Alt 15.06.2012, 22:29   #1
Trojan.Downloader in Registry Key - Standard

Trojan.Downloader in Registry Key


auf meinem Rechner sind 5 infizierte Registrierungsschlüssel und eine infizierte Datei.
Ich habe es durch das Programm Malwarebytes Anti-Malware gefunden.
Bei der infizierten Datei habe ich den Inhalt in Quarantäne verschoben mittels Avira.
Nun benötige ich eure Hilfe, denn ich weiß nicht wie ich diese Viren entfernen kann.

Hier der Log
Malwarebytes Anti-Malware

Datenbank Version: v2012.06.14.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Tuan :: TUAN-PC [Administrator]

Schutz: Aktiviert

15.06.2012 21:35:47
mbam-log-2012-06-15 (21-45-01).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 253017
Laufzeit: 7 Minute(n), 19 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 5
HKCR\CLSID\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKCR\gencrawler_gc.GenCrawler (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Tuan\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.dll (Trojan.Downloader) -> Keine Aktion durchgeführt.


Alt 18.06.2012, 13:32   #2
/// Winkelfunktion
/// TB-Süch-Tiger™
Trojan.Downloader in Registry Key - Standard

Trojan.Downloader in Registry Key

Bitte erstmal routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

 hier steht das Log


Alt 20.06.2012, 12:21   #3
Trojan.Downloader in Registry Key - Standard

Trojan.Downloader in Registry Key

so geschafft
Malwarebytes Anti-Malware

Datenbank Version: v2012.06.14.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Tuan :: TUAN-PC [Administrator]

Schutz: Aktiviert

19.06.2012 20:38:37
mbam-log-2012-06-19 (23-12-27).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 487834
Laufzeit: 2 Stunde(n), 33 Minute(n), 33 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 3
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)


ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=1593b593cd52b846be5f07e71428a7f5
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-06-19 10:11:31
# local_time=2012-06-20 12:11:31 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 21528916 21528916 0 0
# compatibility_mode=4096 16777215 100 0 0 0 0 0
# compatibility_mode=5892 16776573 100 100 20831 177673409 0 0
# compatibility_mode=8192 67108863 100 0 99 99 0 0
# scanned=55294
# found=0
# cleaned=0
# scan_time=3209
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=1593b593cd52b846be5f07e71428a7f5
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-06-20 11:18:31
# local_time=2012-06-20 01:18:31 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 21568124 21568124 0 0
# compatibility_mode=4096 16777215 100 0 0 0 0 0
# compatibility_mode=5892 16776573 100 100 60039 177712617 0 0
# compatibility_mode=8192 67108863 100 0 39307 39307 0 0
# scanned=245034
# found=0

Alt 20.06.2012, 12:30   #4
/// Winkelfunktion
/// TB-Süch-Tiger™
Trojan.Downloader in Registry Key - Standard

Trojan.Downloader in Registry Key

Datenbank Version: v2012.06.14.07
Du hast Malwarebytes vorher nicht aktualisiert. Bitte updaten und einen neuen Vollscan machen.
Logfiles bitte immer in CODE-Tags posten

Alt 20.06.2012, 19:43   #5
Trojan.Downloader in Registry Key - Standard

Trojan.Downloader in Registry Key

und nochmal das Ganze ^^

Malwarebytes Anti-Malware

Datenbank Version: v2012.06.20.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Tuan :: TUAN-PC [Administrator]

Schutz: Aktiviert

20.06.2012 18:18:57
mbam-log-2012-06-20 (20-39-47).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 486545
Laufzeit: 2 Stunde(n), 20 Minute(n), 43 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 3
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)


Alt 21.06.2012, 10:20   #6
/// Winkelfunktion
/// TB-Süch-Tiger™
Trojan.Downloader in Registry Key - Standard

Trojan.Downloader in Registry Key


Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!
--> Trojan.Downloader in Registry Key

Alt 21.06.2012, 13:16   #7
Trojan.Downloader in Registry Key - Standard

Trojan.Downloader in Registry Key

ich stelle mich gerade total dämlich an
wie schicke ich diese Funde in die Quarantäne?

EDIT: habe es geschafft

Alt 21.06.2012, 14:59   #8
/// Winkelfunktion
/// TB-Süch-Tiger™
Trojan.Downloader in Registry Key - Standard

Trojan.Downloader in Registry Key

Log dazu bitte posten
Logfiles bitte immer in CODE-Tags posten

Alt 21.06.2012, 22:22   #9
Trojan.Downloader in Registry Key - Standard

Trojan.Downloader in Registry Key

Habe die Funde durch Quick-Scan in Quarantäne verschoben, aber sicherlich willst du einen vollständigen Scan. Also habe ich mir mal die Mühe gemacht.
Malwarebytes Anti-Malware

Datenbank Version: v2012.06.20.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Tuan :: TUAN-PC [Administrator]

Schutz: Aktiviert

21.06.2012 20:49:37
mbam-log-2012-06-21 (20-49-37).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 486323
Laufzeit: 2 Stunde(n), 16 Minute(n), 6 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)


Alt 22.06.2012, 09:57   #10
/// Winkelfunktion
/// TB-Süch-Tiger™
Trojan.Downloader in Registry Key - Standard

Trojan.Downloader in Registry Key

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

 hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die OTL.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Kopiere nun den kompletten Inhalt aus der untenstehenden Codebox in die Textbox von OTL - wenn OTL auf deutsch ist wird sie mit beschriftet
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.exe /s
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Klick auf .
  • Kopiere nun den Inhalt aus OTL.txt hier in Deinen Thread
Logfiles bitte immer in CODE-Tags posten

Alt 22.06.2012, 18:08   #11
Trojan.Downloader in Registry Key - Standard

Trojan.Downloader in Registry Key


OTL Logfile:
OTL logfile created on: 22.06.2012 18:39:56 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\Tuan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 1,90 Gb Available Physical Memory | 63,32% Memory free
6,21 Gb Paging File | 4,76 Gb Available in Paging File | 76,76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 583,02 Gb Total Space | 310,66 Gb Free Space | 53,28% Space Free | Partition Type: NTFS
Drive D: | 13,15 Gb Total Space | 1,82 Gb Free Space | 13,85% Space Free | Partition Type: NTFS
Computer Name: TUAN-PC | User Name: Tuan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.06.22 18:37:50 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Tuan\Desktop\OTL.exe
PRC - [2012.05.08 16:01:33 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.08 16:01:24 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.05.08 16:01:23 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.08 16:01:22 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.04.06 04:16:24 | 000,451,072 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2012.04.06 04:15:50 | 000,217,600 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2012.04.05 21:56:18 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2009.07.24 15:05:24 | 000,139,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2009.06.26 17:21:00 | 000,757,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\vVX3000.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.02.23 15:05:34 | 000,111,856 | ---- | M] (Yahoo! Inc) -- C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
PRC - [2008.11.09 22:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008.05.02 02:44:08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2008.05.02 02:40:56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2007.04.18 17:01:34 | 000,065,536 | ---- | M] (Hewlett-Packard Company) -- C:\hp\support\hpsysdrv.exe
========== Modules (No Company Name) ==========
MOD - [2012.06.17 13:29:41 | 000,240,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\9104e78d8897df008eed3a2af3bda6a2\WindowsFormsIntegration.ni.dll
MOD - [2012.06.15 22:12:01 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012.06.15 15:18:28 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012.06.15 15:18:18 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012.06.15 15:18:01 | 014,329,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7343fbab1ba137db2f8b284047ef3f3c\PresentationFramework.ni.dll
MOD - [2012.06.15 15:16:08 | 012,219,392 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b6293b0c23321c255c2530aea8e32bb\PresentationCore.ni.dll
MOD - [2012.05.13 17:00:35 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\5fd0071c259b92078ced7cd752a14730\UIAutomationProvider.ni.dll
MOD - [2012.05.13 16:58:25 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012.05.13 16:57:47 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012.05.11 18:45:08 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012.05.11 18:44:08 | 002,295,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\0f2b877ed16daa577f95be735a63d19c\System.Core.ni.dll
MOD - [2012.05.11 18:44:02 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c8c3ab08933fef9fb6657da871395c46\PresentationFramework.Aero.ni.dll
MOD - [2012.05.11 18:43:26 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\54426ee1881b42af5b090e223f43823c\WindowsBase.ni.dll
MOD - [2012.05.11 18:43:21 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012.05.11 18:42:40 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2012.04.06 03:09:10 | 000,037,376 | ---- | M] () -- C:\Windows\System32\atitmpxx.dll
MOD - [2012.04.05 22:00:20 | 000,369,152 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2012.04.05 21:56:24 | 000,095,232 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
MOD - [2011.07.29 01:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2011.06.24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.05.28 22:04:56 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2009.03.30 06:42:12 | 000,434,176 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\\System.Windows.Forms.resources.dll
MOD - [2009.03.30 06:42:12 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\\System.resources.dll
MOD - [2009.03.30 06:42:11 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\\mscorlib.resources.dll
MOD - [2009.02.25 03:16:56 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\\PresentationFramework.resources.dll
MOD - [2009.02.25 03:16:56 | 000,110,592 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationCore.resources\\PresentationCore.resources.dll
MOD - [2009.02.25 03:16:56 | 000,090,112 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\WindowsBase.resources\\WindowsBase.resources.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\G DATA InternetSecurity TotalCare\AVKTuner\AVKTunerService.exe -- (AVK Tuner Service)
SRV - [2012.06.18 13:50:45 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.06.15 15:18:24 | 000,257,224 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.05.08 16:01:33 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.08 16:01:23 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.04.06 04:15:50 | 000,217,600 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2012.04.05 21:56:18 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.04.02 19:44:32 | 000,489,256 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2009.07.24 15:05:24 | 000,139,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2008.11.09 22:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008.05.02 02:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2008.02.03 13:00:00 | 000,129,992 | ---- | M] (EasyBits Sofware AS) [Auto | Running] -- C:\Windows\System32\ezsvc7.dll -- (ezSharedSvc)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT)
DRV - [2012.05.08 16:01:35 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.08 16:01:35 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.04.06 07:21:10 | 009,334,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2012.04.06 07:21:10 | 009,334,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2012.04.06 03:10:22 | 000,275,968 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.03.05 16:04:30 | 000,045,184 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\aoddriver2.sys -- (AODDriver4.1)
DRV - [2012.03.05 16:04:30 | 000,045,184 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\aoddriver2.sys -- (AODDriver4.01)
DRV - [2012.02.23 14:31:36 | 000,083,984 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdLH3.sys -- (AtiHDAudioService)
DRV - [2011.10.11 15:00:01 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.02.18 09:18:22 | 000,037,944 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\amdiox86.sys -- (amdiox86)
DRV - [2010.02.02 23:39:43 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\seehcri.sys -- (seehcri)
DRV - [2010.02.02 23:39:42 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2010.02.02 23:39:42 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt)
DRV - [2009.10.08 19:08:47 | 000,271,360 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2009.10.08 19:08:36 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2009.06.26 17:21:02 | 001,956,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VX3000.sys -- (VX3000)
DRV - [2008.06.11 22:32:34 | 000,061,424 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\HP\DVDPlay\000.fcl -- ({22D78859-9CE9-4B77-BF18-AC83E81A9263})
DRV - [2008.06.06 21:13:40 | 000,145,440 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32)
DRV - [2008.06.06 21:13:40 | 000,133,152 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvrd32.sys -- (nvrd32)
DRV - [2008.05.22 11:39:34 | 000,015,360 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008.05.21 13:44:10 | 001,049,760 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2008.02.29 03:13:36 | 000,079,120 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2008.02.29 03:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2008.02.29 03:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2008.02.29 03:12:56 | 000,063,120 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042mou.Sys -- (L8042mou)
DRV - [2007.01.23 16:44:00 | 000,020,496 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2005.12.12 19:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PS2.sys -- (Ps2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{879950C1-3353-486B-893E-6E23EE9D5329}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
IE - HKLM\..\SearchScopes\{C0057537-1C1F-405C-B6EB-050826BA3A2A}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com/?p=us
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&AF=109130&tt=261211_ctrl&babsrc=SP_ss&mntrId=5e90e91800000000000000ff9250e086
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.de/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_de
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{879950C1-3353-486B-893E-6E23EE9D5329}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{C0057537-1C1F-405C-B6EB-050826BA3A2A}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-rog
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "MyAshampoo Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://de.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: battlefieldheroespatcher@ea.com:
FF - prefs.js..extensions.enabledItems: battlefieldplay4free@ea.com:
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: screencaptureelite@plugin:
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.2
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..keyword.URL: "hxxp://search.babylon.com/?AF=109130&tt=261211_ctrl&babsrc=adbartrp&mntrId=5e90e91800000000000000ff9250e086&q="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_257.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=0.80.0: C:\Program Files\Battlelog Web Plugins\0.80.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version= C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.7.1: C:\Users\Tuan\AppData\Local\Yahoo!\BrowserPlus\2.7.1\Plugins\npybrowserplus_2.7.1.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.12.18 15:14:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.18 13:50:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.16 17:20:30 | 000,000,000 | ---D | M]
[2010.07.13 16:07:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tuan\AppData\Roaming\mozilla\Extensions
[2012.06.13 15:56:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions
[2011.02.13 21:54:47 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.16 19:05:44 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.05.19 17:27:51 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012.06.13 15:56:59 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\battlefieldheroespatcher@ea.com
[2011.11.08 18:41:31 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\battlefieldplay4free@ea.com
[2012.05.24 18:42:05 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\ich@maltegoetz.de
[2011.03.18 17:31:45 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\personas@christopher.beard
[2011.12.30 18:25:13 | 000,000,000 | ---D | M] (Screen Capture Elite) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\screencaptureelite@plugin
[2011.03.24 13:03:00 | 000,000,923 | ---- | M] () -- C:\Users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\searchplugins\conduit.xml
[2011.10.29 16:23:12 | 000,003,915 | ---- | M] () -- C:\Users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\searchplugins\sweetim.xml
[2012.05.02 18:01:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.12.18 15:14:16 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2012.01.29 17:47:23 | 000,634,964 | ---- | M] () (No name found) -- C:\USERS\TUAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\W97YN8XT.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2009.06.24 14:37:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012.06.18 13:50:46 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.04.01 17:31:59 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012.06.18 13:50:42 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.12.29 15:53:47 | 000,002,351 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012.06.18 13:50:42 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.18 13:50:42 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.18 13:50:42 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.18 13:50:42 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.18 13:50:42 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2012.01.24 23:56:19 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts:       localhost
O2 - BHO: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - No CLSID value found.
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) -  - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - No CLSID value found.
O3 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKU\S-1-5-21-449065279-793341504-1815772316-1000..\Run: [Media Finder] "C:\Program Files\Media Finder\Media Finder.exe" /opentotray File not found
O4 - HKU\S-1-5-21-449065279-793341504-1815772316-1000..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe File not found
O4 - HKU\S-1-5-21-449065279-793341504-1815772316-1000..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to iPhone Converter - C:\Users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoiphoneconverter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Save YouTube Video - Reg Error: Value error. File not found
O8 - Extra context menu item: Save YouTube Video as MP3 - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..Trusted Ranges: Range2 ([*] in Lokales Intranet)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.31.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.27.2.cab (Battlefield Play4Free Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{68FF45E2-D6D8-4607-9E46-7D06E815F2D9}: DhcpNameServer =
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Tuan\Pictures\Bilder - Vietnam\fotolia_32611031_subscription_xl.jpg
O24 - Desktop BackupWallPaper: C:\Users\Tuan\Pictures\Bilder - Vietnam\fotolia_32611031_subscription_xl.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.10.27 17:51:08 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
NetSvcs: ezSharedSvc - C:\Windows\System32\ezsvc7.dll (EasyBits Sofware AS)
MsConfig - StartUpFolder: C:^Users^Tuan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe - ()
MsConfig - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MsConfig - StartUpReg: VirtualCloneDrive - hkey= - key= - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0
SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - 
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - 
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\System32\lhacm.acm (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012.06.22 18:37:49 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Tuan\Desktop\OTL.exe
[2012.06.22 16:04:59 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{11D8809E-9691-4963-BADB-4E5CF4616FEE}
[2012.06.22 16:04:27 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{676D2760-CE16-4F5C-B7C2-CA68D309DBEC}
[2012.06.21 14:00:12 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{04C6060E-4AA8-4C88-8E1B-827501C0824A}
[2012.06.21 13:59:44 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{602BC025-9956-42CF-9D59-BCB6E1CED67C}
[2012.06.20 09:59:04 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{C1EF38C1-416C-4844-8DEB-36EDE56809DB}
[2012.06.20 09:58:54 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{629806D2-B1DD-49BC-AF31-E906D34B3C03}
[2012.06.20 09:57:01 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{4326AE52-BCE3-4590-B9C6-74789DDCCE76}
[2012.06.20 09:56:22 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{19C742B3-19CE-4178-B059-E0708267510C}
[2012.06.19 23:16:22 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.06.19 17:19:15 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{2FF460C1-5330-47ED-BB49-2A8B2A65A323}
[2012.06.19 17:18:49 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{A8BE6743-DF47-4B30-95BE-0B46CC53BA76}
[2012.06.18 13:06:45 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{A53F91B2-D669-4AD3-8FCD-32189F9EA9BF}
[2012.06.17 13:19:21 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{9CB88282-9BF4-41F6-B79C-DCF941D7EF5A}
[2012.06.16 15:17:42 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{951DFB62-ABC5-4807-8965-4EEF6741E7FB}
[2012.06.15 18:10:35 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\Macromedia
[2012.06.15 14:47:27 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{C11F68A2-E72E-4CA1-BD20-DA1628B143DB}
[2012.06.14 15:51:59 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{227DAF5C-8B85-462A-B235-1AB41F308B70}
[2012.06.14 15:51:48 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{0EC1874F-3F88-468C-9EEC-E95D71CADA72}
[2012.06.13 15:29:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012.06.13 15:27:26 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012.06.13 15:27:20 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012.06.13 15:09:26 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{E4CBA780-7DFA-4A3E-BD97-FF9BFF825DD1}
[2012.06.13 15:09:10 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{96C92AAB-FF5B-4E5A-B7AE-3BFEB66889BB}
[2012.06.12 14:32:33 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{59B7EBF6-5D77-4DF8-85A6-E354F807EA53}
[2012.06.12 14:32:15 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{F86B784C-B4B0-4441-9036-A094BD93CF6A}
[2012.06.11 14:14:14 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{D43C751B-8152-4CFB-856A-347623986437}
[2012.06.11 14:14:04 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{0672FFD9-669E-4705-AF2C-1DC9F5A06C5C}
[2012.06.10 17:00:10 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\Ubisoft Game Launcher
[2012.06.10 15:04:21 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{95F5C849-C0F9-464D-9D38-9E8F4AB04A44}
[2012.06.10 15:04:11 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{A0486032-12BA-4030-AABF-6E196D1F6027}
[2012.06.10 15:03:20 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{2EF6181B-F4A5-40C8-A3F6-26A2A5978AEC}
[2012.06.10 15:03:07 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{F8122837-E91D-4E33-BFA7-87F0BDD161FE}
[2012.06.08 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{3C8C2B42-5AA4-447E-8F4B-FF5BA78F2A3A}
[2012.06.08 14:54:03 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{0E6513F3-A8A4-49B4-BE8D-1D4CE4EB3D73}
[2012.06.07 13:53:52 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{F815CABD-9229-4CF1-BB0C-BC293CFFC4E7}
[2012.06.07 13:53:40 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{2C5A9D6C-B0F6-4C72-A6D5-B326CB01EA04}
[2012.06.07 13:53:04 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{64EB8058-BB79-4EEF-9070-6166A53D92C3}
[2012.06.06 15:11:23 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{463FDC6B-C84A-4145-9FCB-1470741B0E34}
[2012.06.06 15:11:08 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{CC906567-80FE-4CF6-8372-01F61041773B}
[2012.06.05 18:54:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
[2012.06.05 18:54:23 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Roaming\pdfforge
[2012.06.05 18:54:19 | 000,079,360 | ---- | C] (pdfforge GbR) -- C:\Windows\System32\pdfcmon.dll
[2012.06.05 18:54:17 | 000,000,000 | ---D | C] -- C:\Program Files\PDFCreator
[2012.06.05 17:47:18 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{F8B76F58-66C7-408A-8011-F111D812B869}
[2012.06.05 17:46:08 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{F96724CB-55DA-4F4B-B16B-DDEC5AF7AF07}
[2012.06.03 14:23:21 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{A9700C93-2802-4A3E-A111-23D4AF778A6C}
[2012.06.03 14:23:11 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{E2F9609D-6AB8-44C8-9549-2BB72A0EB964}
[2012.06.03 14:21:22 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{00591358-77C0-44C3-867D-CB35CAB3517D}
[2012.06.03 14:21:08 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{D64B1FC5-0E7A-4C27-B468-96D6A30A3E45}
[2012.06.02 14:54:50 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{5949A055-418A-4771-A64A-524D91B5C3BD}
[2012.06.02 14:54:40 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{66BEB0F0-7061-41B6-BFAF-B2816BAD9A3D}
[2012.06.01 20:11:35 | 002,557,952 | ---- | C] (Nokia Corporation and/or its subsidiary(-ies)) -- C:\Windows\System32\QtCore4.dll
[2012.06.01 20:11:33 | 000,405,176 | ---- | C] (Newtonsoft) -- C:\Windows\System32\Newtonsoft.Json.Net20.dll
[2012.06.01 16:17:37 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{564D78B3-C966-4629-9118-5C8CBE911378}
[2012.06.01 16:17:27 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{8175111A-135F-4A46-AD89-C093B71ACEB9}
[2012.06.01 16:13:31 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{D29C3E40-BCAF-4BAA-8967-AB453A1373A4}
[2012.05.31 14:47:27 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{17781506-E67D-4093-9374-E731701E85F7}
[2012.05.31 14:46:58 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{B4448378-CE32-4EE6-A685-098D2FF9087F}
[2012.05.30 13:53:53 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{332B615F-4970-47CE-AAE7-A6E9A87180FC}
[2012.05.30 13:53:43 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{2DDE9AEB-7248-4C97-B659-A38F402EF2EA}
[2012.05.29 19:04:19 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Roaming\redsn0w
[2012.05.29 15:43:08 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{0D31CC38-7402-4E4D-8D0B-37AD8B42DC14}
[2012.05.29 15:42:48 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{717E5F3E-BAFC-4AD6-9FD1-0FBC3A0CDF46}
[2012.05.29 15:41:21 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{D8FDE98E-D7BE-4319-93E1-D13D0F9A548B}
[2012.05.28 14:56:14 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{036024E5-8C55-4BFB-B14D-6ACE3A0DA12C}
[2012.05.28 14:56:04 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{14011417-E7C4-4E67-A9FC-AD01B1C25678}
[2012.05.28 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{D0997A7B-C99D-4D5A-8019-04F94F5EC1AD}
[2012.05.27 13:37:37 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{2E40EF69-C3AD-4B6D-80D7-C361BEAA80D6}
[2012.05.27 13:37:26 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{5C5B9595-BA96-4584-8E9D-CC685C27D250}
[2012.05.25 15:36:00 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{E371F7FD-0D93-442A-B211-2B851D9F8F5E}
[2012.05.25 15:35:48 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{E492BBF1-1CAF-489B-9005-07E525A1D34B}
[2012.05.24 18:34:47 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{A369DB24-FC4D-4196-8FD4-706EB24D6A43}
[2012.05.24 18:34:31 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{5ACA2ACD-C8F4-4312-B33C-021EC1F56757}
========== Files - Modified Within 30 Days ==========
[2012.06.22 18:40:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.06.22 18:37:50 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Tuan\Desktop\OTL.exe
[2012.06.22 18:33:39 | 000,014,893 | ---- | M] () -- C:\Users\Tuan\Desktop\Lebenslauf.odt
[2012.06.22 18:13:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.22 18:03:49 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.22 18:03:49 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.22 16:03:57 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.06.22 16:03:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.21 14:07:53 | 000,021,459 | ---- | M] () -- C:\Users\Tuan\Desktop\TU Berlin.odt
[2012.06.20 21:24:32 | 000,671,212 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.06.20 21:24:32 | 000,631,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.06.20 21:24:32 | 000,144,380 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.06.20 21:24:32 | 000,118,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.06.20 13:44:54 | 000,139,048 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012.06.20 13:44:43 | 000,282,296 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2012.06.20 13:42:58 | 000,280,736 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2012.06.15 21:29:20 | 000,041,984 | ---- | M] () -- C:\Users\Tuan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.06.15 15:13:28 | 000,354,248 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.06.13 15:29:03 | 000,001,626 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.06.05 18:54:26 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\PDFArchitect.lnk
[2012.06.05 18:54:26 | 000,000,790 | ---- | M] () -- C:\Users\Public\Desktop\PDFCreator.lnk
[2012.05.29 19:20:05 | 000,000,318 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForTuan.job
========== Files Created - No Company Name ==========
[2012.06.21 00:30:30 | 000,014,893 | ---- | C] () -- C:\Users\Tuan\Desktop\Lebenslauf.odt
[2012.06.20 21:26:43 | 000,021,459 | ---- | C] () -- C:\Users\Tuan\Desktop\TU Berlin.odt
[2012.06.13 15:29:03 | 000,001,626 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.06.05 18:54:26 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\PDFArchitect.lnk
[2012.06.05 18:54:26 | 000,000,790 | ---- | C] () -- C:\Users\Public\Desktop\PDFCreator.lnk
[2012.04.13 18:47:51 | 000,000,023 | ---- | C] () -- C:\Windows\clofghls.dll
[2012.04.05 22:34:22 | 000,159,232 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2012.02.24 15:02:07 | 000,000,680 | ---- | C] () -- C:\Users\Tuan\AppData\Local\d3d9caps.dat
[2012.01.24 20:02:15 | 000,000,000 | ---- | C] () -- C:\Users\Tuan\defogger_reenable
[2012.01.24 00:29:17 | 000,041,984 | ---- | C] () -- C:\Users\Tuan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.10 23:10:08 | 000,601,728 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2011.10.25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\System32\OVDecoder.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2011.07.03 15:49:14 | 000,001,449 | ---- | C] () -- C:\Windows\wininit.ini
[2011.07.03 15:48:24 | 000,040,960 | ---- | C] () -- C:\Windows\RAUNINST.EXE
[2011.06.28 18:57:29 | 000,000,000 | ---- | C] () -- C:\Windows\System32\Access.dat
[2011.06.09 14:53:22 | 000,002,146 | ---- | C] () -- C:\Users\Tuan\.recently-used.xbel
[2011.06.03 17:01:06 | 000,000,479 | ---- | C] () -- C:\Windows\eReg.dat
[2010.10.19 18:18:44 | 002,434,856 | ---- | C] () -- C:\Windows\System32\pbsvc_bc2.exe
[2010.09.17 12:05:07 | 000,037,376 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2010.07.13 16:07:33 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009.06.21 20:24:31 | 000,023,888 | ---- | C] () -- C:\Users\Tuan\AppData\Roaming\UserTile.png
[2009.05.18 15:12:39 | 000,000,760 | ---- | C] () -- C:\Users\Tuan\AppData\Roaming\setup_ldm.iss
[2009.04.01 21:25:09 | 000,000,000 | ---- | C] () -- C:\Users\Tuan\AppData\Roaming\wklnhst.dat
[2009.04.01 17:24:34 | 000,139,152 | ---- | C] () -- C:\Users\Tuan\AppData\Roaming\PnkBstrK.sys
========== LOP Check ==========
[2011.05.14 16:14:34 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Ashampoo
[2011.07.03 20:35:32 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DisneyInteractiveStudios
[2012.06.20 10:01:58 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DVDVideoSoft
[2011.02.13 21:54:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.08.06 19:05:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\GetRightToGo
[2011.03.12 14:22:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\GrabPro
[2011.05.24 18:08:51 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\gtk-2.0
[2010.09.26 17:42:30 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Image Zone Express
[2011.06.25 17:14:48 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Leadertech
[2011.12.29 16:21:14 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\LucasArts
[2010.02.10 21:39:19 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\muvee Technologies
[2010.12.08 23:50:31 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\OpenOffice.org
[2012.05.16 19:05:37 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Orbit
[2011.12.21 16:20:24 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Origin
[2012.06.05 19:04:45 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\pdfforge
[2009.06.21 20:24:31 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\PeerNetworking
[2010.09.26 17:42:30 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Printer Info Cache
[2010.11.01 20:25:49 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\ProgSense
[2012.06.01 20:33:09 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\redsn0w
[2011.12.23 23:49:14 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Syke
[2009.04.01 21:25:11 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Template
[2011.02.23 18:33:09 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\The Creative Assembly
[2012.06.10 16:59:11 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Ubisoft
[2010.10.02 15:59:36 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\WinBatch
[2012.04.13 18:04:24 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Windows Live Writer
[2009.09.28 13:59:51 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Zoner
[2012.06.21 23:23:45 | 000,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.12.04 22:53:12 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Adobe
[2011.11.19 21:07:10 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Apple Computer
[2011.05.14 16:14:34 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Ashampoo
[2009.03.23 18:38:41 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\ATI
[2011.10.14 19:03:36 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Avira
[2009.04.12 20:09:14 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\CyberLink
[2011.07.03 20:35:32 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DisneyInteractiveStudios
[2010.04.26 15:32:57 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DivX
[2012.06.20 10:01:58 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DVDVideoSoft
[2011.02.13 21:54:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.08.06 19:05:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\GetRightToGo
[2009.03.27 21:59:26 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Google
[2011.03.12 14:22:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\GrabPro
[2011.05.24 18:08:51 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\gtk-2.0
[2010.11.18 22:04:54 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Help
[2009.03.23 18:38:55 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Hewlett-Packard
[2010.09.25 22:12:16 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\HP
[2011.03.25 18:10:04 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\HpUpdate
[2009.03.23 18:38:10 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Identities
[2010.09.26 17:42:30 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Image Zone Express
[2009.04.04 20:49:56 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\InstallShield
[2011.06.25 17:14:48 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Leadertech
[2009.03.23 19:42:52 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Logitech
[2011.12.29 16:21:14 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\LucasArts
[2009.03.23 18:34:35 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Macromedia
[2012.01.23 22:39:20 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Malwarebytes
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Media Center Programs
[2011.04.11 21:16:39 | 000,000,000 | --SD | M] -- C:\Users\Tuan\AppData\Roaming\Microsoft
[2010.07.13 16:07:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Mozilla
[2010.02.10 21:39:19 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\muvee Technologies
[2010.12.08 23:50:31 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\OpenOffice.org
[2012.05.16 19:05:37 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Orbit
[2011.12.21 16:20:24 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Origin
[2012.06.05 19:04:45 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\pdfforge
[2009.06.21 20:24:31 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\PeerNetworking
[2010.09.26 17:42:30 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Printer Info Cache
[2010.11.01 20:25:49 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\ProgSense
[2012.06.01 20:33:09 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\redsn0w
[2010.10.19 18:40:38 | 000,000,000 | RH-D | M] -- C:\Users\Tuan\AppData\Roaming\SecuROM
