========== Extra Registry (SafeList) ==========
========== File Associations ==========
.cpl [@ = cplfile] -- D:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- D:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "D:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "D:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "D:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
========== Processes (SafeList) ==========
PRC - D:\Users\Computer\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - D:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - D:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - D:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
PRC - D:\ace_client240\League of Legends\air\LolClient.exe ()
PRC - D:\ace_client240\League of Legends\lol.launcher.exe (Solid State Networks)
PRC - D:\Program Files\ICQ6Toolbar\ICQ Service.exe ()
PRC - D:\Program Files\Nero\Update\NASvc.exe (Nero AG)
PRC - D:\Users\Computer\Desktop\DieUhr.exe (Kay Bruns)
PRC - D:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - D:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - D:\Program Files\OpenOffice.org 3\program\swriter.exe (OpenOffice.org)
PRC - D:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - D:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe (ASUSTeK Inc.)
PRC - D:\Windows\explorer.exe (Microsoft Corporation)
PRC - D:\Program Files\Rainlendar2\Rainlendar2.exe ()
PRC - D:\Windows\System32\ASDR.exe ()
PRC - D:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - D:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - D:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - D:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
========== Modules (SafeList) ==========
MOD - D:\Users\Computer\Desktop\OTL.exe (OldTimer Tools)
MOD - D:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - D:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - D:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - D:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - D:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - D:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - D:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - D:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - D:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - D:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - D:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - D:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
Drivers32: msacm.l3acm - D:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - D:\Windows\System32\iccvid.dll (Radius Inc.)
[2010.04.13 14:53:14 | 000,022,016 | ---- | C] () -- D:\Windows\System32\ODBCSTF.DLL
[2010.04.13 14:53:09 | 000,009,216 | ---- | C] () -- D:\Windows\System32\CBNVDD.DLL
[2010.03.03 16:05:41 | 000,281,760 | ---- | C] () -- D:\Windows\System32\drivers\atksgt.sys
[2010.03.03 16:05:41 | 000,025,888 | ---- | C] () -- D:\Windows\System32\drivers\lirsgt.sys
[2009.07.14 02:55:09 | 000,587,776 | ---- | C] () -- D:\Windows\System32\hpotscl1.dll
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- D:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- D:\Windows\System32\BWContextHandler.dll
========== Purity Check ==========
========== Custom Scans ==========
< %APPDATA%\*. >
[2010.07.09 23:54:46 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Adobe
[2010.05.13 18:57:26 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\CadSoft
[2010.07.13 13:22:44 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\dvdcss
[2010.07.12 12:57:33 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Emtybe
[2010.04.28 15:44:44 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\EssentialPIM
[2010.07.12 16:48:59 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Foxit Software
[2010.04.20 15:38:23 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Google
[2010.05.15 13:37:20 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\ibf
[2010.07.29 11:28:27 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\ICQ
[2010.03.02 19:49:28 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Identities
[2010.07.12 13:25:33 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Ilyq
[2010.04.28 15:27:16 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Kalenderchen
[2010.03.02 20:58:04 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Leadertech
[2010.03.02 20:53:24 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Logishrd
[2010.03.02 20:53:18 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Logitech
[2010.05.12 16:39:09 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\LolClient
[2010.03.03 15:52:14 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2010.03.02 20:59:13 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Macromedia
[2010.07.16 11:55:51 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Malwarebytes
[2010.05.18 22:56:40 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\MAXON
[2009.07.14 10:56:41 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Media Center Programs
[2010.07.28 10:53:18 | 000,000,000 | --SD | M] -- D:\Users\Computer\AppData\Roaming\Microsoft
[2010.04.13 11:54:52 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Miranda
[2010.06.18 03:04:37 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\mIRC
[2010.03.02 20:07:48 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Mozilla
[2010.07.26 22:10:01 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Mumble
[2010.06.29 20:58:57 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Nero
[2010.03.04 16:35:26 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\OpenOffice.org
[2010.07.29 15:14:50 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Skype
[2010.07.29 11:28:01 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\skypePM
[2010.05.06 13:58:21 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\stickies
[2010.03.02 21:08:00 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\teamspeak2
[2010.04.15 15:56:25 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Thunderbird
[2010.05.06 17:54:32 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\To-Do DeskList
[2010.04.07 23:21:46 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Toribash
[2010.04.13 12:17:47 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Trillian
[2010.03.20 23:58:47 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\TS3Client
[2010.03.03 16:07:13 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Ubisoft
[2010.07.13 13:24:15 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\vlc
[2010.04.17 13:47:02 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\Winamp
[2010.04.30 15:09:24 | 000,000,000 | ---D | M] -- D:\Users\Computer\AppData\Roaming\WinRAR
< %APPDATA%\*.exe /s >
[2010.07.14 16:10:50 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- D:\Users\Computer\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2010.03.02 20:58:04 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- D:\Users\Computer\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2010.07.13 16:20:30 | 000,388,096 | R--- | M] (Trend Micro Inc.) -- D:\Users\Computer\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
[2010.05.11 18:02:27 | 000,022,486 | R--- | M] () -- D:\Users\Computer\AppData\Roaming\Microsoft\Installer\{E1CD7BA2-B906-40F5-902C-31177F040CB4}\ARPPRODUCTICON.exe
[2010.05.11 18:02:27 | 000,022,486 | R--- | M] () -- D:\Users\Computer\AppData\Roaming\Microsoft\Installer\{E1CD7BA2-B906-40F5-902C-31177F040CB4}\NewShortcut1_E1CD7BA2B90640F5902C31177F040CB4_9.exe
[2010.05.11 18:02:27 | 000,022,486 | R--- | M] () -- D:\Users\Computer\AppData\Roaming\Microsoft\Installer\{E1CD7BA2-B906-40F5-902C-31177F040CB4}\NewShortcut3_E1CD7BA2B90640F5902C31177F040CB4_8.exe
< %SYSTEMDRIVE%\*.exe >
[2003.06.29 14:31:14 | 000,799,232 | ---- | M] (Jos Maas) -- D:\omb.exe
[1 D:\*.tmp files -> D:\*.tmp -> ]
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- D:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
