Oh, mensch... Das ist mir aber unangenehm... Dann hier der dritte Versuch der Otl. txt: Code:
OTL logfile created on: 09.08.2011 10:19:50 - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Alli\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 0,86 Gb Available Physical Memory | 43,24% Memory free
4,24 Gb Paging File | 2,73 Gb Available in Paging File | 64,45% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 271,72 Gb Total Space | 80,13 Gb Free Space | 29,49% Space Free | Partition Type: NTFS
Drive D: | 26,34 Gb Total Space | 18,12 Gb Free Space | 68,80% Space Free | Partition Type: FAT32
Computer Name: ALLI-PC | User Name: Alli | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Alli\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Users\Alli\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\Stardock\MyColors\VistaSrv.exe (Stardock Corporation)
PRC - C:\Program Files\Stardock\MyColors\WBVista.exe ()
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVECapSvc.exe ()
PRC - C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVESched.exe ()
PRC - C:\Program Files\Home Cinema\TV Enhance\TVEService.exe (CyberLink Corp.)
PRC - C:\Program Files\Sceneo\Bonavista\Services\PVR\pvrservice.exe (Buhl Data Service GmbH)
PRC - C:\Program Files\Sceneo\Bonavista\Services\ODSBC\ODSBCApp.exe (ODSoft multimedia)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
PRC - C:\Program Files\Common Files\X10\Common\X10nets.exe (X10)
========== Modules (SafeList) ==========
MOD - C:\Users\Alli\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (FirebirdServerMAGIXInstance) -- File not found
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (SearchAnonymizer) -- C:\Users\Alli\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe ()
SRV - (WindowBlinds) -- C:\Program Files\Stardock\MyColors\VistaSrv.exe (Stardock Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TVECapSvc) TVEnhance Background Capture Service (TBCS) -- C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVECapSvc.exe ()
SRV - (TVESched) TVEnhance Task Scheduler (TTS)) -- C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVESched.exe ()
SRV - (srvcPVR) -- C:\Program Files\Sceneo\Bonavista\Services\PVR\pvrservice.exe (Buhl Data Service GmbH)
SRV - (x10nets) -- C:\Program Files\Common Files\X10\Common\X10nets.exe (X10)
========== Driver Services (SafeList) ==========
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ACEDRV07) -- C:\Windows\System32\drivers\ACEDRV07.sys (Protect Software GmbH)
DRV - (netr73) -- C:\Windows\System32\drivers\netr73.sys (Ralink Technology Corp.)
DRV - (Ph3xIB32) -- C:\Windows\System32\drivers\Ph3xIB32.sys (Philips Semiconductors GmbH)
DRV - (3xHybrid) -- C:\Windows\System32\drivers\3xHybrid.sys (Philips Semiconductors GmbH)
DRV - (PAC207) -- C:\Windows\System32\drivers\PFC027.SYS (PixArt Imaging Inc.)
DRV - (XUIF) -- C:\Windows\System32\drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
DRV - (X10Hid) -- C:\Windows\System32\drivers\x10hid.sys (X10 Wireless Technology, Inc.)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (xfilt) -- C:\Windows\system32\DRIVERS\xfilt.sys (VIA Technologies,Inc)
DRV - (videX32) -- C:\Windows\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (speedfan) -- C:\Windows\system32\speedfan.sys (Windows (R) 2000 DDK provider)
DRV - (giveio) -- C:\Windows\system32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.de"
FF - prefs.js..extensions.enabledItems: {AA994882-F391-4d2e-806F-8908DA4814ED}:2.11.9
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: extension@virtusdesigns.com:3.6.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {184AA5E6-741D-464a-820E-94B3ABC2F3B4}:1.0
FF - prefs.js..extensions.enabledItems: {7694c49c-9fbd-11dc-8314-0800200c9a66}:3.6.6
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.6&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Users\Alli\Documents\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Users\Alli\components [2011.06.30 13:41:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Users\Alli\plugins [2011.06.23 20:19:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.08.08 19:33:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{184AA5E6-741D-464a-820E-94B3ABC2F3B4}: C:\Users\Alli\AppData\Roaming\5015 [2011.04.09 19:14:37 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Users\Alli\components [2011.06.30 13:41:16 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Users\Alli\plugins [2011.06.23 20:19:47 | 000,000,000 | ---D | M]
[2009.01.02 19:26:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Extensions
[2011.08.09 10:16:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions
[2010.04.27 20:31:47 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.08.09 10:16:51 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010.08.12 20:11:51 | 000,000,000 | ---D | M] (Aquatint Black) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{7694c49c-9fbd-11dc-8314-0800200c9a66}
[2010.07.30 23:01:05 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.03.22 23:25:44 | 000,000,000 | ---D | M] (kikin plugin) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{AA994882-F391-4d2e-806F-8908DA4814ED}
[2010.08.12 20:11:55 | 000,000,000 | ---D | M] (Virtus Search Opt-in) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\extension@virtusdesigns.com
[2011.08.09 10:16:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\staged
[2010.08.12 20:11:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\extension@virtusdesigns.com\__MACOSX
[2010.08.12 20:11:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\extension@virtusdesigns.com\chrome
[2010.08.12 20:11:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\extension@virtusdesigns.com\defaults
[2010.08.12 20:11:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{7694c49c-9fbd-11dc-8314-0800200c9a66}\chrome\mac\mozapps\extensions
[2010.08.12 20:11:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{7694c49c-9fbd-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions
[2011.08.08 09:57:51 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-1.xml
[2011.03.23 21:00:06 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-10.xml
[2011.05.01 17:27:58 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-11.xml
[2011.06.23 20:20:19 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-12.xml
[2011.06.23 20:21:33 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-13.xml
[2010.07.29 23:10:36 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-2.xml
[2010.09.10 21:50:37 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-3.xml
[2010.09.10 21:53:02 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-4.xml
[2010.10.22 13:29:12 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-5.xml
[2010.10.29 16:38:34 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-6.xml
[2010.12.11 11:10:05 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-7.xml
[2010.12.11 12:12:16 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-8.xml
[2011.03.06 17:39:51 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-9.xml
[2010.06.26 19:20:34 | 000,000,947 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin.xml
[2010.12.31 14:24:09 | 000,001,218 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\kikin-search.xml
[2009.09.28 16:22:14 | 000,001,834 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\{4FD7DEE0-9C1A-4682-850D-0C2BAF2D1540}.xml
[2009.09.28 16:22:14 | 000,002,041 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\{B64016E1-B873-4DE1-888B-6FA625E65466}.xml
[2009.09.28 16:22:14 | 000,002,152 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\{CD745A81-B703-421E-8957-49F3D4F1D491}.xml
[2011.08.08 19:33:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2011.04.09 19:14:37 | 000,000,000 | ---D | M] (Java String Helper) -- C:\USERS\ALLI\APPDATA\ROAMING\5015
[2011.07.08 09:31:38 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,736 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files\kikin\ie_kikin.dll (kikin)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [InstantOn] C:\Program Files\CyberLink\PowerCinema Linux\ion_install.exe ()
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\Home Cinema\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Monitor] C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Ocs_SM] C:\Users\Alli\AppData\Roaming\OCS\SM\SearchAnonymizer.exe ()
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TVBroadcast] C:\Program Files\Sceneo\Bonavista\Services\ODSBC\ODSBCApp.exe (ODSoft multimedia)
O4 - HKLM..\Run: [TVEService] C:\Program Files\Home Cinema\TV Enhance\TVEService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [EA Core] File not found
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [msnmsgr] File not found
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - File not found
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files\kikin\ie_kikin.dll (kikin)
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: icq.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: icq.com ([start] http in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Alli\Pictures\2009\1.Winter\Schnee\CIMG0088.JPG
O24 - Desktop BackupWallPaper: C:\Users\Alli\Pictures\2009\1.Winter\Schnee\CIMG0088.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{5377d325-477d-11df-b516-0019db538ee6}\Shell - "" = AutoRun
O33 - MountPoints2\{5377d325-477d-11df-b516-0019db538ee6}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
O33 - MountPoints2\{59439e66-4cf2-11de-aef2-0019db538ee6}\Shell - "" = AutoRun
O33 - MountPoints2\{59439e66-4cf2-11de-aef2-0019db538ee6}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{d0d54177-cb7e-11dd-9bb4-0019db538ee6}\Shell\AutoRun\command - "" = G:\Menu.exe
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.08.08 14:02:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.08.08 14:02:16 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.08.08 14:01:13 | 003,447,576 | ---- | C] (Piriform Ltd) -- C:\Users\Alli\Desktop\ccsetup309.exe
[2011.08.08 13:05:11 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Users\Alli\Desktop\OTL.exe
[2011.08.08 10:23:29 | 000,000,000 | ---D | C] -- C:\Users\Alli\AppData\Roaming\Malwarebytes
[2011.08.08 10:23:11 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.08.08 10:23:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.08.08 10:23:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.08.08 10:23:07 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.08.08 10:23:06 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.08.07 15:19:01 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2011.07.13 20:59:44 | 002,043,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.07.13 20:59:05 | 000,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2011.07.13 20:59:05 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[1 C:\Users\Alli\AppData\Roaming\*.tmp files -> C:\Users\Alli\AppData\Roaming\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011.08.09 09:25:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.08.09 00:19:28 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.08.09 00:19:28 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.08.09 00:18:20 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{3B71DEDA-8EF0-4F1A-8789-F75916A1D24D}.job
[2011.08.08 19:33:58 | 000,000,810 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.08.08 14:05:32 | 000,000,768 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.08.08 14:01:18 | 003,447,576 | ---- | M] (Piriform Ltd) -- C:\Users\Alli\Desktop\ccsetup309.exe
[2011.08.08 13:05:19 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Alli\Desktop\OTL.exe
[2011.08.08 10:23:11 | 000,000,870 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.08.07 13:46:43 | 000,628,504 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.08.07 13:46:43 | 000,595,798 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.08.07 13:46:43 | 000,126,054 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.08.07 13:46:43 | 000,103,872 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.07.20 15:37:05 | 000,096,768 | ---- | M] () -- C:\Users\Alli\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.07.14 03:22:29 | 000,403,776 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[1 C:\Users\Alli\AppData\Roaming\*.tmp files -> C:\Users\Alli\AppData\Roaming\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.08.08 19:33:58 | 000,000,822 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011.08.08 19:33:58 | 000,000,810 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.08.08 14:02:18 | 000,000,768 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.08.08 10:23:11 | 000,000,870 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.04.09 20:08:50 | 000,000,024 | ---- | C] () -- C:\Users\Alli\AppData\Roaming\urhtps.dat
[2009.09.11 20:37:06 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.09.11 20:37:05 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.06.11 11:09:38 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2009.03.21 18:39:06 | 000,025,343 | ---- | C] () -- C:\Users\Alli\AppData\Roaming\UserTile.png
[2008.10.21 16:26:11 | 000,053,248 | ---- | C] () -- C:\Windows\System32\mgxasio2.dll
[2008.10.21 16:24:27 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2008.08.25 10:19:53 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.02.01 22:21:39 | 000,192,512 | ---- | C] () -- C:\Windows\System32\srkey.exe
[2008.02.01 20:55:17 | 000,001,000 | ---- | C] () -- C:\Windows\registry.ini
[2008.02.01 20:55:17 | 000,000,438 | ---- | C] () -- C:\Windows\registry-oem.ini
[2008.02.01 13:55:10 | 000,058,792 | ---- | C] () -- C:\Windows\System32\wbload.dll
[2008.01.23 16:48:11 | 000,399,360 | ---- | C] () -- C:\Windows\System32\Smab.dll
[2008.01.23 16:48:10 | 000,502,784 | ---- | C] () -- C:\Windows\x2.64.exe
[2008.01.23 16:48:10 | 000,240,128 | ---- | C] () -- C:\Windows\System32\x.264.exe
[2008.01.23 16:48:10 | 000,217,073 | ---- | C] () -- C:\Windows\meta4.exe
[2008.01.23 16:48:10 | 000,066,560 | ---- | C] () -- C:\Windows\MOTA113.exe
[2008.01.23 16:48:10 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2007.06.25 19:31:21 | 000,000,552 | ---- | C] () -- C:\Users\Alli\AppData\Local\d3d8caps.dat
[2007.05.19 10:55:48 | 000,001,199 | ---- | C] () -- C:\Windows\WININIT.INI
[2007.05.19 10:55:34 | 000,000,000 | ---- | C] () -- C:\Windows\odbcddp.ini
[2007.05.19 10:55:17 | 000,000,178 | ---- | C] () -- C:\Windows\_delis43.ini
[2007.05.19 10:54:22 | 000,001,612 | ---- | C] () -- C:\Windows\ODBC.INI
[2007.05.19 10:54:22 | 000,000,892 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2007.05.19 10:54:12 | 000,000,161 | ---- | C] () -- C:\Windows\KLETT.INI
[2007.05.19 10:54:05 | 000,247,296 | ---- | C] () -- C:\Windows\UN160407.EXE
[2007.04.27 20:24:25 | 000,000,052 | ---- | C] () -- C:\Users\Alli\AppData\Roaming\Default.PLS
[2007.04.27 10:35:30 | 000,000,025 | ---- | C] () -- C:\Windows\CDE D88PLUS.ini
[2007.04.27 10:27:34 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2007.04.27 10:27:34 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
[2007.04.27 10:27:34 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2007.04.27 10:27:34 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2007.04.27 10:27:34 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2007.04.27 10:27:34 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2007.04.27 10:27:34 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2007.04.27 10:27:34 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
[2007.04.27 10:27:34 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
[2007.04.27 10:27:34 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2007.04.27 10:27:34 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2007.04.27 10:27:33 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
[2007.04.27 10:27:33 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
[2007.04.27 10:27:33 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2007.04.27 10:27:33 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2007.04.27 10:27:33 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2007.04.27 10:27:33 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2007.04.27 10:27:33 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2007.04.27 10:27:33 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2007.04.27 10:18:49 | 000,003,904 | ---- | C] () -- C:\Users\Alli\AppData\Roaming\wklnhst.dat
[2007.04.26 16:00:48 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2007.04.25 20:40:21 | 000,007,052 | ---- | C] () -- C:\Users\Alli\AppData\Local\d3d9caps.dat
[2007.04.21 23:59:20 | 000,096,768 | ---- | C] () -- C:\Users\Alli\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.02.12 11:30:06 | 000,299,008 | ---- | C] () -- C:\Windows\System32\midas.dll
[2007.02.12 11:30:06 | 000,120,320 | ---- | C] () -- C:\Windows\System32\UnzDll.dll
[2007.02.10 17:17:37 | 000,006,768 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2007.02.09 16:43:52 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2007.02.09 15:32:51 | 000,127,184 | ---- | C] () -- C:\Windows\Unwise.exe
[2007.02.09 15:12:31 | 000,003,072 | ---- | C] () -- C:\Windows\System32\34CoInstaller.dll
[2006.12.11 06:06:31 | 000,000,000 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2006.11.02 17:33:31 | 000,628,504 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 17:33:31 | 000,126,054 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,403,776 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 000,595,798 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,103,872 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:27:46 | 000,000,518 | ---- | C] () -- C:\Windows\System32\SP207.INI
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.09.20 08:34:10 | 000,000,000 | ---- | C] () -- C:\Windows\Buhl.ini
[2002.03.21 15:39:02 | 000,073,728 | ---- | C] () -- C:\Windows\System32\UNACEV2.DLL
[1996.04.03 21:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys
========== LOP Check ==========
[2011.04.09 19:14:37 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\5015
[2007.04.27 12:47:28 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\ACD Systems
[2008.02.12 16:23:06 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Atari
[2009.10.10 09:31:27 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Desktopicon
[2008.02.03 21:14:33 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\EPSON
[2008.12.16 17:29:02 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\fun communications
[2010.11.15 20:43:38 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\gtk-2.0
[2011.07.07 18:49:01 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\ICQ
[2010.04.05 19:52:00 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\kikin
[2011.04.09 19:14:07 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\kock
[2008.04.17 17:21:27 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\LimeWire
[2008.10.21 16:35:37 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\MAGIX
[2009.05.16 21:58:03 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\McLoad
[2007.04.27 12:37:59 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\MusicIP
[2010.12.23 17:41:38 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\NCH Swift Sound
[2009.09.28 16:22:09 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\OCS
[2009.01.13 22:49:20 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\OpenOffice.org
[2009.09.28 16:22:14 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Opera
[2009.03.21 18:39:06 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\PeerNetworking
[2007.04.27 10:19:03 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Template
[2011.04.16 08:39:04 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\UAs
[2008.02.15 19:27:12 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Ulead Systems
[2008.05.01 13:14:18 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Windows Live Writer
[2011.04.16 08:44:10 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\xmldm
[2008.05.01 13:00:50 | 000,000,252 | ---- | M] () -- C:\Windows\Tasks\Auf Updates für Windows Live Toolbar prüfen.job
[2011.08.08 12:40:05 | 000,032,530 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.08.09 00:18:20 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{3B71DEDA-8EF0-4F1A-8789-F75916A1D24D}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 64 bytes -> C:\Users\Alli\Jason Derulo - Revolution (New 2010) (Official Off New Album).mp3:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Alli\Documents\Pitbull_-_Hotel_Room_Service_Official_Video_2oo9_High_Quali.mp3:TOC.WMV
< End of report > |