Black-Night | 07.10.2010 11:42 | vielen dank ersteinmal
hier ist avira
29.09.2012
4mal gefunden und gelöscht
In der Datei 'C:\Windows\System32\dwmhone.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen3' [trojan] gefunden.
Ausgeführte Aktion: Datei löschen
2mal gefunden und gelöscht
In der Datei 'C:\Users\Stuffi\AppData\Local\Temp\tmp8010.tmp.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Datei löschen
2mal gefunden und gelöscht
In der Datei 'C:\Users\Stuffi\AppData\Local\Temp\eapp32hst.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen3' [trojan] gefunden.
Ausgeführte Aktion: Datei löschen
3mal gefunden und gelöscht
In der Datei 'C:\Users\Stuffi\AppData\Local\Temp\tmp8010.tmp.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Datei löschen
In der Datei 'C:\Users\Stuffi\AppData\Local\Temp\eapp32hst.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen3' [trojan] gefunden.
Ausgeführte Aktion: Datei löschen
In der Datei 'C:\Users\Stuffi\AppData\Local\Temp\tmp8010.tmp.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Datei löschen
In der Datei 'C:\Users\Stuffi\AppData\Local\Temp\eapp32hst.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen3' [trojan] gefunden.
Ausgeführte Aktion: Datei löschen
In der Datei 'C:\Users\Stuffi\AppData\Local\Temp\eapp32hst.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen3' [trojan] gefunden.
Ausgeführte Aktion: Datei löschen
6mal gefunden und gelöscht
In der Datei 'C:\Users\Stuffi\AppData\Local\Temp\tmp8010.tmp.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Datei löschen
2mal gefunden und gelöscht
In der Datei 'C:\Users\Stuffi\AppData\Local\Temp\eapp32hst.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen3' [trojan] gefunden.
Ausgeführte Aktion: Datei löschen
126mal gefunden und gelöscht
In der Datei 'C:\Users\Stuffi\AppData\Local\Temp\eapp32hst.dll'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen3' [trojan] gefunden.
Ausgeführte Aktion: Datei löschen
dann otlOTL Logfile: Code:
OTL logfile created on: 07.10.2010 12:07:49 - Run 1
OTL by OldTimer - Version 3.2.1.2 Folder = C:\Users\Stuffi\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1.015,00 Mb Total Physical Memory | 313,00 Mb Available Physical Memory | 31,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 51,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55,66 Gb Total Space | 16,51 Gb Free Space | 29,66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 54,66 Gb Total Space | 18,99 Gb Free Space | 34,74% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 931,51 Gb Total Space | 373,66 Gb Free Space | 40,11% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Computer Name: STUFFIS-LAPPI
Current User Name: Stuffi
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Stuffi\Downloads\-olt-.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Windows\System32\iashost.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Orphalese Tarot\DeckService.exe (Orphalese Data Solutions Ltd)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Stuffi\Downloads\-olt-.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (TuneUp.Defrag) -- C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe (TuneUp Software)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (TomTomHOMEService) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) -- C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (wlidsvc) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (SBSDWSCService) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (Orphalese Deck Service) -- C:\Orphalese Tarot\DeckService.exe (Orphalese Data Solutions Ltd)
SRV - (O&O Defrag) -- C:\Windows\System32\oodag.exe (O&O Software GmbH)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TNaviSrv) -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (lxbc_device) -- C:\Windows\System32\lxbccoms.exe ( )
SRV - (ASLDRService) -- C:\Program Files\ATK Hotkey\ASLDRSrv.exe ()
SRV - (UPnPService) -- C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe (Magix AG)
SRV - (CFSvcs) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (UleadBurningHelper) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (TODDSrv) -- C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
========== Driver Services (SafeList) ==========
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (Lbd) -- C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ElbyCDIO) -- C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (fssfltr) -- C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (ACEDRV07) -- C:\Windows\System32\drivers\ACEDRV07.sys (Protect Software GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (nmwcdnsu) -- C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (Sentinel) -- C:\Windows\System32\Drivers\SENTINEL.SYS ()
DRV - (SVKP) -- C:\Windows\System32\SVKP.sys (AntiCracking)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (ialm) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (acehlp10) -- C:\Windows\System32\drivers\acehlp10.sys (Protect Software GmbH)
DRV - (acedrv10) -- C:\Windows\System32\drivers\ACEDRV10.sys (Protect Software GmbH)
DRV - (motmodem) -- C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (VClone) -- C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (tos_sps32) -- C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (ADIHdAudAddService) -- C:\Windows\System32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (RTL8023xp) -- C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (ElbyDelay) -- C:\Windows\System32\drivers\ElbyDelay.sys (Elaborate Bytes AG)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (KR10N) -- C:\Windows\system32\drivers\kr10n.sys (TOSHIBA CORPORATION)
DRV - (KR10I) -- C:\Windows\system32\drivers\kr10i.sys (TOSHIBA CORPORATION)
DRV - (MTsensor) -- C:\Windows\System32\drivers\ATKACPI.sys (ATK0100)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (tdcmdpst) -- C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (speedfan) -- C:\Windows\system32\speedfan.sys (Windows (R) 2000 DDK provider)
DRV - (sfsync04) StarForce Protection Synchronization Driver (version 4.x) -- C:\Windows\System32\drivers\sfsync04.sys (Protection Technology (StarForce))
DRV - (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a) -- C:\Windows\System32\drivers\sfdrv01a.sys (Protection Technology (StarForce))
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\System32\drivers\sfhlp02.sys (Protection Technology (StarForce))
DRV - (Hardlock) -- C:\Windows\System32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (giveio) -- C:\Windows\system32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKLM\..\URLSearchHook: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2422499485-3765178413-3129067992-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKU\S-1-5-21-2422499485-3765178413-3129067992-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2422499485-3765178413-3129067992-1000\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-2422499485-3765178413-3129067992-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Winamp Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Veoh Web Player Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.googel.de"
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6.3
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {12e4c684-c03e-4e4d-85bc-0c065e7a9489}:5.23.2.10
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: searchrecs@veoh.com:1.5.2
FF - prefs.js..extensions.enabledItems: {9815d32d-08c2-42ca-a8c6-43e501a4512f}:0.3.3
FF - prefs.js..extensions.enabledItems: {cd90bf73-20f6-44ef-993d-bb920303bd2e}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:3.2.3
FF - prefs.js..extensions.enabledItems: youtube2mp3@mondayx.de:1.0.7
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:4.0.0
FF - prefs.js..extensions.enabledItems: {20EDA46E-2436-46E3-BB5C-853B9EA5DE5C}:1.9.1
FF - prefs.js..extensions.enabledItems: {9f94fab0-58a2-11dd-ae16-0800200c9a66}:3.0.26
FF - prefs.js..extensions.enabledItems: {2458abc0-f443-11dd-87af-0800200c9a66}:3.6.3.1.03.04.10
FF - prefs.js..extensions.enabledItems: nasanightlaunch@example.com:0.6.20100805
FF - prefs.js..extensions.enabledItems: {e7348bc0-16f6-11de-8c30-0800200c9a66}:3.6.19.02.10
FF - prefs.js..extensions.enabledItems: theme@yogurttree.com:0.6.2
FF - prefs.js..keyword.URL: "hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50-ff-shoutcast-ab-en-us&query="
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord
FF - HKLM\software\mozilla\Firefox\Extensions\\{20EDA46E-2436-46E3-BB5C-853B9EA5DE5C}: C:\Users\Stuffi\AppData\Local\{20EDA46E-2436-46E3-BB5C-853B9EA5DE5C} [2010.09.29 01:24:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.10.04 22:31:49 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.10.04 22:31:49 | 000,000,000 | ---D | M]
[2008.08.25 17:46:04 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\mozilla\Extensions
[2008.04.01 19:52:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Extensions\{6334D996-EA3E-4a0e-AA8D-15BA56B37241}
[2008.08.25 17:46:04 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2010.10.06 15:35:08 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions
[2010.09.01 04:19:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2009.03.08 20:27:02 | 000,000,000 | ---D | M] (SHOUTcast Radio Toolbar) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{12e4c684-c03e-4e4d-85bc-0c065e7a9489}
[2010.06.01 09:24:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.04.17 08:51:08 | 000,000,000 | ---D | M] (Bloody Red) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{2458abc0-f443-11dd-87af-0800200c9a66}
[2010.02.19 22:03:52 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010.09.29 00:23:44 | 000,000,000 | ---D | M] (ReloadEvery) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2008.05.09 15:01:25 | 000,000,000 | ---D | M] (BlackJapanMAX) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{8e12f188-352c-4476-8198-e9b8f4a4353a}
[2010.08.10 09:48:45 | 000,000,000 | ---D | M] (Tor-Proxy.NET Toolbar) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{9815d32d-08c2-42ca-a8c6-43e501a4512f}
[2009.08.24 10:08:38 | 000,000,000 | ---D | M] (AvantGarde Rosepetal) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{9f94fab0-58a2-11dd-ae16-0800200c9a66}
[2008.10.15 17:15:16 | 000,000,000 | ---D | M] (Blue Ice 2) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{a8dd47cf-239f-48c4-8379-e6b4cbafdcfa}
[2009.08.24 10:08:38 | 000,000,000 | ---D | M] (MushroomKingdom) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{BF32D2C8-9C75-404b-ACF4-880DB4679236}
[2010.09.08 08:49:24 | 000,000,000 | ---D | M] (Fast Video Download (with SearchMenu)) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2010.08.31 21:17:40 | 000,000,000 | ---D | M] (Veoh Web Player Toolbar) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{cd90bf73-20f6-44ef-993d-bb920303bd2e}
[2010.06.01 09:25:00 | 000,000,000 | ---D | M] (Torbutton) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2010.02.21 09:24:44 | 000,000,000 | ---D | M] (Pink Fox) -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\{e7348bc0-16f6-11de-8c30-0800200c9a66}
[2009.05.22 10:53:19 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\moveplayer@movenetworks.com
[2010.09.01 04:19:06 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\nasanightlaunch@example.com
[2010.08.09 23:28:06 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\searchrecs@veoh.com
[2010.04.17 08:51:10 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\theme@yogurttree.com
[2010.09.10 16:41:44 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\mozilla\Firefox\Profiles\akwi0k9g.default\extensions\youtube2mp3@mondayx.de
[2010.06.29 17:22:34 | 000,000,933 | ---- | M] () -- C:\Users\Stuffi\AppData\Roaming\Mozilla\FireFox\Profiles\akwi0k9g.default\searchplugins\conduit.xml
[2008.06.21 21:13:48 | 000,002,921 | ---- | M] () -- C:\Users\Stuffi\AppData\Roaming\Mozilla\FireFox\Profiles\akwi0k9g.default\searchplugins\daemon-search.xml
[2010.10.04 07:02:39 | 000,000,950 | ---- | M] () -- C:\Users\Stuffi\AppData\Roaming\Mozilla\FireFox\Profiles\akwi0k9g.default\searchplugins\icqplugin-1.xml
[2008.02.19 18:16:46 | 000,000,951 | ---- | M] () -- C:\Users\Stuffi\AppData\Roaming\Mozilla\FireFox\Profiles\akwi0k9g.default\searchplugins\icqplugin.xml
[2009.03.08 22:44:46 | 000,001,184 | ---- | M] () -- C:\Users\Stuffi\AppData\Roaming\Mozilla\FireFox\Profiles\akwi0k9g.default\searchplugins\winamp-search.xml
[2010.10.07 12:05:27 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.06.01 15:06:42 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.04.12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.01.12 22:03:50 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2010.07.28 20:20:58 | 000,001,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.07.28 20:20:58 | 000,002,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.07.28 20:20:58 | 000,006,805 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.07.28 20:20:58 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.07.28 20:20:58 | 000,001,105 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.02.20 01:22:35 | 000,250,462 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 8731 more lines...
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar mit Pop-Up-Blocker) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-2422499485-3765178413-3129067992-1000\..\Toolbar\ShellBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKU\S-1-5-21-2422499485-3765178413-3129067992-1000\..\Toolbar\WebBrowser: (no name) - {0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8} - No CLSID value found.
O3 - HKU\S-1-5-21-2422499485-3765178413-3129067992-1000\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKU\S-1-5-21-2422499485-3765178413-3129067992-1000\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Byavubohido] C:\Users\Stuffi\AppData\Local\uvoxesakorilowad.DLL File not found
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-2422499485-3765178413-3129067992-1000..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: eBay - Der weltweite Online Marktplatz - {76577871-04EC-495E-A12B-91F7C3600AFA} - File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Stuffi\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
O24 - Desktop BackupWallPaper: C:\Users\Stuffi\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.04.12 12:36:34 | 000,000,000 | ---D | M] - C:\Autorun Eater -- [ NTFS ]
O33 - MountPoints2\{0dddb45b-6e3c-11dd-8dd2-001a92fa7b35}\Shell\AutoRun\command - "" = I:\InstallTomTomHOME.exe -- File not found
O33 - MountPoints2\{88393af8-c22d-11dc-a6c5-001a92fa7b35}\Shell - "" = AutoRun
O33 - MountPoints2\{88393af8-c22d-11dc-a6c5-001a92fa7b35}\Shell\AutoRun\command - "" = D:\Autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBSautocheck turegopt) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O36 - AppCertDlls: ciphl386 - (C:\Windows\system32\dwmhone.dll) - C:\Windows\System32\dwmhone.dll File not found
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: UxTuneUp - C:\Windows\System32\uxtuneup.dll (TuneUp Software)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009.09.11 18:22:58 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: Byavubohido - hkey= - key= - C:\Users\Stuffi\AppData\Local\uvoxesakorilowad.DLL File not found
MsConfig - StartUpReg: PC Suite Tray - hkey= - key= - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
MsConfig - StartUpReg: TkBellExe - hkey= - key= - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
MsConfig - State: "startup" - 2
MsConfig - State: "services" - 2
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sdauxservice - Reg Error: Value error.
SafeBootMin: sdcoreservice - Reg Error: Value error.
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SafeBootNet: Messenger - File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sdauxservice - Reg Error: Value error.
SafeBootNet: sdcoreservice - Reg Error: Value error.
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Reg Error: Value error.
SafeBootNet: WudfUsbccidDriver - Reg Error: Value error.
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 8.5.1
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 8.5.1
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D} - Microsoft .NET Framework 1.1 Security Update (KB953297)
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\System32\lhacm.acm (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
OTL cannot create restorepoints on Vista OSs!
========== Files/Folders - Created Within 30 Days ==========
[2010.10.06 11:10:12 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan
[2010.10.05 18:25:35 | 000,000,000 | ---D | C] -- C:\Program Files\MSECACHE
[2010.10.04 22:50:04 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2010.10.04 22:19:10 | 000,000,000 | ---D | C] -- C:\Users\Stuffi\AppData\Roaming\Canneverbe Limited
[2010.10.04 22:19:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
[2010.10.04 22:18:16 | 000,000,000 | ---D | C] -- C:\CDBurnerXP
[2010.10.04 19:38:43 | 000,909,176 | ---- | C] (Microsoft Corporation) -- C:\Users\Stuffi\Desktop\WGAPluginInstall.exe
[2010.10.01 07:35:24 | 000,000,000 | ---D | C] -- C:\Sophos
[2010.09.30 23:06:10 | 000,000,000 | ---D | C] -- C:\Users\Stuffi\Desktop\gmer1015
[2010.09.30 22:43:06 | 000,000,000 | ---D | C] -- C:\e5445938d3f1b486dfd34b5e2078
[2010.09.29 19:23:53 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll
[2010.09.29 19:23:53 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll
[2010.09.29 19:23:53 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll
[2010.09.29 19:23:53 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll
[2010.09.29 19:23:52 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll
[2010.09.29 19:23:52 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll
[2010.09.29 19:23:52 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll
[2010.09.29 19:23:51 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll
[2010.09.29 19:23:51 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll
[2010.09.29 19:23:51 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll
[2010.09.29 19:23:50 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2010.09.29 19:23:50 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll
[2010.09.29 19:23:50 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2010.09.29 19:23:50 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll
[2010.09.29 19:23:49 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2010.09.29 19:23:49 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2010.09.29 19:23:48 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2010.09.29 19:23:48 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2010.09.29 19:23:45 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2010.09.29 19:23:42 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2010.09.29 19:23:42 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2010.09.29 19:23:41 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2010.09.29 19:23:41 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2010.09.29 19:23:41 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2010.09.29 19:23:41 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2010.09.29 19:23:40 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2010.09.29 18:50:38 | 000,000,000 | ---D | C] -- C:\Users\Stuffi\Desktop\sims dl
[2010.09.29 01:24:46 | 000,000,000 | ---D | C] -- C:\Users\Stuffi\AppData\Local\{20EDA46E-2436-46E3-BB5C-853B9EA5DE5C}
[2010.09.17 13:35:43 | 000,000,000 | ---D | C] -- C:\Users\Stuffi\AppData\Local\memocard
[2010.09.17 13:34:41 | 000,000,000 | ---D | C] -- C:\MemoCard
[2010.09.15 14:59:42 | 000,000,000 | ---D | C] -- C:\Users\Stuffi\Desktop\EHSA
[2010.09.15 14:16:16 | 000,000,000 | ---D | C] -- C:\Lernkartei
[2010.09.15 14:15:54 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\Setup1.exe
[2010.09.15 14:15:50 | 001,392,671 | ---- | C] (Microsoft Corporation) -- C:\Windows\msvbvm60.dll
[2010.09.15 14:15:50 | 000,151,622 | ---- | C] (Microsoft Corporation) -- C:\Windows\modcas.dll
[2010.09.15 14:15:50 | 000,125,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\vb6de.dll
[2010.09.15 14:15:50 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\odestkit.dll
[2010.09.15 14:15:50 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\ODEUNST.EXE
[2010.09.15 12:31:22 | 000,000,000 | ---D | C] -- C:\Users\Stuffi\Documents\FinePrint files
[2010.09.15 12:30:26 | 000,401,408 | ---- | C] (FinePrint Software, LLC) -- C:\Windows\System32\fpres632.dll
[2010.09.15 12:30:26 | 000,385,024 | ---- | C] (FinePrint Software, LLC) -- C:\Windows\System32\fpmon6.dll
[2010.09.15 12:06:02 | 000,000,000 | ---D | C] -- C:\CUEcards
[2010.09.15 00:25:10 | 000,317,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MP4SDECD.DLL
[2010.09.14 20:03:06 | 000,000,000 | ---D | C] -- C:\Users\Stuffi\AppData\Roaming\Scribus
[2010.09.14 20:00:25 | 000,000,000 | ---D | C] -- C:\Scribus 1.3.8
[2010.09.11 12:40:23 | 000,000,000 | ---D | C] -- C:\Users\Stuffi\AppData\Roaming\pics
[2010.09.11 12:40:23 | 000,000,000 | ---D | C] -- C:\ProgramData\pics
[2010.09.11 12:37:25 | 000,000,000 | ---D | C] -- C:\Users\Stuffi\Desktop\raetsel
[2010.09.10 21:00:50 | 000,000,000 | ---D | C] -- C:\Users\Stuffi\Documents\Astalavista
[2010.09.10 17:07:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Borland Shared
[2010.09.10 17:06:30 | 000,304,128 | ---- | C] (InstallShield Corporation, Inc.) -- C:\Windows\unin0407.exe
[2010.09.03 20:11:26 | 000,995,328 | ---- | C] ( ) -- C:\Windows\System32\lxbcusb1.dll
[2010.09.03 20:11:26 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxbcinpa.dll
[2010.09.03 20:11:26 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxbciesc.dll
[2010.09.03 20:11:26 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXBChcp.dll
[2010.09.03 20:11:25 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\lxbcserv.dll
[2010.09.03 20:11:25 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxbcpmui.dll
[2010.09.03 20:11:25 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxbclmpm.dll
[2010.09.03 20:11:25 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxbcprox.dll
[2010.09.03 20:11:25 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxbcpplc.dll
[2010.09.03 20:11:24 | 000,696,320 | ---- | C] ( ) -- C:\Windows\System32\lxbchbn3.dll
[2010.09.03 20:11:20 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\lxbccomm.dll
[2010.09.03 20:11:19 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxbccomc.dll
[2010.06.02 05:22:02 | 000,089,944 | ---- | C] (Microsoft Corporation) -- C:\Users\Stuffi\DSETUP.dll
[2009.04.02 07:30:08 | 000,092,064 | ---- | C] (MCCI) -- C:\Users\Stuffi\mqdmmdm.sys
[2009.04.02 07:30:08 | 000,079,328 | ---- | C] (MCCI) -- C:\Users\Stuffi\mqdmserd.sys
[2009.04.02 07:30:08 | 000,066,656 | ---- | C] (MCCI) -- C:\Users\Stuffi\mqdmbus.sys
[2009.04.02 07:30:08 | 000,009,232 | ---- | C] (MCCI) -- C:\Users\Stuffi\mqdmmdfl.sys
[2009.04.02 07:30:08 | 000,006,208 | ---- | C] (MCCI) -- C:\Users\Stuffi\mqdmcmnt.sys
[2009.04.02 07:30:08 | 000,005,936 | ---- | C] (MCCI) -- C:\Users\Stuffi\mqdmwhnt.sys
[2009.04.02 07:30:08 | 000,004,048 | ---- | C] (MCCI) -- C:\Users\Stuffi\mqdmcr.sys
[2009.04.02 07:19:25 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Users\Stuffi\usbsermptxp.sys
[2009.04.02 07:19:25 | 000,022,768 | ---- | C] (Microsoft Corporation) -- C:\Users\Stuffi\usbsermpt.sys
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.10.07 12:09:48 | 006,291,456 | ---- | M] () -- C:\Users\Stuffi\ntuser.dat
[2010.10.07 11:06:20 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.10.07 11:06:20 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.10.07 10:25:18 | 000,191,488 | ---- | M] () -- C:\Users\Stuffi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.10.07 07:22:23 | 000,027,741 | ---- | M] () -- C:\Users\Stuffi\Desktop\fehlermeldung.jpg
[2010.10.07 07:12:00 | 000,341,586 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.10.07 07:12:00 | 000,171,288 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.10.07 07:12:00 | 000,092,822 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.10.07 07:12:00 | 000,048,278 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.10.07 07:12:00 | 000,019,578 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.10.07 07:06:39 | 008,405,015 | ---- | M] () -- C:\Windows\TempFile
[2010.10.07 07:06:23 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.10.07 07:05:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.10.07 07:03:53 | 000,524,288 | -HS- | M] () -- C:\Users\Stuffi\ntuser.dat{c25c0a47-9a13-11df-80be-001a92fa7b35}.TMContainer00000000000000000001.regtrans-ms
[2010.10.07 07:03:53 | 000,065,536 | -HS- | M] () -- C:\Users\Stuffi\ntuser.dat{c25c0a47-9a13-11df-80be-001a92fa7b35}.TM.blf
[2010.10.07 07:03:37 | 004,097,563 | -H-- | M] () -- C:\Users\Stuffi\AppData\Local\IconCache.db
[2010.10.06 18:32:10 | 000,136,832 | ---- | M] () -- C:\Users\Stuffi\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.10.06 18:29:52 | 000,444,976 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.10.06 15:10:11 | 000,491,424 | ---- | M] () -- C:\Windows\System32\OODBS.lor
[2010.10.04 22:18:19 | 000,001,465 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2010.10.04 19:38:46 | 000,909,176 | ---- | M] (Microsoft Corporation) -- C:\Users\Stuffi\Desktop\WGAPluginInstall.exe
[2010.10.01 07:30:22 | 001,339,288 | ---- | M] () -- C:\Users\Stuffi\Desktop\sar_15_sfx.exe
[2010.09.30 22:42:26 | 000,278,161 | ---- | M] () -- C:\Users\Stuffi\Desktop\gmer1015.zip
[2010.09.30 20:05:26 | 000,003,854 | ---- | M] () -- C:\Users\Stuffi\Desktop\cc_20100930_200429.reg
[2010.09.30 19:14:55 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
[2010.09.29 09:16:48 | 000,000,120 | ---- | M] () -- C:\Users\Stuffi\AppData\Local\Oxafepa.dat
[2010.09.29 01:24:56 | 000,000,000 | ---- | M] () -- C:\Users\Stuffi\AppData\Local\Rmitefova.bin
[2010.09.29 00:34:47 | 000,057,192 | ---- | M] () -- C:\Users\Stuffi\Desktop\regelkalender.pdf
[2010.09.22 11:25:41 | 000,013,093 | ---- | M] () -- C:\Users\Stuffi\Desktop\backimage.jpg
[2010.09.21 06:41:55 | 000,948,224 | ---- | M] () -- C:\Users\Stuffi\Desktop\Amigurumi.doc
[2010.09.21 06:26:32 | 000,611,045 | ---- | M] () -- C:\Users\Stuffi\Desktop\WolleUndDesignEnglischeStrickbegriffe2004.pdf
[2010.09.20 06:32:10 | 000,000,062 | ---- | M] () -- C:\CPU-DATA.INI
[2010.09.17 13:34:57 | 000,001,403 | ---- | M] () -- C:\Users\Public\Desktop\memoCARD.lnk
[2010.09.17 12:52:06 | 000,000,665 | ---- | M] () -- C:\Windows\Lexstat.ini
[2010.09.15 14:15:54 | 000,331,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\Setup1.exe
[2010.09.15 14:15:50 | 001,392,671 | ---- | M] (Microsoft Corporation) -- C:\Windows\msvbvm60.dll
[2010.09.15 14:15:50 | 000,151,622 | ---- | M] (Microsoft Corporation) -- C:\Windows\modcas.dll
[2010.09.15 14:15:50 | 000,125,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\vb6de.dll
[2010.09.15 14:15:50 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\odestkit.dll
[2010.09.15 14:15:50 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\ODEUNST.EXE
[2010.09.14 19:07:41 | 001,036,531 | ---- | M] () -- C:\Users\Stuffi\Desktop\lexmark bed.an..pdf
[2010.09.11 18:49:11 | 000,030,538 | ---- | M] () -- C:\Users\Stuffi\Desktop\singer190707REX_228x614.jpg
[2010.09.11 17:43:50 | 000,000,926 | ---- | M] () -- C:\Windows\posteriza.INI
[2010.09.11 17:26:45 | 000,035,840 | -H-- | M] () -- C:\Users\Stuffi\AppData\Roaming\MBSGWorldPlugin3550.dll
[2010.09.11 17:26:44 | 000,065,024 | -H-- | M] () -- C:\Users\Stuffi\AppData\Roaming\MBSPicturePlugin3595.dll
[2010.09.11 17:26:44 | 000,027,648 | -H-- | M] () -- C:\Users\Stuffi\AppData\Roaming\MBSRegistrationPlugin3596.dll
[2010.09.11 17:26:43 | 000,120,832 | -H-- | M] () -- C:\Users\Stuffi\AppData\Roaming\MBSJPEGDecompressionPlugin3597.dll
[2010.09.11 17:26:42 | 000,086,528 | -H-- | M] () -- C:\Users\Stuffi\AppData\Roaming\rbap500.dll
[2010.09.11 15:04:57 | 000,000,846 | ---- | M] () -- C:\Users\Stuffi\Documents\jürgen.lst
[2010.09.11 14:07:21 | 000,000,453 | ---- | M] () -- C:\Users\Stuffi\Documents\cyffhoff rätzel.lst
[2010.09.11 12:39:38 | 000,330,240 | ---- | M] () -- C:\Windows\PICSUninstall.exe
[2010.09.10 16:53:14 | 003,752,469 | ---- | M] () -- C:\Users\Stuffi\Desktop\E-De-Cologne - Zimboculture.mp3
[2010.09.10 16:50:10 | 006,533,152 | ---- | M] () -- C:\Users\Stuffi\Desktop\Buzz Fuzz - D-Leria(2).mp3
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.10.07 07:22:23 | 000,027,741 | ---- | C] () -- C:\Users\Stuffi\Desktop\fehlermeldung.jpg
[2010.10.04 22:18:19 | 000,001,465 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2010.10.01 07:30:08 | 001,339,288 | ---- | C] () -- C:\Users\Stuffi\Desktop\sar_15_sfx.exe
[2010.09.30 22:42:20 | 000,278,161 | ---- | C] () -- C:\Users\Stuffi\Desktop\gmer1015.zip
[2010.09.30 20:05:19 | 000,003,854 | ---- | C] () -- C:\Users\Stuffi\Desktop\cc_20100930_200429.reg
[2010.09.30 19:14:55 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
[2010.09.29 01:24:56 | 000,000,120 | ---- | C] () -- C:\Users\Stuffi\AppData\Local\Oxafepa.dat
[2010.09.29 01:24:56 | 000,000,000 | ---- | C] () -- C:\Users\Stuffi\AppData\Local\Rmitefova.bin
[2010.09.29 00:34:46 | 000,057,192 | ---- | C] () -- C:\Users\Stuffi\Desktop\regelkalender.pdf
[2010.09.22 11:25:31 | 000,013,093 | ---- | C] () -- C:\Users\Stuffi\Desktop\backimage.jpg
[2010.09.21 06:41:54 | 000,948,224 | ---- | C] () -- C:\Users\Stuffi\Desktop\Amigurumi.doc
[2010.09.21 06:26:32 | 000,611,045 | ---- | C] () -- C:\Users\Stuffi\Desktop\WolleUndDesignEnglischeStrickbegriffe2004.pdf
[2010.09.20 06:32:10 | 000,000,062 | ---- | C] () -- C:\CPU-DATA.INI
[2010.09.17 13:34:57 | 000,001,403 | ---- | C] () -- C:\Users\Public\Desktop\memoCARD.lnk
[2010.09.14 19:07:41 | 001,036,531 | ---- | C] () -- C:\Users\Stuffi\Desktop\lexmark bed.an..pdf
[2010.09.11 18:48:56 | 000,030,538 | ---- | C] () -- C:\Users\Stuffi\Desktop\singer190707REX_228x614.jpg
[2010.09.11 17:25:41 | 000,035,840 | -H-- | C] () -- C:\Users\Stuffi\AppData\Roaming\MBSGWorldPlugin3550.dll
[2010.09.11 17:25:37 | 000,065,024 | -H-- | C] () -- C:\Users\Stuffi\AppData\Roaming\MBSPicturePlugin3595.dll
[2010.09.11 17:25:37 | 000,027,648 | -H-- | C] () -- C:\Users\Stuffi\AppData\Roaming\MBSRegistrationPlugin3596.dll
[2010.09.11 17:25:36 | 000,120,832 | -H-- | C] () -- C:\Users\Stuffi\AppData\Roaming\MBSJPEGDecompressionPlugin3597.dll
[2010.09.11 17:25:35 | 000,086,528 | -H-- | C] () -- C:\Users\Stuffi\AppData\Roaming\rbap500.dll
[2010.09.11 15:04:57 | 000,000,846 | ---- | C] () -- C:\Users\Stuffi\Documents\jürgen.lst
[2010.09.11 13:57:20 | 000,000,453 | ---- | C] () -- C:\Users\Stuffi\Documents\cyffhoff rätzel.lst
[2010.09.11 12:39:38 | 000,330,240 | ---- | C] () -- C:\Windows\PICSUninstall.exe
[2010.09.10 17:07:26 | 000,185,344 | ---- | C] () -- C:\Windows\System32\BDEADMIN.CPL
[2010.09.10 16:53:11 | 003,752,469 | ---- | C] () -- C:\Users\Stuffi\Desktop\E-De-Cologne - Zimboculture.mp3
[2010.09.10 16:50:06 | 006,533,152 | ---- | C] () -- C:\Users\Stuffi\Desktop\Buzz Fuzz - D-Leria(2).mp3
[2010.09.03 20:11:26 | 000,413,696 | ---- | C] () -- C:\Windows\System32\lxbcutil.dll
[2010.09.03 20:11:26 | 000,274,432 | ---- | C] () -- C:\Windows\System32\LXBCinst.dll
[2010.09.03 17:27:27 | 000,000,132 | ---- | C] () -- C:\Windows\System32\lxbzplc.ini
[2010.09.03 16:00:02 | 000,004,990 | ---- | C] () -- C:\ProgramData\mtbjfghn.xbe
[2010.09.03 14:09:41 | 000,000,926 | ---- | C] () -- C:\Windows\posteriza.INI
[2010.09.01 16:01:35 | 000,000,032 | ---- | C] () -- C:\Windows\Menu.INI
[2010.07.28 08:46:29 | 000,524,288 | -HS- | C] () -- C:\Users\Stuffi\ntuser.dat{c25c0a47-9a13-11df-80be-001a92fa7b35}.TMContainer00000000000000000002.regtrans-ms
[2010.07.28 08:46:29 | 000,524,288 | -HS- | C] () -- C:\Users\Stuffi\ntuser.dat{c25c0a47-9a13-11df-80be-001a92fa7b35}.TMContainer00000000000000000001.regtrans-ms
[2010.07.28 08:46:28 | 000,065,536 | -HS- | C] () -- C:\Users\Stuffi\ntuser.dat{c25c0a47-9a13-11df-80be-001a92fa7b35}.TM.blf
[2010.07.08 18:24:38 | 000,000,431 | ---- | C] () -- C:\Windows\viewer.ini
[2010.06.02 05:22:54 | 001,412,902 | ---- | C] () -- C:\Users\Stuffi\OCT2006_d3dx9_31_x64.cab
[2010.06.02 05:22:54 | 001,127,217 | ---- | C] () -- C:\Users\Stuffi\OCT2006_d3dx9_31_x86.cab
[2010.06.02 05:22:54 | 000,273,960 | ---- | C] () -- C:\Users\Stuffi\Nov2008_XAudio_x64.cab
[2010.06.02 05:22:54 | 000,272,611 | ---- | C] () -- C:\Users\Stuffi\Nov2008_XAudio_x86.cab
[2010.06.02 05:22:54 | 000,182,361 | ---- | C] () -- C:\Users\Stuffi\OCT2006_XACT_x64.cab
[2010.06.02 05:22:54 | 000,138,017 | ---- | C] () -- C:\Users\Stuffi\OCT2006_XACT_x86.cab
[2010.06.02 05:22:54 | 000,086,037 | ---- | C] () -- C:\Users\Stuffi\Oct2005_xinput_x64.cab
[2010.06.02 05:22:54 | 000,045,359 | ---- | C] () -- C:\Users\Stuffi\Oct2005_xinput_x86.cab
[2010.06.02 05:22:52 | 001,906,878 | ---- | C] () -- C:\Users\Stuffi\Nov2008_d3dx9_40_x64.cab
[2010.06.02 05:22:52 | 001,550,796 | ---- | C] () -- C:\Users\Stuffi\Nov2008_d3dx9_40_x86.cab
[2010.06.02 05:22:52 | 000,965,421 | ---- | C] () -- C:\Users\Stuffi\Nov2008_d3dx10_40_x86.cab
[2010.06.02 05:22:52 | 000,121,794 | ---- | C] () -- C:\Users\Stuffi\Nov2008_XACT_x64.cab
[2010.06.02 05:22:52 | 000,092,684 | ---- | C] () -- C:\Users\Stuffi\Nov2008_XACT_x86.cab
[2010.06.02 05:22:52 | 000,054,522 | ---- | C] () -- C:\Users\Stuffi\Nov2008_X3DAudio_x64.cab
[2010.06.02 05:22:52 | 000,021,851 | ---- | C] () -- C:\Users\Stuffi\Nov2008_X3DAudio_x86.cab
[2010.06.02 05:22:50 | 000,994,154 | ---- | C] () -- C:\Users\Stuffi\Nov2008_d3dx10_40_x64.cab
[2010.06.02 05:22:50 | 000,196,762 | ---- | C] () -- C:\Users\Stuffi\NOV2007_XACT_x64.cab
[2010.06.02 05:22:50 | 000,148,264 | ---- | C] () -- C:\Users\Stuffi\NOV2007_XACT_x86.cab
[2010.06.02 05:22:50 | 000,046,144 | ---- | C] () -- C:\Users\Stuffi\NOV2007_X3DAudio_x64.cab
[2010.06.02 05:22:50 | 000,018,496 | ---- | C] () -- C:\Users\Stuffi\NOV2007_X3DAudio_x86.cab
[2010.06.02 05:22:48 | 001,802,058 | ---- | C] () -- C:\Users\Stuffi\Nov2007_d3dx9_36_x64.cab
[2010.06.02 05:22:48 | 001,709,360 | ---- | C] () -- C:\Users\Stuffi\Nov2007_d3dx9_36_x86.cab
[2010.06.02 05:22:48 | 000,864,600 | ---- | C] () -- C:\Users\Stuffi\Nov2007_d3dx10_36_x64.cab
[2010.06.02 05:22:48 | 000,803,884 | ---- | C] () -- C:\Users\Stuffi\Nov2007_d3dx10_36_x86.cab
[2010.06.02 05:22:48 | 000,273,018 | ---- | C] () -- C:\Users\Stuffi\Mar2009_XAudio_x86.cab
[2010.06.02 05:22:46 | 000,275,044 | ---- | C] () -- C:\Users\Stuffi\Mar2009_XAudio_x64.cab
[2010.06.02 05:22:46 | 000,121,506 | ---- | C] () -- C:\Users\Stuffi\Mar2009_XACT_x64.cab
[2010.06.02 05:22:46 | 000,092,740 | ---- | C] () -- C:\Users\Stuffi\Mar2009_XACT_x86.cab
[2010.06.02 05:22:38 | 000,054,600 | ---- | C] () -- C:\Users\Stuffi\Mar2009_X3DAudio_x64.cab
[2010.06.02 05:22:38 | 000,021,298 | ---- | C] () -- C:\Users\Stuffi\Mar2009_X3DAudio_x86.cab
[2010.06.02 05:22:36 | 001,973,702 | ---- | C] () -- C:\Users\Stuffi\Mar2009_d3dx9_41_x64.cab
[2010.06.02 05:22:36 | 001,612,446 | ---- | C] () -- C:\Users\Stuffi\Mar2009_d3dx9_41_x86.cab
[2010.06.02 05:22:36 | 001,067,160 | ---- | C] () -- C:\Users\Stuffi\Mar2009_d3dx10_41_x64.cab
[2010.06.02 05:22:36 | 001,040,745 | ---- | C] () -- C:\Users\Stuffi\Mar2009_d3dx10_41_x86.cab
[2010.06.02 05:22:36 | 000,251,194 | ---- | C] () -- C:\Users\Stuffi\Mar2008_XAudio_x64.cab
[2010.06.02 05:22:36 | 000,226,250 | ---- | C] () -- C:\Users\Stuffi\Mar2008_XAudio_x86.cab
[2010.06.02 05:22:36 | 000,122,336 | ---- | C] () -- C:\Users\Stuffi\Mar2008_XACT_x64.cab
[2010.06.02 05:22:36 | 000,093,734 | ---- | C] () -- C:\Users\Stuffi\Mar2008_XACT_x86.cab
[2010.06.02 05:22:34 | 001,769,862 | ---- | C] () -- C:\Users\Stuffi\Mar2008_d3dx9_37_x64.cab
[2010.06.02 05:22:34 | 001,443,282 | ---- | C] () -- C:\Users\Stuffi\Mar2008_d3dx9_37_x86.cab
[2010.06.02 05:22:34 | 000,818,260 | ---- | C] () -- C:\Users\Stuffi\Mar2008_d3dx10_37_x86.cab
[2010.06.02 05:22:34 | 000,055,058 | ---- | C] () -- C:\Users\Stuffi\Mar2008_X3DAudio_x64.cab
[2010.06.02 05:22:34 | 000,021,867 | ---- | C] () -- C:\Users\Stuffi\Mar2008_X3DAudio_x86.cab
[2010.06.02 05:22:32 | 000,937,246 | ---- | C] () -- C:\Users\Stuffi\Jun2010_d3dx9_43_x64.cab
[2010.06.02 05:22:32 | 000,844,884 | ---- | C] () -- C:\Users\Stuffi\Mar2008_d3dx10_37_x64.cab
[2010.06.02 05:22:32 | 000,768,036 | ---- | C] () -- C:\Users\Stuffi\Jun2010_d3dx9_43_x86.cab
[2010.06.02 05:22:32 | 000,278,060 | ---- | C] () -- C:\Users\Stuffi\Jun2010_XAudio_x86.cab
[2010.06.02 05:22:32 | 000,277,338 | ---- | C] () -- C:\Users\Stuffi\Jun2010_XAudio_x64.cab
[2010.06.02 05:22:32 | 000,124,596 | ---- | C] () -- C:\Users\Stuffi\Jun2010_XACT_x64.cab
[2010.06.02 05:22:32 | 000,093,686 | ---- | C] () -- C:\Users\Stuffi\Jun2010_XACT_x86.cab
[2010.06.02 05:22:30 | 000,762,188 | ---- | C] () -- C:\Users\Stuffi\Jun2010_d3dcsx_43_x86.cab
[2010.06.02 05:22:30 | 000,235,955 | ---- | C] () -- C:\Users\Stuffi\Jun2010_d3dx10_43_x64.cab
[2010.06.02 05:22:30 | 000,197,283 | ---- | C] () -- C:\Users\Stuffi\Jun2010_d3dx10_43_x86.cab
[2010.06.02 05:22:30 | 000,138,205 | ---- | C] () -- C:\Users\Stuffi\Jun2010_d3dx11_43_x64.cab
[2010.06.02 05:22:30 | 000,109,445 | ---- | C] () -- C:\Users\Stuffi\Jun2010_d3dx11_43_x86.cab
[2010.06.02 05:22:28 | 000,944,460 | ---- | C] () -- C:\Users\Stuffi\Jun2010_D3DCompiler_43_x64.cab
[2010.06.02 05:22:28 | 000,931,471 | ---- | C] () -- C:\Users\Stuffi\Jun2010_D3DCompiler_43_x86.cab
[2010.06.02 05:22:28 | 000,752,783 | ---- | C] () -- C:\Users\Stuffi\Jun2010_d3dcsx_43_x64.cab
[2010.06.02 05:22:20 | 000,269,024 | ---- | C] () -- C:\Users\Stuffi\JUN2008_XAudio_x86.cab
[2010.06.02 05:22:18 | 001,792,608 | ---- | C] () -- C:\Users\Stuffi\JUN2008_d3dx9_38_x64.cab
[2010.06.02 05:22:18 | 001,463,878 | ---- | C] () -- C:\Users\Stuffi\JUN2008_d3dx9_38_x86.cab
[2010.06.02 05:22:18 | 000,867,828 | ---- | C] () -- C:\Users\Stuffi\JUN2008_d3dx10_38_x64.cab
[2010.06.02 05:22:18 | 000,849,919 | ---- | C] () -- C:\Users\Stuffi\JUN2008_d3dx10_38_x86.cab
[2010.06.02 05:22:18 | 000,269,628 | ---- | C] () -- C:\Users\Stuffi\JUN2008_XAudio_x64.cab
[2010.06.02 05:22:18 | 000,152,909 | ---- | C] () -- C:\Users\Stuffi\JUN2007_XACT_x86.cab
[2010.06.02 05:22:18 | 000,121,054 | ---- | C] () -- C:\Users\Stuffi\JUN2008_XACT_x64.cab
[2010.06.02 05:22:18 | 000,093,128 | ---- | C] () -- C:\Users\Stuffi\JUN2008_XACT_x86.cab
[2010.06.02 05:22:18 | 000,055,154 | ---- | C] () -- C:\Users\Stuffi\JUN2008_X3DAudio_x64.cab
[2010.06.02 05:22:18 | 000,021,905 | ---- | C] () -- C:\Users\Stuffi\JUN2008_X3DAudio_x86.cab
[2010.06.02 05:22:16 | 001,607,774 | ---- | C] () -- C:\Users\Stuffi\JUN2007_d3dx9_34_x64.cab
[2010.06.02 05:22:16 | 001,607,286 | ---- | C] () -- C:\Users\Stuffi\JUN2007_d3dx9_34_x86.cab
[2010.06.02 05:22:16 | 001,064,925 | ---- | C] () -- C:\Users\Stuffi\Jun2005_d3dx9_26_x86.cab
[2010.06.02 05:22:16 | 000,699,044 | ---- | C] () -- C:\Users\Stuffi\JUN2007_d3dx10_34_x64.cab
[2010.06.02 05:22:16 | 000,698,472 | ---- | C] () -- C:\Users\Stuffi\JUN2007_d3dx10_34_x86.cab
[2010.06.02 05:22:16 | 000,197,122 | ---- | C] () -- C:\Users\Stuffi\JUN2007_XACT_x64.cab
[2010.06.02 05:22:16 | 000,180,785 | ---- | C] () -- C:\Users\Stuffi\JUN2006_XACT_x64.cab
[2010.06.02 05:22:16 | 000,133,671 | ---- | C] () -- C:\Users\Stuffi\JUN2006_XACT_x86.cab
[2010.06.02 05:22:14 | 001,336,002 | ---- | C] () -- C:\Users\Stuffi\Jun2005_d3dx9_26_x64.cab
[2010.06.02 05:22:14 | 000,277,191 | ---- | C] () -- C:\Users\Stuffi\Feb2010_XAudio_x86.cab
[2010.06.02 05:22:14 | 000,276,960 | ---- | C] () -- C:\Users\Stuffi\Feb2010_XAudio_x64.cab
[2010.06.02 05:22:14 | 000,122,446 | ---- | C] () -- C:\Users\Stuffi\Feb2010_XACT_x64.cab
[2010.06.02 05:22:14 | 000,093,180 | ---- | C] () -- C:\Users\Stuffi\Feb2010_XACT_x86.cab
[2010.06.02 05:22:12 | 000,194,675 | ---- | C] () -- C:\Users\Stuffi\FEB2007_XACT_x64.cab
[2010.06.02 05:22:12 | 000,147,983 | ---- | C] () -- C:\Users\Stuffi\FEB2007_XACT_x86.cab
[2010.06.02 05:22:12 | 000,054,678 | ---- | C] () -- C:\Users\Stuffi\Feb2010_X3DAudio_x64.cab
[2010.06.02 05:22:12 | 000,020,713 | ---- | C] () -- C:\Users\Stuffi\Feb2010_X3DAudio_x86.cab
[2010.06.02 05:22:10 | 000,178,359 | ---- | C] () -- C:\Users\Stuffi\Feb2006_XACT_x64.cab
[2010.06.02 05:22:10 | 000,132,409 | ---- | C] () -- C:\Users\Stuffi\Feb2006_XACT_x86.cab
[2010.06.02 05:22:04 | 001,084,720 | ---- | C] () -- C:\Users\Stuffi\Feb2006_d3dx9_29_x86.cab
[2010.06.02 05:22:02 | 001,801,048 | ---- | C] () -- C:\Users\Stuffi\dsetup32.dll
[2010.06.02 05:22:02 | 001,574,376 | ---- | C] () -- C:\Users\Stuffi\DEC2006_d3dx9_32_x86.cab
[2010.06.02 05:22:02 | 001,362,796 | ---- | C] () -- C:\Users\Stuffi\Feb2006_d3dx9_29_x64.cab
[2010.06.02 05:22:02 | 001,247,499 | ---- | C] () -- C:\Users\Stuffi\Feb2005_d3dx9_24_x64.cab
[2010.06.02 05:22:02 | 001,013,225 | ---- | C] () -- C:\Users\Stuffi\Feb2005_d3dx9_24_x86.cab
[2010.06.02 05:22:02 | 000,192,475 | ---- | C] () -- C:\Users\Stuffi\DEC2006_XACT_x64.cab
[2010.06.02 05:22:02 | 000,145,599 | ---- | C] () -- C:\Users\Stuffi\DEC2006_XACT_x86.cab
[2010.06.02 05:22:02 | 000,094,011 | ---- | C] () -- C:\Users\Stuffi\dxupdate.cab
[2010.06.02 05:22:02 | 000,042,410 | ---- | C] () -- C:\Users\Stuffi\dxdllreg_x86.cab
[2010.06.02 05:22:00 | 001,571,154 | ---- | C] () -- C:\Users\Stuffi\DEC2006_d3dx9_32_x64.cab
[2010.06.02 05:22:00 | 001,357,976 | ---- | C] () -- C:\Users\Stuffi\Dec2005_d3dx9_28_x64.cab
[2010.06.02 05:22:00 | 001,079,456 | ---- | C] () -- C:\Users\Stuffi\Dec2005_d3dx9_28_x86.cab
[2010.06.02 05:22:00 | 000,273,264 | ---- | C] () -- C:\Users\Stuffi\Aug2009_XAudio_x64.cab
[2010.06.02 05:22:00 | 000,272,642 | ---- | C] () -- C:\Users\Stuffi\Aug2009_XAudio_x86.cab
[2010.06.02 05:22:00 | 000,212,807 | ---- | C] () -- C:\Users\Stuffi\DEC2006_d3dx10_00_x64.cab
[2010.06.02 05:22:00 | 000,191,720 | ---- | C] () -- C:\Users\Stuffi\DEC2006_d3dx10_00_x86.cab
[2010.06.02 05:22:00 | 000,122,408 | ---- | C] () -- C:\Users\Stuffi\Aug2009_XACT_x64.cab
[2010.06.02 05:22:00 | 000,093,106 | ---- | C] () -- C:\Users\Stuffi\Aug2009_XACT_x86.cab
[2010.06.02 05:21:58 | 000,930,116 | ---- | C] () -- C:\Users\Stuffi\Aug2009_d3dx9_42_x64.cab
[2010.06.02 05:21:58 | 000,728,456 | ---- | C] () -- C:\Users\Stuffi\Aug2009_d3dx9_42_x86.cab
[2010.06.02 05:21:58 | 000,232,635 | ---- | C] () -- C:\Users\Stuffi\Aug2009_d3dx10_42_x64.cab
[2010.06.02 05:21:58 | 000,192,131 | ---- | C] () -- C:\Users\Stuffi\Aug2009_d3dx10_42_x86.cab
[2010.06.02 05:21:58 | 000,136,301 | ---- | C] () -- C:\Users\Stuffi\Aug2009_d3dx11_42_x64.cab
[2010.06.02 05:21:58 | 000,105,044 | ---- | C] () -- C:\Users\Stuffi\Aug2009_d3dx11_42_x86.cab
[2010.06.02 05:21:56 | 003,319,740 | ---- | C] () -- C:\Users\Stuffi\Aug2009_d3dcsx_42_x86.cab
[2010.06.02 05:21:56 | 003,112,111 | ---- | C] () -- C:\Users\Stuffi\Aug2009_d3dcsx_42_x64.cab
[2010.06.02 05:21:56 | 000,900,598 | ---- | C] () -- C:\Users\Stuffi\Aug2009_D3DCompiler_42_x86.cab
[2010.06.02 05:21:46 | 000,919,044 | ---- | C] () -- C:\Users\Stuffi\Aug2009_D3DCompiler_42_x64.cab
[2010.06.02 05:21:46 | 000,271,412 | ---- | C] () -- C:\Users\Stuffi\Aug2008_XAudio_x64.cab
[2010.06.02 05:21:46 | 000,271,038 | ---- | C] () -- C:\Users\Stuffi\Aug2008_XAudio_x86.cab
[2010.06.02 05:21:44 | 001,794,084 | ---- | C] () -- C:\Users\Stuffi\Aug2008_d3dx9_39_x64.cab
[2010.06.02 05:21:44 | 001,464,672 | ---- | C] () -- C:\Users\Stuffi\Aug2008_d3dx9_39_x86.cab
[2010.06.02 05:21:44 | 000,849,167 | ---- | C] () -- C:\Users\Stuffi\Aug2008_d3dx10_39_x86.cab
[2010.06.02 05:21:44 | 000,198,096 | ---- | C] () -- C:\Users\Stuffi\AUG2007_XACT_x64.cab
[2010.06.02 05:21:44 | 000,153,012 | ---- | C] () -- C:\Users\Stuffi\AUG2007_XACT_x86.cab
[2010.06.02 05:21:44 | 000,121,772 | ---- | C] () -- C:\Users\Stuffi\Aug2008_XACT_x64.cab
[2010.06.02 05:21:44 | 000,092,996 | ---- | C] () -- C:\Users\Stuffi\Aug2008_XACT_x86.cab
[2010.06.02 05:21:42 | 001,800,160 | ---- | C] () -- C:\Users\Stuffi\AUG2007_d3dx9_35_x64.cab
[2010.06.02 05:21:42 | 001,708,152 | ---- | C] () -- C:\Users\Stuffi\AUG2007_d3dx9_35_x86.cab
[2010.06.02 05:21:42 | 000,867,612 | ---- | C] () -- C:\Users\Stuffi\Aug2008_d3dx10_39_x64.cab
[2010.06.02 05:21:42 | 000,852,286 | ---- | C] () -- C:\Users\Stuffi\AUG2007_d3dx10_35_x64.cab
[2010.06.02 05:21:42 | 000,796,867 | ---- | C] () -- C:\Users\Stuffi\AUG2007_d3dx10_35_x86.cab
[2010.06.02 05:21:40 | 001,350,542 | ---- | C] () -- C:\Users\Stuffi\Aug2005_d3dx9_27_x64.cab
[2010.06.02 05:21:40 | 001,077,644 | ---- | C] () -- C:\Users\Stuffi\Aug2005_d3dx9_27_x86.cab
[2010.06.02 05:21:40 | 000,182,903 | ---- | C] () -- C:\Users\Stuffi\AUG2006_XACT_x64.cab
[2010.06.02 05:21:40 | 000,137,235 | ---- | C] () -- C:\Users\Stuffi\AUG2006_XACT_x86.cab
[2010.06.02 05:21:40 | 000,087,142 | ---- | C] () -- C:\Users\Stuffi\AUG2006_xinput_x64.cab
[2010.06.02 05:21:40 | 000,053,302 | ---- | C] () -- C:\Users\Stuffi\APR2007_xinput_x86.cab
[2010.06.02 05:21:40 | 000,046,058 | ---- | C] () -- C:\Users\Stuffi\AUG2006_xinput_x86.cab
[2010.06.02 05:21:38 | 001,606,039 | ---- | C] () -- C:\Users\Stuffi\APR2007_d3dx9_33_x86.cab
[2010.06.02 05:21:38 | 000,195,766 | ---- | C] () -- C:\Users\Stuffi\APR2007_XACT_x64.cab
[2010.06.02 05:21:38 | 000,151,225 | ---- | C] () -- C:\Users\Stuffi\APR2007_XACT_x86.cab
[2010.06.02 05:21:38 | 000,096,817 | ---- | C] () -- C:\Users\Stuffi\APR2007_xinput_x64.cab
[2010.06.02 05:21:36 | 001,607,358 | ---- | C] () -- C:\Users\Stuffi\APR2007_d3dx9_33_x64.cab
[2010.06.02 05:21:36 | 000,698,612 | ---- | C] () -- C:\Users\Stuffi\APR2007_d3dx10_33_x64.cab
[2010.06.02 05:21:36 | 000,695,865 | ---- | C] () -- C:\Users\Stuffi\APR2007_d3dx10_33_x86.cab
[2010.06.02 05:21:34 | 000,046,010 | ---- | C] () -- C:\Users\Stuffi\Apr2006_xinput_x86.cab
[2010.06.02 05:21:20 | 000,087,101 | ---- | C] () -- C:\Users\Stuffi\Apr2006_xinput_x64.cab
[2010.06.02 05:21:18 | 004,162,630 | ---- | C] () -- C:\Users\Stuffi\Apr2006_MDX1_x86_Archive.cab
[2010.06.02 05:21:18 | 000,916,430 | ---- | C] () -- C:\Users\Stuffi\Apr2006_MDX1_x86.cab
[2010.06.02 05:21:18 | 000,179,133 | ---- | C] () -- C:\Users\Stuffi\Apr2006_XACT_x64.cab
[2010.06.02 05:21:18 | 000,133,103 | ---- | C] () -- C:\Users\Stuffi\Apr2006_XACT_x86.cab
[2010.06.02 05:21:16 | 001,397,830 | ---- | C] () -- C:\Users\Stuffi\Apr2006_d3dx9_30_x64.cab
[2010.06.02 05:21:16 | 001,347,354 | ---- | C] () -- C:\Users\Stuffi\Apr2005_d3dx9_25_x64.cab
[2010.06.02 05:21:16 | 001,115,221 | ---- | C] () -- C:\Users\Stuffi\Apr2006_d3dx9_30_x86.cab
[2010.06.02 05:21:16 | 001,078,962 | ---- | C] () -- C:\Users\Stuffi\Apr2005_d3dx9_25_x86.cab
[2010.05.04 21:26:15 | 000,000,000 | ---- | C] () -- C:\Windows\PanelExe.INI
[2010.05.04 21:25:24 | 000,000,000 | ---- | C] () -- C:\Windows\FileMgrExe.INI
[2010.04.02 19:06:14 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.02.11 09:55:58 | 000,000,098 | ---- | C] () -- C:\Windows\etkinst.ini
[2010.01.12 15:26:50 | 000,290,816 | ---- | C] () -- C:\Windows\System32\decdll.dll
[2009.12.11 18:47:37 | 000,307,200 | ---- | C] () -- C:\Windows\System32\AscSQLite.dll
[2009.11.20 13:21:55 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2009.11.17 11:19:03 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2009.11.17 11:19:01 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2009.10.08 20:28:17 | 000,000,019 | ---- | C] () -- C:\Windows\KNP.INI
[2009.08.03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009.07.20 16:01:56 | 000,016,070 | ---- | C] () -- C:\Windows\German2.ini
[2009.07.13 13:02:12 | 000,000,321 | ---- | C] () -- C:\Windows\Sampler.INI
[2009.07.13 13:02:10 | 000,000,344 | ---- | C] () -- C:\Windows\BeatBox.INI
[2009.07.13 09:08:03 | 000,000,086 | ---- | C] () -- C:\Windows\MusicMaker.INI
[2009.06.19 15:42:36 | 000,000,094 | ---- | C] () -- C:\Users\Stuffi\AppData\Local\fusioncache.dat
[2009.05.23 21:23:04 | 000,000,008 | ---- | C] () -- C:\Users\Stuffi\AppData\Roaming\NMM-MetaData.db
[2009.04.03 12:38:59 | 000,001,351 | ---- | C] () -- C:\Windows\psmplay.ini
[2009.04.02 08:25:16 | 000,000,025 | ---- | C] () -- C:\Windows\MotoSkin.INI
[2009.04.02 07:30:08 | 000,009,913 | ---- | C] () -- C:\Users\Stuffi\MCCI_MDM.INF
[2009.04.02 07:30:08 | 000,006,989 | ---- | C] () -- C:\Users\Stuffi\MCCI_BUS.INF
[2009.04.02 07:30:08 | 000,004,477 | ---- | C] () -- C:\Users\Stuffi\MCCI_SDM.INF
[2009.04.02 07:30:05 | 000,020,848 | ---- | C] () -- C:\Users\Stuffi\1238650205-(null) - Kopie
[2009.04.02 07:30:05 | 000,015,884 | ---- | C] () -- C:\Users\Stuffi\1238650204-(null) - Kopie (7)
[2009.04.02 07:30:05 | 000,009,232 | ---- | C] () -- C:\Users\Stuffi\1238650205-(null)
[2009.04.02 07:30:04 | 000,018,104 | ---- | C] () -- C:\Users\Stuffi\1238650204-(null) - Kopie
[2009.04.02 07:30:04 | 000,016,524 | ---- | C] () -- C:\Users\Stuffi\1238650204-(null) - Kopie (3)
[2009.04.02 07:30:04 | 000,016,348 | ---- | C] () -- C:\Users\Stuffi\1238650204-(null) - Kopie (5)
[2009.04.02 07:30:04 | 000,006,947 | ---- | C] () -- C:\Users\Stuffi\1238650204-(null)
[2009.04.02 07:30:04 | 000,006,009 | ---- | C] () -- C:\Users\Stuffi\1238650204-(null) - Kopie (4)
[2009.04.02 07:30:04 | 000,005,877 | ---- | C] () -- C:\Users\Stuffi\1238650204-(null) - Kopie (2)
[2009.04.02 07:30:04 | 000,005,813 | ---- | C] () -- C:\Users\Stuffi\1238650204-(null) - Kopie (6)
[2009.04.02 07:19:25 | 000,009,232 | ---- | C] () -- C:\Users\Stuffi\USB_MOT_BRIT.INF
[2009.04.02 07:19:25 | 000,007,201 | ---- | C] () -- C:\Users\Stuffi\USBMOT2000.INF
[2009.04.02 07:19:25 | 000,006,141 | ---- | C] () -- C:\Users\Stuffi\USBMOT2000XP.INF
[2009.04.02 07:19:25 | 000,005,960 | ---- | C] () -- C:\Users\Stuffi\USB_MOT_A1000.INF
[2009.04.02 07:19:25 | 000,005,880 | ---- | C] () -- C:\Users\Stuffi\USB_CMCS_2000.INF
[2009.04.02 07:19:20 | 000,025,424 | ---- | C] () -- C:\Users\Stuffi\1238649560-oem44.PNF
[2009.04.02 07:19:20 | 000,010,070 | ---- | C] () -- C:\Users\Stuffi\1238649560-oem44.inf
[2009.04.02 07:18:42 | 000,044,865 | ---- | C] () -- C:\Users\Stuffi\Motorola_Driver_Log.txt
[2009.02.23 14:05:15 | 000,000,028 | ---- | C] () -- C:\Windows\Robota.INI
[2009.02.23 13:35:54 | 000,053,248 | ---- | C] () -- C:\Windows\System32\mgxasio2.dll
[2009.02.23 13:33:53 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2009.02.22 00:10:44 | 000,000,016 | -H-- | C] () -- C:\Users\Stuffi\AppData\Roaming\mxfilerelatedcache.mxc2
[2009.02.22 00:10:43 | 000,000,016 | -H-- | C] () -- C:\Users\Stuffi\AppData\Local\mxfilerelatedcache.mxc2
[2009.02.19 22:51:29 | 000,000,000 | ---- | C] () -- C:\Windows\OODCNT.INI
[2009.02.19 22:24:09 | 000,000,000 | ---- | C] () -- C:\Windows\ToDisc.INI
[2009.01.31 00:28:29 | 000,114,816 | ---- | C] () -- C:\Windows\System32\MSMT4232.DLL
[2009.01.31 00:14:00 | 000,000,409 | ---- | C] () -- C:\Windows\cmbtll.ini
[2009.01.31 00:14:00 | 000,000,185 | ---- | C] () -- C:\Windows\cmbtctl.ini
[2009.01.31 00:11:18 | 000,000,091 | ---- | C] () -- C:\Windows\combit.ini
[2009.01.31 00:11:18 | 000,000,063 | ---- | C] () -- C:\Windows\VISKARTE.INI
[2008.12.27 23:11:31 | 000,073,216 | ---- | C] () -- C:\Windows\System32\drivers\sentinel.sys
[2008.12.27 23:11:31 | 000,002,421 | ---- | C] () -- C:\Windows\System32\drivers\enport.sys
[2008.12.17 08:48:21 | 000,000,016 | -H-- | C] () -- C:\Users\Stuffi\mxfilerelatedcache.mxc2
[2008.12.14 12:59:10 | 000,000,377 | ---- | C] () -- C:\Users\Stuffi\Dokumente - Verknüpfung.lnk
[2008.12.08 14:02:04 | 000,005,456 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2008.12.06 19:49:18 | 000,000,039 | ---- | C] () -- C:\Windows\Irremote.ini
[2008.11.15 13:17:25 | 000,000,665 | ---- | C] () -- C:\Windows\Lexstat.ini
[2008.11.15 12:49:50 | 000,344,064 | ---- | C] () -- C:\Windows\System32\lxbccoin.dll
[2008.11.15 12:49:50 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxbcvs.dll
[2008.11.14 13:55:42 | 000,000,050 | ---- | C] () -- C:\Windows\MegaManager.INI
[2008.10.27 20:50:20 | 000,228,354 | ---- | C] () -- C:\Users\Stuffi\AppData\Local\wgymqui_nav.dat
[2008.10.27 20:50:20 | 000,005,024 | ---- | C] () -- C:\Users\Stuffi\AppData\Local\wgymqui.dat
[2008.10.27 20:50:20 | 000,001,704 | ---- | C] () -- C:\Users\Stuffi\AppData\Local\wgymqui_navps.dat
[2008.10.01 14:18:32 | 000,000,020 | -HS- | C] () -- C:\Users\Stuffi\ntuser.ini
[2008.08.14 15:33:46 | 000,035,024 | ---- | C] () -- C:\Windows\System32\drivers\fses.sys
[2008.06.21 20:49:04 | 000,001,294 | ---- | C] () -- C:\Windows\wininit.ini
[2008.04.28 23:19:56 | 000,524,288 | -HS- | C] () -- C:\Users\Stuffi\ntuser.dat{06b0b65a-1567-11dd-b098-001a92fa7b35}.TMContainer00000000000000000002.regtrans-ms
[2008.04.28 12:11:16 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008.04.28 12:11:16 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008.04.28 12:11:16 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008.04.28 12:11:16 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008.04.28 12:11:16 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008.04.28 12:11:16 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008.04.28 12:11:16 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008.04.28 12:11:16 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008.04.28 12:11:16 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008.04.20 20:07:28 | 000,000,187 | ---- | C] () -- C:\Windows\Lcars.ini
[2008.03.30 12:50:39 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2008.02.19 22:23:13 | 000,031,007 | ---- | C] () -- C:\Users\Stuffi\AppData\Roaming\UserTile.png
[2008.02.11 19:55:18 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1437.dll
[2008.02.06 22:54:35 | 000,000,002 | ---- | C] () -- C:\Windows\msoffice.ini
[2008.01.24 02:29:14 | 000,000,952 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2008.01.20 06:26:32 | 000,000,748 | ---- | C] () -- C:\Windows\ODBC.INI
[2008.01.14 04:47:14 | 000,000,029 | ---- | C] () -- C:\Windows\games.INI
[2008.01.14 02:37:49 | 000,001,356 | ---- | C] () -- C:\Users\Stuffi\AppData\Local\d3d9caps.dat
[2008.01.14 01:33:02 | 000,191,488 | ---- | C] () -- C:\Users\Stuffi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.01.13 23:11:14 | 006,291,456 | ---- | C] () -- C:\Users\Stuffi\ntuser.dat
[2008.01.13 23:11:14 | 000,262,144 | -H-- | C] () -- C:\Users\Stuffi\ntuser.dat.LOG2
[2008.01.13 23:11:14 | 000,262,144 | -H-- | C] () -- C:\Users\Stuffi\ntuser.dat.LOG1
[2008.01.02 17:57:36 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1409.dll
[2007.05.24 14:01:06 | 000,007,119 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2007.05.24 13:35:15 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2007.05.24 13:32:29 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2007.05.24 13:32:29 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2007.05.24 13:32:29 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2007.05.24 13:32:29 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2007.05.24 13:32:29 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2007.05.24 13:32:29 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2007.05.24 13:25:55 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2007.05.24 13:24:01 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2007.05.24 13:24:01 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2007.05.24 13:24:01 | 000,010,146 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2007.05.24 13:24:01 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2007.05.24 12:48:36 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2007.05.24 12:47:57 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1244.dll
[2007.03.30 00:00:40 | 000,203,264 | R--- | C] () -- C:\Windows\System32\CddbCdda.dll
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2003.05.15 21:39:00 | 000,155,136 | ---- | C] () -- C:\Windows\System32\unrar.dll
[1996.04.03 21:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys
========== LOP Check ==========
[2008.06.09 03:38:25 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\.purple
[2010.10.04 21:54:41 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Ashampoo
[2010.04.02 17:07:11 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\avidemux
[2010.09.26 21:12:29 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Azureus
[2009.02.23 15:01:33 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Babylon
[2008.12.11 01:02:53 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\BinarySense
[2010.10.04 22:19:10 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Canneverbe Limited
[2010.09.03 16:00:05 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Carambis
[2010.07.19 14:11:58 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Cytyom
[2010.09.29 17:12:16 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\DAEMON Tools
[2009.07.13 00:00:39 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\DarkWave Studio
[2009.12.02 07:57:57 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Desktopicon
[2009.03.08 16:08:42 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Dexpot
[2010.07.20 09:28:43 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Foxit Software
[2010.02.08 15:18:19 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\FreeVideoConverter
[2008.12.19 00:26:15 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\GibbHill Properties Ltd
[2009.04.22 07:59:43 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\GMX
[2010.07.14 14:47:32 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\gtk-2.0
[2008.05.15 02:44:42 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\ICQ
[2008.05.15 02:18:45 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\ICQ Toolbar
[2009.08.12 13:45:04 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Image Zone Express
[2008.05.23 05:55:23 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\IrfanView
[2009.08.15 17:52:11 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Leadertech
[2009.03.07 14:49:18 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\LimeWire
[2010.08.24 17:00:32 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Lionhead Studios
[2009.07.16 13:12:25 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\MAGIX
[2010.09.29 11:51:23 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Mairyh
[2008.11.14 13:51:29 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Megaupload
[2008.05.12 21:39:42 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Miranda
[2009.05.23 21:23:05 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Nokia
[2009.03.30 19:33:49 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\OpenOffice.org
[2010.08.13 12:55:19 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Opera
[2010.10.06 21:24:53 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Ossy
[2010.08.03 20:13:49 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Otheoz
[2008.01.18 14:38:33 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Participatory Culture Foundation
[2008.09.13 18:49:42 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\PC Suite
[2008.10.11 22:08:35 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\PCF-VLC
[2008.02.19 22:23:13 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\PeerNetworking
[2010.09.11 12:40:23 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\pics
[2008.12.08 15:52:13 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Printer Info Cache
[2010.09.28 19:02:03 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\QuickScan
[2010.01.25 08:42:25 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\RDecke
[2010.09.14 20:07:35 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Scribus
[2009.03.18 21:39:15 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Shareaza
[2008.02.07 16:09:48 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\SmartSurfer
[2008.10.15 11:00:59 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Spamihilator
[2008.08.25 17:45:59 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\TomTom
[2009.03.04 23:16:55 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Toshiba
[2008.01.14 14:53:08 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\TuneUp Software
[2010.02.05 21:54:20 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\TuxPaint
[2009.11.17 11:25:39 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Ubisoft
[2008.03.04 12:37:01 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Ulead Systems
[2009.10.21 21:19:00 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\UltimateZip
[2008.09.04 17:04:32 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\uTorrent
[2008.03.04 11:50:21 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\WEBDE
[2008.11.24 23:33:49 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Wormux
[2010.04.02 09:50:38 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Xilisoft
[2010.10.07 07:04:18 | 000,032,580 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2008.06.09 03:38:25 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\.purple
[2008.12.17 09:46:53 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Adobe
[2010.04.02 19:34:28 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Ahead
[2008.02.06 22:55:06 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\AOL
[2009.10.31 11:25:29 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Apple Computer
[2010.10.04 21:54:41 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Ashampoo
[2010.04.02 17:07:11 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\avidemux
[2009.04.10 11:41:32 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\AVS4YOU
[2010.09.26 21:12:29 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Azureus
[2009.02.23 15:01:33 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Babylon
[2008.12.11 01:02:53 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\BinarySense
[2010.10.04 22:19:10 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Canneverbe Limited
[2010.09.03 16:00:05 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Carambis
[2010.07.19 14:11:58 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Cytyom
[2010.09.29 17:12:16 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\DAEMON Tools
[2009.07.13 00:00:39 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\DarkWave Studio
[2009.12.02 07:57:57 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Desktopicon
[2009.03.08 16:08:42 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Dexpot
[2008.01.19 17:34:28 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\DivX
[2010.09.29 17:12:16 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\dvdcss
[2009.06.25 01:30:04 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\dvdcss-BackupByVLCPortable
[2010.07.20 09:28:43 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Foxit Software
[2010.02.08 15:18:19 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\FreeVideoConverter
[2008.12.19 00:26:15 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\GibbHill Properties Ltd
[2009.04.22 07:59:43 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\GMX
[2008.09.16 16:04:12 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Google
[2010.07.14 14:47:32 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\gtk-2.0
[2008.12.08 22:17:04 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\HP
[2008.05.15 02:44:42 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\ICQ
[2008.05.15 02:18:45 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\ICQ Toolbar
[2008.01.13 23:13:56 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Identities
[2009.08.12 13:45:04 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Image Zone Express
[2008.01.24 02:24:55 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\InstallShield
[2008.05.23 05:55:23 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\IrfanView
[2009.08.15 17:52:11 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Leadertech
[2009.03.07 14:49:18 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\LimeWire
[2010.08.24 17:00:32 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Lionhead Studios
[2008.01.14 00:45:48 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Macromedia
[2009.07.16 13:12:25 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\MAGIX
[2010.09.29 11:51:23 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Mairyh
[2009.01.12 16:12:31 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Malwarebytes
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Media Center Programs
[2008.11.14 13:51:29 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Megaupload
[2010.10.06 08:28:03 | 000,000,000 | --SD | M] -- C:\Users\Stuffi\AppData\Roaming\Microsoft
[2008.05.12 21:39:42 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Miranda
[2008.04.01 19:52:16 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Mozilla
[2010.04.18 14:51:18 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Nero
[2009.05.23 21:23:05 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Nokia
[2009.03.30 19:33:49 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\OpenOffice.org
[2010.08.13 12:55:19 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Opera
[2010.10.06 21:24:53 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Ossy
[2010.08.03 20:13:49 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Otheoz
[2008.01.18 14:38:33 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Participatory Culture Foundation
[2008.09.13 18:49:42 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\PC Suite
[2008.10.11 22:08:35 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\PCF-VLC
[2008.02.19 22:23:13 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\PeerNetworking
[2010.09.11 12:40:23 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\pics
[2008.12.08 15:52:13 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Printer Info Cache
[2010.09.28 19:02:03 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\QuickScan
[2010.01.25 08:42:25 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\RDecke
[2008.11.24 19:07:22 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Real
[2010.09.14 20:07:35 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Scribus
[2009.03.18 21:39:15 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Shareaza
[2010.03.05 13:13:38 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Skype
[2010.03.05 13:13:25 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\skypePM
[2008.02.07 16:09:48 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\SmartSurfer
[2008.10.15 11:00:59 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Spamihilator
[2008.11.14 10:04:54 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\teamspeak2
[2008.08.25 17:45:59 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\TomTom
[2009.03.04 23:16:55 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Toshiba
[2008.01.14 14:53:08 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\TuneUp Software
[2010.02.05 21:54:20 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\TuxPaint
[2009.11.17 11:25:39 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Ubisoft
[2008.03.04 12:37:01 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Ulead Systems
[2009.10.21 21:19:00 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\UltimateZip
[2008.09.04 17:04:32 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\uTorrent
[2010.10.07 12:03:42 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\vlc
[2008.03.04 11:50:21 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\WEBDE
[2010.04.25 09:03:33 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Winamp
[2008.01.14 00:51:52 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\WinRAR
[2008.11.24 23:33:49 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Wormux
[2010.04.02 09:50:38 | 000,000,000 | ---D | M] -- C:\Users\Stuffi\AppData\Roaming\Xilisoft
< %APPDATA%\*.exe /s >
[2009.02.08 13:28:23 | 000,010,134 | R--- | M] () -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{23BB7035-B5A4-47B1-81E4-51E88A31F3DD}\ARPPRODUCTICON.exe
[2009.02.08 13:28:24 | 000,008,854 | R--- | M] () -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{23BB7035-B5A4-47B1-81E4-51E88A31F3DD}\ck_software.de.url_49086A1D874D4FBC906FEF470C7CE829.exe
[2009.02.08 13:28:24 | 000,204,800 | R--- | M] (Macrovision Corporation) -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{23BB7035-B5A4-47B1-81E4-51E88A31F3DD}\visitenkarten.exe1_49086A1D874D4FBC906FEF470C7CE829.exe
[2009.02.08 13:28:24 | 000,204,800 | R--- | M] (Macrovision Corporation) -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{23BB7035-B5A4-47B1-81E4-51E88A31F3DD}\visitenkarten.exe_49086A1D874D4FBC906FEF470C7CE829.exe
[2009.03.13 17:02:17 | 000,010,134 | R--- | M] () -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{81BEDFC2-CD4B-4D3B-AF88-2EE7EAEC812F}\_27FC0B1E244C1D46306F2A.exe
[2009.03.13 17:02:17 | 000,134,984 | R--- | M] () -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{81BEDFC2-CD4B-4D3B-AF88-2EE7EAEC812F}\_6EEA5261A5E665D26E8C80.exe
[2009.03.13 17:02:17 | 000,010,134 | R--- | M] () -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{81BEDFC2-CD4B-4D3B-AF88-2EE7EAEC812F}\_C7356206FDA831A9E3AF79.exe
[2009.03.13 17:02:17 | 000,134,984 | R--- | M] () -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{81BEDFC2-CD4B-4D3B-AF88-2EE7EAEC812F}\_E4F363F9282A42AFED0EE1.exe
[2009.03.11 18:32:00 | 000,040,960 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
[2009.03.11 18:32:01 | 000,040,960 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
[2009.03.11 18:32:01 | 000,008,854 | R--- | M] () -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\Uninstall_Project64__9559F7CA5E344237A2D9D856464AD727.exe
[2010.09.11 17:32:19 | 000,015,086 | R--- | M] () -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{A8EC49E4-5EB8-444C-8CE0-446904D5E629}\_6FEFF9B68218417F98F549.exe
[2010.09.11 17:32:20 | 000,015,086 | R--- | M] () -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{A8EC49E4-5EB8-444C-8CE0-446904D5E629}\_7388FD78BF342A77A38BCE.exe
[2010.09.11 17:32:20 | 000,015,086 | R--- | M] () -- C:\Users\Stuffi\AppData\Roaming\Microsoft\Installer\{A8EC49E4-5EB8-444C-8CE0-446904D5E629}\_831906F2FDA02E6A09BEB0.exe
< %SYSTEMDRIVE%\*.exe >
[2010.04.19 09:11:09 | 000,019,286 | ---- | M] () -- C:\cleanup.exe
[2007.03.22 01:10:01 | 000,229,440 | ---- | M] () -- C:\KeyViewer.exe
[2007.03.16 02:23:58 | 000,304,048 | ---- | M] ( ) -- C:\Setup.exe
< MD5 for: AGP440.SYS >
[2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009.04.10 23:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\drivers\atapi.sys
[2008.01.18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.03.07 04:05:10 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.03.07 04:05:10 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.03.07 04:05:09 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: EXPLORER.EXE >
[2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\explorer.exe
[2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008.10.30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2008.01.14 04:23:40 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2008.01.14 04:23:39 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009.04.10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008.10.28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006.11.02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008.01.18 23:33:12 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: IASTORV.SYS >
[2008.01.18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: KR10N.SYS >
[2007.01.18 16:47:18 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) MD5=6E9922332386C2A49936B30B2B6FD298 -- C:\Toshiba\Drivers\Raid\Kr10i\KR10N.sys
[2007.01.18 16:47:18 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) MD5=6E9922332386C2A49936B30B2B6FD298 -- C:\Toshiba\Drivers\Raid\Kr10n\KR10N.sys
[2007.01.18 16:47:18 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) MD5=6E9922332386C2A49936B30B2B6FD298 -- C:\Windows\System32\drivers\KR10N.sys
[2007.01.18 16:47:18 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) MD5=6E9922332386C2A49936B30B2B6FD298 -- C:\Windows\System32\DriverStore\FileRepository\kr10.inf_95888b8d\KR10N.sys
< MD5 for: NETLOGON.DLL >
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.18 23:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\System32\netlogon.dll
[2008.01.18 23:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.18 23:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.18 23:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008.01.18 23:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\System32\scecli.dll
[2008.01.18 23:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< MD5 for: USER32.DLL >
[2007.05.24 13:09:42 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=63B4F59D7C89B1BF5277F1FFEFD491CD -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_cb39bc5b7047127e\user32.dll
[2009.04.10 23:28:26 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
[2007.05.24 13:09:43 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=9D9F061EDA75425FC67F0365E3467C86 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_cbc258dc896598f1\user32.dll
[2006.11.02 11:46:13 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=E698A5437B89A285ACA3FF022356810A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_cb01aa4570716e5e\user32.dll
[2008.01.18 23:36:48 | 000,627,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2008.01.18 23:36:48 | 000,627,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
< MD5 for: USERINIT.EXE >
[2008.01.18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
< MD5 for: WINLOGON.EXE >
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.18 23:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\System32\winlogon.exe
[2008.01.18 23:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
[2008.01.18 21:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.18 21:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[1 C:\Windows\system32\drivers\*.tmp files -> C:\Windows\system32\drivers\*.tmp -> ]
< %systemroot%\System32\config\*.sav >
[2007.05.24 12:35:06 | 006,664,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2007.05.24 12:35:04 | 000,102,400 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2007.05.24 12:35:07 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2007.05.24 12:35:19 | 015,720,448 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2007.05.24 12:35:21 | 006,008,832 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008.01.18 23:38:04 | 000,242,744 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll
[2008.01.18 23:36:12 | 000,225,792 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\SLC.dll
[2010.03.05 16:01:02 | 000,420,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\vbscript.dll
[3 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
========== Alternate Data Streams ==========
@Alternate Data Stream - 192 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 16 bytes -> C:\Users\Stuffi\Documents\Shareaza Downloads:Shareaza.GUID
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:F8B88761
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:2BE9FEFC
@Alternate Data Stream - 12 bytes -> C:\Windows\System32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD}
< End of report > --- --- --- |