windrose | 17.05.2010 22:40 | Sorry aber die Datei kkkdwju.sys finde ich nicht!! :confused:
Ich kann den Inhalt aus der codebox auch nicht bei VirusTotal reinkopieren.
was mache ich falsch? :headbang: Code:
OTL logfile created on: 5/17/2010 5:06:15 PM - Run 2
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\Guenther\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 80.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 4000 4000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.74 Gb Total Space | 201.70 Gb Free Space | 43.31% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SHUTTLE
Current User Name: Guenther
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/05/17 16:53:57 | 000,571,392 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Guenther\Desktop\OTL.exe
PRC - [2010/05/16 22:15:21 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/05/16 22:15:21 | 000,710,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/05/16 22:15:21 | 000,620,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/05/16 22:15:21 | 000,508,184 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/05/16 22:15:19 | 002,064,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/05/16 22:15:19 | 000,916,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgemc.exe
PRC - [2010/05/16 22:15:18 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/02/04 00:00:02 | 002,630,000 | ---- | M] (SWE Sven Ritter) -- C:\Program Files\SpeedProject\SpeedCommander 13\SpeedCommander.exe
PRC - [2009/11/13 07:31:14 | 000,092,008 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2009/05/19 14:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/09/14 07:01:56 | 000,492,600 | ---- | M] () -- C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
PRC - [2007/09/14 05:55:26 | 000,427,288 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2007/04/20 14:22:22 | 000,079,324 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files\WeatherProfessional\database\bin\pg_ctl.exe
PRC - [2007/04/20 14:22:04 | 003,596,659 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files\WeatherProfessional\database\bin\postgres.exe
PRC - [2007/03/21 16:00:04 | 000,355,096 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2004/11/08 15:48:56 | 000,237,568 | ---- | M] (Delta) -- C:\Program Files\Belkin Bulldog Plus\upsd.exe
========== Modules (SafeList) ==========
MOD - [2010/05/17 16:53:57 | 000,571,392 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Guenther\Desktop\OTL.exe
MOD - [2009/05/25 01:41:34 | 000,304,128 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll
MOD - [2008/04/13 20:11:50 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cabinet.dll
MOD - [2008/04/13 20:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2010/05/16 22:15:19 | 000,916,760 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/05/16 22:15:18 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/04/19 10:25:38 | 000,430,152 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2009/11/13 07:31:14 | 000,092,008 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2009/06/18 20:49:54 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/05/19 14:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2008/10/29 10:50:23 | 000,077,824 | ---- | M] (Extensoft) [Disabled | Stopped] -- C:\Program Files\Extensions for Windows\Extensions\Updater\ExtensionsUpdatesService.exe -- (Extensions Updates Service)
SRV - [2007/09/14 07:01:56 | 000,492,600 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe -- (TryAndDecideService)
SRV - [2007/09/14 05:55:26 | 000,427,288 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2007/04/20 14:22:22 | 000,079,324 | ---- | M] (PostgreSQL Global Development Group) [Auto | Running] -- C:\Program Files\WeatherProfessional\database\bin\pg_ctl.exe -- (pgsql-8.2)
SRV - [2007/03/21 16:00:04 | 000,355,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2004/11/08 15:48:56 | 000,237,568 | ---- | M] (Delta) [Auto | Running] -- C:\Program Files\Belkin Bulldog Plus\upsd.exe -- (UPSentry_Smart)
========== Driver Services (SafeList) ==========
DRV - [2010/05/16 22:15:40 | 000,242,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/05/16 22:15:37 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/05/16 22:15:33 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2009/07/07 18:27:50 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/06/18 18:58:55 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\timntr.sys -- (timounter)
DRV - [2009/06/18 18:58:55 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2009/06/18 18:58:48 | 000,129,248 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\snapman.sys -- (snapman)
DRV - [2009/06/18 18:58:46 | 000,368,736 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\tdrpman.sys -- (tdrpman)
DRV - [2009/05/09 04:14:20 | 000,014,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nuidfltr.sys -- (NuidFltr)
DRV - [2009/03/28 03:03:00 | 006,280,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2009/03/15 06:25:46 | 000,056,268 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2009/02/06 21:08:42 | 000,055,152 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2009/01/13 22:13:52 | 000,049,160 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2009/01/13 22:13:44 | 000,014,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2009/01/13 22:13:28 | 000,029,192 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2009/01/13 22:13:20 | 000,019,336 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2008/08/14 10:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\adfs.sys -- (adfs)
DRV - [2008/04/13 14:36:38 | 000,020,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hidbatt.sys -- (HidBatt)
DRV - [2008/04/13 12:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/12/03 03:40:56 | 000,047,249 | R--- | M] (FTDI Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2007/07/06 14:16:34 | 000,016,000 | ---- | M] (USBest Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\UT_FPRd.sys -- (USB_FPRd)
DRV - [2007/06/19 22:14:40 | 004,432,384 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/03/21 15:58:56 | 000,304,920 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\iaStor.sys -- (iaStor)
DRV - [2006/11/02 11:01:00 | 000,250,496 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2005/08/16 17:50:50 | 000,278,016 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZD1211U.sys -- (WLAN(WLAN)) XPC 802.11b/g Wireless Kit Driver(WLAN)
DRV - [2004/10/25 16:40:58 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZDPSp50.sys -- (ZDPSp50)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://my.yahoo.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "hxxp://cm.my.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.8
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.1.21
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.10.2
FF - prefs.js..extensions.enabledItems: {d37dc5d0-431d-44e5-8c91-49419370caa1}:2.6.17
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: support@lastpass.com:1.68.2
FF - prefs.js..extensions.enabledItems: {3354F302-9928-4b07-B947-82F65A8FF70D}:2.0.2009110201
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.3
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.6.3
FF - prefs.js..extensions.enabledItems: smartbookmarksbar@remy.juteau:1.4.3
FF - prefs.js..extensions.enabledItems: weatherwatcherlive@singerscreations.com:1.0.13
FF - prefs.js..extensions.enabledItems: foxmarks@kei.com:3.6.14
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/05/16 22:15:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/05/16 22:15:26 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/13 12:36:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/13 12:36:01 | 000,000,000 | ---D | M]
[2009/06/18 22:40:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Extensions
[2009/06/18 22:40:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Extensions\home2@tomtom.com
[2010/05/17 06:55:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions
[2010/03/25 19:45:08 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010/05/10 07:01:52 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2010/04/11 06:25:50 | 000,000,000 | ---D | M] (FlashGot) -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2010/04/27 00:43:08 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/25 19:45:09 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\{3354F302-9928-4b07-B947-82F65A8FF70D}
[2010/04/13 07:06:55 | 000,000,000 | ---D | M] (ReloadEvery) -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2010/05/04 14:45:48 | 000,000,000 | ---D | M] (FoxClocks) -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2010/04/12 17:58:39 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/04/21 03:18:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\foxmarks@kei.com
[2010/04/13 07:06:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\personas@christopher.beard
[2010/03/25 19:12:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\smartbookmarksbar@remy.juteau
[2010/05/04 22:01:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\support@lastpass.com
[2010/03/25 19:45:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\extensions\weatherwatcherlive@singerscreations.com
[2010/01/11 16:22:54 | 000,002,477 | ---- | M] () -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\searchplugins\diigo--google.xml
[2010/04/30 17:18:56 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\searchplugins\icqplugin-1.xml
[2008/07/10 13:07:28 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\Guenther\Application Data\Mozilla\Firefox\Profiles\5qj462i5.default\searchplugins\icqplugin.xml
[2010/05/17 06:55:34 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009/07/11 00:39:25 | 000,072,960 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
O1 HOSTS File: ([2010/05/16 17:20:27 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files\kikin\ie_kikin.dll (kikin)
O3 - HKLM\..\Toolbar: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files\kikin\ie_kikin.dll (kikin)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1243652328765 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Guenther\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Guenther\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/29 22:18:29 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 90 Days ==========
[2010/05/17 16:53:56 | 000,571,392 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Guenther\Desktop\OTL.exe
[2010/05/17 06:55:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Guenther\Local Settings\Application Data\AVG Security Toolbar
[2010/05/16 22:15:40 | 000,242,896 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/05/16 22:15:40 | 000,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2010/05/16 22:15:37 | 000,216,200 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/05/16 22:15:33 | 000,029,512 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/05/16 22:15:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2010/05/16 22:15:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/05/16 22:15:03 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/05/16 21:58:20 | 095,153,416 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Guenther\Desktop\avg_free_stf_eu_90_819a2842.exe
[2010/05/16 17:27:28 | 000,000,000 | ---D | C] -- C:\Combo-Fix
[2010/05/16 17:02:43 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/05/16 16:59:17 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/05/16 16:59:16 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/05/16 16:59:16 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/05/16 16:59:16 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/05/16 16:58:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/05/16 16:29:57 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/05/15 07:03:35 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Guenther\Recent
[2010/05/13 08:13:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Guenther\Application Data\Malwarebytes
[2010/05/13 08:13:29 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/05/13 08:13:28 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/05/13 08:13:28 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/13 08:13:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/05/12 19:47:23 | 000,000,000 | ---D | C] -- C:\found.000
[2010/05/11 17:46:14 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2010/05/11 17:45:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\61D3AAE1D5214CD7939B37813DE8F955.TMP
[2010/05/11 17:45:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010/05/11 14:34:34 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/05/11 14:20:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/05/08 17:41:57 | 000,000,000 | ---D | C] -- C:\Program Files\easyHDR PRO 2
[2010/05/08 17:41:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Guenther\easyHDR PRO 2
[2010/05/08 17:14:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Guenther\Application Data\onOne Software
[2010/05/08 17:14:03 | 000,000,000 | ---D | C] -- C:\Program Files\onOne Software
[2010/05/08 17:14:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\onOne Software
[2010/05/05 14:47:01 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2010/05/05 13:21:38 | 000,000,000 | ---D | C] -- C:\$AVG
[2010/05/04 16:32:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/05/04 16:32:18 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2010/05/04 16:31:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Guenther\My Documents\AVG
[2010/05/01 17:55:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Guenther\Local Settings\Application Data\ACD Systems
[2010/05/01 17:55:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Guenther\Application Data\ACD Systems
[2010/05/01 17:52:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2010/05/01 17:52:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ACD Systems
[2010/05/01 17:52:21 | 000,000,000 | ---D | C] -- C:\Program Files\ACD Systems
[2010/05/01 17:50:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Guenther\Local Settings\Application Data\Downloaded Installations
[2010/04/11 15:44:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Navigator Systems
[2010/04/07 07:17:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Guenther\My Documents\Bank
[2010/04/03 06:00:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\TuneUp Software
[2010/04/03 05:36:05 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2010/03/31 08:43:31 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/03/28 18:52:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Guenther\Application Data\vlc
[2010/03/28 17:17:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2010/03/25 21:00:23 | 000,000,000 | ---D | C] -- C:\Program Files\JRE
[2010/03/25 20:39:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010/05/17 16:53:57 | 000,571,392 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Guenther\Desktop\OTL.exe
[2010/05/17 16:47:25 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/05/17 16:47:00 | 000,194,667 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/05/17 16:47:00 | 000,018,980 | ---- | M] () -- C:\WINDOWS\System32\nvwsapps.xml
[2010/05/17 16:46:57 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/05/17 16:46:56 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/05/17 07:19:56 | 003,670,016 | ---- | M] () -- C:\Documents and Settings\Guenther\NTUSER.DAT
[2010/05/17 06:58:21 | 060,075,572 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/05/16 22:15:40 | 000,242,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/05/16 22:15:40 | 000,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2010/05/16 22:15:40 | 000,001,516 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/05/16 22:15:37 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/05/16 22:15:33 | 000,113,461 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/05/16 22:15:33 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/05/16 22:12:32 | 095,153,416 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Guenther\Desktop\avg_free_stf_eu_90_819a2842.exe
[2010/05/16 17:33:21 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/05/16 17:20:27 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/05/16 17:02:47 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/05/16 16:23:29 | 003,689,722 | R--- | M] () -- C:\Documents and Settings\Guenther\Desktop\Combo-Fix.exe
[2010/05/16 11:07:55 | 000,039,424 | ---- | M] () -- C:\Documents and Settings\Guenther\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/16 07:35:26 | 000,011,776 | ---- | M] () -- C:\Documents and Settings\Guenther\My Documents\viren.doc
[2010/05/13 08:13:33 | 000,000,705 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/04 16:05:48 | 000,000,210 | ---- | M] () -- C:\Boot.bak
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/26 15:58:12 | 000,256,512 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2010/04/16 21:25:14 | 000,007,168 | ---- | M] () -- C:\Documents and Settings\Guenther\My Documents\Order Form.xls
[2010/04/07 19:06:16 | 000,008,192 | ---- | M] () -- C:\Documents and Settings\Guenther\My Documents\OFM.xls
[2010/04/02 07:53:43 | 000,025,262 | ---- | M] () -- C:\Documents and Settings\Guenther\My Documents\cc_20100402_075337.reg
[2010/03/26 06:46:02 | 000,019,072 | ---- | M] () -- C:\Documents and Settings\Guenther\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/26 06:14:17 | 000,550,666 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/26 06:14:17 | 000,462,390 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/03/26 06:14:17 | 000,078,608 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/03/26 06:12:14 | 002,004,160 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/05/16 22:15:40 | 000,001,516 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/05/16 22:15:33 | 000,113,461 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/05/16 22:15:28 | 060,075,572 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/05/16 17:02:47 | 000,000,210 | ---- | C] () -- C:\Boot.bak
[2010/05/16 17:02:44 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/05/16 16:59:17 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/05/16 16:59:17 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/05/16 16:59:16 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/05/16 16:59:16 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/05/16 16:59:16 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/05/16 16:23:29 | 003,689,722 | R--- | C] () -- C:\Documents and Settings\Guenther\Desktop\Combo-Fix.exe
[2010/05/16 07:35:26 | 000,011,776 | ---- | C] () -- C:\Documents and Settings\Guenther\My Documents\viren.doc
[2010/05/13 08:13:33 | 000,000,705 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/16 21:25:06 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\Guenther\My Documents\Order Form.xls
[2010/04/07 19:06:15 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\Guenther\My Documents\OFM.xls
[2010/04/02 07:53:40 | 000,025,262 | ---- | C] () -- C:\Documents and Settings\Guenther\My Documents\cc_20100402_075337.reg
[2009/07/07 18:27:50 | 000,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/06/18 20:49:29 | 000,000,614 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/06/18 17:18:05 | 000,000,609 | R--- | C] () -- C:\WINDOWS\System32\ftdiun2k.ini
[2009/05/29 22:30:41 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD.dll
[2009/05/29 22:30:41 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD64.DLL
[2007/09/27 13:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 13:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 13:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/06/28 12:43:00 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007/06/28 12:43:00 | 001,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007/06/28 12:43:00 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007/06/28 12:43:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007/06/28 12:43:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006/05/20 16:44:46 | 000,051,392 | ---- | C] () -- C:\WINDOWS\System32\drivers\atnt40k.sys
[2002/12/13 12:50:00 | 000,021,696 | ---- | C] () -- C:\WINDOWS\System32\lmpcl5d$.ini
========== LOP Check ==========
[2010/05/01 17:52:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2009/07/07 18:11:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acronis
[2010/05/16 22:17:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/05/16 22:15:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2009/06/18 21:48:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2010/03/31 08:43:31 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/06/18 22:28:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Extensions
[2010/03/28 17:17:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2009/07/25 14:03:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Martau
[2010/05/08 17:14:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\onOne Software
[2010/05/11 17:31:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/18 22:52:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
[2009/06/30 12:27:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/07/07 13:13:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{1C806443-3EF6-4749-9244-5B8BB16AC237}
[2009/07/07 18:27:47 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{44C0A247-3014-411F-95CB-B1729C1B82D5}
[2009/06/18 20:30:01 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/06/18 17:19:02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{6E81C7A8-EA69-4F66-A6DA-F1E4B472DE1C}
[2010/04/03 05:36:05 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2009/07/07 13:08:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{E43D54EF-B3D5-44DC-8466-C4CC70E63FDD}
[2010/05/01 17:55:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\ACD Systems
[2009/06/18 18:44:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Acronis
[2009/07/07 18:30:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\AquaSoft
[2010/05/15 07:03:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Azureus
[2009/07/07 18:16:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Barbecue
[2009/06/19 10:42:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\COWON
[2009/07/11 00:39:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Foxit
[2009/09/11 11:34:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Foxit Software
[2009/07/23 14:17:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Jpeg Resampler
[2009/07/28 10:31:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\jpg-Illuminator
[2009/06/19 08:57:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\kikin
[2009/07/03 11:35:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Mp3tag
[2010/05/08 17:16:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\onOne Software
[2009/06/18 21:40:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\OpenOffice.org
[2009/08/26 12:59:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\PanoramaStudio
[2009/07/07 18:16:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\PhotoAlbum
[2010/04/17 06:38:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\SpeedProject
[2009/09/18 20:03:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\TomTom
[2009/06/18 20:30:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\TuneUp Software
[2009/07/07 18:16:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\WebShow
[2009/06/02 12:47:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Windows Desktop Search
[2009/06/18 17:02:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guenther\Application Data\Windows Search
========== Purity Check ==========
========== Custom Scans ==========
< MD5 for: NDIS.SYS >
[2008/04/13 15:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008/04/13 15:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008/04/13 15:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys
[2008/04/13 15:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2006/02/28 08:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report > |