
[2011.05.16 15:21:19 | 000,304,828 | ---- | M] () -- C:\Users\Michl\Desktop\Nirolift.pdf
[2011.05.16 11:10:06 | 000,107,832 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011.05.15 18:28:00 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011.05.15 14:41:51 | 000,001,694 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.05.14 06:27:00 | 022,286,952 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2011.05.14 06:27:00 | 018,583,144 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2011.05.14 06:27:00 | 016,456,296 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2011.05.14 06:27:00 | 015,223,912 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll
[2011.05.14 06:27:00 | 013,011,560 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2011.05.14 06:27:00 | 011,992,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2011.05.14 06:27:00 | 008,865,896 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2011.05.14 06:27:00 | 007,123,560 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2011.05.14 06:27:00 | 006,555,752 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2011.05.14 06:27:00 | 006,289,512 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll
[2011.05.14 06:27:00 | 005,301,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2011.05.14 06:27:00 | 003,040,360 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll
[2011.05.14 06:27:00 | 002,943,592 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2011.05.14 06:27:00 | 002,804,328 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2011.05.14 06:27:00 | 002,644,072 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
[2011.05.14 06:27:00 | 002,560,616 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll
[2011.05.14 06:27:00 | 002,335,336 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2011.05.14 06:27:00 | 002,212,968 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2011.05.14 06:27:00 | 002,082,408 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2011.05.14 06:27:00 | 001,496,168 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6420150.dll
[2011.05.14 06:27:00 | 001,427,048 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvgenco642090.dll
[2011.05.14 06:27:00 | 000,794,216 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\easyupdatusapiu64.dll
[2011.05.14 06:27:00 | 000,117,864 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll
[2011.05.14 06:27:00 | 000,067,176 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011.05.14 06:27:00 | 000,061,544 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
[2011.05.14 06:27:00 | 000,057,960 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011.05.14 06:27:00 | 000,012,392 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvBridge.kmd
[2011.05.14 06:27:00 | 000,007,384 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
[2011.05.11 23:47:38 | 000,071,680 | ---- | M] (Beepa P/L) -- C:\Windows\SysNative\frapsv64.dll
[2011.05.11 23:47:36 | 000,065,536 | ---- | M] (Beepa P/L) -- C:\Windows\SysWow64\frapsvid.dll
[2011.05.11 11:59:16 | 000,001,718 | ---- | M] () -- C:\Users\Michl\Desktop\Kuma Games.lnk
[2011.05.10 14:10:59 | 000,040,112 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2011.05.10 14:10:55 | 000,199,304 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2011.05.10 14:10:44 | 000,253,888 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2011.05.10 14:04:08 | 000,600,920 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2011.05.10 14:04:07 | 000,287,576 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2011.05.10 14:02:41 | 000,053,592 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2011.05.10 13:59:59 | 000,031,064 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2011.05.10 13:59:48 | 000,064,344 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011.05.10 13:59:37 | 000,022,360 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.06.03 18:39:22 | 000,000,512 | ---- | C] () -- C:\Users\Michl\Desktop\MBR.dat
[2011.06.03 18:36:41 | 000,098,565 | ---- | C] () -- C:\Users\Michl\Desktop\Malwarebyts.jpg
[2011.06.03 18:30:53 | 000,000,948 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.06.03 10:38:11 | 000,395,109 | ---- | C] () -- C:\Users\Michl\Desktop\76341_TheWitcher2-KeyArt-02.jpg
[2011.06.03 10:23:01 | 000,018,453 | ---- | C] () -- C:\Users\Michl\Desktop\Combo Fix Fehler.jpg
[2011.06.02 14:27:34 | 000,104,674 | ---- | C] () -- C:\Users\Michl\Desktop\HD Auslastung.jpg
[2011.06.01 07:30:31 | 000,073,116 | ---- | C] () -- C:\Users\Michl\Desktop\AVAST Container.jpg
[2011.05.30 23:26:35 | 000,054,981 | ---- | C] () -- C:\Users\Michl\Desktop\www.searchqu,com.jpg
[2011.05.30 22:40:27 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011.05.30 22:40:27 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011.05.30 22:40:27 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.05.30 22:40:27 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.05.30 22:40:27 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.05.30 21:36:30 | 000,038,630 | ---- | C] () -- C:\Users\Michl\Desktop\Firefox.jpg
[2011.05.30 20:49:17 | 000,001,477 | ---- | C] () -- C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk
[2011.05.30 20:11:45 | 000,001,431 | ---- | C] () -- C:\Users\Public\Desktop\MagicTunePremium.lnk
[2011.05.30 11:54:24 | 000,000,524 | ---- | C] () -- C:\Users\Michl\Desktop\Fraps.lnk
[2011.05.30 08:33:57 | 001,524,112 | ---- | C] () -- C:\Windows\SysWow64\bandoolmx.dll
[2011.05.30 08:31:59 | 000,000,866 | ---- | C] () -- C:\Users\Public\Desktop\iLivid Download Manager.lnk
[2011.05.28 07:21:35 | 4293,451,776 | -HS- | C] () -- C:\hiberfil.sys
[2011.05.28 07:07:11 | 000,007,384 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2011.05.27 20:48:32 | 000,051,480 | ---- | C] () -- C:\Users\Michl\Desktop\Zwischenablage02.jpg
[2011.05.26 17:19:51 | 000,580,689 | ---- | C] () -- C:\Users\Michl\Desktop\Typenschein Peugeot 206.pdf
[2011.05.26 17:17:52 | 000,001,707 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk
[2011.05.23 10:55:00 | 000,408,698 | ---- | C] () -- C:\Users\Michl\Documents\UPC.pdf
[2011.05.23 10:55:00 | 000,389,945 | ---- | C] () -- C:\Users\Michl\Documents\UPC3.pdf
[2011.05.23 10:55:00 | 000,380,536 | ---- | C] () -- C:\Users\Michl\Documents\UPC 2.pdf
[2011.05.23 09:42:40 | 000,032,613 | ---- | C] () -- C:\Users\Michl\Desktop\Tastaturbelegung Witcher 2.jpg
[2011.05.21 18:31:29 | 000,000,802 | ---- | C] () -- C:\Users\Public\Desktop\Xfire.lnk
[2011.05.21 07:25:57 | 000,001,745 | ---- | C] () -- C:\Users\Public\Desktop\3DMark 11.lnk
[2011.05.19 20:41:18 | 000,000,221 | ---- | C] () -- C:\Users\Michl\Desktop\The Witcher 2.url
[2011.05.19 19:43:25 | 004,710,557 | ---- | C] () -- C:\Users\Michl\Desktop\The Witcher 2 Manual - German.pdf
[2011.05.16 15:21:18 | 000,304,828 | ---- | C] () -- C:\Users\Michl\Desktop\Nirolift.pdf
[2011.05.15 14:41:51 | 000,001,694 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.05.11 11:59:16 | 000,001,718 | ---- | C] () -- C:\Users\Michl\Desktop\Kuma Games.lnk
[2011.05.09 07:20:43 | 000,000,900 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011.04.17 21:57:54 | 000,041,872 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2011.01.24 13:32:41 | 000,000,029 | ---- | C] () -- C:\Windows\sfbm.INI
[2010.12.02 18:32:06 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2010.09.08 15:39:07 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2010.09.04 15:58:30 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2010.09.04 15:58:30 | 000,014,392 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2010.09.04 15:58:24 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini
[2010.06.28 14:31:28 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2010.06.28 11:49:09 | 000,000,091 | ---- | C] () -- C:\Windows\BsMobileModel.ini
[2010.06.28 11:32:23 | 000,002,114 | ---- | C] () -- C:\Windows\SysWow64\SHORTCUT.INI
[2010.06.28 11:31:11 | 000,000,128 | ---- | C] () -- C:\Windows\SysWow64\REMOTEDEVICE.INI
[2010.06.28 11:28:16 | 000,006,532 | ---- | C] () -- C:\Windows\SysWow64\LOCALSERVICE.INI
[2010.06.28 11:28:16 | 000,000,100 | ---- | C] () -- C:\Windows\SysWow64\LOCALDEVICE.INI
[2010.06.27 21:11:00 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\BSPRINT.INI
[2010.04.20 18:22:44 | 000,000,047 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010.02.18 14:27:38 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2010.01.07 19:09:25 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\StrStorage.dll
[2009.12.14 13:30:17 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2009.11.06 10:58:04 | 000,178,975 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2009.10.25 11:44:56 | 000,005,632 | ---- | C] () -- C:\Windows\SysWow64\drivers\StarOpen.sys
[2009.10.25 11:40:31 | 000,000,039 | ---- | C] () -- C:\Windows\Irremote.ini
[2009.10.03 19:40:42 | 000,003,972 | ---- | C] () -- C:\Windows\SysWow64\drivers\PciBus.sys
[2009.10.01 11:19:32 | 000,000,093 | ---- | C] () -- C:\Users\Michl\AppData\Local\fusioncache.dat
[2009.09.21 22:03:47 | 000,000,466 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009.09.16 15:59:37 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2009.09.07 17:01:45 | 001,562,452 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009.08.25 16:04:29 | 000,001,086 | ---- | C] () -- C:\Users\Michl\AppData\Local\F1C3C386.il
[2009.08.25 16:04:29 | 000,000,280 | ---- | C] () -- C:\Users\Michl\AppData\Local\IndexIE_F1C3C386.il
[2009.08.22 10:44:18 | 000,038,423 | ---- | C] () -- C:\Users\Michl\AppData\Roaming\Kommagetrennte Werte (DOS).ADR
[2009.08.13 09:27:24 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
[2009.08.13 09:26:18 | 000,007,119 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2009.08.11 17:19:36 | 010,452,992 | ---- | C] () -- C:\ProgramData\sandra.mda
[2009.08.10 21:26:41 | 000,107,832 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2009.08.10 21:26:20 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2009.08.10 21:26:19 | 002,337,865 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2009.08.07 13:36:18 | 000,000,000 | ---- | C] () -- C:\Windows\oodcnt.INI
[2009.08.01 11:24:06 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.08.01 11:23:59 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009.08.01 11:23:48 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009.08.01 11:23:48 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2009.07.31 23:41:11 | 003,596,288 | ---- | C] () -- C:\Windows\SysWow64\qt-dx331.dll
[2009.07.31 23:41:11 | 000,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2009.07.31 23:41:11 | 000,205,824 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009.07.31 23:41:11 | 000,168,448 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2009.07.31 23:41:11 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2009.07.31 23:41:10 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2009.07.31 23:23:24 | 000,313,207 | ---- | C] () -- C:\Windows\SysWow64\ctstatic.dat
[2009.07.31 23:23:24 | 000,053,932 | ---- | C] () -- C:\Windows\SysWow64\ctdaught.dat
[2009.07.31 23:23:24 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CTBURST.DLL
[2009.07.31 23:22:09 | 000,003,072 | ---- | C] () -- C:\Windows\SysWow64\CTXFIGER.DLL
[2009.07.31 23:20:53 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2009.07.31 23:20:53 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2009.07.31 19:45:20 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2009.07.31 18:55:58 | 000,001,100 | ---- | C] () -- C:\Users\Michl\AppData\Local\d3d8caps.dat
[2009.07.31 18:55:52 | 000,001,356 | ---- | C] () -- C:\Users\Michl\AppData\Local\d3d9caps.dat
[2009.07.31 18:51:34 | 000,057,344 | ---- | C] () -- C:\Users\Michl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.07.31 18:50:10 | 000,001,460 | ---- | C] () -- C:\Users\Michl\AppData\Local\d3d9caps64.dat
[2009.06.04 02:37:06 | 000,000,054 | ---- | C] () -- C:\Windows\SysWow64\ctzapxx.ini
[2009.06.04 01:37:08 | 000,021,093 | ---- | C] () -- C:\Windows\SysWow64\instwdm.ini
[2009.06.04 00:55:20 | 000,002,560 | ---- | C] () -- C:\Windows\SysWow64\CtxfiRes.dll
[2009.06.04 00:40:44 | 000,321,512 | ---- | C] () -- C:\Windows\SysWow64\ctdlang.dat
[2009.06.04 00:40:44 | 000,056,509 | ---- | C] () -- C:\Windows\SysWow64\ctdnlstr.dat
[2009.06.04 00:33:04 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\enlocstr.exe
[2009.05.27 09:49:00 | 000,000,285 | ---- | C] () -- C:\Windows\SysWow64\kill.ini
[2007.03.05 09:09:04 | 000,037,888 | ---- | C] () -- C:\Windows\SysWow64\PSCONV.EXE
[2006.11.02 17:35:48 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:37:14 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006.11.02 14:24:17 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006.11.02 14:18:17 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006.11.02 11:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.10.09 15:29:22 | 000,032,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\BTNetFilter.sys
[2005.10.04 17:28:12 | 000,071,680 | ---- | C] () -- C:\Windows\SysWow64\CTMMACTL.DLL
========== LOP Check ==========
[2011.03.19 18:07:28 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\.minecraft
[2011.05.30 11:45:11 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\Bandoo
[2011.03.03 11:17:34 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\BitTorrent
[2009.11.15 12:13:27 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\Broad Intelligence
[2011.01.11 18:36:36 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\Canneverbe Limited
[2009.08.20 08:41:47 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\EPSON
[2009.08.05 18:42:30 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\GrabPro
[2010.12.30 17:13:27 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\gtk-2.0
[2009.10.01 11:19:34 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\HEROLD Business Data
[2009.09.14 16:20:19 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\IrfanView
[2011.02.23 20:32:19 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\Kalypso Media
[2010.08.15 17:41:13 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\MAGIX
[2010.09.26 11:59:53 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\Need for Speed World
[2009.11.15 12:13:29 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\OpenCandy
[2009.08.07 11:08:34 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\Orbit
[2009.12.12 18:46:35 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\ProtectDisc
[2011.02.16 11:19:38 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\RIFT
[2010.11.15 20:51:56 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\runic games
[2011.02.13 11:42:08 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\SAMSUNG
[2009.09.09 22:13:16 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\SecondLife
[2009.11.06 12:07:51 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\SoftMaker
[2010.04.23 18:41:13 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\TS3Client
[2011.03.07 13:06:16 | 000,000,000 | ---D | M] -- C:\Users\Michl\AppData\Roaming\Ubisoft
[2011.06.03 10:24:09 | 000,032,562 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.06.03 18:45:49 | 000,000,438 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{6242D63D-81AE-4DB4-A58D-CF609B1522E2}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2010.02.12 19:51:31 | 000,000,000 | ---D | M] -- C:\.jagex_cache_32
[2009.07.31 19:55:55 | 000,000,000 | ---D | M] -- C:\557cdd409ec7b42b452f72cc3bfa
[2009.08.01 11:36:50 | 000,000,000 | ---D | M] -- C:\Boot
[2009.11.01 09:43:31 | 000,000,000 | ---D | M] -- C:\CloneDVDTemp
[2010.03.05 14:15:10 | 000,000,000 | ---D | M] -- C:\CoreTemp
[2009.08.06 18:33:27 | 000,000,000 | ---D | M] -- C:\CrashReport
[2006.11.02 17:41:02 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2009.07.31 18:48:22 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2011.03.02 15:48:27 | 000,000,000 | ---D | M] -- C:\dosprogs
[2011.02.25 19:00:28 | 000,000,000 | ---D | M] -- C:\downloads
[2010.07.25 22:19:28 | 000,000,000 | ---D | M] -- C:\DS2Temp
[2011.06.01 13:22:05 | 000,000,000 | ---D | M] -- C:\Fraps
[2011.05.16 11:19:55 | 000,000,000 | ---D | M] -- C:\Install
[2009.08.01 11:51:47 | 000,000,000 | R--D | M] -- C:\MSOCache
[2011.02.27 20:11:26 | 000,000,000 | ---D | M] -- C:\My Music
[2009.08.10 13:49:06 | 000,000,000 | ---D | M] -- C:\NV5003056.TMP
[2010.09.04 16:31:16 | 000,000,000 | ---D | M] -- C:\NVIDIA
[2011.05.16 11:18:45 | 000,000,000 | ---D | M] -- C:\Patches
[2009.08.01 17:38:07 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2011.05.16 11:21:14 | 000,000,000 | ---D | M] -- C:\Pics
[2011.05.30 20:11:45 | 000,000,000 | R--D | M] -- C:\Programme
[2011.06.03 18:30:49 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2011.06.03 18:30:52 | 000,000,000 | ---D | M] -- C:\ProgramData
[2009.07.31 18:48:22 | 000,000,000 | -HSD | M] -- C:\Programme
[2011.03.10 21:22:42 | 000,000,000 | ---D | M] -- C:\PWRD
[2011.06.03 17:09:05 | 000,000,000 | ---D | M] -- C:\Qoobox
[2011.05.30 20:08:14 | 000,000,000 | ---D | M] -- C:\Samsung
[2011.06.03 18:44:51 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2011.05.28 07:15:31 | 000,000,000 | R--D | M] -- C:\Users
[2011.05.16 11:21:12 | 000,000,000 | ---D | M] -- C:\Vids
[2011.05.16 11:21:13 | 000,000,000 | ---D | M] -- C:\VISTA Buch
[2009.12.23 18:20:43 | 000,000,000 | ---D | M] -- C:\VivoxLogs
[2011.06.03 17:09:04 | 000,000,000 | ---D | M] -- C:\Windows
< %PROGRAMFILES%\*.exe >
< %PROGRAMFILES%\*. >
[2011.03.08 10:48:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
[2009.08.08 13:19:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
[2010.09.04 15:58:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ASUS
[2011.05.30 08:34:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bandoo
[2011.05.15 14:39:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour
[2011.05.24 06:56:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CDBurnerXP
[2011.06.03 17:04:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
[2011.05.16 11:15:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Creative
[2011.01.24 15:40:39 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Creative Installation Information
[2011.03.02 16:10:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\DOSBox-0.74
[2010.09.08 15:40:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\DVDVideoSoft
[2011.01.20 22:33:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\EA Games
[2010.12.10 21:04:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Elaborate Bytes
[2010.04.20 09:54:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Electronic Arts
[2009.08.19 18:07:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\epson
[2009.08.07 15:40:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\GIMP-2.0
[2011.02.22 14:58:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google
[2009.10.01 11:11:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HEROLD
[2009.08.02 08:22:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Huawei technologies
[2011.05.30 08:33:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iLivid
[2011.05.30 20:49:15 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2011.04.18 20:11:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
[2009.09.13 15:20:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iPhone-Konfigurationsprogramm
[2009.09.14 16:20:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\IrfanView
[2011.05.15 14:41:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes
[2010.06.27 21:09:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\IVT Corporation
[2011.05.17 12:31:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java
[2009.07.31 23:43:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\K-Lite Codec Pack
[2011.05.24 10:51:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Kuma Games
[2009.08.13 09:30:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MAGIX
[2011.06.03 18:30:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.05.20 08:25:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MAXCRM-Trial
[2009.11.15 12:39:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MediaCoder
[2009.08.29 09:23:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft
[2009.08.29 09:24:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Games
[2010.04.24 11:09:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
[2010.12.12 22:22:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
[2011.04.23 11:25:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
[2009.08.01 11:54:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Visual Studio
[2009.10.01 11:12:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Visual Studio .NET 2003
[2009.08.01 11:52:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2009.08.14 21:34:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Works
[2010.07.25 08:57:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
[2011.05.30 20:49:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MonitorDriver
[2011.05.09 07:20:42 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
[2009.08.01 11:54:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
[2010.12.12 22:21:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSECache
[2009.08.14 19:35:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSXML 4.0
[2009.10.25 11:38:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Nero
[2011.05.28 07:15:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NVIDIA Corporation
[2009.08.11 19:50:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NVIDIA nTune Performance Application
[2009.07.31 23:22:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenAL
[2009.08.25 19:41:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenXML-ODF Translator
[2010.11.05 18:53:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Pando Networks
[2011.05.26 17:17:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\pdf24
[2010.12.11 21:08:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime
[2006.11.02 17:06:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
[2011.02.13 11:42:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Samsung
[2009.08.22 09:04:39 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Skype
[2009.09.16 15:58:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SlySoft
[2010.06.26 09:56:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SMPlayer
[2009.08.25 17:17:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SoftMaker Office 2006 (Trial)
[2010.07.16 13:17:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Software Informer
[2011.06.03 10:52:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Steam
[2011.01.25 15:34:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\StefansFreedive
[2009.09.10 16:19:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SystemRequirementsLab
[2011.05.30 23:04:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Trend Micro
[2011.02.15 23:27:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\UltraISO
[2006.11.02 17:33:57 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Uninstall Information
[2010.04.20 09:47:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\USB Vibration Joystick
[2009.08.01 11:33:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Calendar
[2009.07.31 20:08:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
[2011.05.30 08:31:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows iLivid Toolbar
[2010.12.16 14:05:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
[2010.10.20 18:36:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
[2006.11.02 17:06:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
[2009.08.01 11:33:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Gallery
[2009.11.01 11:49:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
[2009.08.01 11:33:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar
[2009.08.01 11:42:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WinRAR
[2011.05.21 18:31:42 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Xfire
[2011.05.21 18:32:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\XfireXO
< %LOCALAPPDATA%\*.exe >
< %systemroot%\*. /mp /s >
< MD5 for: EXPLORER.EXE >
[2006.11.02 13:15:52 | 003,086,848 | ---- | M] (Microsoft Corporation) MD5=5D768BEB711FF67ADC8FAD4E2F6ABB02 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_ab9c809a352ecf21\explorer.exe
[2009.04.11 00:10:18 | 003,079,168 | ---- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 -- C:\Windows\ERDNT\cache86\explorer.exe
[2009.04.11 00:10:18 | 003,079,168 | ---- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 -- C:\Windows\explorer.exe
[2009.04.11 00:10:18 | 003,079,168 | ---- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_afbebba22f3bab41\explorer.exe
[2009.04.10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\SysWOW64\explorer.exe
[2009.04.10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_ba1365f4639c6d3c\explorer.exe
[2008.01.19 00:00:16 | 003,080,704 | ---- | M] (Microsoft Corporation) MD5=F6D765FB6B457542D954682F50C26E4F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_add342963219dff5\explorer.exe
[2006.11.02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_b5f12aec698f911c\explorer.exe
[2008.01.18 23:33:12 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_b827ece8667aa1f0\explorer.exe
< MD5 for: REGEDIT.EXE >
[2006.11.02 13:16:04 | 000,161,792 | ---- | M] (Microsoft Corporation) MD5=272D4789B7BAAEDDE73E85A380A670DD -- C:\Windows\winsxs\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.0.6000.16386_none_4e168eec974b06f9\regedit.exe
[2008.01.19 00:00:32 | 000,161,792 | ---- | M] (Microsoft Corporation) MD5=467A3B03E924B7B7EDD16D34740574B0 -- C:\Windows\regedit.exe
[2008.01.18 23:33:26 | 000,134,656 | ---- | M] (Microsoft Corporation) MD5=467A3B03E924B7B7EDD16D34740574B0 -- C:\Windows\SysWOW64\regedit.exe
[2008.01.18 23:33:26 | 000,134,656 | ---- | M] (Microsoft Corporation) MD5=467A3B03E924B7B7EDD16D34740574B0 -- C:\Windows\winsxs\wow64_microsoft-windows-registry-editor_31bf3856ad364e35_6.0.6001.18000_none_5aa1fb3ac896d9c8\regedit.exe
[2008.01.19 00:00:32 | 000,161,792 | ---- | M] (Microsoft Corporation) MD5=5DFBCE56E689D90AE9E2FB278F80058E -- C:\Windows\ERDNT\cache86\regedit.exe
[2008.01.19 00:00:32 | 000,161,792 | ---- | M] (Microsoft Corporation) MD5=5DFBCE56E689D90AE9E2FB278F80058E -- C:\Windows\winsxs\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.0.6001.18000_none_504d50e8943617cd\regedit.exe
[2006.11.02 11:45:35 | 000,134,656 | ---- | M] (Microsoft Corporation) MD5=F13123E76FDA33E55F11E0EB832E832A -- C:\Windows\winsxs\wow64_microsoft-windows-registry-editor_31bf3856ad364e35_6.0.6000.16386_none_586b393ecbabc8f4\regedit.exe
< MD5 for: USERINIT.EXE >
[2008.01.18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\ERDNT\cache86\userinit.exe
[2008.01.18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008.01.18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
[2006.11.02 13:16:15 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=46D5B6B80E4A5997F508F938F96B7628 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_3610939d8d22586d\userinit.exe
[2008.01.19 00:00:42 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\ERDNT\cache64\userinit.exe
[2008.01.19 00:00:42 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008.01.19 00:00:42 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
< MD5 for: WININIT.EXE >
[2008.01.18 23:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\ERDNT\cache86\wininit.exe
[2008.01.18 23:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008.01.18 23:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.19 00:00:46 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\ERDNT\cache64\wininit.exe
[2008.01.19 00:00:46 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\SysNative\wininit.exe
[2008.01.19 00:00:46 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
[2006.11.02 13:16:20 | 000,122,368 | ---- | M] (Microsoft Corporation) MD5=6F92CE5B50283B0C0A7A539ED552039A -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_8ada9256bfc30704\wininit.exe
[2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
< MD5 for: WINLOGON.EXE >
[2009.04.11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\ERDNT\cache64\winlogon.exe
[2009.04.11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009.04.11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008.01.19 00:00:46 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 13:16:20 | 000,397,312 | ---- | M] (Microsoft Corporation) MD5=9642EED809219A2F914DD8E40A09C48B -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_c9aada9e9063dc57\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.18 23:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 512 bytes -> C:\ProgramData\TEMP:05EE1EEF
< End of report > --- --- --- |