Sunbeam83 | 24.10.2012 11:55 | OTL Logfile: Code:
OTL logfile created on: 19.10.2012 04:58:01 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = D:\Users\******\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
8,00 Gb Total Physical Memory | 6,01 Gb Available Physical Memory | 75,17% Memory free
20,00 Gb Paging File | 17,77 Gb Available in Paging File | 88,89% Paging File free
Paging file location(s): d:\pagefile.sys 12288 12288 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = D:\Program Files (x86)
Drive C: | 59,52 Gb Total Space | 45,91 Gb Free Space | 77,14% Space Free | Partition Type: NTFS
Drive D: | 97,66 Gb Total Space | 62,38 Gb Free Space | 63,87% Space Free | Partition Type: NTFS
Drive E: | 833,85 Gb Total Space | 832,36 Gb Free Space | 99,82% Space Free | Partition Type: NTFS
Drive K: | 929,32 Gb Total Space | 268,65 Gb Free Space | 28,91% Space Free | Partition Type: NTFS
Drive M: | 1863,01 Gb Total Space | 1774,86 Gb Free Space | 95,27% Space Free | Partition Type: NTFS
Drive Y: | 933,68 Gb Total Space | 932,40 Gb Free Space | 99,86% Space Free | Partition Type: NTFS
Computer Name: ******KÖPPEN-PC | User Name: ****** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.10.19 04:55:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Users\******\Desktop\OTL.exe
PRC - [2012.10.19 04:48:56 | 000,050,477 | ---- | M] () -- D:\Users\******\Desktop\Defogger.exe
PRC - [2012.10.02 12:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.24 16:05:00 | 000,384,888 | ---- | M] (BlueStack Systems, Inc.) -- D:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
PRC - [2012.09.24 16:04:32 | 000,393,080 | ---- | M] (BlueStack Systems, Inc.) -- D:\Program Files (x86)\BlueStacks\HD-Service.exe
PRC - [2012.09.24 16:04:28 | 000,367,480 | ---- | M] (BlueStack Systems) -- D:\Program Files (x86)\BlueStacks\HD-SharedFolder.exe
PRC - [2012.09.24 16:04:20 | 000,260,472 | ---- | M] (BlueStack Systems) -- D:\Program Files (x86)\BlueStacks\HD-BlockDevice.exe
PRC - [2012.09.24 16:04:16 | 000,375,672 | ---- | M] (BlueStack Systems) -- D:\Program Files (x86)\BlueStacks\HD-Network.exe
PRC - [2012.09.24 14:46:16 | 001,328,736 | ---- | M] (Secunia) -- D:\Program Files (x86)\Secunia\PSI\PSIA.exe
PRC - [2012.09.24 14:46:16 | 000,656,480 | ---- | M] (Secunia) -- D:\Program Files (x86)\Secunia\PSI\sua.exe
PRC - [2012.09.07 15:23:10 | 002,637,624 | ---- | M] (Orbitdownloader.com) -- D:\Program Files (x86)\Orbitdownloader\orbitdm.exe
PRC - [2012.09.07 15:14:36 | 000,557,056 | ---- | M] (Orbitdownloader.com) -- D:\Program Files (x86)\Orbitdownloader\orbitnet.exe
PRC - [2012.08.31 16:02:02 | 002,754,984 | ---- | M] (TeamViewer GmbH) -- D:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012.08.21 11:12:26 | 004,282,728 | ---- | M] (AVAST Software) -- D:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012.08.21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) -- D:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.08.17 04:37:56 | 000,277,504 | ---- | M] (Intel Corporation) -- D:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2012.08.17 04:37:50 | 000,007,168 | ---- | M] (Intel Corporation) -- D:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011.05.24 10:33:30 | 001,840,128 | ---- | M] (MAGIX AG) -- D:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
========== Modules (No Company Name) ==========
MOD - [2012.10.19 04:48:56 | 000,050,477 | ---- | M] () -- D:\Users\******\Desktop\Defogger.exe
MOD - [2012.10.08 06:10:06 | 001,226,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\6831f648f5b925f1194f691b0b491662\System.WorkflowServices.ni.dll
MOD - [2012.10.08 06:09:37 | 000,369,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\dc86fe1c7a6e3a7ce9e9c1f13d9b1e8e\System.ServiceModel.Routing.ni.dll
MOD - [2012.10.08 06:09:36 | 001,140,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\ec057796972ce41b751eaa3a8306fbcb\System.ServiceModel.Discovery.ni.dll
MOD - [2012.10.08 06:09:35 | 000,082,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\d09c237ee72af3935f1a01388ef8e315\System.ServiceModel.Channels.ni.dll
MOD - [2012.10.08 06:09:25 | 001,086,464 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\f42c2acdb000001066c78acfc6cd8655\System.ServiceModel.Web.ni.dll
MOD - [2012.10.08 06:07:52 | 001,393,152 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\5055b60e339143bbace5871f5fe4b114\System.ServiceModel.Activities.ni.dll
MOD - [2012.10.08 06:07:48 | 001,072,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\bd28f26b18b8ffeee1a0fbaa98f5810e\System.IdentityModel.ni.dll
MOD - [2012.10.08 06:07:46 | 018,058,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\cfece6f67593b4d8bb58d23b7fdcc470\System.ServiceModel.ni.dll
MOD - [2012.10.08 06:07:32 | 000,027,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorDataMgrSvcInt#\d4adb751b6243b8669237a5259e4a035\IAStorDataMgrSvcInterfaces.ni.dll
MOD - [2012.10.08 06:07:29 | 000,026,112 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorCommon\7da8678130c6186e5635f0dab9de8bae\IAStorCommon.ni.dll
MOD - [2012.10.08 06:07:26 | 000,361,472 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorUtil\eaf38851778a2b0b790de0f2f41af37b\IAStorUtil.ni.dll
MOD - [2012.10.08 06:07:07 | 001,021,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\79ac99fe5274fb82ffcff2c15f71854c\System.Runtime.DurableInstancing.ni.dll
MOD - [2012.10.08 06:07:06 | 002,647,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\8a9fac9cb825b5d2db0bdb867fff940e\System.Runtime.Serialization.ni.dll
MOD - [2012.10.08 06:07:06 | 000,143,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\bb97517e4ca64e02282fca24612ce8ad\SMDiagnostics.ni.dll
MOD - [2012.10.08 06:06:56 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll
MOD - [2012.10.08 04:47:35 | 013,198,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3971e166cf827b6726e142f344061dc9\System.Windows.Forms.ni.dll
MOD - [2012.10.08 04:47:28 | 001,666,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c40f40ef36622109793788049fbe9ab\System.Drawing.ni.dll
MOD - [2012.10.08 04:45:30 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll
MOD - [2012.10.08 04:45:28 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\623d2a0f11dd82bb9bc13d1cb981b239\System.Configuration.ni.dll
MOD - [2012.10.08 04:45:26 | 007,069,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll
MOD - [2012.10.08 04:45:21 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
MOD - [2012.10.08 04:45:17 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
MOD - [2012.09.07 15:19:12 | 000,397,312 | ---- | M] () -- D:\Program Files (x86)\Orbitdownloader\wtlctrl.dll
========== Services (SafeList) ==========
SRV:64bit: - [2012.10.06 14:49:46 | 000,009,216 | ---- | M] () [Auto | Running] -- D:\Program Files\USBLogon\usblonsvc.exe -- (USBLogonService)
SRV:64bit: - [2012.08.21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- D:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2012.07.28 04:09:44 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011.09.27 21:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- D:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe -- (LBTServ)
SRV:64bit: - [2011.01.26 13:38:11 | 000,350,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\inetsrv\ftpsvc.dll -- (ftpsvc)
SRV:64bit: - [2010.11.21 05:24:51 | 000,049,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\snmp.exe -- (SNMP)
SRV:64bit: - [2010.11.21 05:24:38 | 000,189,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\mqtgsvc.exe -- (MSMQTriggers)
SRV:64bit: - [2010.11.21 05:24:38 | 000,015,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\inetsrv\inetinfo.exe -- (IISADMIN)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- D:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:64bit: - [2009.07.14 03:41:10 | 000,035,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\iprip.dll -- (iprip)
SRV:64bit: - [2009.07.14 03:39:56 | 000,010,752 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\inetsrv\WMSvc.exe -- (WMSVC)
SRV:64bit: - [2009.07.14 03:39:47 | 000,010,240 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\TCPSVCS.EXE -- (simptcp)
SRV:64bit: - [2009.07.14 03:39:20 | 000,009,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\mqsvc.exe -- (MSMQ)
SRV:64bit: - [2009.07.14 03:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\CISVC.EXE -- (CISVC)
SRV - [2012.10.14 07:24:19 | 000,115,168 | ---- | M] (Mozilla Foundation) [Auto | Stopped] -- D:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.10.13 10:59:52 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.10.02 12:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.09.24 16:05:00 | 000,384,888 | ---- | M] (BlueStack Systems, Inc.) [Auto | Running] -- D:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe -- (BstHdLogRotatorSvc)
SRV - [2012.09.24 16:04:32 | 000,393,080 | ---- | M] (BlueStack Systems, Inc.) [Auto | Running] -- D:\Program Files (x86)\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc)
SRV - [2012.09.24 14:46:16 | 001,328,736 | ---- | M] (Secunia) [Auto | Running] -- D:\Program Files (x86)\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2012.09.24 14:46:16 | 000,656,480 | ---- | M] (Secunia) [Auto | Running] -- D:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2012.08.31 16:02:02 | 002,754,984 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- D:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012.08.17 04:37:50 | 000,007,168 | ---- | M] (Intel Corporation) [Auto | Running] -- D:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- D:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.01.18 14:38:28 | 000,155,320 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- D:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
SRV - [2011.05.24 10:33:30 | 001,840,128 | ---- | M] (MAGIX AG) [Auto | Running] -- D:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2011.04.26 13:54:12 | 002,702,848 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- D:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2010.11.21 05:25:10 | 000,047,616 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\snmp.exe -- (SNMP)
SRV - [2010.11.21 05:24:51 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2010.11.21 05:24:51 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)
SRV - [2010.11.21 05:24:51 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.07.14 03:14:42 | 000,009,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\TCPSVCS.EXE -- (simptcp)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.10.14 08:19:29 | 000,027,760 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc)
DRV:64bit: - [2012.10.14 08:19:29 | 000,014,448 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt)
DRV:64bit: - [2012.09.12 15:20:04 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2012.08.21 11:13:13 | 000,969,200 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2012.08.21 11:13:13 | 000,359,464 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2012.08.21 11:13:13 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2012.08.21 11:13:12 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2012.08.21 11:13:12 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2012.08.21 11:13:11 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2012.08.20 14:48:50 | 000,019,032 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdrvio.sys -- (pwdrvio)
DRV:64bit: - [2012.08.20 14:48:48 | 000,012,384 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdspio.sys -- (pwdspio)
DRV:64bit: - [2012.08.17 04:33:42 | 000,645,952 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:64bit: - [2012.08.17 04:33:38 | 000,027,456 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF)
DRV:64bit: - [2012.07.28 06:07:44 | 010,278,912 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.07.28 03:14:46 | 000,368,640 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.06.05 13:45:16 | 000,237,968 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.12.16 16:20:10 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2011.09.02 08:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2011.09.02 08:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:24:15 | 000,146,432 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rmcast.sys -- (RMCAST)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 02:26:13 | 000,189,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mqac.sys -- (MQAC)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.03.01 23:05:32 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2007.05.09 01:00:00 | 000,183,200 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\V0470Vid.sys -- (VF0470Vid)
DRV - [2012.10.08 02:22:42 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2012.09.24 16:04:50 | 000,071,032 | ---- | M] (BlueStack Systems) [Kernel | Auto | Running] -- D:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys -- (BstHdDrv)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D4 A4 66 F9 21 A3 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "https://www.google.de/"
FF - prefs.js..extensions.enabledAddons: wrc@avast.com:7.0.1466
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.10
FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.10
FF - prefs.js..extensions.enabledAddons: {988da70d-b78d-44a1-a9c7-ed11832a9e2e}:1.3
FF - prefs.js..extensions.enabledAddons: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}:2.6.7
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: D:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: D:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: D:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: D:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: D:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: D:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: D:\Program Files\AVAST Software\Avast\WebRep\FF [2012.10.05 21:04:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: D:\Program Files (x86)\Mozilla Firefox\components [2012.10.14 07:24:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: D:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.1\extensions\\Components: D:\Program Files (x86)\Mozilla Thunderbird\components [2012.10.11 16:54:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.1\extensions\\Plugins: D:\Program Files (x86)\Mozilla Thunderbird\plugins
[2012.10.05 21:51:11 | 000,000,000 | ---D | M] (No name found) -- D:\Users\******\AppData\Roaming\Mozilla\Extensions
[2012.10.05 21:51:11 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- D:\Users\******\AppData\Roaming\Mozilla\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.10.05 21:51:11 | 000,000,000 | ---D | M] (DownloadHelper) -- D:\Users\******\AppData\Roaming\Mozilla\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.10.05 21:51:11 | 000,000,000 | ---D | M] (IMinent Toolbar) -- D:\Users\******\AppData\Roaming\Mozilla\Extensions\{C9B68337-E93A-44EA-94DC-CB300EC06444}
[2012.10.05 21:51:11 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- D:\Users\******\AppData\Roaming\Mozilla\Extensions\battlefieldplay4free@ea.com
[2012.10.05 21:51:11 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- D:\Users\******\AppData\Roaming\Mozilla\Extensions\ich@maltegoetz.de
[2012.10.18 18:16:10 | 000,000,000 | ---D | M] (No name found) -- D:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\5g4bf4er.default\extensions
[2012.10.18 18:16:10 | 000,000,000 | ---D | M] (PriceGong) -- D:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\5g4bf4er.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
[2012.10.06 01:20:40 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- D:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\5g4bf4er.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.10.08 23:50:25 | 000,000,000 | ---D | M] (DownloadHelper) -- D:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\5g4bf4er.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.08.30 18:22:28 | 000,079,759 | ---- | M] () (No name found) -- D:\Users\******\AppData\Roaming\Mozilla\Extensions\jid0-VYmz57LiwomhDdFigX6o1UAZnIE@jetpack.xpi
[2012.08.31 00:13:38 | 000,340,132 | ---- | M] () (No name found) -- D:\Users\******\AppData\Roaming\Mozilla\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
[2012.08.31 00:12:48 | 000,709,293 | ---- | M] () (No name found) -- D:\Users\******\AppData\Roaming\Mozilla\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2012.10.12 21:28:29 | 000,015,162 | ---- | M] () (No name found) -- D:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\5g4bf4er.default\extensions\{988da70d-b78d-44a1-a9c7-ed11832a9e2e}.xpi
[2012.10.14 07:24:16 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files (x86)\mozilla firefox\extensions
[2012.10.14 07:24:16 | 000,000,000 | ---D | M] (Skype Click to Call) -- D:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.10.05 21:04:17 | 000,000,000 | ---D | M] (avast! WebRep) -- D:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
File not found (No name found) -- D:\USERS\****** ******\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5G4BF4ER.DEFAULT\EXTENSIONS\{8A9386B4-E958-4C4C-ADF4-8F26DB3E4829}
File not found (No name found) -- D:\USERS\****** ******\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5G4BF4ER.DEFAULT\EXTENSIONS\{988DA70D-B78D-44A1-A9C7-ED11832A9E2E}.XPI
File not found (No name found) -- D:\USERS\****** ******\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5G4BF4ER.DEFAULT\EXTENSIONS\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
File not found (No name found) -- D:\USERS\****** ******\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5G4BF4ER.DEFAULT\EXTENSIONS\{B9DB16A4-6EDC-47EC-A1F4-B86292ED211D}
[2012.10.14 07:24:20 | 000,261,600 | ---- | M] (Mozilla Foundation) -- D:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.08.25 04:49:52 | 000,001,392 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.25 04:49:52 | 000,002,465 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.08.25 04:49:52 | 000,001,153 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.25 04:49:52 | 000,006,805 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.25 04:49:52 | 000,001,178 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.25 04:49:52 | 000,001,105 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - D:\Program Files (x86)\PriceGong\2.6.7\PriceGongIE.dll (PriceGong)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - D:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O4:64bit: - HKLM..\Run: [EvtMgr6] D:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [MsmqIntCert] C:\Windows\SysNative\mqrt.dll (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] D:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avast] D:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [IAStorIcon] D:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [StartCCC] D:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk = D:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
O4 - Startup: D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SystemExplorerDisabled [2012.10.13 11:06:50 | 000,000,000 | -H-D | M]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: &Download by Orbit - D:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: &Grab video by Orbit - D:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Do&wnload selected by Orbit - D:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Down&load all by Orbit - D:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Free YouTube Download - D:\Users\******\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - D:\Users\******\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: &Download by Orbit - D:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - D:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - D:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - D:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Free YouTube Download - D:\Users\******\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - D:\Users\******\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - D:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - D:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4BF905C7-4B4C-420D-8345-806629704CEA}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EFA8E424-6B7C-4AA9-8D78-2E9AF48B83F9}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~2\COMMON~1\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (d:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - d:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{e37e847d-15a3-11e2-a9d9-001fd0a154cb}\Shell - "" = AutoRun
O33 - MountPoints2\{e37e847d-15a3-11e2-a9d9-001fd0a154cb}\Shell\AutoRun\command - "" = L:\Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012.10.19 04:55:25 | 000,602,112 | ---- | C] (OldTimer Tools) -- D:\Users\******\Desktop\OTL.exe
[2012.10.19 04:54:16 | 000,000,000 | ---D | C] -- D:\Users\******\Desktop\Log Daten
[2012.10.19 04:53:08 | 000,000,000 | ---D | C] -- D:\Users\******\Desktop\Programme
[2012.10.19 04:44:16 | 010,669,952 | ---- | C] (Malwarebytes Corporation ) -- D:\Users\******\Desktop\mbam-setup-1.65.1.1000.exe
[2012.10.19 03:04:15 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\MyPhoneExplorer
[2012.10.18 23:29:11 | 000,000,000 | ---D | C] -- C:\Users
[2012.10.18 21:06:24 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\TeamViewer
[2012.10.18 18:54:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup
[2012.10.18 18:16:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong
[2012.10.18 18:16:09 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\PriceGong
[2012.10.18 18:16:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
[2012.10.18 18:16:01 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\MyPhoneExplorer
[2012.10.18 08:31:36 | 000,000,000 | ---D | C] -- D:\Users\******\Documents\DVDVideoSoft
[2012.10.18 07:58:28 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\FreeCommanderXE
[2012.10.18 07:58:27 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\FreeCommander XE
[2012.10.18 06:54:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7M
[2012.10.18 06:54:27 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\ICQ Search
[2012.10.18 06:54:07 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\ICQ
[2012.10.18 06:54:03 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\ICQ7M
[2012.10.18 06:50:18 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueStacksSetup
[2012.10.18 06:50:08 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\BlueStacks
[2012.10.18 06:50:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
[2012.10.18 06:50:08 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueStacks
[2012.10.18 06:14:27 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Radeon RAMDisk
[2012.10.18 06:06:28 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\ProgSense
[2012.10.18 06:06:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Orbit
[2012.10.18 06:06:25 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\GrabPro
[2012.10.18 06:06:25 | 000,000,000 | ---D | C] -- C:\downloads
[2012.10.18 06:06:22 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Orbitdownloader
[2012.10.18 06:05:36 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Orbit
[2012.10.18 05:59:49 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\JDownloader
[2012.10.15 00:25:06 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2012.10.14 11:31:33 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Opera
[2012.10.14 11:31:33 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\Opera
[2012.10.14 11:31:30 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Opera
[2012.10.14 08:19:29 | 000,027,760 | ---- | C] (Sony Ericsson Mobile Communications) -- C:\Windows\SysNative\drivers\ggsemc.sys
[2012.10.14 08:19:29 | 000,014,448 | ---- | C] (Sony Ericsson Mobile Communications) -- C:\Windows\SysNative\drivers\ggflt.sys
[2012.10.14 08:19:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony Ericsson
[2012.10.14 08:19:24 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Sony Ericsson
[2012.10.14 08:19:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2012.10.14 08:19:05 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\Java
[2012.10.14 08:18:55 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Java
[2012.10.14 08:16:56 | 000,000,000 | ---D | C] -- D:\Users\******\Podcasts
[2012.10.14 08:16:56 | 000,000,000 | ---D | C] -- D:\Users\******\Documents\Media Go
[2012.10.14 08:14:36 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\Sony
[2012.10.14 08:14:34 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\Sony Shared
[2012.10.14 08:14:04 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\Downloaded Installations
[2012.10.14 08:13:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony Corporation
[2012.10.14 08:12:36 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Sony Media Go Install
[2012.10.14 08:12:36 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Sony
[2012.10.14 08:07:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2012.10.14 08:07:29 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Sony
[2012.10.14 08:07:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony
[2012.10.14 07:24:16 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Mozilla Firefox
[2012.10.13 12:18:35 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RMPrepUSB
[2012.10.13 12:18:34 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\RMPrepUSB
[2012.10.13 11:09:13 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\SeriousBit
[2012.10.13 11:06:50 | 000,000,000 | -H-D | C] -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SystemExplorerDisabled
[2012.10.13 10:59:09 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\Secunia PSI
[2012.10.13 10:52:37 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\System Explorer
[2012.10.13 10:52:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EnhanceMySe7en
[2012.10.13 10:52:24 | 000,000,000 | ---D | C] -- D:\Program Files\EnhanceMySe7en
[2012.10.13 10:52:06 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Secunia
[2012.10.13 10:51:48 | 000,000,000 | ---D | C] -- D:\Program Files\USBLogon
[2012.10.13 10:51:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quadsoft USBLogon
[2012.10.13 04:24:11 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\MAGIX
[2012.10.13 04:24:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
[2012.10.13 04:24:09 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\simplitec
[2012.10.13 04:24:09 | 000,000,000 | ---D | C] -- C:\ProgramData\simplitec
[2012.10.13 04:24:08 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\simplitec
[2012.10.13 04:24:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\simplitec
[2012.10.13 04:24:06 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX
[2012.10.13 04:24:04 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\MAGIX Services
[2012.10.13 04:24:02 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\MSXML 4.0
[2012.10.13 04:23:23 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Tonium
[2012.10.13 04:22:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tonium
[2012.10.13 04:22:48 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Tonium
[2012.10.13 04:22:10 | 000,000,000 | ---D | C] -- D:\Users\******\Documents\MAGIX Downloads
[2012.10.13 04:22:09 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\MAGIX
[2012.10.12 21:38:01 | 000,000,000 | ---D | C] -- D:\Users\******\dwhelper
[2012.10.10 22:59:47 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\CrystalDiskInfo
[2012.10.09 05:38:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard Home Edition 7.6
[2012.10.09 05:38:52 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\MiniTool Partition Wizard Home Edition 7.6
[2012.10.08 22:51:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hewlett-Packard Company
[2012.10.08 21:22:08 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Malwarebytes
[2012.10.08 21:22:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.08 21:22:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.08 21:22:03 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.10.08 21:22:03 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.10.08 03:40:01 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Seagate
[2012.10.08 03:40:00 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Seagate
[2012.10.08 03:39:29 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012.10.08 03:29:30 | 000,000,000 | ---D | C] -- D:\Users\******\Documents\TCeinstellung
[2012.10.08 03:16:05 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012.10.08 01:33:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE
[2012.10.08 01:33:45 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\GIGABYTE
[2012.10.08 00:31:36 | 000,000,000 | ---D | C] -- D:\Program Files\Tracker Software
[2012.10.07 23:08:02 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2012.10.07 23:08:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2012.10.07 23:08:01 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\SpeedFan
[2012.10.07 19:29:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012.10.07 19:28:22 | 000,000,000 | ---D | C] -- D:\Program Files\Microsoft Silverlight
[2012.10.07 19:28:22 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Microsoft Silverlight
[2012.10.07 19:20:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64
[2012.10.07 19:20:23 | 000,000,000 | ---D | C] -- D:\Program Files\K-Lite Codec Pack x64
[2012.10.07 14:37:55 | 000,000,000 | ---D | C] -- D:\Users\******\Documents\iMacros
[2012.10.07 12:36:36 | 000,000,000 | ---D | C] -- D:\Users\******\Tracing
[2012.10.07 12:34:24 | 000,000,000 | ---D | C] -- C:\Windows\de
[2012.10.07 12:33:47 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2012.10.07 12:33:31 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2012.10.07 12:33:31 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2012.10.07 12:33:29 | 000,000,000 | ---D | C] -- D:\Program Files\Windows Live
[2012.10.07 12:33:23 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2012.10.07 12:33:16 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Windows Live
[2012.10.07 12:32:40 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Microsoft SkyDrive
[2012.10.07 12:32:39 | 000,000,000 | R--D | C] -- D:\Users\******\SkyDrive
[2012.10.07 12:32:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft SkyDrive
[2012.10.07 12:32:12 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\Windows Live
[2012.10.07 12:31:56 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\Windows Live
[2012.10.07 08:23:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emerge Desktop
[2012.10.07 08:09:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs
[2012.10.07 08:09:01 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Shark007
[2012.10.07 08:09:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Shark007
[2012.10.07 08:08:58 | 001,416,704 | ---- | C] (MPC-HC Team) -- C:\Windows\SysNative\VSFilter.dll
[2012.10.07 08:08:58 | 000,361,472 | ---- | C] (fccHandler) -- C:\Windows\SysNative\aacacm.acm
[2012.10.07 08:08:58 | 000,180,736 | ---- | C] (fccHandler) -- C:\Windows\SysNative\ac3acm.acm
[2012.10.07 08:08:58 | 000,124,909 | ---- | C] (Open Source Software community project) -- C:\Windows\SysNative\pthreadGC2.dll
[2012.10.07 08:08:58 | 000,000,000 | ---D | C] -- D:\Program Files\Shark007
[2012.10.06 21:45:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
[2012.10.06 21:44:53 | 000,811,008 | ---- | C] (Pizzolato Davide - www.xdp.it) -- C:\Windows\SysWow64\cximage.dll
[2012.10.06 21:41:24 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Skype
[2012.10.06 21:41:21 | 000,000,000 | R--D | C] -- D:\Program Files (x86)\Skype
[2012.10.06 21:41:21 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\Skype
[2012.10.06 21:41:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012.10.06 21:41:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2012.10.06 19:25:29 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\vlc
[2012.10.06 19:01:09 | 000,000,000 | ---D | C] -- D:\Users\******\Local Settings
[2012.10.06 18:57:08 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\SoundControl
[2012.10.06 18:57:03 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SoundControl
[2012.10.06 18:57:03 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\SoundControl
[2012.10.06 18:56:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mixxx
[2012.10.06 18:56:50 | 000,000,000 | ---D | C] -- D:\Program Files\Mixxx
[2012.10.06 01:30:13 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Microsoft
[2012.10.06 01:20:39 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.10.06 01:20:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2012.10.06 01:19:11 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\DVDVideoSoft
[2012.10.06 01:19:11 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\DVDVideoSoft
[2012.10.06 01:18:39 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\DVDVideoSoft
[2012.10.05 23:39:30 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\wargaming.net
[2012.10.05 23:39:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
[2012.10.05 23:39:20 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
[2012.10.05 23:11:02 | 000,000,000 | ---D | C] -- D:\Program Files\Easersoft
[2012.10.05 23:05:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.10.05 23:05:27 | 000,000,000 | ---D | C] -- D:\Program Files\VideoLAN
[2012.10.05 23:00:24 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Mozilla Maintenance Service
[2012.10.05 23:00:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.10.05 22:17:43 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\TeamViewer
[2012.10.05 22:08:06 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Microsoft.NET
[2012.10.05 21:22:04 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\TS3Client
[2012.10.05 21:20:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
[2012.10.05 21:04:25 | 000,359,464 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012.10.05 21:04:25 | 000,059,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012.10.05 21:04:25 | 000,054,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012.10.05 21:04:25 | 000,025,232 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012.10.05 21:04:25 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\Google
[2012.10.05 21:04:25 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Google
[2012.10.05 21:04:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012.10.05 21:04:24 | 000,969,200 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012.10.05 21:04:24 | 000,285,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012.10.05 21:04:24 | 000,071,600 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012.10.05 21:04:12 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012.10.05 21:04:12 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.10.05 21:04:04 | 000,000,000 | ---D | C] -- D:\Program Files\AVAST Software
[2012.10.05 21:04:04 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012.10.05 21:00:39 | 000,000,000 | ---D | C] -- D:\Program Files\TeamSpeak 3 Client
[2012.10.05 20:55:38 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\Macromedia
[2012.10.05 20:52:42 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\Mozilla
[2012.10.05 20:50:21 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Thunderbird
[2012.10.05 20:50:21 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\Thunderbird
[2012.10.05 20:50:21 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Mozilla
[2012.10.05 20:47:21 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\MozBackup
[2012.10.05 20:46:37 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Mozilla Thunderbird
[2012.10.05 20:16:25 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\WinRAR
[2012.10.05 20:16:25 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012.10.05 20:16:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012.10.05 20:16:23 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\WinRAR
[2012.10.05 20:16:19 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\7-Zip
[2012.10.05 20:16:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.10.05 20:10:20 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\ElevatedDiagnostics
[2012.10.05 19:55:15 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Macromedia
[2012.10.05 19:55:15 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Adobe
[2012.10.05 19:55:02 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2012.10.05 19:17:23 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\Intel Corporation
[2012.10.05 19:16:43 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Intel Corporation
[2012.10.05 19:15:43 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\ATI
[2012.10.05 19:15:43 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\ATI
[2012.10.05 19:15:43 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012.10.05 19:07:49 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
[2012.10.05 19:04:25 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\SysWow64\CSVer.dll
[2012.10.05 19:04:25 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Intel
[2012.10.05 19:04:13 | 000,000,000 | ---D | C] -- C:\Intel
[2012.10.05 19:03:07 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\AMD APP
[2012.10.05 19:03:06 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\ATI Technologies
[2012.10.05 19:03:06 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\ATI Technologies
[2012.10.05 19:03:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012.10.05 19:02:47 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\ATI Technologies
[2012.10.05 19:02:46 | 000,000,000 | ---D | C] -- D:\Program Files\ATI
[2012.10.05 19:02:01 | 000,000,000 | ---D | C] -- D:\Program Files\ATI Technologies
[2012.10.05 18:59:23 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\LogiShrd
[2012.10.05 18:58:38 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Leadertech
[2012.10.05 18:58:37 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\LogiShrd
[2012.10.05 18:58:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
[2012.10.05 18:58:25 | 000,000,000 | ---D | C] -- D:\Users\Public\Documents\LogiShrd
[2012.10.05 18:58:23 | 000,000,000 | ---D | C] -- D:\Program Files\Logitech
[2012.10.05 18:58:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Logishrd
[2012.10.05 18:58:19 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012.10.05 18:57:10 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\LogiShrd
[2012.10.05 18:57:08 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Logitech
[2012.10.05 18:57:08 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Logishrd
[2012.10.05 18:55:51 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2012.10.05 18:55:47 | 002,080,120 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib64.dll
[2012.10.05 18:55:47 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2012.10.05 18:55:47 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2012.10.05 18:55:47 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2012.10.05 18:55:47 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2012.10.05 18:55:47 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2012.10.05 18:55:47 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2012.10.05 18:55:47 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2012.10.05 18:55:47 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2012.10.05 18:55:47 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2012.10.05 18:55:47 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2012.10.05 18:55:46 | 002,535,008 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
[2012.10.05 18:55:46 | 002,028,920 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ64.dll
[2012.10.05 18:55:46 | 000,834,936 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPOShell64.dll
[2012.10.05 18:55:46 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2012.10.05 18:55:46 | 000,110,592 | ---- | C] (Real Sound Lab SIA) -- C:\Windows\SysNative\CONEQMSAPOGUILibrary.dll
[2012.10.05 18:55:46 | 000,000,000 | -H-D | C] -- D:\Program Files (x86)\InstallShield Installation Information
[2012.10.05 18:55:46 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Realtek
[2012.10.05 18:54:51 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\InstallShield
[2012.10.05 18:53:29 | 000,000,000 | ---D | C] -- D:\Program Files\Realtek
[2012.10.05 18:53:27 | 007,163,744 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEP64H.dll
[2012.10.05 18:53:27 | 000,433,504 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EED64H.dll
[2012.10.05 18:53:27 | 000,372,056 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64H.dll
[2012.10.05 18:53:27 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RH3DHT64.dll
[2012.10.05 18:53:27 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RH3DAA64.dll
[2012.10.05 18:53:27 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64H.dll
[2012.10.05 18:53:27 | 000,141,152 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEL64H.dll
[2012.10.05 18:53:27 | 000,123,744 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEA64H.dll
[2012.10.05 18:53:27 | 000,097,624 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64H.dll
[2012.10.05 18:53:27 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64H.dll
[2012.10.05 18:53:27 | 000,074,592 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEG64H.dll
[2012.10.05 18:53:16 | 000,000,000 | -H-D | C] -- D:\Program Files (x86)\Temp
[2012.10.05 18:43:21 | 000,000,000 | ---D | C] -- D:\Users\Public\Documents\DriverGenius
[2012.10.05 18:42:56 | 000,000,000 | ---D | C] -- C:\ProgramData\DriverGenius
[2012.10.05 18:34:33 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\XPSViewer
[2012.10.05 18:34:33 | 000,000,000 | ---D | C] -- C:\Windows\ShellNew
[2012.10.05 18:34:33 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\msmq
[2012.10.05 18:34:33 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\FxsTmp
[2012.10.05 18:34:33 | 000,000,000 | ---D | C] -- C:\Windows\ehome
[2012.10.05 18:34:33 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\BestPractices
[2012.10.05 18:34:33 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\BestPractices
[2012.10.05 18:34:33 | 000,000,000 | ---D | C] -- C:\Windows\addins
[2012.10.05 18:34:32 | 000,000,000 | RH-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
[2012.10.05 18:34:32 | 000,000,000 | ---D | C] -- C:\inetpub
[2012.10.05 18:34:32 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\FxsTmp
[2012.10.05 18:34:30 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Windows Sidebar
[2012.10.05 18:34:30 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Windows Media Player
[2012.10.05 18:34:30 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Reference Assemblies
[2012.10.05 18:34:30 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\MSBuild
[2012.10.05 18:34:28 | 000,000,000 | ---D | C] -- D:\Program Files\Windows Sidebar
[2012.10.05 18:34:27 | 000,000,000 | ---D | C] -- D:\Program Files\Windows Journal
[2012.10.05 18:34:27 | 000,000,000 | ---D | C] -- D:\Program Files\Microsoft Games
[2012.10.05 18:34:26 | 000,000,000 | ---D | C] -- D:\Program Files\Reference Assemblies
[2012.10.05 18:34:26 | 000,000,000 | ---D | C] -- D:\Program Files\MSBuild
[2012.10.05 18:29:31 | 000,000,000 | -H-D | C] -- D:\Program Files (x86)\Uninstall Information
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files\Windows Portable Devices
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Windows Portable Devices
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files\Windows Photo Viewer
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Windows Photo Viewer
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files\Windows NT
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Windows NT
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files\Windows Media Player
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Windows Mail
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Windows Defender
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\System
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\SpeechEngines
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\Services
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\microsoft shared
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Internet Explorer
[2012.10.05 18:29:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files
[2012.10.05 18:29:30 | 000,000,000 | -H-D | C] -- D:\Program Files\Uninstall Information
[2012.10.05 18:29:30 | 000,000,000 | ---D | C] -- D:\Program Files\Windows Mail
[2012.10.05 18:29:30 | 000,000,000 | ---D | C] -- D:\Program Files\Windows Defender
[2012.10.05 18:29:30 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\System
[2012.10.05 18:29:30 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\SpeechEngines
[2012.10.05 18:29:30 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\Services
[2012.10.05 18:29:30 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\Microsoft Shared
[2012.10.05 18:29:30 | 000,000,000 | ---D | C] -- D:\Program Files\DVD Maker
[2012.10.05 18:29:30 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\Videos
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\Saved Games
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\Pictures
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\Music
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\Links
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\Favorites
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\Downloads
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\Documents
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\Desktop
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\Contacts
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.10.05 17:54:15 | 000,000,000 | R--D | C] -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.10.05 17:54:15 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\VirtualStore
[2012.10.05 17:54:15 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\Temp
[2012.10.05 17:54:15 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Media Center Programs
[2012.10.05 17:54:15 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Identities
[2012.10.05 17:52:08 | 000,000,000 | R--D | C] -- D:\Users\******\Searches
[2012.10.05 17:50:43 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Local\Microsoft
[2012.10.05 17:50:26 | 000,000,000 | ---D | C] -- D:\Users\******\AppData\Roaming\Microsoft
[2012.10.05 17:50:26 | 000,000,000 | ---D | C] -- D:\Users\******\AppData
[2012.10.05 17:12:49 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2012.10.05 16:55:36 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2012.10.05 16:19:22 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012.10.05 16:19:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2012.10.05 16:19:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2012.10.05 16:19:21 | 000,000,000 | -HSD | C] -- C:\Programme
[2012.10.05 16:19:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2012.10.05 16:19:21 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2012.10.05 16:19:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2012.10.05 16:19:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2012.10.05 16:19:19 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.10.05 16:13:40 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2012.10.05 16:13:27 | 000,000,000 | -HSD | C] -- C:\System Volume Information
========== Files - Modified Within 30 Days ==========
[2012.10.19 04:55:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Users\******\Desktop\OTL.exe
[2012.10.19 04:54:53 | 000,000,000 | ---- | M] () -- D:\Users\******\defogger_reenable
[2012.10.19 04:48:56 | 000,050,477 | ---- | M] () -- D:\Users\******\Desktop\Defogger.exe
[2012.10.19 04:45:27 | 000,001,149 | ---- | M] () -- D:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.19 04:44:19 | 010,669,952 | ---- | M] (Malwarebytes Corporation ) -- D:\Users\******\Desktop\mbam-setup-1.65.1.1000.exe
[2012.10.19 04:44:02 | 000,001,781 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Orbit.lnk
[2012.10.19 03:04:28 | 001,833,466 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.10.19 03:04:28 | 000,784,310 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.10.19 03:04:28 | 000,723,360 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.10.19 03:04:28 | 000,179,100 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.10.19 03:04:28 | 000,146,200 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.10.19 01:01:10 | 000,021,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.19 01:01:10 | 000,021,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.18 23:42:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.17 14:28:15 | 000,000,000 | -H-- | M] () -- D:\Users\******\Documents\Default.rdp
[2012.10.14 08:35:36 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ggsemc_01009.Wdf
[2012.10.14 08:35:36 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ggflt_01009.Wdf
[2012.10.14 08:19:29 | 000,027,760 | ---- | M] (Sony Ericsson Mobile Communications) -- C:\Windows\SysNative\drivers\ggsemc.sys
[2012.10.14 08:19:29 | 000,014,448 | ---- | M] (Sony Ericsson Mobile Communications) -- C:\Windows\SysNative\drivers\ggflt.sys
[2012.10.13 17:22:55 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.08 22:11:50 | 001,801,110 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.10.08 01:46:06 | 000,001,376 | ---- | M] () -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
[2012.10.07 23:08:01 | 000,000,045 | ---- | M] () -- C:\Windows\SysWow64\initdebug.nfo
[2012.10.05 22:03:55 | 000,274,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.10.05 21:30:34 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.10.05 21:30:34 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2012.10.05 21:04:24 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012.10.05 19:15:14 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2012.10.05 18:36:44 | 000,000,535 | ---- | M] () -- C:\Windows\SysWow64\mapisvc.inf
[2012.10.05 17:20:20 | 000,000,035 | ---- | M] () -- C:\Windows\VB.MNM
[2012.10.05 16:15:52 | 000,159,772 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2012.10.05 16:15:52 | 000,159,772 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2012.10.05 16:14:14 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.09.29 19:54:26 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.09.20 20:00:00 | 000,127,488 | ---- | M] () -- C:\Windows\SysNative\ff_vfw.dll
========== Files Created - No Company Name ==========
[2012.10.19 04:54:53 | 000,000,000 | ---- | C] () -- D:\Users\******\defogger_reenable
[2012.10.19 04:48:55 | 000,050,477 | ---- | C] () -- D:\Users\******\Desktop\Defogger.exe
[2012.10.18 18:22:05 | 000,001,149 | ---- | C] () -- D:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.18 06:06:29 | 000,001,781 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Orbit.lnk
[2012.10.18 06:00:19 | 000,002,051 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
[2012.10.18 06:00:19 | 000,002,035 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.10.18 06:00:19 | 000,001,980 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.10.17 14:28:15 | 000,000,000 | -H-- | C] () -- D:\Users\******\Documents\Default.rdp
[2012.10.14 11:31:31 | 000,001,761 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2012.10.14 08:35:36 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ggsemc_01009.Wdf
[2012.10.14 08:35:36 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ggflt_01009.Wdf
[2012.10.13 10:59:58 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.13 10:52:07 | 000,000,981 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012.10.09 05:38:58 | 002,966,720 | ---- | C] () -- C:\Windows\SysNative\pwNative.exe
[2012.10.09 05:38:58 | 000,019,032 | ---- | C] () -- C:\Windows\SysNative\pwdrvio.sys
[2012.10.09 05:38:58 | 000,012,384 | ---- | C] () -- C:\Windows\SysNative\pwdspio.sys
[2012.10.08 01:46:06 | 000,001,376 | ---- | C] () -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
[2012.10.07 23:08:01 | 000,000,045 | ---- | C] () -- C:\Windows\SysWow64\initdebug.nfo
[2012.10.07 12:34:18 | 000,001,183 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[2012.10.07 12:34:14 | 000,001,246 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
[2012.10.07 12:33:44 | 000,001,356 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2012.10.07 12:33:42 | 000,002,372 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2012.10.07 12:32:39 | 000,002,231 | ---- | C] () -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
[2012.10.07 08:09:00 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2012.10.07 08:08:58 | 004,408,832 | ---- | C] () -- C:\Windows\SysNative\x264vfw.dll
[2012.10.07 08:08:58 | 000,580,096 | ---- | C] () -- C:\Windows\SysNative\ac3filter.acm
[2012.10.07 08:08:58 | 000,206,336 | ---- | C] () -- C:\Windows\SysNative\unrar.dll
[2012.10.07 08:08:58 | 000,148,992 | ---- | C] ( ) -- C:\Windows\SysNative\lagarith.dll
[2012.10.07 08:08:58 | 000,137,216 | ---- | C] () -- C:\Windows\SysNative\mlc.dll
[2012.10.07 08:08:58 | 000,127,488 | ---- | C] () -- C:\Windows\SysNative\ff_vfw.dll
[2012.10.06 21:44:54 | 000,057,656 | ---- | C] () -- C:\Windows\SysNative\drivers\V0470PC.bmp
[2012.10.06 21:44:54 | 000,003,632 | ---- | C] () -- C:\Windows\VF0470.uns
[2012.10.06 21:44:53 | 000,188,891 | ---- | C] () -- C:\Windows\SysWow64\V0470Cvw.bff
[2012.10.05 22:17:46 | 000,000,988 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012.10.05 21:30:34 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.10.05 21:30:34 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012.10.05 21:04:24 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2012.10.05 20:47:05 | 000,001,044 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.10.05 20:46:38 | 000,001,990 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2012.10.05 19:15:14 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.10.05 18:55:47 | 000,336,393 | ---- | C] () -- C:\Windows\SysNative\drivers\RTAIODAT.DAT
[2012.10.05 18:37:40 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012.10.05 18:37:38 | 000,001,246 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2012.10.05 18:37:37 | 000,001,222 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012.10.05 18:37:37 | 000,001,216 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2012.10.05 18:37:36 | 000,001,409 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2012.10.05 18:37:22 | 001,801,110 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.10.05 18:36:44 | 000,001,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2012.10.05 17:20:20 | 000,000,035 | ---- | C] () -- C:\Windows\VB.MNM
[2012.10.05 16:19:43 | 000,001,461 | ---- | C] () -- D:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.10.05 16:14:14 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.07.28 03:39:50 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.07.28 03:39:50 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012.10.11 02:18:55 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\DVDVideoSoft
[2012.10.06 01:20:40 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.10.18 06:06:25 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\GrabPro
[2012.10.18 22:25:09 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\ICQ
[2012.10.18 06:54:27 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\ICQ Search
[2012.10.05 18:58:38 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\Leadertech
[2012.10.13 04:29:19 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\MAGIX
[2012.10.19 03:08:09 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\MyPhoneExplorer
[2012.10.14 11:31:33 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\Opera
[2012.10.19 04:44:02 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\Orbit
[2012.10.18 06:06:28 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\ProgSense
[2012.10.13 11:09:13 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\SeriousBit
[2012.10.07 08:09:01 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\Shark007
[2012.10.13 04:24:09 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\simplitec
[2012.10.14 08:16:54 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\Sony
[2012.10.07 16:58:22 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\SoundControl
[2012.10.18 21:56:41 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\TeamViewer
[2012.10.05 20:50:21 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\Thunderbird
[2012.10.13 04:23:23 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\Tonium
[2012.10.06 02:28:15 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\TS3Client
[2012.10.06 01:32:43 | 000,000,000 | ---D | M] -- D:\Users\******\AppData\Roaming\wargaming.net
========== Purity Check ==========
< End of report > --- --- --- |