Mich hat's auch erwischt - AKM Virus hallo liebe board-mitglieder!
habe seit gestern auch diesen virus (akm, 50 euro, weiß, vollbild, sperrt vieles,...) und auch mit diesem windows pe die OTL.txt erstellen lassen... ich würde mich sehr über hilfe freuen :)
wieso macht es uns dieser virus so schwer ihn zu entfernen? die zielgruppe zahlt eh... mein entschluss dagegen steht längst fest: virus entfernen und nicht zahlen!
OTL Logfile: Code:
OTL logfile created on: 5/6/2012 2:22:39 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
64bit-Windows 7 Professional Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\Windows | %ProgramFiles% = D:\Program Files (x86)
Drive C: | 55.90 Gb Total Space | 53.04 Gb Free Space | 94.89% Space Free | Partition Type: NTFS
Drive D: | 111.79 Gb Total Space | 69.86 Gb Free Space | 62.49% Space Free | Partition Type: NTFS
Drive E: | 146.48 Gb Total Space | 10.36 Gb Free Space | 7.07% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 72.86 Gb Free Space | 7.82% Space Free | Partition Type: NTFS
Drive G: | 132.98 Gb Total Space | 21.28 Gb Free Space | 16.01% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand] -- D:\Windows\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012/04/25 12:22:36 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand] -- D:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2012/04/01 15:07:13 | 000,253,600 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- D:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/02/29 03:16:46 | 000,158,856 | R--- | M] (Skype Technologies) [Auto] -- D:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/02/10 00:13:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) [Auto] -- D:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/02/09 15:05:32 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto] -- D:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012/01/28 11:57:36 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand] -- D:\Program Files (x86)\Common Files\Creative Labs Shared\Service\DDLLicensing.exe -- (Creative Dolby Digital Live Pack Licensing Service)
SRV - [2012/01/12 13:25:33 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand] -- D:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto] -- D:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/12/09 09:39:52 | 000,135,584 | ---- | M] (Futuremark Corporation) [On_Demand] -- D:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2010/12/02 05:15:14 | 000,915,584 | ---- | M] () [Auto] -- D:\Program Files (x86)\ASUS\AAHM\1.00.13\aaHMSvc.exe -- (asHmComSvc)
SRV - [2010/11/05 18:54:22 | 000,013,336 | ---- | M] (Intel Corporation) [Auto] -- D:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
SRV - [2010/11/03 12:30:14 | 000,918,144 | ---- | M] () [Auto] -- D:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe -- (asComSvc)
SRV - [2010/10/27 11:18:52 | 000,052,896 | ---- | M] (Atheros Commnucations) [Auto] -- D:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2010/10/21 12:52:26 | 000,586,880 | ---- | M] () [Auto] -- D:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe -- (AsSysCtrlService)
SRV - [2010/03/18 08:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- D:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/02/23 05:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto] -- D:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/03/25 04:26:34 | 000,115,272 | ---- | M] (MotioninJoy) [Kernel | On_Demand] -- D:\Windows\System32\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV:64bit: - [2012/01/30 12:49:18 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System] -- D:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012/01/17 08:45:56 | 000,188,224 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011/12/07 13:42:28 | 000,074,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2010/12/28 15:45:54 | 000,412,776 | ---- | M] (Realtek ) [Kernel | On_Demand] -- D:\Windows\System32\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010/12/08 13:17:40 | 000,369,640 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand] -- D:\Windows\System32\drivers\asmtxhci.sys -- (asmtxhci)
DRV:64bit: - [2010/12/08 13:17:38 | 000,122,856 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand] -- D:\Windows\System32\drivers\asmthub3.sys -- (asmthub3)
DRV:64bit: - [2010/11/22 03:09:06 | 000,303,408 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot] -- D:\Windows\System32\drivers\mv91xx.sys -- (mv91xx)
DRV:64bit: - [2010/11/20 23:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 23:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\system32\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/20 23:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\system32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/10/27 10:50:28 | 000,301,680 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2010/10/27 10:50:28 | 000,279,152 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2010/10/27 10:50:28 | 000,203,624 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2010/10/27 10:50:28 | 000,156,520 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2010/10/27 10:50:28 | 000,058,992 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2010/10/27 10:50:28 | 000,055,336 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand] -- D:\Windows\System32\drivers\AthDfu.sys -- (ATHDFU)
DRV:64bit: - [2010/10/27 10:50:28 | 000,038,248 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2010/10/27 10:50:28 | 000,031,080 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2010/10/19 11:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:64bit: - [2010/08/17 20:28:32 | 000,026,136 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ICCWDT.sys -- (ICCWDT) Intel(R) Watchdog Timer Driver (Intel(R) WDT)
DRV:64bit: - [2010/05/05 16:30:52 | 001,561,688 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ha20x2k.sys -- (ha20x2k)
DRV:64bit: - [2010/05/05 16:30:42 | 000,118,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- D:\Windows\System32\drivers\emupia2k.sys -- (emupia)
DRV:64bit: - [2010/05/05 16:30:34 | 000,213,080 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV:64bit: - [2010/05/05 16:30:26 | 000,015,960 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV:64bit: - [2010/05/05 16:30:18 | 000,179,288 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ctoss2k.sys -- (ossrv)
DRV:64bit: - [2010/05/05 16:30:10 | 000,684,376 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)
DRV:64bit: - [2010/05/05 16:30:02 | 000,580,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ctac32k.sys -- (ctac32k)
DRV:64bit: - [2010/05/05 16:29:52 | 001,417,304 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\CTEXFIFX.SYS -- (CTEXFIFX.SYS)
DRV:64bit: - [2010/05/05 16:29:52 | 001,417,304 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\CTEXFIFX.sys -- (CTEXFIFX)
DRV:64bit: - [2010/05/05 16:29:42 | 000,094,808 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\CTHWIUT.SYS -- (CTHWIUT.SYS)
DRV:64bit: - [2010/05/05 16:29:42 | 000,094,808 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\CTHWIUT.sys -- (CTHWIUT)
DRV:64bit: - [2010/05/05 16:29:34 | 000,202,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\CT20XUT.SYS -- (CT20XUT.SYS)
DRV:64bit: - [2010/05/05 16:29:34 | 000,202,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\CT20XUT.sys -- (CT20XUT)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- D:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a)
DRV - [2010/05/26 20:43:00 | 000,014,648 | ---- | M] () [Kernel | On_Demand] -- D:\Program Files (x86)\MSI Afterburner\RTCore64.sys -- (RTCore64)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\Admin_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\Admin_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\Admin_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\Admin_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FA A7 08 12 F6 02 CD 01 [binary data]
IE - HKU\Admin_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Kathrin_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\Kathrin_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\Kathrin_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 12 1C 76 30 B4 26 CD 01 [binary data]
IE - HKU\Kathrin_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Kirby_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\Kirby_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\Kirby_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F2 FB 14 8C 1B DC CC 01 [binary data]
IE - HKU\Kirby_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Tank_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Tobi_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\Tobi_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\Tobi_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F2 FB 14 8C 1B DC CC 01 [binary data]
IE - HKU\Tobi_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: D:\Windows\System32\Macromed\Flash\NPSWF64_11_1_102.dll ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: D:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: D:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE: File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision: D:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming: D:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: D:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/02/01 08:44:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012/01/26 07:47:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2012/01/29 09:10:44 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Tank\AppData\Roaming\Mozilla\Extensions
File not found (No name found) --
() (No name found) -- D:\USERS\TANK\APPDATA\ROAMING\THUNDERBIRD\PROFILES\8BKCLU23.DEFAULT\EXTENSIONS\TBTESTPILOT@LABS.MOZILLA.COM.XPI
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - D:\Windows\System32\drivers\etc\hosts
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - D:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AthBtTray] D:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AtherosBtStack] D:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [RtHDVCpl] D:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [CTxfiHlp] D:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [IAStorIcon] D:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
O4 - HKLM..\Run: [VX5LWxsct4OYCCz] D:\Users\Admin\AppData\Roaming\itunes_service86.exe ()
O4 - HKU\Admin_ON_D..\Run: [DAEMON Tools Lite] D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\Admin_ON_D..\Run: [VX5LWxsct4OYCCz] D:\Users\Admin\AppData\Roaming\itunes_service86.exe ()
O4 - HKU\Kathrin_ON_D..\Run: [DAEMON Tools Lite] D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\Kirby_ON_D..\Run: [DAEMON Tools Lite] D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\LocalService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\Tobi_ON_D..\Run: [DAEMON Tools Lite] D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\UpdatusUser_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_D..\RunOnce: [mctadmin] File not found
O4 - HKU\NetworkService_ON_D..\RunOnce: [mctadmin] File not found
O4 - HKU\UpdatusUser_ON_D..\RunOnce: [mctadmin] File not found
O4 - Startup: D:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk ()
O4 - Startup: D:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\Admin_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Admin_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKU\Admin_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\Admin_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - D:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - D:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - D:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (C:\Users\Admin\AppData\Roaming\itunes_service86.exe) - D:\Users\Admin\AppData\Roaming\itunes_service86.exe ()
O20 - HKLM Winlogon: UserInit - (C:\Users\Admin\AppData\Roaming\itunes_service86.exe) - D:\Users\Admin\AppData\Roaming\itunes_service86.exe ()
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKU\Admin_ON_D Winlogon: Shell - (C:\Users\Admin\AppData\Roaming\itunes_service86.exe) - D:\Users\Admin\AppData\Roaming\itunes_service86.exe ()
O20 - HKU\Admin_ON_D Winlogon: UserInit - (C:\Users\Admin\AppData\Roaming\itunes_service86.exe) - D:\Users\Admin\AppData\Roaming\itunes_service86.exe ()
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
NetSvcs:64bit: AppMgmt - D:\Windows\System32\appmgmts.dll (Microsoft Corporation)
MsConfig:64bit - StartUpReg: ASUS ShellProcess Execute - hkey= - key= - File not found
MsConfig:64bit - State: "startup" - 2
MsConfig:64bit - State: "bootini" - 2
========== Files/Folders - Created Within 30 Days ==========
[2012/05/06 06:58:04 | 000,000,000 | ---D | C] -- D:\Users\Kathrin\AppData\Roaming\HPAppData
[2012/05/06 06:28:56 | 000,000,000 | ---D | C] -- D:\Users\Kathrin\AppData\Roaming\LSoft Technologies
[2012/05/06 06:28:56 | 000,000,000 | ---D | C] -- D:\Users\Kathrin\AppData\Roaming\InstallShield Installation Information
[2012/05/06 06:28:56 | 000,000,000 | ---D | C] -- D:\Users\Kathrin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Active@ ISO Burner
[2012/05/06 06:27:16 | 127,231,689 | ---- | C] (Igor Pavlov) -- D:\Users\Kathrin\Desktop\OTLPENet.exe
[2012/05/05 18:18:18 | 010,063,000 | ---- | C] (Malwarebytes Corporation ) -- D:\Users\Kathrin\Desktop\mbam-setup-1.61.0.1400.exe
[2012/05/05 18:15:02 | 114,806,658 | ---- | C] (Igor Pavlov) -- D:\Users\Kathrin\Desktop\OTLPENet.exe.bqbiep5.partial
[2012/05/05 18:07:52 | 000,000,000 | ---D | C] -- D:\Users\Kathrin\AppData\Roaming\vlc
[2012/05/05 18:01:17 | 000,000,000 | ---D | C] -- D:\_OTL
[2012/05/05 17:59:16 | 000,595,456 | ---- | C] (OldTimer Tools) -- D:\Users\Kathrin\Desktop\OTL.exe
[2012/05/05 17:51:52 | 000,000,000 | ---D | C] -- D:\Users\Kathrin\AppData\Roaming\Trillian
[2012/05/04 13:40:11 | 000,000,000 | ---D | C] -- D:\Users\Admin\AppData\Roaming\HPAppData
[2012/05/02 07:14:35 | 000,000,000 | ---D | C] -- D:\Users\Admin\Desktop\chili
[2012/04/30 16:32:28 | 000,000,000 | ---D | C] -- D:\Users\Admin\Desktop\CrystalDiskMark3_0_1c
[2012/04/28 15:44:50 | 000,000,000 | ---D | C] -- D:\ProgramData\RELOADED
[2012/04/25 12:25:53 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/04/25 12:25:53 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\Skype
[2012/04/25 12:22:19 | 000,102,400 | ---- | C] (Creative Technology Ltd) -- D:\Windows\SysWow64\cttele32.dll
[2012/04/25 10:40:05 | 000,000,000 | ---D | C] -- D:\Users\Admin\Documents\CAPCOM
[2012/04/22 11:08:10 | 000,000,000 | ---D | C] -- D:\Users\Admin\AppData\Roaming\vlc
[2012/04/11 17:03:15 | 000,096,256 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\mshtmled.dll
[2012/04/11 17:03:15 | 000,072,704 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\mshtmled.dll
[2012/04/11 17:03:14 | 002,311,168 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\jscript9.dll
[2012/04/11 17:03:14 | 001,799,168 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\jscript9.dll
[2012/04/11 17:03:14 | 001,493,504 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\inetcpl.cpl
[2012/04/11 17:03:14 | 001,427,456 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\inetcpl.cpl
[2012/04/11 17:03:14 | 000,818,688 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\jscript.dll
[2012/04/11 17:03:14 | 000,716,800 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\jscript.dll
[2012/04/11 17:03:14 | 000,248,320 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\ieui.dll
[2012/04/11 17:03:14 | 000,237,056 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\url.dll
[2012/04/11 17:03:14 | 000,231,936 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\url.dll
[2012/04/11 17:03:14 | 000,176,640 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\ieui.dll
[2012/04/11 17:03:10 | 005,559,152 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\ntoskrnl.exe
[2012/04/11 17:03:09 | 003,968,368 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\ntkrnlpa.exe
[2012/04/11 17:03:09 | 003,913,072 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\ntoskrnl.exe
[2012/04/11 17:02:38 | 000,220,672 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\wintrust.dll
[2012/04/11 17:02:38 | 000,172,544 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\wintrust.dll
[2012/04/11 17:02:38 | 000,159,232 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\imagehlp.dll
[2012/04/11 17:02:38 | 000,081,408 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\imagehlp.dll
[2012/04/11 17:02:38 | 000,023,408 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\drivers\fs_rec.sys
[2010/05/05 14:59:10 | 000,060,928 | ---- | C] ( ) -- D:\Windows\SysWow64\a3d.dll
[2010/05/05 14:38:18 | 000,012,800 | ---- | C] ( ) -- D:\Windows\SysWow64\killapps.exe
========== Files - Modified Within 30 Days ==========
[2012/05/06 08:48:13 | 2129,190,911 | -HS- | M] () -- D:\hiberfil.sys
[2012/05/06 06:58:48 | 000,067,584 | --S- | M] () -- D:\Windows\bootstat.dat
[2012/05/06 06:58:47 | 000,061,256 | ---- | M] () -- D:\Windows\System32\BMXStateBkp-{00000009-00000000-00000002-00001102-00000005-00211102}.rfx
[2012/05/06 06:58:47 | 000,061,256 | ---- | M] () -- D:\Windows\System32\BMXState-{00000009-00000000-00000002-00001102-00000005-00211102}.rfx
[2012/05/06 06:58:47 | 000,000,788 | ---- | M] () -- D:\Windows\System32\DVCState-{00000009-00000000-00000002-00001102-00000005-00211102}.rfx
[2012/05/06 06:56:26 | 000,000,035 | ---- | M] () -- D:\Users\Public\Documents\AtherosServiceConfig.ini
[2012/05/06 06:55:21 | 000,021,504 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/06 06:55:21 | 000,021,504 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/06 06:52:39 | 000,653,928 | ---- | M] () -- D:\Windows\System32\perfh007.dat
[2012/05/06 06:52:39 | 000,615,810 | ---- | M] () -- D:\Windows\System32\perfh009.dat
[2012/05/06 06:52:39 | 000,129,800 | ---- | M] () -- D:\Windows\System32\perfc007.dat
[2012/05/06 06:52:39 | 000,106,190 | ---- | M] () -- D:\Windows\System32\perfc009.dat
[2012/05/06 06:32:53 | 127,231,689 | ---- | M] (Igor Pavlov) -- D:\Users\Kathrin\Desktop\OTLPENet.exe
[2012/05/06 06:13:09 | 000,003,224 | ---- | M] () -- D:\bootsqm.dat
[2012/05/06 06:11:20 | 000,000,884 | ---- | M] () -- D:\Windows\tasks\Adobe Flash Player Updater.job
[2012/05/05 18:24:24 | 114,806,658 | ---- | M] (Igor Pavlov) -- D:\Users\Kathrin\Desktop\OTLPENet.exe.bqbiep5.partial
[2012/05/05 18:18:26 | 010,063,000 | ---- | M] (Malwarebytes Corporation ) -- D:\Users\Kathrin\Desktop\mbam-setup-1.61.0.1400.exe
[2012/05/05 18:02:11 | 000,595,456 | ---- | M] (OldTimer Tools) -- D:\Users\Kathrin\Desktop\OTL.exe
[2012/05/05 17:44:12 | 000,298,496 | ---- | M] () -- D:\Users\Admin\AppData\Roaming\itunes_service86.exe
[2012/05/03 15:11:10 | 000,062,558 | ---- | M] () -- D:\Users\Admin\Desktop\Foto.JPG
[2012/04/30 17:02:00 | 000,000,080 | ---- | M] () -- D:\Users\Admin\AppData\Local\CrystalDiskMark30.ini
[2012/04/30 16:32:22 | 000,815,348 | ---- | M] () -- D:\Users\Admin\Desktop\CrystalDiskMark3_0_1c.rar
[2012/04/30 15:57:50 | 000,018,831 | ---- | M] () -- D:\Users\Admin\Desktop\Benchmark_RAMDisk.pdf
[2012/04/30 15:41:54 | 000,718,503 | ---- | M] () -- D:\Users\Admin\Desktop\Memo.m4a
[2012/04/28 13:55:58 | 000,000,435 | ---- | M] () -- D:\Users\Public\Desktop\The Walking Dead.lnk
[2012/04/25 12:47:39 | 000,001,346 | ---- | M] () -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live ID.lnk
[2012/04/25 12:25:53 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/04/25 12:22:53 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
[2012/04/25 12:22:17 | 000,466,520 | ---- | M] (Creative Labs) -- D:\Windows\System32\wrap_oal.dll
[2012/04/25 12:22:17 | 000,445,016 | ---- | M] (Creative Labs) -- D:\Windows\SysWow64\wrap_oal.dll
[2012/04/25 12:22:17 | 000,123,480 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- D:\Windows\System32\OpenAL32.dll
[2012/04/25 12:22:17 | 000,109,144 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- D:\Windows\SysWow64\OpenAL32.dll
[2012/04/25 12:22:17 | 000,000,159 | RH-- | M] () -- D:\Windows\ctfile.rfc
[2012/04/15 17:23:35 | 000,012,711 | ---- | M] () -- D:\Users\Admin\Documents\algenkur.ods
[2012/04/11 14:07:44 | 000,000,000 | R--D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
========== Files Created - No Company Name ==========
[2012/05/06 06:13:09 | 000,003,224 | ---- | C] () -- D:\bootsqm.dat
[2012/05/05 17:44:17 | 000,298,496 | ---- | C] () -- D:\Users\Admin\AppData\Roaming\itunes_service86.exe
[2012/05/03 15:11:08 | 000,062,558 | ---- | C] () -- D:\Users\Admin\Desktop\Foto.JPG
[2012/04/30 16:32:41 | 000,000,080 | ---- | C] () -- D:\Users\Admin\AppData\Local\CrystalDiskMark30.ini
[2012/04/30 16:32:20 | 000,815,348 | ---- | C] () -- D:\Users\Admin\Desktop\CrystalDiskMark3_0_1c.rar
[2012/04/30 15:57:50 | 000,018,831 | ---- | C] () -- D:\Users\Admin\Desktop\Benchmark_RAMDisk.pdf
[2012/04/30 15:41:54 | 000,718,503 | ---- | C] () -- D:\Users\Admin\Desktop\Memo.m4a
[2012/04/30 15:32:19 | 006,074,924 | ---- | C] () -- D:\Users\Admin\Desktop\SONG0009.WAV
[2012/04/30 15:27:26 | 012,554,412 | ---- | C] () -- D:\Users\Admin\Desktop\SONG0019.WAV
[2012/04/30 15:18:54 | 035,419,436 | ---- | C] () -- D:\Users\Admin\Desktop\SONG0026.WAV
[2012/04/30 15:16:04 | 020,299,756 | ---- | C] () -- D:\Users\Admin\Desktop\SONG0028.WAV
[2012/04/28 13:55:58 | 000,000,435 | ---- | C] () -- D:\Users\Public\Desktop\The Walking Dead.lnk
[2012/04/25 12:47:39 | 000,001,346 | ---- | C] () -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live ID.lnk
[2012/04/25 12:24:15 | 000,061,256 | ---- | C] () -- D:\Windows\System32\BMXStateBkp-{00000009-00000000-00000002-00001102-00000005-00211102}.rfx
[2012/04/25 12:24:15 | 000,061,256 | ---- | C] () -- D:\Windows\System32\BMXState-{00000009-00000000-00000002-00001102-00000005-00211102}.rfx
[2012/04/25 12:24:15 | 000,000,788 | ---- | C] () -- D:\Windows\System32\DVCState-{00000009-00000000-00000002-00001102-00000005-00211102}.rfx
[2012/04/25 12:22:17 | 000,190,976 | ---- | C] () -- D:\Windows\System32\APOMgr64.DLL
[2012/04/25 12:22:17 | 000,148,480 | ---- | C] () -- D:\Windows\SysWow64\APOMngr.DLL
[2012/04/25 12:22:17 | 000,089,088 | ---- | C] () -- D:\Windows\System32\CmdRtr64.DLL
[2012/04/25 12:22:17 | 000,073,728 | ---- | C] () -- D:\Windows\SysWow64\CmdRtr.DLL
[2012/04/25 12:22:17 | 000,000,159 | RH-- | C] () -- D:\Windows\ctfile.rfc
[2012/04/15 17:23:35 | 000,012,711 | ---- | C] () -- D:\Users\Admin\Documents\algenkur.ods
[2012/02/18 06:06:44 | 000,007,604 | ---- | C] () -- D:\Users\Admin\AppData\Local\resmon.resmoncfg
[2012/02/09 15:05:44 | 000,416,064 | ---- | C] () -- D:\Windows\SysWow64\nvStreaming.exe
[2012/02/01 08:41:59 | 000,183,121 | ---- | C] () -- D:\Windows\hpoins38.dat
[2012/02/01 08:41:59 | 000,000,548 | ---- | C] () -- D:\Windows\hpomdl38.dat
[2012/01/28 18:15:48 | 001,001,680 | ---- | C] () -- D:\Windows\PE_Rom.dll
[2012/01/28 17:50:04 | 000,014,464 | ---- | C] () -- D:\Windows\SysWow64\drivers\AsUpIO.sys
[2012/01/28 17:47:49 | 000,013,440 | ---- | C] () -- D:\Windows\SysWow64\drivers\AsIO.sys
[2012/01/28 12:09:04 | 000,003,072 | ---- | C] () -- D:\Windows\SysWow64\CTXFIGER.DLL
[2012/01/26 06:56:44 | 000,001,769 | ---- | C] () -- D:\Windows\Language_trs.ini
[2012/01/26 06:56:40 | 000,026,272 | ---- | C] () -- D:\Windows\Ascd_tmp.ini
[2011/09/28 11:44:14 | 000,179,271 | ---- | C] () -- D:\Windows\SysWow64\xlive.dll.cat
[2010/11/20 23:24:49 | 000,252,928 | ---- | C] () -- D:\Windows\SysWow64\DShowRdpFilter.dll
[2010/05/05 14:56:46 | 000,002,560 | ---- | C] () -- D:\Windows\SysWow64\CtxfiRes.dll
[2010/05/05 14:46:30 | 000,321,512 | ---- | C] () -- D:\Windows\SysWow64\ctdlang.dat
[2010/05/05 14:46:30 | 000,056,509 | ---- | C] () -- D:\Windows\SysWow64\ctdnlstr.dat
[2010/05/05 14:38:22 | 000,007,680 | ---- | C] () -- D:\Windows\SysWow64\enlocstr.exe
[2010/05/05 14:37:52 | 000,021,204 | ---- | C] () -- D:\Windows\SysWow64\instwdm.ini
[2010/05/05 14:37:50 | 000,000,054 | ---- | C] () -- D:\Windows\SysWow64\ctzapxx.ini
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- D:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- D:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- D:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- D:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- D:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 18:25:04 | 000,197,632 | ---- | C] () -- D:\Windows\SysWow64\ir32_32.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- D:\Windows\SysWow64\msjetoledb40.dll
[2009/07/06 08:47:08 | 000,000,285 | ---- | C] () -- D:\Windows\SysWow64\kill.ini
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- D:\Windows\SysWow64\mlang.dat
[2009/04/02 08:30:14 | 000,010,296 | ---- | C] () -- D:\Windows\SysWow64\drivers\ASUSHWIO.SYS
========== LOP Check ==========
[2012/01/26 06:55:26 | 000,000,000 | -HSD | M] -- D:\ProgramData\Anwendungsdaten
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Application Data
[2012/01/28 17:47:51 | 000,000,000 | ---D | M] -- D:\ProgramData\ASUS
[2012/01/28 17:59:33 | 000,000,000 | ---D | M] -- D:\ProgramData\ASUS OC Profiles
[2012/02/07 06:13:54 | 000,000,000 | ---D | M] -- D:\ProgramData\Canneverbe Limited
[2012/01/30 12:48:44 | 000,000,000 | ---D | M] -- D:\ProgramData\DAEMON Tools Lite
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Desktop
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Documents
[2012/01/26 06:55:26 | 000,000,000 | -HSD | M] -- D:\ProgramData\Dokumente
[2012/01/26 06:55:26 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favoriten
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favorites
[2012/01/28 16:09:42 | 000,000,000 | ---D | M] -- D:\ProgramData\PMS
[2012/04/28 15:44:50 | 000,000,000 | ---D | M] -- D:\ProgramData\RELOADED
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Start Menu
[2012/01/26 06:55:26 | 000,000,000 | -HSD | M] -- D:\ProgramData\Startmenü
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Templates
[2012/01/26 06:55:26 | 000,000,000 | -HSD | M] -- D:\ProgramData\Vorlagen
[2012/03/25 07:05:45 | 000,032,632 | ---- | M] () -- D:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2012/02/01 17:59:12 | 000,000,000 | -HSD | M] -- D:\$Recycle.Bin
[2012/03/01 12:40:12 | 000,000,000 | -HSD | M] -- D:\Boot
[2012/04/28 07:12:02 | 000,000,000 | -H-D | M] -- D:\Config.Msi
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\Documents and Settings
[2012/01/26 06:55:26 | 000,000,000 | -HSD | M] -- D:\Dokumente und Einstellungen
[2012/01/26 07:01:28 | 000,000,000 | ---D | M] -- D:\Intel
[2012/04/25 05:48:37 | 000,000,000 | ---D | M] -- D:\JDownloader
[2012/01/26 07:22:56 | 000,000,000 | ---D | M] -- D:\NVIDIA
[2009/07/13 23:20:08 | 000,000,000 | ---D | M] -- D:\PerfLogs
[2012/03/26 15:32:16 | 000,000,000 | R--D | M] -- D:\Program Files
[2012/04/04 12:47:12 | 000,000,000 | R--D | M] -- D:\Program Files (x86)
[2012/04/28 15:44:50 | 000,000,000 | -H-D | M] -- D:\ProgramData
[2012/01/26 06:55:26 | 000,000,000 | -HSD | M] -- D:\Programme
[2012/01/26 06:55:26 | 000,000,000 | -HSD | M] -- D:\Recovery
[2012/05/04 07:47:04 | 000,000,000 | -HSD | M] -- D:\System Volume Information
[2012/02/08 14:55:08 | 000,000,000 | R--D | M] -- D:\Users
[2012/05/05 17:49:34 | 000,000,000 | ---D | M] -- D:\Windows
[2012/02/29 11:57:18 | 000,000,000 | ---D | M] -- D:\WindowsESD
[2012/05/05 18:01:17 | 000,000,000 | ---D | M] -- D:\_OTL
< %PROGRAMFILES%\*.exe >
Invalid Environment Variable: %LOCALAPPDATA%\*.exe
< %systemroot%\*. /mp /s >
< MD5 for: AGP440.SYS >
[2009/07/13 21:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- D:\Windows\System32\drivers\AGP440.sys
[2009/07/13 21:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- D:\Windows\System32\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009/07/13 21:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- D:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009/07/13 21:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- D:\Windows\System32\drivers\atapi.sys
[2009/07/13 21:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- D:\Windows\System32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/13 21:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- D:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- D:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- D:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 21:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- D:\Windows\System32\cngaudit.dll
[2009/07/13 21:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- D:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- D:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- D:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- D:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- D:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 23:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- D:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- D:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- D:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 23:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- D:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: IASTOR.SYS >
[2010/11/05 18:45:48 | 000,438,808 | ---- | M] (Intel Corporation) MD5=D7921D5A870B11CC1ADAB198A519D50A -- D:\Windows\System32\drivers\iaStor.sys
[2010/11/05 18:45:48 | 000,438,808 | ---- | M] (Intel Corporation) MD5=D7921D5A870B11CC1ADAB198A519D50A -- D:\Windows\System32\DriverStore\FileRepository\iaahci.inf_amd64_neutral_710b330fb3531234\iaStor.sys
< MD5 for: IASTORV.SYS >
[2010/11/20 23:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- D:\Windows\System32\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010/11/20 23:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- D:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011/03/11 02:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- D:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/03/11 02:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- D:\Windows\System32\drivers\iaStorV.sys
[2011/03/11 02:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- D:\Windows\System32\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011/03/11 02:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- D:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2010/11/20 23:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- D:\Windows\System32\netlogon.dll
[2010/11/20 23:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- D:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/20 23:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- D:\Windows\SysWOW64\netlogon.dll
[2010/11/20 23:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- D:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2011/03/11 02:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- D:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/03/11 02:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- D:\Windows\System32\drivers\nvstor.sys
[2011/03/11 02:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- D:\Windows\System32\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/11 02:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- D:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/20 23:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- D:\Windows\System32\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/20 23:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- D:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2010/11/20 23:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- D:\Windows\SysWOW64\scecli.dll
[2010/11/20 23:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- D:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/20 23:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- D:\Windows\System32\scecli.dll
[2010/11/20 23:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- D:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: USER32.DLL >
[2010/11/20 23:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- D:\Windows\SysWOW64\user32.dll
[2010/11/20 23:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- D:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2010/11/20 23:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- D:\Windows\System32\user32.dll
[2010/11/20 23:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- D:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
< MD5 for: USERINIT.EXE >
[2010/11/20 23:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- D:\Windows\SysWOW64\userinit.exe
[2010/11/20 23:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- D:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/20 23:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- D:\Windows\System32\userinit.exe
[2010/11/20 23:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- D:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010/11/20 23:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- D:\Windows\System32\winlogon.exe
[2010/11/20 23:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- D:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2009/07/13 20:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- D:\Windows\System32\drivers\ws2ifsl.sys
[2009/07/13 20:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- D:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\system32\config\*.sav >
< %systemroot%\system32\*.dll \lockedfiles >
Invalid Environment Variable: %USERPROFILE%\*.*
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.exe
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.dll
Invalid Environment Variable: %USERPROFILE%\Application Data\*.exe
< End of report > --- --- ---
[/CODE] |