Code:
OTL logfile created on: 20.02.2010 10:49:58 - Run 1
OTL by OldTimer - Version 3.1.30.1 Folder = C:\Users\xxxxxxxx\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 53,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 78,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 248,58 Gb Total Space | 178,80 Gb Free Space | 71,93% Space Free | Partition Type: NTFS
Drive D: | 49,50 Gb Total Space | 6,21 Gb Free Space | 12,54% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NB_2009
Current User Name: xxxxxxxx
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\xxxxxxxx\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programs\Sandboxie\SbieSvc.exe (tzuk)
PRC - C:\Programme\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Programme\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
PRC - C:\Programs\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
PRC - C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Programme\Softex\OmniPass\scureapp.exe ()
PRC - C:\Programme\Softex\OmniPass\OmniServ.exe (Softex Inc.)
PRC - C:\Programme\Softex\OmniPass\opvapp.exe ()
PRC - C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe (Nero AG)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Windows\System32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\HomeCinema\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Programme\Launch Manager\WisLMSvc.exe (Wistron Corp.)
PRC - C:\Programme\Launch Manager\WButton.exe (Wistron)
PRC - C:\Programme\Launch Manager\HotkeyApp.exe (Wistron)
PRC - C:\Programme\Launch Manager\LaunchAp.exe ()
PRC - C:\Programme\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Programme\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\Programme\HomeCinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Programme\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Programme\Launch Manager\OSD.exe (Wistron Corp.)
PRC - C:\Windows\System32\IoctlSvc.exe (Prolific Technology Inc.)
PRC - C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
PRC - C:\Windows\System32\MDM.EXE (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\xxxxxxxx\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (BOLVSVCXK) -- C:\Users\xxxxxxxx\AppData\Local\Temp\BOLVSVCXK.exe (Sysinternals - www.sysinternals.com)
SRV - (TKKMUFJ) -- C:\Users\xxxxxxxx\AppData\Local\Temp\TKKMUFJ.exe (Sysinternals - www.sysinternals.com)
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (SbieSvc) -- C:\Programs\Sandboxie\SbieSvc.exe (tzuk)
SRV - (gupdate) Google Update Service (gupdate) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (avg9emc) -- C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (SMServer) -- C:\Windows\System32\snmvtsvc.exe (SMServer)
SRV - (gusvc) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (nvsvc) -- C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
SRV - (uvnc_service) -- C:\Programs\UltraVNC\WinVNC.exe (UltraVNC)
SRV - (odserv) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (omniserv) -- C:\Programme\Softex\OmniPass\OmniServ.exe (Softex Inc.)
SRV - (WinVNC4) -- C:\Programs\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)
SRV - (NMIndexingService) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (Nero AG)
SRV - (Nero BackItUp Scheduler 3) -- C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe (Nero AG)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (IAANTMON) Intel(R) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (WisLMSvc) -- C:\Program Files\Launch Manager\WisLMSvc.exe (Wistron Corp.)
SRV - (IGDCTRL) -- C:\Programs\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (RichVideo) Cyberlink RichVideo Service(CRVS) -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (PLFlash DeviceIoControl Service) -- C:\Windows\System32\IoctlSvc.exe (Prolific Technology Inc.)
SRV - (ehstart) -- C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (AutoShutdown) -- C:\Programs\AutoShutdown\AS_Service.exe (Barefoot Productions, Inc.)
SRV - (x10nets) -- C:\Programme\Common Files\X10\Common\X10nets.exe (X10)
SRV - (Visual Studio Analyzer RPC bridge) -- C:\Programs\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\VARPC.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (Lbd) -- C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (SbieDrv) -- C:\Programs\Sandboxie\SbieDrv.sys (tzuk)
DRV - (tbhsd) -- C:\Windows\System32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (RRNetCapMP) -- C:\Windows\System32\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV - (RRNetCap) -- C:\Windows\System32\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV - (AvgTdiX) -- C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) -- C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) -- C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (MusCAudio) -- C:\Windows\System32\drivers\MusCAudio.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (LVMST) -- C:\Windows\System32\drivers\LVMST.sys (Animation Technologies Inc.)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (VClone) -- C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (LTXMD_VAC) Litex Media Virtual Audio Cable (WDM) -- C:\Windows\System32\drivers\lmvac.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (WINUSB) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (ElbyCDIO) -- C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (ISODrive) -- C:\Programs\UltraISO\drivers\ISODrive.sys (EZB Systems, Inc.)
DRV - (iTurns) -- C:\Windows\System32\drivers\iTurnsDriver.sys (Pixbyte Development SL)
DRV - (TotRec7) -- C:\Windows\System32\drivers\TotRec7.sys (High Criteria inc.)
DRV - (YMIDUSBW) Yamaha USB-MIDI Driver (WDM) -- C:\Windows\System32\drivers\ymidusbw.sys (Yamaha Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (RTSTOR) -- C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (netr28) -- C:\Windows\System32\drivers\netr28.sys (Ralink Technology, Corp.)
DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor) -- C:\Windows\System32\drivers\atswpdrv.sys (AuthenTec, Inc.)
DRV - (usbanyka) -- C:\Windows\System32\drivers\usbanyka.sys (Anyka (Guangzhou) Software Technology Co., Ltd.)
DRV - (vncmirror) -- C:\Windows\System32\drivers\vncmirror.sys (RealVNC Ltd.)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys ()
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NETw4v32) Intel(R) -- C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (PhilCap) -- C:\Windows\System32\drivers\PhilCap.sys (NXP Semiconductors Germany GmbH)
DRV - (Si3531) -- C:\Windows\system32\DRIVERS\Si3531.sys (Silicon Image, Inc)
DRV - (SiFilter) -- C:\Windows\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiRemFil) -- C:\Windows\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (PAC207) -- C:\Windows\System32\drivers\PFC027.SYS (PixArt Imaging Inc.)
DRV - (XUIF) -- C:\Windows\System32\drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (X10Hid) -- C:\Windows\System32\drivers\x10hid.sys (X10 Wireless Technology, Inc.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (secdrv) -- C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (PxHelp20) -- C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (drhard) -- C:\Windows\System32\drivers\drhard.sys (Licensed for Gebhard Software)
DRV - (CLEDX) -- C:\Windows\System32\drivers\cledx.sys (Team H2O)
DRV - (Hotkey) -- C:\Windows\System32\drivers\HOTKEY.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.medion.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.medion.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.medion.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.0.6
FF - prefs.js..extensions.enabledItems: {b80e3187-dfe3-879f-dc50-c893d60ae36c}:4.6.6.3
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2009.12.13 09:15:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Programs\MozillaFirefox\components [2010.02.18 14:26:08 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Programs\MozillaFirefox\plugins [2010.02.18 14:26:08 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.1\extensions\\Components: C:\Programs\MozillaThunderbird\components [2010.02.05 10:58:02 | 000,000,000 | ---D | M]
[2009.12.10 17:07:43 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxx\AppData\Roaming\mozilla\Extensions
[2009.12.10 17:07:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xxxxxxxx\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.02.19 10:27:13 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxx\AppData\Roaming\mozilla\Firefox\Profiles\1qjfkobl.default\extensions
[2010.02.04 09:14:36 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\xxxxxxxx\AppData\Roaming\mozilla\Firefox\Profiles\1qjfkobl.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009.11.20 09:49:09 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxx\AppData\Roaming\mozilla\Firefox\Profiles\1qjfkobl.default\extensions\elemhidehelper@adblockplus.org
[2010.02.15 14:04:18 | 000,000,261 | ---- | M] () -- C:\Users\xxxxxxxx\AppData\Roaming\Mozilla\FireFox\Profiles\1qjfkobl.default\searchplugins\Search.xml
O1 HOSTS File: ([2009.11.16 15:52:54 | 000,001,044 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 http://bin-layer.de
O1 - Hosts: 127.0.0.1 http://layer-ads.de/
O1 - Hosts: 127.0.0.1 http://www.euros4click.de
O1 - Hosts: 127.0.0.1 layer-ads.de
O1 - Hosts: 127.0.0.1 http://www.forced-klicks.de
O1 - Hosts: 127.0.0.1 http://www.sponsorads.de
O1 - Hosts: 127.0.0.1 http://www.paidsolution.de
O1 - Hosts: 127.0.0.1 http://www.crody.de
O1 - Hosts: 127.0.0.1 http://www.bin-layer.de
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (SolidConverter PDF) - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Programs\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll (VoyagerSoft, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programme\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programs\Spybot\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (SolidConverter PDF) - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Programs\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll (VoyagerSoft, LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Programme\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\HomeCinema\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe ()
O4 - HKLM..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSD.exe (Wistron Corp.)
O4 - HKLM..\Run: [Monitor] C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [muBlinder] C:\Windows\muBlinder.exe (KRX)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OmniPass] C:\Programme\Softex\OmniPass\scureapp.exe ()
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPStart] C:\Programme\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [toolbar_eula_launcher] C:\Programme\GoogleEULA\EULALauncher.exe ( )
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePPShortCut] C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Programs\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKLM..\Run: [Wbutton] C:\Program Files\Launch Manager\Wbutton.exe (Wistron)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SandboxieControl] C:\Programs\Sandboxie\SbieCtrl.exe (tzuk)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Programs\AllMusicConverter\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Programs\AllMusicConverter\YouTubeRipper.dll ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programs\Spybot\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: Microsoft XML Parser for Java file:///C:/Windows/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programme\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL File not found
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010.02.20 09:26:00 | 000,549,376 | ---- | C] (OldTimer Tools) -- C:\Users\xxxxxxxx\Desktop\OTL.exe
[2010.02.19 11:57:20 | 000,000,000 | ---D | C] -- C:\Program
[2010.02.19 11:36:15 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\Pavark
[2010.02.19 11:17:04 | 000,000,000 | --SD | C] -- C:\cf.exe
[2010.02.19 11:16:35 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010.02.19 11:06:49 | 000,000,000 | --SD | C] -- C:\cf18998c
[2010.02.19 10:44:57 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010.02.19 10:44:57 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010.02.19 10:44:56 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010.02.19 10:44:49 | 000,000,000 | --SD | C] -- C:\cf
[2010.02.19 10:44:49 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010.02.18 10:26:48 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Local\BuildAGadget Content
[2010.02.17 20:32:51 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2010.02.17 19:58:49 | 000,000,000 | ---D | C] -- C:\ProgramData\UIB
[2010.02.17 19:58:48 | 000,000,000 | ---D | C] -- C:\Windows\System32\BIOAPIFFDB
[2010.02.17 19:46:37 | 000,146,688 | ---- | C] (AuthenTec, Inc.) -- C:\Windows\System32\drivers\atswpdrv.sys
[2010.02.17 19:46:27 | 000,000,000 | ---D | C] -- C:\Programme\AuthenTec
[2010.02.17 19:24:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.02.17 19:24:19 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Java
[2010.02.17 19:24:04 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.02.17 19:24:03 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.02.17 19:24:03 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.02.17 19:23:49 | 000,000,000 | ---D | C] -- C:\Programme\Java
[2010.02.17 19:21:49 | 000,000,000 | ---D | C] -- C:\Programme\Softex
[2010.02.17 17:03:00 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Roaming\InstallShield
[2010.02.17 17:02:39 | 000,000,000 | ---D | C] -- C:\temp
[2010.02.16 15:15:16 | 000,000,000 | R--D | C] -- C:\Sandbox
[2010.02.16 14:40:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010.02.16 13:52:12 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Roaming\QuickScan
[2010.02.16 12:57:05 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2010.02.16 12:57:02 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvfw32.dll
[2010.02.16 12:57:02 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avifil32.dll
[2010.02.16 12:57:02 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciavi32.dll
[2010.02.16 12:00:15 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.02.16 10:42:45 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.02.16 10:42:42 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.02.16 10:42:12 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2010.02.15 19:04:27 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2010.02.15 16:22:44 | 000,000,000 | -H-D | C] -- C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010.02.15 16:21:31 | 000,000,000 | ---D | C] -- C:\Programme\Lavasoft
[2010.02.15 16:21:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2010.02.15 16:16:40 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010.02.15 16:16:30 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Roaming\SUPERAntiSpyware.com
[2010.02.15 13:50:32 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Roaming\Thinstall
[2010.02.07 11:59:32 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Roaming\WinRAR
[2010.02.07 11:57:27 | 000,000,000 | ---D | C] -- C:\Cryptload
[2010.02.06 12:30:39 | 000,000,000 | ---D | C] -- C:\Programme\PixiePack Codec Pack
[2010.02.06 12:04:03 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Local\RapidSolution
[2010.02.06 11:16:19 | 000,000,000 | ---D | C] -- C:\ProgramData\RapidSolution
[2010.02.06 11:12:03 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\TuneClone
[2010.02.06 10:54:19 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\SolidDocuments
[2010.02.06 10:54:17 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Roaming\SolidDocuments
[2010.02.06 10:53:09 | 000,000,000 | ---D | C] -- C:\Programme\Soliddocuments
[2010.02.06 10:13:24 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Roaming\AccurateRip
[2010.02.06 10:00:19 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Local\WMA-MP3.com
[2010.02.06 09:57:45 | 000,025,616 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\System32\drivers\lmvac.sys
[2010.02.06 09:28:23 | 000,000,000 | ---D | C] -- C:\Converted
[2010.02.02 18:28:14 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Roaming\CDRoller
[2010.02.02 17:45:42 | 000,245,760 | ---- | C] (SMServer) -- C:\Windows\System32\snmvtsvc.exe
[2010.02.02 17:45:40 | 000,023,096 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\System32\MusCAudio.sys
[2010.02.02 17:45:40 | 000,023,096 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\System32\drivers\MusCAudio.sys
[2010.02.02 17:45:40 | 000,010,936 | ---- | C] (Windows (R) 2000 DDK provider) -- C:\Windows\System32\MusCVideo.dll
[2010.02.02 17:45:40 | 000,003,768 | ---- | C] (Windows (R) 2000 DDK provider) -- C:\Windows\System32\MusCVideo.sys
[2010.02.01 09:05:58 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxx\AppData\Local\QuickPar
[2010.01.30 12:34:35 | 000,086,016 | ---- | C] (MindVision Software) -- C:\Windows\unvise32.exe
[2010.01.30 12:34:22 | 000,000,000 | ---D | C] -- C:\Programme\Hexacto Games
[2010.01.22 10:14:26 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2010.01.22 10:14:25 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2010.01.22 10:14:25 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010.01.22 10:14:25 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010.01.22 10:14:25 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2010.01.22 10:14:24 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2010.01.22 10:14:24 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2010.01.22 10:14:24 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2010.01.22 10:14:24 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2010.01.22 10:14:24 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2010.01.22 10:14:24 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2010.01.22 10:14:24 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010.01.22 10:14:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2010.01.22 10:14:24 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.02.20 10:50:18 | 004,194,304 | -HS- | M] () -- C:\Users\xxxxxxxx\ntuser.dat
[2010.02.20 10:36:07 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010.02.20 09:38:32 | 000,001,482 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2010.02.20 09:36:00 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010.02.20 09:26:14 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Users\xxxxxxxx\Desktop\OTL.exe
[2010.02.20 09:21:30 | 000,293,376 | ---- | M] () -- C:\Users\xxxxxxxx\Desktop\vltrpkbr.exe
[2010.02.20 09:04:51 | 055,938,014 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2010.02.20 09:01:34 | 000,065,372 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010.02.20 09:01:18 | 000,065,372 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010.02.20 09:00:57 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.02.20 09:00:56 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.02.20 09:00:52 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.02.20 09:00:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.02.20 09:00:18 | 3217,489,920 | -HS- | M] () -- C:\hiberfil.sys
[2010.02.19 18:41:11 | 000,524,288 | -HS- | M] () -- C:\Users\xxxxxxxx\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.02.19 18:41:11 | 000,065,536 | -HS- | M] () -- C:\Users\xxxxxxxx\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.02.19 18:05:17 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010.02.19 17:00:44 | 000,002,453 | ---- | M] () -- C:\Users\xxxxxxxx\Desktop\HiJackThis.lnk
[2010.02.19 15:24:14 | 801,898,476 | ---- | M] () -- C:\Windows\System32\KNJYS
[2010.02.19 15:24:14 | 544,604,159 | ---- | M] () -- C:\Windows\System32\PANJVOI
[2010.02.19 14:56:16 | 000,142,336 | ---- | M] () -- C:\Users\xxxxxxxx\Desktop\cm.exe
[2010.02.19 14:13:24 | 000,000,000 | ---- | M] () -- C:\Windows\System32\UEGYL
[2010.02.19 10:59:56 | 000,192,512 | ---- | M] (ICSharpCode.net) -- C:\Windows\ICSharpCode.SharpZipLib.dll
[2010.02.19 10:32:04 | 003,864,099 | R--- | M] () -- C:\Users\xxxxxxxx\Desktop\cf.exe
[2010.02.19 10:09:21 | 000,000,680 | ---- | M] () -- C:\Users\xxxxxxxx\AppData\Local\d3d9caps.dat
[2010.02.18 17:59:25 | 000,033,658 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\cc_20100218_175802.reg
[2010.02.18 17:56:37 | 000,000,082 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\cc_20100218_175634.reg
[2010.02.18 17:00:14 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010.02.18 15:13:43 | 000,001,623 | ---- | M] () -- C:\Users\xxxxxxxx\Desktop\Command Prompt.lnk
[2010.02.17 20:44:28 | 000,018,620 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Omni_MW.opi
[2010.02.17 20:04:25 | 001,427,406 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.02.17 20:04:25 | 000,621,952 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.02.17 20:04:25 | 000,590,082 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.02.17 20:04:25 | 000,123,852 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.02.17 20:04:25 | 000,102,094 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.02.17 19:23:52 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deploytk.dll
[2010.02.17 19:23:52 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.02.17 19:23:52 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.02.17 19:23:52 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.02.17 11:46:55 | 000,106,496 | ---- | M] () -- C:\Users\xxxxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.02.16 14:31:16 | 001,253,537 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Lenco_MMC290.PDF
[2010.02.16 12:47:46 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2010.02.15 19:56:50 | 000,000,559 | ---- | M] () -- C:\Windows\win.ini
[2010.02.15 19:45:47 | 000,067,404 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\snap.jpg
[2010.02.15 18:49:05 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2010.02.15 18:48:11 | 000,015,880 | ---- | M] () -- C:\Windows\System32\lsdelete.exe
[2010.02.15 18:38:17 | 000,001,054 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2010.02.15 18:24:47 | 000,000,926 | ---- | M] () -- C:\Users\Public\Desktop\Basic4ppc Desktop.lnk
[2010.02.15 18:19:28 | 000,116,552 | ---- | M] () -- C:\Users\xxxxxxxx\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.02.15 11:36:06 | 000,141,156 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Meistro_StromAntrag.pdf
[2010.02.12 17:11:49 | 000,861,818 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Lenco_CR31-USB-SD_GER.pdf
[2010.02.10 10:51:10 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2010.02.10 10:04:06 | 000,001,640 | ---- | M] () -- C:\Users\xxxxxxxx\Desktop\PeerBlock.lnk
[2010.02.09 09:49:27 | 000,000,093 | ---- | M] () -- C:\Windows\vbaddin.ini
[2010.02.08 10:00:41 | 000,524,705 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\AllZ.csv
[2010.02.08 10:00:40 | 001,164,442 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\AllR.csv
[2010.02.08 10:00:40 | 000,000,000 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\AllS.csv
[2010.02.08 10:00:39 | 000,901,959 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\AllO.csv
[2010.02.08 10:00:39 | 000,394,162 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\AllJ.csv
[2010.02.08 10:00:39 | 000,032,327 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\AllK.csv
[2010.02.08 10:00:38 | 001,995,439 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\AllH.csv
[2010.02.08 10:00:35 | 000,328,999 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\AllC.csv
[2010.02.08 10:00:35 | 000,000,000 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\AllF.csv
[2010.02.08 10:00:34 | 000,863,034 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\AllB.csv
[2010.02.08 09:44:50 | 001,954,304 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\HausVerbrauch_BadSalzschlirf.xls
[2010.02.08 09:21:59 | 000,030,340 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\history_2010.dat
[2010.02.07 11:24:25 | 005,861,221 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Lenco_CR-2850_manual_GER.pdf
[2010.02.06 12:51:16 | 000,026,624 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Pkw-Angebotsanforderung Neukunden.xls
[2010.02.06 12:05:22 | 000,000,902 | ---- | M] () -- C:\Users\Public\Desktop\Tunebite 7.lnk
[2010.02.06 11:27:16 | 000,013,848 | ---- | M] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp Music Converter.dat
[2010.02.06 11:26:55 | 000,033,846 | ---- | M] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp Music Converter.bmp
[2010.02.06 11:03:33 | 000,000,116 | ---- | M] () -- C:\Windows\ConverterCore.INI
[2010.02.06 11:03:28 | 000,165,888 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Meistro_StromAntrag.doc
[2010.02.06 10:56:58 | 000,194,611 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Vattenfall_823800440806(2).doc
[2010.02.06 10:14:05 | 000,003,658 | ---- | M] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp m4a Codec.dat
[2010.02.06 10:13:54 | 000,033,846 | ---- | M] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp m4a Codec.bmp
[2010.02.06 09:11:33 | 000,103,478 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Meistro_Strom.JPG
[2010.02.05 10:52:16 | 000,001,761 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities.lnk
[2010.02.04 18:31:22 | 000,151,269 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Bote20100204.jpg
[2010.02.04 17:41:42 | 000,006,809 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\03.02.Bi27.jpg
[2010.02.04 16:53:02 | 000,064,288 | ---- | M] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2010.02.03 12:03:26 | 000,127,908 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Vattenfall_823800440806(2).pdf
[2010.02.03 10:34:22 | 000,000,012 | ---- | M] () -- C:\Windows\Recorder.dat
[2010.02.02 18:28:18 | 000,000,742 | ---- | M] () -- C:\Users\xxxxxxxx\Desktop\CDRoller.lnk
[2010.02.02 17:45:57 | 000,001,601 | ---- | M] () -- C:\Users\Public\Desktop\AllMusicConverter CDRipper.lnk
[2010.02.02 17:45:56 | 000,001,644 | ---- | M] () -- C:\Users\Public\Desktop\AllMusicConverter.lnk
[2010.02.02 17:23:43 | 000,000,772 | ---- | M] () -- C:\Users\xxxxxxxx\Desktop\CD Recovery Toolbox Free.lnk
[2010.02.01 09:45:43 | 000,643,072 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Expense.mdb
[2010.01.26 10:49:45 | 000,876,000 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\philips_ajm180_12_dfu_eng.pdf
[2010.01.23 11:14:23 | 000,454,410 | ---- | M] () -- C:\Users\xxxxxxxx\Documents\Lenco_CR-2800_manuals_ENG.pdf
[2010.01.22 16:47:59 | 000,000,700 | ---- | M] () -- C:\Users\xxxxxxxx\Desktop\Mp3Split.lnk
[2010.01.21 11:27:19 | 000,162,816 | ---- | M] (Firelight Technologies Pty, Ltd) -- C:\Windows\System32\fmod.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.02.20 09:21:13 | 000,293,376 | ---- | C] () -- C:\Users\xxxxxxxx\Desktop\vltrpkbr.exe
[2010.02.20 08:56:30 | 3217,489,920 | -HS- | C] () -- C:\hiberfil.sys
[2010.02.19 14:57:13 | 000,142,336 | ---- | C] () -- C:\Users\xxxxxxxx\Desktop\cm.exe
[2010.02.19 14:45:24 | 544,604,159 | ---- | C] () -- C:\Windows\System32\PANJVOI
[2010.02.19 14:24:56 | 801,898,476 | ---- | C] () -- C:\Windows\System32\KNJYS
[2010.02.19 14:13:24 | 000,000,000 | ---- | C] () -- C:\Windows\System32\UEGYL
[2010.02.19 10:44:57 | 000,261,632 | ---- | C] () -- C:\Windows\PEV.exe
[2010.02.19 10:44:57 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010.02.19 10:44:57 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010.02.19 10:44:56 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010.02.19 10:44:56 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010.02.19 10:32:56 | 003,864,099 | R--- | C] () -- C:\Users\xxxxxxxx\Desktop\cf.exe
[2010.02.19 09:40:53 | 000,000,680 | ---- | C] () -- C:\Users\xxxxxxxx\AppData\Local\d3d9caps.dat
[2010.02.18 17:58:04 | 000,033,658 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\cc_20100218_175802.reg
[2010.02.18 17:56:37 | 000,000,082 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\cc_20100218_175634.reg
[2010.02.18 17:00:13 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010.02.17 20:44:16 | 000,018,620 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Omni_MW.opi
[2010.02.17 20:34:14 | 000,013,824 | ---- | C] () -- C:\Windows\System32\vchannel.dll
[2010.02.16 15:14:32 | 000,001,482 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2010.02.16 14:30:56 | 001,253,537 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Lenco_MMC290.PDF
[2010.02.16 12:47:46 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010.02.16 10:56:13 | 000,015,880 | ---- | C] () -- C:\Windows\System32\lsdelete.exe
[2010.02.15 19:45:46 | 000,067,404 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\snap.jpg
[2010.02.15 18:38:17 | 000,001,054 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2010.02.15 18:24:47 | 000,000,926 | ---- | C] () -- C:\Users\Public\Desktop\Basic4ppc Desktop.lnk
[2010.02.15 11:36:00 | 000,141,156 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Meistro_StromAntrag.pdf
[2010.02.12 17:11:40 | 000,861,818 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Lenco_CR31-USB-SD_GER.pdf
[2010.02.07 11:24:01 | 005,861,221 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Lenco_CR-2850_manual_GER.pdf
[2010.02.06 12:51:15 | 000,026,624 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Pkw-Angebotsanforderung Neukunden.xls
[2010.02.06 12:05:22 | 000,000,902 | ---- | C] () -- C:\Users\Public\Desktop\Tunebite 7.lnk
[2010.02.06 11:27:16 | 000,033,846 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp Music Converter.bmp
[2010.02.06 11:27:16 | 000,013,848 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp Music Converter.dat
[2010.02.06 11:03:33 | 000,000,116 | ---- | C] () -- C:\Windows\ConverterCore.INI
[2010.02.06 11:03:26 | 000,165,888 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Meistro_StromAntrag.doc
[2010.02.06 10:56:57 | 000,194,611 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Vattenfall_823800440806(2).doc
[2010.02.06 10:14:05 | 000,033,846 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp m4a Codec.bmp
[2010.02.06 10:14:05 | 000,003,658 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp m4a Codec.dat
[2010.02.06 10:13:23 | 005,082,488 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2010.02.06 09:10:57 | 000,103,478 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Meistro_Strom.JPG
[2010.02.04 18:31:20 | 000,151,269 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Bote20100204.jpg
[2010.02.04 17:41:29 | 000,006,809 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\03.02.Bi27.jpg
[2010.02.03 12:03:26 | 000,127,908 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Vattenfall_823800440806(2).pdf
[2010.02.02 18:31:23 | 000,000,742 | ---- | C] () -- C:\Users\xxxxxxxx\Desktop\CDRoller.lnk
[2010.02.02 17:45:57 | 000,001,601 | ---- | C] () -- C:\Users\Public\Desktop\AllMusicConverter CDRipper.lnk
[2010.02.02 17:45:56 | 000,001,644 | ---- | C] () -- C:\Users\Public\Desktop\AllMusicConverter.lnk
[2010.02.02 17:45:40 | 000,019,099 | ---- | C] () -- C:\Windows\System32\MusCAudio.inf
[2010.02.02 17:45:40 | 000,002,577 | ---- | C] () -- C:\Windows\System32\MusCVideo.inf
[2010.02.02 17:45:40 | 000,002,539 | ---- | C] () -- C:\Windows\System32\MusCVideo.cat
[2010.02.02 17:45:40 | 000,002,100 | ---- | C] () -- C:\Windows\System32\MusCAudio.cat
[2010.02.02 17:23:43 | 000,000,772 | ---- | C] () -- C:\Users\xxxxxxxx\Desktop\CD Recovery Toolbox Free.lnk
[2010.01.31 09:31:48 | 000,001,096 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010.01.31 09:31:46 | 000,001,092 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010.01.26 10:49:19 | 000,876,000 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\philips_ajm180_12_dfu_eng.pdf
[2010.01.23 11:14:13 | 000,454,410 | ---- | C] () -- C:\Users\xxxxxxxx\Documents\Lenco_CR-2800_manuals_ENG.pdf
[2010.01.22 16:47:59 | 000,000,700 | ---- | C] () -- C:\Users\xxxxxxxx\Desktop\Mp3Split.lnk
[2010.01.10 11:58:21 | 000,000,053 | ---- | C] () -- C:\Windows\REGKEYNT.INI
[2010.01.06 10:12:21 | 000,014,115 | ---- | C] () -- C:\Windows\twspmm.ini
[2009.11.25 15:38:51 | 000,237,568 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2009.10.08 15:57:44 | 000,000,032 | ---- | C] () -- C:\Windows\CD_Start.INI
[2009.09.24 16:09:56 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.23 03:29:12 | 003,190,784 | ---- | C] () -- C:\Windows\System32\libavcodec.dll
[2009.09.23 03:29:12 | 000,741,376 | ---- | C] () -- C:\Windows\System32\audxlib.dll
[2009.09.23 03:29:12 | 000,662,016 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009.09.23 03:29:12 | 000,511,488 | ---- | C] () -- C:\Windows\System32\ff_x264.dll
[2009.09.23 03:29:12 | 000,405,504 | ---- | C] () -- C:\Windows\System32\libmplayer.dll
[2009.09.23 03:29:12 | 000,245,760 | ---- | C] () -- C:\Windows\System32\ff_libfaad2.dll
[2009.09.23 03:29:12 | 000,221,184 | ---- | C] () -- C:\Windows\System32\ff_kernelDeint.dll
[2009.09.23 03:29:12 | 000,200,704 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll
[2009.09.23 03:29:12 | 000,155,648 | ---- | C] () -- C:\Windows\System32\ff_libdts.dll
[2009.09.23 03:29:12 | 000,143,360 | ---- | C] () -- C:\Windows\System32\ff_theora.dll
[2009.09.23 03:29:12 | 000,122,880 | ---- | C] () -- C:\Windows\System32\ff_samplerate.dll
[2009.09.23 03:29:12 | 000,118,784 | ---- | C] () -- C:\Windows\System32\ff_libmad.dll
[2009.09.23 03:29:12 | 000,114,688 | ---- | C] () -- C:\Windows\System32\libmpeg2_ff.dll
[2009.09.23 03:29:12 | 000,097,280 | ---- | C] () -- C:\Windows\System32\ff_realaac.dll
[2009.09.23 03:29:12 | 000,079,872 | ---- | C] () -- C:\Windows\System32\ff_tremor.dll
[2009.09.23 03:29:12 | 000,040,960 | ---- | C] () -- C:\Windows\System32\ff_liba52.dll
[2009.09.23 03:29:12 | 000,038,400 | ---- | C] () -- C:\Windows\System32\ff_unrar.dll
[2009.09.23 03:29:12 | 000,026,624 | ---- | C] () -- C:\Windows\System32\ff_wmv9.dll
[2009.09.23 03:29:12 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2009.08.03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dllOLD
[2009.07.28 17:31:58 | 000,000,267 | ---- | C] () -- C:\Windows\w32demo8.ini
[2009.07.17 13:21:18 | 000,027,503 | ---- | C] () -- C:\Users\xxxxxxxx\AppData\Roaming\UserTile.png
[2009.07.07 13:21:33 | 000,003,072 | ---- | C] () -- C:\Windows\System32\716xCoInstallerMST.dll
[2009.06.30 13:04:39 | 000,106,496 | ---- | C] () -- C:\Users\xxxxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.06.27 17:35:08 | 000,065,372 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009.06.27 17:35:08 | 000,065,372 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009.06.24 11:35:48 | 000,000,216 | ---- | C] () -- C:\Windows\Ulead32.ini
[2009.06.22 17:48:22 | 000,028,124 | ---- | C] () -- C:\Users\xxxxxxxx\AppData\Roaming\nvModes.001
[2009.06.22 17:20:41 | 000,028,124 | ---- | C] () -- C:\Users\xxxxxxxx\AppData\Roaming\nvModes.dat
[2009.06.21 16:23:25 | 000,000,126 | ---- | C] () -- C:\Windows\mdm.ini
[2009.06.21 16:23:12 | 000,000,288 | ---- | C] () -- C:\Windows\ODBC.INI
[2009.06.21 12:36:06 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009.06.21 09:49:34 | 000,000,114 | ---- | C] () -- C:\Users\xxxxxxxx\AppData\Roaming\wklnhst.dat
[2009.03.02 11:33:32 | 000,067,584 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2008.10.07 08:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008.10.07 08:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008.07.23 10:03:08 | 000,009,867 | ---- | C] () -- C:\Windows\System32\drivers\HOTKEY.sys
[2008.07.23 09:04:44 | 000,308,248 | ---- | C] () -- C:\Windows\System32\drivers\iaStor.sys
[2008.03.19 07:58:36 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008.03.19 07:57:24 | 000,009,824 | ---- | C] () -- C:\Windows\System32\716xCoInstaller.dll
[2007.05.02 18:43:30 | 000,143,360 | ---- | C] () -- C:\Windows\System32\bioapi_mds300.dll
[2007.05.02 18:43:30 | 000,106,496 | ---- | C] () -- C:\Windows\System32\bioapi100.dll
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:27:46 | 000,000,518 | ---- | C] () -- C:\Windows\System32\SP207.INI
[2005.01.25 14:15:42 | 000,010,240 | R--- | C] () -- C:\Windows\System32\PA207USD.DLL
[1998.06.09 23:00:00 | 000,015,120 | ---- | C] () -- C:\Windows\System32\REPUTIL.DLL
[1998.05.17 23:00:00 | 000,014,017 | ---- | C] () -- C:\Windows\JAUTOEXP.INI
[1998.04.23 23:00:00 | 000,000,218 | ---- | C] () -- C:\Windows\FRONTPG.INI
========== Alternate Data Streams ==========
@Alternate Data Stream - 980 bytes -> C:\Users\xxxxxxxx\Documents\2009_01_16_Schritte.eml:OECustomProperty
@Alternate Data Stream - 976 bytes -> C:\Users\xxxxxxxx\Documents\(Attn ).eml:OECustomProperty
@Alternate Data Stream - 868 bytes -> C:\Users\xxxxxxxx\Documents\Mozart.eml:OECustomProperty
@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:D282699C
@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0B174FAE
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:66E02052
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:8CE646EE
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:CB0AACC9
< End of report >