Code:
OTViewIt logfile created on: 07/09/2008 12:34:27 - Run 2
OTViewIt by OldTimer - Version 1.0.1.8 Folder = C:\Documents and Settings\Carsten\Desktop
Windows Server 2003 Service Pack 2 (Version = 5.2.3790) - Type = NTWorkstation
Internet Explorer (Version = 6.0.3790.1830)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
4.00 Gb Total Physical Memory | 3.33 Gb Available Physical Memory | 83.30% Memory free
3.76 Gb Paging File | 3.39 Gb Available in Paging File | 90.36% Paging File free
Paging file location(s):
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 25.00 Gb Total Space | 12.48 Gb Free Space | 49.90% Space Free | Partition Type: NTFS
Drive D: | 40.00 Gb Total Space | 29.90 Gb Free Space | 74.75% Space Free | Partition Type: NTFS
Drive E: | 150.00 Gb Total Space | 63.74 Gb Free Space | 42.49% Space Free | Partition Type: NTFS
Drive F: | 25.00 Gb Total Space | 6.02 Gb Free Space | 24.10% Space Free | Partition Type: NTFS
Drive G: | 25.00 Gb Total Space | 8.45 Gb Free Space | 33.80% Space Free | Partition Type: NTFS
Drive H: | 245.76 Gb Total Space | 6.43 Gb Free Space | 2.62% Space Free | Partition Type: NTFS
Drive I: | 245.76 Gb Total Space | 6.48 Gb Free Space | 2.64% Space Free | Partition Type: NTFS
Drive J: | 45.03 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 4.36 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: CASI
Current User Name: Carsten
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
===== Processes - Non-Microsoft Only =====
[07/19/2008 04:25 PM | 00,016,056 | ---- | M] (ALWIL Software) - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
[07/19/2008 04:38 PM | 00,147,640 | ---- | M] (ALWIL Software) - C:\Program Files\Alwil Software\Avast4\ashServ.exe
[07/19/2008 04:38 PM | 00,078,008 | ---- | M] (ALWIL Software) - C:\Program Files\Alwil Software\Avast4\ashDisp.exe
[05/14/2008 06:42 PM | 05,958,656 | ---- | M] () - C:\Program Files (x86)\ASUS\Six Engine\SixEngine.exe
===== Win32 Services - Non-Microsoft Only =====
(aswUpdSv) avast! iAVS4 Control Service [Auto | Running]
[07/19/2008 04:25 PM | 00,016,056 | ---- | M] (ALWIL Software) - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
(avast! Antivirus) avast! Antivirus [Auto | Running]
[07/19/2008 04:38 PM | 00,147,640 | ---- | M] (ALWIL Software) - C:\Program Files\Alwil Software\Avast4\ashServ.exe
(avast! Mail Scanner) avast! Mail Scanner [On_Demand | Stopped]
[07/19/2008 04:38 PM | 00,250,040 | ---- | M] (ALWIL Software) - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
(avast! Web Scanner) avast! Web Scanner [On_Demand | Stopped]
[07/23/2008 04:25 PM | 00,348,344 | ---- | M] (ALWIL Software) - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
(Creative Audio Engine Licensing Service) Creative Audio Engine Licensing Service [On_Demand | Stopped]
[08/27/2008 12:17 PM | 00,079,360 | ---- | M] (Creative Labs) - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
(dmadmin) Logical Disk Manager Administrative Service [On_Demand | Stopped]
File not found - %SystemRoot%\System32\dmadmin.exe
(Eventlog) Event Log [Auto | Running]
File not found - %SystemRoot%\system32\services.exe
(HTTPFilter) HTTP SSL [On_Demand | Stopped]
File not found - %SystemRoot%\System32\lsass.exe
(ImapiService) IMAPI CD-Burning COM Service [On_Demand | Stopped]
File not found - C:\WINDOWS\system32\imapi.exe
(MSDTC) Distributed Transaction Coordinator [On_Demand | Stopped]
File not found - C:\WINDOWS\system32\msdtc.exe
(Netlogon) Net Logon [On_Demand | Stopped]
File not found - %SystemRoot%\system32\lsass.exe
(NtLmSsp) NT LM Security Support Provider [On_Demand | Stopped]
File not found - %SystemRoot%\system32\lsass.exe
(NVSvc) NVIDIA Display Driver Service [Auto | Running]
File not found - %SystemRoot%\system32\nvsvc64.exe
(PlugPlay) Plug and Play [Auto | Running]
File not found - %SystemRoot%\system32\services.exe
(PolicyAgent) IPSEC Services [Auto | Running]
File not found - %SystemRoot%\system32\lsass.exe
(ProtectedStorage) Protected Storage [Auto | Running]
File not found - %SystemRoot%\system32\lsass.exe
(RDSessMgr) Remote Desktop Help Session Manager [On_Demand | Stopped]
File not found - C:\WINDOWS\system32\sessmgr.exe
(SamSs) Security Accounts Manager [Auto | Running]
File not found - %SystemRoot%\system32\lsass.exe
(TlntSvr) Telnet [Disabled | Stopped]
File not found - C:\WINDOWS\system32\tlntsvr.exe
(vds) Virtual Disk Service [On_Demand | Stopped]
File not found - %SystemRoot%\System32\vds.exe
(VSS) Volume Shadow Copy [On_Demand | Stopped]
File not found - %SystemRoot%\System32\vssvc.exe
(WmiApSrv) WMI Performance Adapter [On_Demand | Stopped]
File not found - C:\WINDOWS\system32\wbem\wmiapsrv.exe
===== Driver Services - Non-Microsoft Only =====
(ACPI) Microsoft ACPI Driver [Boot | Running]
File not found - C:\WINDOWS\system32\DRIVERS\ACPI.sys
(aec) Microsoft Kernel Acoustic Echo Canceller [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\drivers\aec.sys
(AegisP) AEGIS Protocol (IEEE 802.1x) v3.4.10.0 [Auto | Running]
File not found - C:\WINDOWS\System32\DRIVERS\AegisP.sys
(AFD) AFD [System | Running]
File not found - C:\WINDOWS\System32\drivers\afd.sys
(AsIO) AsIO [System | Running]
[12/17/2007 11:14 AM | 00,014,392 | ---- | M] () - C:\WINDOWS\SysWOW64\Drivers\AsIO.sys
(aswFsBlk) aswFsBlk [Auto | Running]
File not found - C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys
(aswMonFlt) aswMonFlt [Auto | Running]
File not found -
(aswRdr) aswRdr [On_Demand | Running]
File not found -
(aswSP) avast! Self Protection [System | Running]
File not found -
(aswTdi) avast! Network Shield Support [System | Running]
File not found -
(AsyncMac) RAS Asynchronous Media Driver [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\asyncmac.sys
(Atmarpc) ATM ARP Client Protocol [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\atmarpc.sys
(audstub) Audio Stub Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\audstub.sys
(Beep) Beep [System | Running]
File not found -
(CCDECODE) Closed Caption Decoder [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\CCDECODE.sys
(CdaC15BA) CdaC15BA [Auto | Running]
File not found - C:\WINDOWS\System32\DRIVERS\CdaC15BA.sys
(CdaD10BA) CdaD10BA [Auto | Running]
File not found - C:\WINDOWS\System32\DRIVERS\CdaD10BA.sys
(Cdfs) Cdfs [Disabled | Running]
File not found -
(Cdrom) CD-ROM Driver [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\cdrom.sys
(COMMONFX.DLL) COMMONFX.DLL [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\COMMONFX.DLL
(crcdisk) CRC Disk Filter Driver [Boot | Running]
File not found - C:\WINDOWS\system32\DRIVERS\crcdisk.sys
(CT20XUT.DLL) CT20XUT.DLL [On_Demand | Running]
File not found - C:\WINDOWS\System32\CT20XUT.DLL
(ctac32k) Creative AC3 Software Decoder [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\ctac32k.sys
(ctaud2k) Creative Audio Driver (WDM) [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\ctaud2k.sys
(CTAUDFX.DLL) CTAUDFX.DLL [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\CTAUDFX.DLL
(CTEAPSFX.DLL) CTEAPSFX.DLL [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\CTEAPSFX.DLL
(CTEDSPFX.DLL) CTEDSPFX.DLL [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\CTEDSPFX.DLL
(CTEDSPIO.DLL) CTEDSPIO.DLL [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\CTEDSPIO.DLL
(CTEDSPSY.DLL) CTEDSPSY.DLL [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\CTEDSPSY.DLL
(CTERFXFX.DLL) CTERFXFX.DLL [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\CTERFXFX.DLL
(CTEXFIFX.DLL) CTEXFIFX.DLL [On_Demand | Running]
File not found - C:\WINDOWS\System32\CTEXFIFX.DLL
(CTHWIUT.DLL) CTHWIUT.DLL [On_Demand | Running]
File not found - C:\WINDOWS\System32\CTHWIUT.DLL
(ctprxy2k) Creative Proxy Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\ctprxy2k.sys
(CTSBLFX.DLL) CTSBLFX.DLL [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\CTSBLFX.DLL
(ctsfm2k) Creative SoundFont Management Device Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\ctsfm2k.sys
(Disk) Disk Driver [Boot | Running]
File not found - C:\WINDOWS\system32\DRIVERS\disk.sys
(dmboot) dmboot [Disabled | Running]
File not found - C:\WINDOWS\System32\drivers\dmboot.sys
(dmio) Logical Disk Manager Driver [Boot | Running]
File not found - C:\WINDOWS\System32\drivers\dmio.sys
(dmload) dmload [Boot | Running]
File not found - C:\WINDOWS\System32\drivers\dmload.sys
(emupia) E-mu Plug-in Architecture Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\emupia2k.sys
(Fips) Fips [System | Running]
File not found -
(FltMgr) FltMgr [Boot | Running]
File not found - C:\WINDOWS\system32\DRIVERS\fltMgr.sys
(Ftdisk) Volume Manager Driver [Boot | Running]
File not found - C:\WINDOWS\system32\DRIVERS\ftdisk.sys
(Gpc) Generic Packet Classifier [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\msgpc.sys
(ha20x2k) Creative 20X HAL Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\ha20x2k.sys
(hidusb) Microsoft HID Class Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\hidusb.sys
(HTTP) HTTP [On_Demand | Running]
File not found - C:\WINDOWS\System32\Drivers\HTTP.sys
(iaStor) Intel AHCI Controller [Boot | Running]
File not found - C:\WINDOWS\system32\DRIVERS\iaStor.sys
(imapi) CD-Burning Filter Driver [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\imapi.sys
(intelppm) Intel Processor Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\intelppm.sys
(Ip6Fw) IPv6 Windows Firewall Driver [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\Ip6Fw.sys
(IpFilterDriver) IP Traffic Filter Driver [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys
(IpInIp) IP in IP Tunnel Driver [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\ipinip.sys
(IpNat) IP Network Address Translator [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\ipnat.sys
(IPSec) IPSEC driver [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\ipsec.sys
(IRENUM) IR Enumerator Service [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\irenum.sys
(isapnp) PnP ISA/EISA Bus Driver [Boot | Running]
File not found - C:\WINDOWS\system32\DRIVERS\isapnp.sys
(Kbdclass) Keyboard Class Driver [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\kbdclass.sys
(kbdhid) Keyboard HID Driver [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\kbdhid.sys
(kmixer) Microsoft Kernel Wave Audio Mixer [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\kmixer.sys
(kncbda) KNC BDA DVB-C [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\kncbda64.sys
(KSecDD) KSecDD [Boot | Running]
File not found -
(ksthunk) Kernel Streaming WOW64 Thunk Service [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\ksthunk.sys
(mbr) mbr [On_Demand | Stopped]
File not found - C:\DOCUME~1\Carsten\LOCALS~1\Temp\mbr.sys
(mnmdd) mnmdd [System | Running]
File not found -
(Mouclass) Mouse Class Driver [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\mouclass.sys
(mouhid) Mouse HID Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\mouhid.sys
(MountMgr) Mount Point Manager [Boot | Running]
File not found -
(MPE) BDA MPE Filter [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\MPE.sys
(MRxDAV) WebDav Client Redirector [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\mrxdav.sys
(MRxSmb) MRxSmb [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
(Msfs) Msfs [System | Running]
File not found -
(MSKSSRV) Microsoft Streaming Service Proxy [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\drivers\MSKSSRV.sys
(MSPCLOCK) Microsoft Streaming Clock Proxy [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\drivers\MSPCLOCK.sys
(MSPQM) Microsoft Streaming Quality Manager Proxy [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\drivers\MSPQM.sys
(mssmbios) Microsoft System Management BIOS Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\mssmbios.sys
(MSTEE) Microsoft Streaming Tee/Sink-to-Sink Converter [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\drivers\MSTEE.sys
(MTsensor) ATK0110 ACPI UTILITY [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\ASACPI.sys
(Mup) Mup [Boot | Running]
File not found -
(NABTSFEC) NABTS/FEC VBI Codec [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys
(NDIS) NDIS System Driver [Boot | Running]
File not found -
(NdisIP) Microsoft TV/Video Connection [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\NdisIP.sys
(NdisTapi) Remote Access NDIS TAPI Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\ndistapi.sys
(Ndisuio) NDIS Usermode I/O Protocol [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\ndisuio.sys
(NdisWan) Remote Access NDIS WAN Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\ndiswan.sys
(NDProxy) NDIS Proxy [On_Demand | Running]
File not found -
(NetBIOS) NetBIOS Interface [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\netbios.sys
(NetBT) NetBios over Tcpip [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\netbt.sys
(Npfs) Npfs [System | Running]
File not found -
(Ntfs) Ntfs [Disabled | Running]
File not found -
(Null) Null [System | Running]
File not found -
(nv) nv [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\nv4_mini.sys
(ossrv) Creative OS Services Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\ctoss2k.sys
(PartMgr) Partition Manager [Boot | Running]
File not found -
(PCI) PCI Bus Driver [Boot | Running]
File not found - C:\WINDOWS\system32\DRIVERS\pci.sys
(PptpMiniport) WAN Miniport (PPTP) [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\raspptp.sys
(PSched) QoS Packet Scheduler [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\psched.sys
(Ptilink) Direct Parallel Link Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\ptilink.sys
(RasAcd) Remote Access Auto Connection Driver [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\rasacd.sys
(Rasl2tp) WAN Miniport (L2TP) [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\rasl2tp.sys
(RasPppoe) Remote Access PPPOE Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\raspppoe.sys
(Raspti) Direct Parallel [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\raspti.sys
(Rdbss) Rdbss [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\rdbss.sys
(RDPCDD) RDPCDD [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
(rdpdr) Terminal Server Device Redirector Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\rdpdr.sys
(redbook) Digital CD Audio Playback Filter Driver [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\redbook.sys
(RT73) RT73 USB Wireless LAN Card Driver [On_Demand | Stopped]
[11/30/2005 11:33 AM | 00,002,048 | ---- | M] () - C:\WINDOWS\System32\drivers\rt73.bin
(SaiHF51A) SaiHF51A [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\SaiHF51A.sys
(SaiMini) SaiMini [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\SaiMini.sys
(SaiNtBus) SaiNtBus [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\SaiBus.sys
(SaiUF51A) SaiUF51A [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\SaiUF51A.sys
(SASDIFSV) SASDIFSV [System | Stopped]
[09/03/2008 02:07 PM | 00,008,944 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) - C:\Program Files (x86)\SUPERAntiSpyware\sasdifsv.sys
(SASENUM) SASENUM [On_Demand | Stopped]
[09/03/2008 02:07 PM | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) - C:\Program Files (x86)\SUPERAntiSpyware\SASENUM.SYS
(SASKUTIL) SASKUTIL [System | Stopped]
[09/03/2008 02:07 PM | 00,055,024 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) - C:\Program Files (x86)\SUPERAntiSpyware\SASKUTIL.SYS
(Secdrv) Security Driver [Auto | Running]
File not found - C:\WINDOWS\System32\DRIVERS\secdrv.sys
(SLIP) BDA Slip De-Framer [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\SLIP.sys
(splitter) Microsoft Kernel Audio Splitter [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\drivers\splitter.sys
(sptd) sptd [Boot | Running]
File not found - C:\WINDOWS\System32\Drivers\sptd.sys
(sr) System Restore Filter Driver [Boot | Running]
File not found - C:\WINDOWS\system32\DRIVERS\sr.sys
(Srv) Srv [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\srv.sys
(streamip) BDA IPSink [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\StreamIP.sys
(swenum) Software Bus Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\swenum.sys
(swmidi) Microsoft Kernel GS Wavetable Synthesizer [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\drivers\swmidi.sys
(sysaudio) Microsoft Kernel System Audio Device [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\sysaudio.sys
(Tcpip) TCP/IP Protocol Driver [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\tcpip.sys
(TermDD) Terminal Device Driver [System | Running]
File not found - C:\WINDOWS\System32\DRIVERS\termdd.sys
(truecrypt) truecrypt [System | Running]
[08/27/2008 12:33 PM | 00,238,784 | ---- | M] (TrueCrypt Foundation) - C:\WINDOWS\SysWOW64\Drivers\truecrypt.sys
(Udfs) Udfs [Disabled | Running]
File not found -
(Update) Microcode Update Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\update.sys
(usbccgp) Microsoft USB Generic Parent Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\usbccgp.sys
(usbehci) Microsoft USB 2.0 Enhanced Host Controller Miniport Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\usbehci.sys
(usbhub) USB2 Enabled Hub [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\usbhub.sys
(usbstor) USB Mass Storage Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS
(usbuhci) Microsoft USB Universal Host Controller Miniport Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\usbuhci.sys
(vga) vga [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\vgapnp.sys
(VgaSave) VGA Display Controller. [System | Running]
File not found - C:\WINDOWS\System32\drivers\vga.sys
(VolSnap) Storage volumes [Boot | Running]
File not found - C:\WINDOWS\system32\DRIVERS\volsnap.sys
(Wanarp) Remote Access IP ARP Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\wanarp.sys
(wdmaud) Microsoft WINMM WDM Audio Compatibility Driver [On_Demand | Running]
File not found - C:\WINDOWS\System32\drivers\wdmaud.sys
(WSTCODEC) World Standard Teletext Codec [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS
(WudfPf) Windows Driver Foundation - User-mode Driver Framework Platform Driver [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\WudfPf.sys
(WudfRd) Windows Driver Foundation - User-mode Driver Framework Reflector [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\wudfrd.sys
(yukonx64) NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller [On_Demand | Running]
File not found - C:\WINDOWS\System32\DRIVERS\yk51x64.sys
========== Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!" = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [07/19/2008 04:38 PM | 00,078,008 | ---- | M] (ALWIL Software)
"CTHelper" = CTHELPER.EXE [02/20/2008 08:58 PM | 00,019,456 | ---- | M] (Creative Technology Ltd)
"CTxfiHlp" = CTXFIHLP.EXE [02/20/2008 08:58 PM | 00,019,968 | ---- | M] (Creative Technology Ltd)
"Six Engine" = "C:\Program Files (x86)\ASUS\Six Engine\SixEngine.exe" -r [05/14/2008 06:42 PM | 05,958,656 | ---- | M] ()
"SunJavaUpdateSched" = "C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM | 00,144,784 | ---- | M] (Sun Microsystems, Inc.)
"VolPanel" = "C:\Program Files (x86)\Creative\Volume Panel\VolPanlu.exe" /r [06/20/2008 01:30 PM | 00,221,300 | ---- | M] (Creative Technology Ltd)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian" = C:\Program Files\PeerGuardian2\pg2.exe [09/18/2005 06:43 PM | 02,217,984 | ---- | M] (Methlabs)
"SUPERAntiSpyware" = C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe [09/03/2008 02:07 PM | 01,576,176 | ---- | M] (SUPERAntiSpyware.com)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall" = %systemroot%\system32\tscupgrd.exe File not found
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall" = %systemroot%\system32\tscupgrd.exe File not found
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall" = %systemroot%\system32\tscupgrd.exe File not found
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall" = %systemroot%\system32\tscupgrd.exe File not found
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-21-2842628995-3559081299-4084640986-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian" = C:\Program Files\PeerGuardian2\pg2.exe [09/18/2005 06:43 PM | 02,217,984 | ---- | M] (Methlabs)
"SUPERAntiSpyware" = C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe [09/03/2008 02:07 PM | 01,576,176 | ---- | M] (SUPERAntiSpyware.com)
[HKEY_USERS\S-1-5-21-2842628995-3559081299-4084640986-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
========== Startup Folders ==========
[Admin Startup Folder - C:\Documents and Settings\Admin\Start Menu\Programs\Startup]
[Administrator Startup Folder - C:\Documents and Settings\Administrator\Start Menu\Programs\Startup]
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[06/09/2006 10:24 AM | 00,618,496 | ---- | M] (Ralink Technology, Corp.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk = C:\Program Files (x86)\RALINK\Common\RaUI.exe
[Carsten Startup Folder - C:\Documents and Settings\Carsten\Start Menu\Programs\Startup]
[Default User Startup Folder - C:\Documents and Settings\Default User\Start Menu\Programs\Startup]
========== BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
HKLM CLSID: (SSVHelper Class) - [06/10/2008 04:27 AM | 00,509,328 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
========== Toolbars ==========
========== AppInit_Dlls ==========
========== Shell Execute Hooks ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" =
HKLM CLSID: (SABShellExecuteHook Class) - [05/13/2008 10:13 AM | 00,077,824 | ---- | M] (SuperAdBlocker.com) C:\Program Files (x86)\SUPERAntiSpyware\SASSEH.DLL
========== HKLM Security Providers ==========
========== HKLM Winlogon Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
= Explorer.exe
>Explorer.exe - [02/18/2007 11:05 AM | 01,053,184 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\System]
= lsass.exe
>lsass.exe - File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
= userinit
>userinit - [02/18/2007 11:05 AM | 00,026,112 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
= %SystemRoot%\system32\logonui.exe
>%SystemRoot%\system32\logonui.exe - [02/18/2007 11:05 AM | 00,516,096 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
= rundll32 shell32,Control_RunDLL "sysdm.cpl"
>rundll32 shell32 - [11/08/2007 12:55 AM | 08,360,448 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
>Control_RunDLL "sysdm.cpl" - [02/18/2007 11:05 AM | 00,301,568 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
========== User's Winlogon Settings ==========
========== Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
"DllName" = C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll [07/23/2008 04:28 PM | 00,352,256 | ---- | M] (SUPERAntiSpyware.com)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DllName" = File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"DllName" = File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DllName" = File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DllName" = File not found
========== Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoActiveDesktop" = 1
"NoActiveDesktopChanges" = 1
"ForceActiveDesktopOn" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"scforceoption" = 0
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 255
"ForceClassicControlPanel" = 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 255
"ForceClassicControlPanel" = 1
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 255
"ForceClassicControlPanel" = 1
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 255
"ForceClassicControlPanel" = 1
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 255
"ForceClassicControlPanel" = 1
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-21-2842628995-3559081299-4084640986-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 255
"ForceClassicControlPanel" = 1
[HKEY_USERS\S-1-5-21-2842628995-3559081299-4084640986-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
========== Lsa Authentication Packages ==========
========== Lsa Security Packages ==========
========== Desktop Components ==========
========== Safeboot Options ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
========== Disabled MsConfig Items ==========
Unable to open key or key not present!
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[08/27/2008 11:52 AM | 00,000,000 | ---- | M] () C:\AUTOEXEC.BAT [ NTFS ]
autorun.inf [[Autorun] | open=setup.exe | ]
[06/05/2007 12:08 PM | 00,000,025 | R--- | M] () J:\autorun.inf [ CDFS ]
========== MountPoints2 ==========
========== DNS Name Servers ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{0E86A432-F572-44EA-BC61-E6A1463D0CC2}]
Servers: | Description:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{0F4E949B-A6F7-4F85-B48A-07E3FF16C49D}]
Servers: | Description: Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{310A632A-9577-4946-A84A-CE46CDF21017}]
Servers: | Description: Marvell Yukon 88E8001/8003/8010 PCI Gigabit Ethernet Controller
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{94697FA3-DB81-4220-8401-87CEA8B14A85}]
Servers: | Description: RT73 USB Wireless LAN Card
========== Hosts File ==========
HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== Files/Folders - Created Within 30 days ==========
[08/27/2008 01:42 PM | R--D | C] - C:\WINDOWS
@Alternate Data Stream - 8 bytes -> %SystemRoot%:
[08/27/2008 01:46 PM | 00,000,213 | -HS- | C] () - C:\boot.ini
[08/27/2008 01:46 PM | ---D | C] - C:\Documents and Settings
[08/27/2008 01:46 PM | -HSD | C] - C:\System Volume Information
[08/27/2008 01:47 PM | R--D | C] - C:\Program Files
[08/27/2008 01:47 PM | R--D | C] - C:\Program Files (x86)
[08/27/2008 01:51 PM | ---D | C] - C:\progs
[08/27/2008 02:00 PM | -HSD | C] - C:\RECYCLER
[08/27/2008 02:35 PM | ---D | C] - C:\Python25
[08/27/2008 11:52 AM | 00,000,000 | ---- | C] () - C:\AUTOEXEC.BAT
[08/27/2008 11:52 AM | 00,000,000 | ---- | C] () - C:\CONFIG.SYS
[08/27/2008 11:52 AM | 00,000,000 | RHS- | C] () - C:\IO.SYS
[08/27/2008 11:52 AM | 00,000,000 | RHS- | C] () - C:\MSDOS.SYS
[08/27/2008 12:54 PM | ---D | C] - C:\mnt
[08/29/2008 05:20 PM | ---D | C] - C:\Fraps
[09/05/2008 10:50 AM | ---D | C] - C:\spoolerlogs
[09/06/2008 05:06 PM | ---D | C] - C:\Downloads
[09/07/2008 10:55 AM | ---D | C] - C:\rsit
[08/27/2008 12:29 PM | 00,010,216 | ---- | C] () - C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[08/27/2008 12:29 PM | 00,011,832 | ---- | C] () - C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[08/27/2008 12:29 PM | 00,014,392 | ---- | C] () - C:\WINDOWS\System32\drivers\AsIO.sys
[08/27/2008 12:33 PM | 00,238,784 | ---- | C] (TrueCrypt Foundation) - C:\WINDOWS\System32\drivers\truecrypt.sys
[09/05/2008 02:56 PM | 00,002,048 | ---- | C] () - C:\WINDOWS\System32\drivers\rt73.bin
[09/07/2008 11:06 AM | 00,085,969 | ---- | C] (GMER) - C:\WINDOWS\System32\drivers\gmer.sys
[2 C:\WINDOWS\System32\*.tmp files]
[08/25/2008 06:42 PM | 00,000,054 | ---- | C] () - C:\WINDOWS\System32\ctzapxx.ini
[08/25/2008 06:42 PM | 00,000,059 | ---- | C] () - C:\WINDOWS\System32\default.sfm
[08/25/2008 06:42 PM | 00,000,059 | ---- | C] () - C:\WINDOWS\System32\default4.sfm
[08/25/2008 06:42 PM | 00,000,059 | ---- | C] () - C:\WINDOWS\System32\default8.sfm
[08/25/2008 06:42 PM | 00,000,307 | ---- | C] () - C:\WINDOWS\System32\kill.ini
[08/25/2008 06:42 PM | 00,005,120 | ---- | C] () - C:\WINDOWS\System32\enlocstr.exe
[08/25/2008 06:42 PM | 00,006,169 | ---- | C] () - C:\WINDOWS\System32\CTAPO64.UDA
[08/25/2008 06:42 PM | 00,010,240 | ---- | C] ( ) - C:\WINDOWS\System32\killapps.exe
[08/25/2008 06:42 PM | 00,017,920 | ---- | C] (Creative Technology, Ltd) - C:\WINDOWS\System32\ctedasio.dll
[08/25/2008 06:42 PM | 00,034,816 | ---- | C] ( ) - C:\WINDOWS\System32\a3d.dll
[08/25/2008 06:42 PM | 00,037,888 | ---- | C] () - C:\WINDOWS\System32\psconv.exe
[08/25/2008 06:42 PM | 00,038,400 | ---- | C] (Creative Technology Limited) - C:\WINDOWS\System32\readreg.exe
[08/25/2008 06:42 PM | 00,043,520 | ---- | C] () - C:\WINDOWS\System32\CTBurst.dll
[08/25/2008 06:42 PM | 00,053,932 | ---- | C] () - C:\WINDOWS\System32\ctdaught.dat
[08/25/2008 06:42 PM | 00,056,509 | ---- | C] () - C:\WINDOWS\System32\ctdnlstr.dat
[08/25/2008 06:42 PM | 00,077,824 | ---- | C] () - C:\WINDOWS\System32\ctmmactl.dll
[08/25/2008 06:42 PM | 00,077,824 | ---- | C] (Creative Labs) - C:\WINDOWS\System32\eaxac3.dll
[08/25/2008 06:42 PM | 00,101,603 | ---- | C] () - C:\WINDOWS\System32\instwdm.ini
[08/25/2008 06:42 PM | 00,313,207 | ---- | C] () - C:\WINDOWS\System32\ctstatic.dat
[08/25/2008 06:42 PM | 00,321,512 | ---- | C] () - C:\WINDOWS\System32\ctdlang.dat
[08/25/2008 06:42 PM | 00,782,336 | ---- | C] (Creative Labs Inc.) - C:\WINDOWS\System32\OALInst.exe
[08/25/2008 06:42 PM | 01,048,576 | ---- | C] () - C:\WINDOWS\System32\CT1MGM.ROM
[08/25/2008 06:42 PM | 02,167,684 | ---- | C] () - C:\WINDOWS\System32\CT2MGM.SF2
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\1025
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\1028
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\1031
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\1033
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\1037
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\1041
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\1042
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\1054
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\2052
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\3076
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\Drivers
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\en
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\export
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\ias
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\InstallShield
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\mui
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\usmt
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\System32\wbem
[08/27/2008 01:43 PM | 00,556,482 | ---- | C] () - C:\WINDOWS\System32\PerfStringBackup.INI
[08/27/2008 01:44 PM | ---D | C] - C:\WINDOWS\System32\en-US
[08/27/2008 01:44 PM | ---D | C] - C:\WINDOWS\System32\XPSViewer
[08/27/2008 01:47 PM | 00,066,082 | ---- | C] () - C:\WINDOWS\System32\C_28594.NLS
[08/27/2008 01:47 PM | 00,066,082 | ---- | C] () - C:\WINDOWS\System32\C_28595.NLS
[08/27/2008 01:47 PM | 00,066,082 | ---- | C] () - C:\WINDOWS\System32\C_28597.NLS
[08/27/2008 01:49 PM | --SD | C] - C:\WINDOWS\System32\config
[08/27/2008 01:56 PM | 00,001,688 | ---- | C] () - C:\WINDOWS\System32\autoexec.nt
[08/27/2008 11:49 AM | ---D | C] - C:\WINDOWS\System32\Com
[08/27/2008 11:51 AM | ---D | C] - C:\WINDOWS\System32\Macromed
[08/27/2008 11:52 AM | 00,016,832 | ---- | C] () - C:\WINDOWS\System32\amcompat.tlb
[08/27/2008 11:52 AM | 00,023,392 | ---- | C] () - C:\WINDOWS\System32\nscompat.tlb
[08/27/2008 11:52 AM | ---D | C] - C:\WINDOWS\System32\ime
[08/27/2008 11:52 AM | ---D | C] - C:\WINDOWS\System32\inetsrv
[08/27/2008 11:57 AM | ---D | C] - C:\WINDOWS\System32\SoftwareDistribution
[08/27/2008 12:00 PM | 00,000,000 | ---- | C] () - C:\WINDOWS\System32\config.nt
[08/27/2008 12:00 PM | 00,380,928 | ---- | C] () - C:\WINDOWS\System32\actskin4.ocx
[08/27/2008 12:00 PM | 01,163,960 | ---- | C] (ALWIL Software) - C:\WINDOWS\System32\aswBoot.exe
[08/27/2008 12:07 PM | ---D | C] - C:\WINDOWS\System32\AGEIA
[08/27/2008 12:14 PM | 00,003,072 | ---- | C] () - C:\WINDOWS\System32\CTXFIRES.DLL
[08/27/2008 12:14 PM | 00,011,776 | ---- | C] (Creative Technology Limited) - C:\WINDOWS\System32\INRES.DLL
[08/27/2008 12:14 PM | ---D | C] - C:\WINDOWS\System32\Data
[08/27/2008 12:15 PM | 00,110,592 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) - C:\WINDOWS\System32\OpenAL32.dll
[08/27/2008 12:15 PM | 00,413,696 | ---- | C] (Creative Labs) - C:\WINDOWS\System32\wrap_oal.dll
[08/27/2008 12:15 PM | 04,174,814 | ---- | C] () - C:\WINDOWS\System32\CT4MGM.SF2
[08/27/2008 12:25 PM | 00,057,856 | ---- | C] () - C:\WINDOWS\System32\MSDvbNP.ax
[08/27/2008 12:25 PM | 00,135,680 | ---- | C] () - C:\WINDOWS\System32\PsisRndr.ax
[08/27/2008 12:25 PM | 00,202,240 | ---- | C] () - C:\WINDOWS\System32\PsisDecd.dll
[08/27/2008 12:26 PM | 00,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) - C:\WINDOWS\System32\CSVer.dll
[08/27/2008 12:29 PM | 00,024,576 | ---- | C] () - C:\WINDOWS\System32\AsIO.dll
[08/27/2008 12:36 PM | 00,421,888 | ---- | C] () - C:\WINDOWS\System32\ac3filter.acm
[08/27/2008 12:38 PM | 00,007,680 | ---- | C] () - C:\WINDOWS\System32\ff_vfw.dll
[08/27/2008 12:38 PM | 00,060,273 | ---- | C] (Open Source Software community project) - C:\WINDOWS\System32\pthreadGC2.dll
[09/05/2008 02:56 PM | 00,295,018 | ---- | C] () - C:\WINDOWS\System32\Install7x.dll
[09/05/2008 02:56 PM | 00,315,392 | ---- | C] () - C:\WINDOWS\System32\AegisI5.exe
[09/06/2008 02:46 PM | 00,163,840 | R--- | C] (Immersion Corporation) - C:\WINDOWS\System32\Sai3F51A.Dll
[3 C:\WINDOWS\*.tmp files]
[08/25/2008 06:42 PM | 03,377,466 | ---- | C] () - C:\WINDOWS\CTDV10K1.CDF
[08/25/2008 06:42 PM | 03,735,544 | ---- | C] () - C:\WINDOWS\CTDV10K2.CDF
[08/25/2008 06:42 PM | 04,958,588 | ---- | C] () - C:\WINDOWS\CTDVAUDY.CDF
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\ADAM
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\addins
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\ADFS
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\AppPatch
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\Config
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\Connection Wizard
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\Cursors
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\Debug
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\Driver Cache
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\Help
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\ime
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\ime (x86)
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\java
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\Media
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\Microsoft.NET
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\msagent
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\msagent64
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\msapps
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\mui
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\NLDRV
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\Provisioning
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\repair
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\Resources
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\security
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\srchasst
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\system
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\system32
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\SysWOW64
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\Temp
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\twain_32
[08/27/2008 01:42 PM | ---D | C] - C:\WINDOWS\WinSxS
[08/27/2008 01:42 PM | -H-D | C] - C:\WINDOWS\inf
[08/27/2008 01:42 PM | R--D | C] - C:\WINDOWS\Web
[08/27/2008 01:42 PM | R-SD | C] - C:\WINDOWS\Fonts
[08/27/2008 01:43 PM | R-SD | C] - C:\WINDOWS\assembly
[08/27/2008 01:47 PM | 00,000,150 | ---- | C] () - C:\WINDOWS\system.ini
[08/27/2008 01:47 PM | 00,000,956 | ---- | C] () - C:\WINDOWS\imsins.BAK
[08/27/2008 01:47 PM | 00,004,161 | ---- | C] () - C:\WINDOWS\ODBCINST.INI
[08/27/2008 01:47 PM | -HSD | C] - C:\WINDOWS\Installer
[08/27/2008 07:23 PM | ---D | C] - C:\WINDOWS\Logs
[08/27/2008 11:50 AM | 00,000,036 | ---- | C] () - C:\WINDOWS\vb.ini
[08/27/2008 11:50 AM | 00,000,037 | ---- | C] () - C:\WINDOWS\vbaddin.ini
[08/27/2008 11:50 AM | 00,001,272 | ---- | C] () - C:\WINDOWS\Blue Lace 16.bmp
[08/27/2008 11:50 AM | 00,009,522 | ---- | C] () - C:\WINDOWS\Zapotec.bmp
[08/27/2008 11:50 AM | 00,016,730 | ---- | C] () - C:\WINDOWS\FeatherTexture.bmp
[08/27/2008 11:50 AM | 00,017,062 | ---- | C] () - C:\WINDOWS\Coffee Bean.bmp
[08/27/2008 11:50 AM | 00,017,336 | ---- | C] () - C:\WINDOWS\Gone Fishing.bmp
[08/27/2008 11:50 AM | 00,017,362 | ---- | C] () - C:\WINDOWS\Rhododendron.bmp
[08/27/2008 11:50 AM | 00,026,582 | ---- | C] () - C:\WINDOWS\Greenstone.bmp
[08/27/2008 11:50 AM | 00,026,680 | ---- | C] () - C:\WINDOWS\River Sumida.bmp
[08/27/2008 11:50 AM | 00,065,832 | ---- | C] () - C:\WINDOWS\Santa Fe Stucco.bmp
[08/27/2008 11:50 AM | 00,065,954 | ---- | C] () - C:\WINDOWS\Prairie Wind.bmp
[08/27/2008 11:50 AM | 00,065,978 | ---- | C] () - C:\WINDOWS\Soap Bubbles.bmp
[08/27/2008 11:50 AM | ---D | C] - C:\WINDOWS\PCHealth
[08/27/2008 11:50 AM | ---D | C] - C:\WINDOWS\Registration
[08/27/2008 11:50 AM | --SD | C] - C:\WINDOWS\Tasks
[08/27/2008 11:51 AM | 00,000,002 | ---- | C] () - C:\WINDOWS\desktop.ini
[08/27/2008 11:51 AM | 00,000,431 | ---- | C] () - C:\WINDOWS\win.ini
[08/27/2008 11:51 AM | 00,000,749 | RH-- | C] () - C:\WINDOWS\WindowsShell.Manifest
[08/27/2008 11:51 AM | 00,144,128 | -HS- | C] () - C:\WINDOWS\winnt.bmp
[08/27/2008 11:51 AM | 00,144,128 | -HS- | C] () - C:\WINDOWS\winnt256.bmp
[08/27/2008 11:51 AM | R--D | C] - C:\WINDOWS\Offline Web Pages
[08/27/2008 11:51 AM | --SD | C] - C:\WINDOWS\Downloaded Program Files
[08/27/2008 11:52 AM | 00,000,000 | ---- | C] () - C:\WINDOWS\control.ini
[08/27/2008 11:52 AM | 00,316,640 | ---- | C] () - C:\WINDOWS\WMSysPr9.prx
[08/27/2008 11:55 AM | 00,002,048 | --S- | C] () - C:\WINDOWS\bootstat.dat
[08/27/2008 11:56 AM | ---D | C] - C:\WINDOWS\Prefetch
[08/27/2008 11:56 AM | ---D | C] - C:\WINDOWS\SoftwareDistribution
[08/27/2008 11:56 AM | -HSD | C] - C:\WINDOWS\CSC
[08/27/2008 12:03 PM | 00,000,000 | ---- | C] () - C:\WINDOWS\nsreg.dat
[08/27/2008 12:07 PM | ---D | C] - C:\WINDOWS\nview
[08/28/2008 11:20 PM | ---D | C] - C:\WINDOWS\Sun
[09/01/2008 11:09 PM | -H-D | C] - C:\WINDOWS\$hf_mig$
[09/05/2008 01:24 PM | ---D | C] - C:\WINDOWS\pss
[09/05/2008 02:56 PM | 00,000,045 | ---- | C] () - C:\WINDOWS\filespec7x
[09/07/2008 11:06 AM | 00,000,080 | ---- | C] () - C:\WINDOWS\gmer_uninstall.cmd
[09/07/2008 11:06 AM | 00,000,250 | ---- | C] () - C:\WINDOWS\gmer.ini
[09/07/2008 11:06 AM | 00,811,008 | ---- | C] () - C:\WINDOWS\gmer.exe
[09/07/2008 11:06 AM | 00,884,736 | ---- | C] () - C:\WINDOWS\gmer.dll
[08/27/2008 11:50 AM | 00,000,065 | RH-- | C] () - C:\WINDOWS\tasks\desktop.ini
[08/27/2008 11:56 AM | 00,000,006 | -H-- | C] () - C:\WINDOWS\tasks\SA.DAT
[08/27/2008 01:30 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
[08/27/2008 01:46 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Microsoft Help
[08/27/2008 01:47 PM | 00,000,062 | -HS- | C] () - C:\Documents and Settings\All Users\Application Data\desktop.ini
[08/27/2008 01:47 PM | --SD | C] - C:\Documents and Settings\All Users\Application Data\Microsoft
[08/27/2008 07:25 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Trymedia
[08/27/2008 12:15 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Creative
[08/29/2008 05:20 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\TEMP
@Alternate Data Stream - 138 bytes -> %AllUsersProfile%\Application Data\TEMP:05EE1EEF
[08/29/2008 05:27 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\DVD Shrink
[09/05/2008 06:24 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[09/06/2008 01:34 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Azureus
[09/06/2008 02:46 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Saitek
[08/27/2008 02:45 PM | 00,000,062 | -HS- | C] () - C:\Documents and Settings\Carsten\Application Data\desktop.ini
[08/27/2008 02:45 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Identities
[08/27/2008 02:45 PM | --SD | C] - C:\Documents and Settings\Carsten\Application Data\Microsoft
[08/27/2008 02:47 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Mozilla
[08/27/2008 02:47 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Subversion
[08/27/2008 02:49 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Thunderbird
[08/27/2008 02:50 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\.purple
[08/27/2008 03:06 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Adobe
[08/27/2008 03:06 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Free Download Manager
[08/27/2008 03:06 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Macromedia
[08/27/2008 03:07 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Notepad++
[08/27/2008 07:00 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\gtk-2.0
[08/27/2008 11:04 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Sun
[08/27/2008 11:21 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Creative
[08/28/2008 03:29 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\DAEMON Tools
[08/28/2008 05:27 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\vlc
[08/28/2008 10:52 AM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\TrueCrypt
[09/04/2008 03:25 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\InfraRecorder
[09/04/2008 07:54 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\ImgBurn
[09/05/2008 06:24 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\SUPERAntiSpyware.com
[09/05/2008 10:52 AM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\OpenOffice.org2
[09/05/2008 11:01 AM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\dvdcss
[09/06/2008 01:25 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Participatory Culture Foundation
[09/06/2008 01:32 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\PCF-VLC
[09/06/2008 01:34 PM | ---D | C] - C:\Documents and Settings\Carsten\Application Data\Azureus
[08/27/2008 02:45 PM | ---D | C] - C:\Documents and Settings\Carsten\Local Settings\Application Data\TSVNCache
[08/27/2008 02:45 PM | --SD | C] - C:\Documents and Settings\Carsten\Local Settings\Application Data\Microsoft
[08/27/2008 02:47 PM | ---D | C] - C:\Documents and Settings\Carsten\Local Settings\Application Data\Mozilla
[08/27/2008 02:50 PM | ---D | C] - C:\Documents and Settings\Carsten\Local Settings\Application Data\Thunderbird
[08/27/2008 02:54 PM | 00,024,520 | ---- | C] () - C:\Documents and Settings\Carsten\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[08/27/2008 02:54 PM | ---D | C] - C:\Documents and Settings\Carsten\Local Settings\Application Data\Microsoft Help
[08/27/2008 04:14 PM | 06,385,962 | -H-- | C] () - C:\Documents and Settings\Carsten\Local Settings\Application Data\IconCache.db
[08/29/2008 03:18 PM | 00,006,144 | ---- | C] () - C:\Documents and Settings\Carsten\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[08/29/2008 07:57 PM | ---D | C] - C:\Documents and Settings\Carsten\Local Settings\Application Data\World in Conflict
[09/06/2008 01:25 PM | ---D | C] - C:\Documents and Settings\Carsten\Local Settings\Application Data\Participatory Culture Foundation
[08/27/2008 01:47 PM | 00,000,062 | -HS- | C] () - C:\Documents and Settings\All Users\Documents\desktop.ini
[08/27/2008 11:50 AM | R--D | C] - C:\Documents and Settings\All Users\Documents\My Pictures
[08/27/2008 11:51 AM | R--D | C] - C:\Documents and Settings\All Users\Documents\My Music
[08/27/2008 12:20 PM | R--D | C] - C:\Documents and Settings\All Users\Documents\My Videos
[08/29/2008 05:12 PM | 00,084,093 | ---- | C] () - C:\Documents and Settings\All Users\Documents\Titan_Quest_Keygen.zip
[08/29/2008 05:43 PM | 00,062,589 | ---- | C] () - C:\Documents and Settings\All Users\Documents\Titan.Quest.v1.30.No-Cd-DvD.Patch.rar
[08/29/2008 05:43 PM | 00,332,827 | ---- | C] () - C:\Documents and Settings\All Users\Documents\unl-tq3c.rar
[08/29/2008 05:51 PM | 00,062,830 | ---- | C] () - C:\Documents and Settings\All Users\Documents\TITAN.QUEST.V1.30.ALL.ATOTIK.NOCD.ZIP
[08/29/2008 05:54 PM | 00,418,244 | ---- | C] () - C:\Documents and Settings\All Users\Documents\TITAN.QUEST.V1.30.ALL.UNLEASHED.NOCD.ZIP
[08/29/2008 07:54 PM | 20,518,866 | ---- | C] () - C:\Documents and Settings\All Users\Documents\b-wic109.7z
[08/29/2008 09:02 PM | 00,084,480 | ---- | C] () - C:\Documents and Settings\All Users\Documents\Titan.Quest_KEYGEN-FFF.exe
[08/30/2008 02:27 AM | 00,309,425 | ---- | C] () - C:\Documents and Settings\All Users\Documents\download2.zip
[09/06/2008 02:47 PM | ---D | C] - C:\Documents and Settings\All Users\Documents\Saitek SD6 Profiles
[09/06/2008 03:35 PM | 33,007,900 | ---- | C] () - C:\Documents and Settings\All Users\Documents\WoA krank Kurator 2.avi
[08/27/2008 02:45 PM | 00,000,078 | -HS- | C] () - C:\Documents and Settings\Carsten\My Documents\desktop.ini
[08/27/2008 02:45 PM | R--D | C] - C:\Documents and Settings\Carsten\My Documents\My Music
[08/27/2008 02:45 PM | R--D | C] - C:\Documents and Settings\Carsten\My Documents\My Pictures
[08/27/2008 02:53 PM | ---D | C] - C:\Documents and Settings\Carsten\My Documents\Visual Studio 2008
[08/27/2008 07:24 PM | ---D | C] - C:\Documents and Settings\Carsten\My Documents\GTA Vice City User Files
[08/27/2008 07:24 PM | ---D | C] - C:\Documents and Settings\Carsten\My Documents\Hitman Blood Money
[08/27/2008 09:59 PM | R--D | C] - C:\Documents and Settings\Carsten\My Documents\My Videos
[08/29/2008 06:24 PM | 28,803,072 | ---- | C] () - C:\Documents and Settings\Carsten\My Documents\windows.iso
[08/29/2008 07:57 PM | ---D | C] - C:\Documents and Settings\Carsten\My Documents\World in Conflict
[08/29/2008 08:03 PM | ---D | C] - C:\Documents and Settings\Carsten\My Documents\My Games
[08/29/2008 09:02 PM | 00,000,622 | ---- | C] () - C:\Documents and Settings\Carsten\My Documents\titan quest.reg
[09/06/2008 01:35 PM | ---D | C] - C:\Documents and Settings\Carsten\My Documents\Azureus Downloads
[09/06/2008 03:26 PM | 00,000,072 | ---- | C] () - C:\Documents and Settings\Carsten\My Documents\hfdhfd.jsf
[08/27/2008 01:10 PM | 00,001,722 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Mozilla Thunderbird.lnk
[08/27/2008 01:21 PM | 00,000,902 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\xplorer2.lnk
[08/27/2008 12:00 PM | 00,001,693 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[08/27/2008 12:05 PM | 00,001,656 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[08/27/2008 12:24 PM | 00,000,925 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Foxit Reader.lnk
[08/27/2008 12:33 PM | 00,000,670 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\TrueCrypt.lnk
[08/27/2008 12:40 PM | 00,001,582 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[08/28/2008 12:51 AM | 00,000,761 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[08/29/2008 05:20 PM | 00,000,482 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Fraps.lnk
[09/05/2008 06:24 PM | 00,000,822 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[08/29/2008 05:27 PM | 00,000,700 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\DVD Shrink 3.2.lnk
[08/30/2008 09:27 PM | 00,000,585 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\Titan Quest.exe.lnk
[09/05/2008 01:44 PM | 00,001,788 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\HijackThis.lnk
[09/05/2008 01:47 PM | 06,637,592 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\SUPERAntiSpyware.exe
[09/05/2008 10:58 AM | 00,008,305 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\stuff.ods
[09/07/2008 10:24 AM | 00,002,097 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\hjtscanlist.zip
[09/07/2008 10:25 AM | 00,030,259 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\hjtscanlist.bat
[09/07/2008 10:55 AM | 00,304,189 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\RSIT.exe
[09/07/2008 10:59 AM | 00,008,958 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\rsit_fehler.png
[09/07/2008 11:04 AM | 00,066,048 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\mbr.exe
[09/07/2008 11:06 AM | 00,811,008 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\gmer.exe
[09/07/2008 11:50 AM | 00,017,577 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\gmer_fehler.png
[09/07/2008 11:53 AM | 00,142,336 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\catchme.exe
[09/07/2008 11:55 AM | 00,102,160 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\RootkitRevealer.chm
[09/07/2008 11:55 AM | 00,231,390 | ---- | C] () - C:\Documents and Settings\Carsten\Desktop\RootkitRevealer.zip
[09/07/2008 11:55 AM | 00,334,720 | ---- | C] (Sysinternals - www.sysinternals.com) - C:\Documents and Settings\Carsten\Desktop\RootkitRevealer.exe
[08/27/2008 01:47 PM | 00,000,084 | -HS- | C] () - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
[09/05/2008 02:57 PM | 00,001,675 | ---- | C] () - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
[08/27/2008 02:45 PM | 00,000,084 | -HS- | C] () - C:\Documents and Settings\Carsten\Start Menu\Programs\Startup\desktop.ini
[08/27/2008 01:46 PM | ---D | C] - C:\Program Files (x86)\Common Files\Merge Modules
[08/27/2008 01:47 PM | ---D | C] - C:\Program Files (x86)\Common Files\Microsoft Shared
[08/27/2008 01:47 PM | ---D | C] - C:\Program Files (x86)\Common Files\ODBC
[08/27/2008 01:47 PM | ---D | C] - C:\Program Files (x86)\Common Files\SpeechEngines
[08/27/2008 01:53 PM | ---D | C] - C:\Program Files (x86)\Common Files\Java
[08/27/2008 11:50 AM | ---D | C] - C:\Program Files (x86)\Common Files\System
[08/27/2008 11:51 AM | ---D | C] - C:\Program Files (x86)\Common Files\Services
[08/27/2008 12:07 PM | ---D | C] - C:\Program Files (x86)\Common Files\Wise Installation Wizard
[08/27/2008 12:14 PM | ---D | C] - C:\Program Files (x86)\Common Files\InstallShield
[08/27/2008 12:15 PM | ---D | C] - C:\Program Files (x86)\Common Files\Creative
[08/27/2008 12:17 PM | ---D | C] - C:\Program Files (x86)\Common Files\Creative Labs Shared
[08/27/2008 12:57 PM | ---D | C] - C:\Program Files (x86)\Common Files\GTK
[08/27/2008 01:02 PM | ---D | C] - C:\Program Files (x86)\DAEMON Tools Lite
[08/27/2008 01:10 PM | ---D | C] - C:\Program Files (x86)\Mozilla Thunderbird
[08/27/2008 01:19 PM | ---D | C] - C:\Program Files (x86)\GIMP-2.0
[08/27/2008 01:21 PM | ---D | C] - C:\Program Files (x86)\zabkat
[08/27/2008 01:30 PM | ---D | C] - C:\Program Files (x86)\Free Download Manager
[08/27/2008 01:41 PM | ---D | C] - C:\Program Files (x86)\MSXML 6.0
[08/27/2008 01:44 PM | ---D | C] - C:\Program Files (x86)\MSBuild
[08/27/2008 01:44 PM | ---D | C] - C:\Program Files (x86)\Reference Assemblies
[08/27/2008 01:46 PM | ---D | C] - C:\Program Files (x86)\Microsoft Visual Studio 9.0
[08/27/2008 01:46 PM | ---D | C] - C:\Program Files (x86)\Microsoft.NET
[08/27/2008 01:47 PM | ---D | C] - C:\Program Files (x86)\Common Files
[08/27/2008 01:48 PM | ---D | C] - C:\Program Files (x86)\Microsoft SQL Server
[08/27/2008 01:53 PM | ---D | C] - C:\Program Files (x86)\Java
[08/27/2008 01:58 PM | ---D | C] - C:\Program Files (x86)\OpenOffice.org 2.4
[08/27/2008 03:08 PM | ---D | C] - C:\Program Files (x86)\Notepad++
[08/27/2008 11:49 AM | ---D | C] - C:\Program Files (x86)\MSN
[08/27/2008 11:49 AM | ---D | C] - C:\Program Files (x86)\Windows NT
[08/27/2008 11:50 AM | ---D | C] - C:\Program Files (x86)\Internet Explorer
[08/27/2008 11:50 AM | ---D | C] - C:\Program Files (x86)\MSN Gaming Zone
[08/27/2008 11:50 AM | ---D | C] - C:\Program Files (x86)\Outlook Express
[08/27/2008 11:50 AM | ---D | C] - C:\Program Files (x86)\Windows Media Player
[08/27/2008 11:51 AM | 00,000,002 | -HS- | C] () - C:\Program Files (x86)\desktop.ini
[08/27/2008 11:51 AM | ---D | C] - C:\Program Files (x86)\Movie Maker
[08/27/2008 11:51 AM | ---D | C] - C:\Program Files (x86)\NetMeeting
[08/27/2008 11:51 AM | ---D | C] - C:\Program Files (x86)\Windows Media Player[Strings]
[08/27/2008 11:51 AM | -H-D | C] - C:\Program Files (x86)\Uninstall Information
[08/27/2008 11:52 AM | ---D | C] - C:\Program Files (x86)\microsoft shared
[08/27/2008 11:52 AM | ---D | C] - C:\Program Files (x86)\speechengines
[08/27/2008 11:52 AM | ---D | C] - C:\Program Files (x86)\system
[08/27/2008 12:05 PM | ---D | C] - C:\Program Files (x86)\Mozilla Firefox
[08/27/2008 12:07 PM | ---D | C] - C:\Program Files (x86)\AGEIA Technologies
[08/27/2008 12:14 PM | -H-D | C] - C:\Program Files (x86)\InstallShield Installation Information
[08/27/2008 12:15 PM | ---D | C] - C:\Program Files (x86)\Creative
[08/27/2008 12:15 PM | -H-D | C] - C:\Program Files (x86)\Creative Installation Information
[08/27/2008 12:24 PM | ---D | C] - C:\Program Files (x86)\Foxit Software
[08/27/2008 12:26 PM | ---D | C] - C:\Program Files (x86)\Intel
[08/27/2008 12:29 PM | ---D | C] - C:\Program Files (x86)\ASUS
[08/27/2008 12:33 PM | ---D | C] - C:\Program Files (x86)\TrueCrypt
[08/27/2008 12:36 PM | ---D | C] - C:\Program Files (x86)\AC3Filter
[08/27/2008 12:38 PM | ---D | C] - C:\Program Files (x86)\ffdshow
[08/27/2008 12:40 PM | ---D | C] - C:\Program Files (x86)\ImgBurn
[08/27/2008 12:57 PM | ---D | C] - C:\Program Files (x86)\Aspell
[08/27/2008 12:57 PM | ---D | C] - C:\Program Files (x86)\Pidgin
[08/28/2008 12:32 AM | ---D | C] - C:\Program Files (x86)\The KMPlayer1431
[08/28/2008 12:51 AM | ---D | C] - C:\Program Files (x86)\VideoLAN
[08/29/2008 05:27 PM | ---D | C] - C:\Program Files (x86)\DVD Shrink
[09/05/2008 01:44 PM | ---D | C] - C:\Program Files (x86)\Trend Micro
[09/05/2008 02:56 PM | ---D | C] - C:\Program Files (x86)\RALINK
[09/05/2008 06:24 PM | ---D | C] - C:\Program Files (x86)\SUPERAntiSpyware
[09/06/2008 01:25 PM | ---D | C] - C:\Program Files (x86)\Participatory Culture Foundation
[09/06/2008 01:34 PM | ---D | C] - C:\Program Files (x86)\Vuze
========== Files - Modified Within 30 days ==========
[08/27/2008 11:49 AM | 00,000,213 | -HS- | M] () - C:\boot.ini
[08/27/2008 11:52 AM | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT
[08/27/2008 11:52 AM | 00,000,000 | ---- | M] () - C:\CONFIG.SYS
[08/27/2008 11:52 AM | 00,000,000 | RHS- | M] () - C:\IO.SYS
[08/27/2008 11:52 AM | 00,000,000 | RHS- | M] () - C:\MSDOS.SYS
[08/27/2008 12:33 PM | 00,238,784 | ---- | M] (TrueCrypt Foundation) - C:\WINDOWS\System32\drivers\truecrypt.sys
[09/07/2008 11:06 AM | 00,085,969 | ---- | M] (GMER) - C:\WINDOWS\System32\drivers\gmer.sys
[2 C:\WINDOWS\System32\*.tmp files]
[08/27/2008 01:45 PM | 00,556,482 | ---- | M] () - C:\WINDOWS\System32\PerfStringBackup.INI
[08/27/2008 12:15 PM | 00,110,592 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) - C:\WINDOWS\System32\OpenAL32.dll
[08/27/2008 12:15 PM | 00,413,696 | ---- | M] (Creative Labs) - C:\WINDOWS\System32\wrap_oal.dll
[08/27/2008 12:25 PM | 00,016,832 | ---- | M] () - C:\WINDOWS\System32\amcompat.tlb
[08/27/2008 12:25 PM | 00,023,392 | ---- | M] () - C:\WINDOWS\System32\nscompat.tlb
[09/03/2008 02:44 PM | 00,000,000 | ---- | M] () - C:\WINDOWS\System32\config.nt
[3 C:\WINDOWS\*.tmp files]
[08/27/2008 01:47 PM | 00,000,150 | ---- | M] () - C:\WINDOWS\system.ini
[08/27/2008 11:50 AM | 00,000,036 | ---- | M] () - C:\WINDOWS\vb.ini
[08/27/2008 11:50 AM | 00,000,037 | ---- | M] () - C:\WINDOWS\vbaddin.ini
[08/27/2008 11:51 AM | 00,000,749 | RH-- | M] () - C:\WINDOWS\WindowsShell.Manifest
[08/27/2008 11:52 AM | 00,000,000 | ---- | M] () - C:\WINDOWS\control.ini
[08/27/2008 11:52 AM | 00,004,161 | ---- | M] () - C:\WINDOWS\ODBCINST.INI
[08/27/2008 11:52 AM | 00,316,640 | ---- | M] () - C:\WINDOWS\WMSysPr9.prx
[08/27/2008 12:03 PM | 00,000,000 | ---- | M] () - C:\WINDOWS\nsreg.dat
[08/27/2008 12:25 PM | 00,000,431 | ---- | M] () - C:\WINDOWS\win.ini
[09/01/2008 11:12 PM | 00,000,956 | ---- | M] () - C:\WINDOWS\imsins.BAK
[09/07/2008 11:06 AM | 00,000,080 | ---- | M] () - C:\WINDOWS\gmer_uninstall.cmd
[09/07/2008 11:06 AM | 00,884,736 | ---- | M] () - C:\WINDOWS\gmer.dll
[09/07/2008 11:07 AM | 00,000,250 | ---- | M] () - C:\WINDOWS\gmer.ini
[09/07/2008 11:58 AM | 00,002,048 | --S- | M] () - C:\WINDOWS\bootstat.dat
[09/07/2008 11:58 AM | 00,000,006 | -H-- | M] () - C:\WINDOWS\tasks\SA.DAT
[08/27/2008 01:47 PM | 00,000,062 | -HS- | M] () - C:\Documents and Settings\All Users\Application Data\desktop.ini
[08/27/2008 01:47 PM | 00,000,062 | -HS- | M] () - C:\Documents and Settings\Carsten\Application Data\desktop.ini
[08/28/2008 11:45 AM | 00,024,520 | ---- | M] () - C:\Documents and Settings\Carsten\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[09/05/2008 01:49 PM | 06,385,962 | -H-- | M] () - C:\Documents and Settings\Carsten\Local Settings\Application Data\IconCache.db
[09/06/2008 10:32 PM | 00,006,144 | ---- | M] () - C:\Documents and Settings\Carsten\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[08/27/2008 01:47 PM | 00,000,062 | -HS- | M] () - C:\Documents and Settings\All Users\Documents\desktop.ini
[08/29/2008 05:12 PM | 00,084,093 | ---- | M] () - C:\Documents and Settings\All Users\Documents\Titan_Quest_Keygen.zip
[08/29/2008 05:43 PM | 00,062,589 | ---- | M] () - C:\Documents and Settings\All Users\Documents\Titan.Quest.v1.30.No-Cd-DvD.Patch.rar
[08/29/2008 05:44 PM | 00,332,827 | ---- | M] () - C:\Documents and Settings\All Users\Documents\unl-tq3c.rar
[08/29/2008 05:51 PM | 00,062,830 | ---- | M] () - C:\Documents and Settings\All Users\Documents\TITAN.QUEST.V1.30.ALL.ATOTIK.NOCD.ZIP
[08/29/2008 05:54 PM | 00,418,244 | ---- | M] () - C:\Documents and Settings\All Users\Documents\TITAN.QUEST.V1.30.ALL.UNLEASHED.NOCD.ZIP
[08/29/2008 07:56 PM | 20,518,866 | ---- | M] () - C:\Documents and Settings\All Users\Documents\b-wic109.7z
[08/30/2008 02:27 AM | 00,309,425 | ---- | M] () - C:\Documents and Settings\All Users\Documents\download2.zip
[09/06/2008 03:28 PM | 33,007,900 | ---- | M] () - C:\Documents and Settings\All Users\Documents\WoA krank Kurator 2.avi
[08/27/2008 02:45 PM | 00,000,078 | -HS- | M] () - C:\Documents and Settings\Carsten\My Documents\desktop.ini
[08/29/2008 06:36 PM | 28,803,072 | ---- | M] () - C:\Documents and Settings\Carsten\My Documents\windows.iso
[08/29/2008 09:03 PM | 00,000,622 | ---- | M] () - C:\Documents and Settings\Carsten\My Documents\titan quest.reg
[09/06/2008 03:26 PM | 00,000,072 | ---- | M] () - C:\Documents and Settings\Carsten\My Documents\hfdhfd.jsf
[08/27/2008 01:10 PM | 00,001,722 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Mozilla Thunderbird.lnk
[08/27/2008 01:21 PM | 00,000,902 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\xplorer2.lnk
[08/27/2008 12:00 PM | 00,001,693 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[08/27/2008 12:05 PM | 00,001,656 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[08/27/2008 12:24 PM | 00,000,925 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Foxit Reader.lnk
[08/27/2008 12:33 PM | 00,000,670 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\TrueCrypt.lnk
[08/27/2008 12:40 PM | 00,001,582 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[08/28/2008 12:51 AM | 00,000,761 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[08/29/2008 05:20 PM | 00,000,482 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Fraps.lnk
[09/05/2008 06:24 PM | 00,000,822 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[08/29/2008 05:27 PM | 00,000,700 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\DVD Shrink 3.2.lnk
[09/05/2008 01:27 PM | 00,000,585 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\Titan Quest.exe.lnk
[09/05/2008 01:44 PM | 00,001,788 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\HijackThis.lnk
[09/05/2008 01:48 PM | 06,637,592 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\SUPERAntiSpyware.exe
[09/05/2008 12:16 PM | 00,008,305 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\stuff.ods
[09/07/2008 10:25 AM | 00,002,097 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\hjtscanlist.zip
[09/07/2008 10:55 AM | 00,304,189 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\RSIT.exe
[09/07/2008 10:59 AM | 00,008,958 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\rsit_fehler.png
[09/07/2008 11:04 AM | 00,066,048 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\mbr.exe
[09/07/2008 11:50 AM | 00,017,577 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\gmer_fehler.png
[09/07/2008 11:53 AM | 00,142,336 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\catchme.exe
[09/07/2008 11:55 AM | 00,231,390 | ---- | M] () - C:\Documents and Settings\Carsten\Desktop\RootkitRevealer.zip
[08/27/2008 11:52 AM | 00,000,084 | -HS- | M] () - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
[09/05/2008 02:57 PM | 00,001,675 | ---- | M] () - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
[08/27/2008 11:52 AM | 00,000,084 | -HS- | M] () - C:\Documents and Settings\Carsten\Start Menu\Programs\Startup\desktop.ini
< End of report >
Extras: