Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- CN OTL logfile created on: 18.10.2012 17:26:37 - Run 1
- OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kai\Downloads
- 64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
- Internet Explorer (Version = 9.0.8112.16421)
- Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
- 7,99 Gb Total Physical Memory | 4,50 Gb Available Physical Memory | 56,33% Memory free
- 15,98 Gb Paging File | 11,46 Gb Available in Paging File | 71,72% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 585,94 Gb Total Space | 286,63 Gb Free Space | 48,92% Space Free | Partition Type: NTFS
- Drive D: | 298,09 Gb Total Space | 264,30 Gb Free Space | 88,67% Space Free | Partition Type: NTFS
- Drive E: | 52,50 Gb Total Space | 33,59 Gb Free Space | 63,98% Space Free | Partition Type: NTFS
- Drive F: | 698,46 Gb Total Space | 498,20 Gb Free Space | 71,33% Space Free | Partition Type: FAT32
- Drive G: | 657,09 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
- Drive S: | 97,66 Gb Total Space | 69,70 Gb Free Space | 71,37% Space Free | Partition Type: NTFS
- Computer Name: KOMPUTER | User Name: Kai | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
- Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2012.10.18 17:25:51 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Kai\Downloads\OTL.exe
- PRC - [2012.10.14 20:34:53 | 001,564,368 | ---- | M] () -- C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe
- PRC - [2012.10.14 18:22:30 | 001,807,800 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe
- PRC - [2012.10.14 18:09:23 | 006,045,848 | ---- | M] () -- c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe
- PRC - [2012.10.04 20:59:04 | 000,071,464 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\GameOverlayUI.exe
- PRC - [2012.10.04 20:58:53 | 000,529,744 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
- PRC - [2012.09.20 21:35:56 | 003,341,464 | ---- | M] (Electronic Arts) -- C:\Program Files (x86)\Origin\Origin.exe
- PRC - [2012.09.18 20:23:02 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- PRC - [2012.08.21 11:02:26 | 001,193,176 | ---- | M] () -- C:\Users\Kai\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
- PRC - [2012.08.17 18:26:14 | 001,353,080 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe
- PRC - [2012.08.03 03:16:04 | 000,408,944 | ---- | M] (AnchorFree Inc.) -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
- PRC - [2012.08.03 03:12:18 | 000,387,440 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
- PRC - [2012.08.03 03:10:40 | 000,476,016 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
- PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
- PRC - [2012.07.23 16:18:42 | 000,383,128 | ---- | M] (BlueStack Systems, Inc.) -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
- PRC - [2012.07.16 16:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
- PRC - [2012.05.19 16:55:25 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
- PRC - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
- PRC - [2012.03.20 11:16:08 | 000,247,872 | ---- | M] () -- C:\PROGRA~2\ICQ6TO~1\ICQSER~1.EXE
- PRC - [2012.01.26 15:08:56 | 003,665,752 | ---- | M] () -- C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe
- PRC - [2012.01.26 14:14:27 | 006,819,160 | ---- | M] (Tobit.Software) -- C:\Program Files (x86)\Tobit Radio.fx\Client\rfx-client.exe
- PRC - [2012.01.18 10:44:33 | 002,057,048 | ---- | M] (Tobit.Software) -- C:\Program Files (x86)\Tobit Radio.fx\Client\rfx-tray.exe
- PRC - [2011.12.24 12:24:36 | 000,202,296 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe
- PRC - [2011.08.22 17:07:32 | 000,354,416 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe
- PRC - [2011.08.22 17:06:56 | 000,432,752 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe
- PRC - [2011.08.22 15:28:42 | 000,079,872 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
- PRC - [2010.09.07 11:46:56 | 000,072,280 | ---- | M] () -- C:\Windows\SysWOW64\XSrvSetup.exe
- PRC - [2009.12.21 17:34:38 | 000,743,992 | ---- | M] (Infowatch) -- C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2012.10.18 17:11:53 | 000,155,232 | -H-- | M] () -- C:\Users\Kai\AppData\Local\Temp\~4B34.tmp
- MOD - [2012.10.14 18:22:30 | 009,814,968 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
- MOD - [2012.10.14 18:09:23 | 006,045,848 | ---- | M] () -- c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe
- MOD - [2012.10.04 20:58:50 | 020,317,008 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll
- MOD - [2012.10.04 20:58:48 | 000,902,480 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.DLL
- MOD - [2012.10.04 20:58:46 | 000,123,232 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avutil-51.dll
- MOD - [2012.10.04 20:58:44 | 000,190,816 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avformat-53.dll
- MOD - [2012.10.04 20:58:42 | 001,099,616 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avcodec-53.dll
- MOD - [2012.09.18 20:23:02 | 002,244,064 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
- MOD - [2012.08.21 11:02:26 | 001,193,176 | ---- | M] () -- C:\Users\Kai\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
- MOD - [2012.05.29 09:33:09 | 000,012,288 | ---- | M] () -- c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\miles\mssds3d.flt
- MOD - [2012.05.29 03:32:26 | 000,153,088 | ---- | M] () -- c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\miles\mssvoice.asi
- MOD - [2012.05.29 02:26:17 | 000,093,696 | ---- | M] () -- c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\miles\mssmp3.asi
- MOD - [2012.05.29 00:09:39 | 000,099,840 | ---- | M] () -- c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\miles\milesEq.flt
- MOD - [2012.05.28 23:14:28 | 000,058,368 | ---- | M] () -- c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\miles\msseax.flt
- MOD - [2012.05.15 02:21:26 | 000,368,448 | ---- | M] () -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
- MOD - [2012.02.20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
- MOD - [2012.02.20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
- MOD - [2012.01.26 12:39:32 | 009,560,576 | ---- | M] () -- C:\Program Files (x86)\Tobit Radio.fx\Client\TOBITCLT.dll
- MOD - [2012.01.26 11:13:36 | 000,215,552 | ---- | M] () -- C:\Program Files (x86)\Tobit Radio.fx\Client\rfx-client$.ger
- MOD - [2011.12.24 12:22:20 | 007,422,352 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtGui4.dll
- MOD - [2011.12.24 12:22:20 | 000,795,024 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtNetwork4.dll
- MOD - [2011.12.24 12:22:16 | 001,270,160 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtScript4.dll
- MOD - [2011.12.24 12:22:16 | 000,192,912 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtSql4.dll
- MOD - [2011.12.24 12:22:14 | 002,453,904 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtDeclarative4.dll
- MOD - [2011.12.24 12:22:12 | 002,126,224 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtCore4.dll
- MOD - [2011.12.24 12:21:10 | 000,459,152 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\dblite.dll
- MOD - [2011.09.05 19:36:52 | 000,025,088 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qgif4.dll
- MOD - [2011.09.05 19:36:50 | 000,180,224 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qjpeg4.dll
- MOD - [2009.08.23 19:58:06 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
- [color=#E56717]========== Services (SafeList) ==========[/color]
- SRV:[b]64bit:[/b] - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
- SRV - [2012.10.17 14:24:31 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
- SRV - [2012.10.15 12:02:21 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
- SRV - [2012.10.14 20:34:53 | 001,564,368 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe -- (Guard.Mail.ru)
- SRV - [2012.10.04 20:58:53 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
- SRV - [2012.09.04 12:16:08 | 000,678,416 | ---- | M] () [Auto | Running] -- C:\Programme\EslWire\service\WireHelperSvc.exe -- (EslWireHelper)
- SRV - [2012.08.29 12:03:36 | 002,369,960 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
- SRV - [2012.08.03 03:20:24 | 000,078,072 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE -- (HssTrayService)
- SRV - [2012.08.03 03:16:04 | 000,408,944 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
- SRV - [2012.08.03 03:12:18 | 000,387,440 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -- (HssWd)
- SRV - [2012.08.03 03:10:40 | 000,476,016 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe -- (hshld)
- SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
- SRV - [2012.07.25 18:58:26 | 000,126,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe -- (Te.Service)
- SRV - [2012.07.25 18:13:16 | 000,139,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe -- (fussvc)
- SRV - [2012.07.23 16:18:42 | 000,383,128 | ---- | M] (BlueStack Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe -- (BstHdLogRotatorSvc)
- SRV - [2012.07.23 16:18:16 | 000,395,416 | ---- | M] (BlueStack Systems, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc)
- SRV - [2012.07.16 16:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
- SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
- SRV - [2012.07.09 00:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
- SRV - [2012.06.17 09:52:14 | 000,098,576 | ---- | M] (SANDBOXIE L.T.D) [Auto | Running] -- C:\Programme\Sandboxie\SbieSvc.exe -- (SbieSvc)
- SRV - [2012.05.19 16:55:25 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
- SRV - [2012.05.15 12:48:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
- SRV - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
- SRV - [2012.03.26 15:28:58 | 005,404,472 | ---- | M] (Moonware Studios) [On_Demand | Stopped] -- C:\Program Files (x86)\webcamXP 5\wService.exe -- (wxpSvc)
- SRV - [2012.03.20 11:16:08 | 000,247,872 | ---- | M] () [Auto | Running] -- C:\PROGRA~2\ICQ6TO~1\ICQSER~1.EXE -- (ICQ Service)
- SRV - [2012.02.11 08:55:04 | 000,129,624 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
- SRV - [2012.01.26 15:08:56 | 003,665,752 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe -- (Radio.fx)
- SRV - [2011.12.24 12:24:36 | 000,202,296 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe -- (AVP)
- SRV - [2011.12.15 19:29:42 | 000,014,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe -- (OpenVPNService)
- SRV - [2011.08.22 17:07:32 | 000,354,416 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
- SRV - [2011.08.22 17:06:56 | 000,432,752 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
- SRV - [2011.08.22 16:34:52 | 011,837,440 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe -- (VMwareHostd)
- SRV - [2011.08.22 15:28:42 | 000,079,872 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService)
- SRV - [2011.08.21 23:11:28 | 000,846,448 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe -- (VMUSBArbService)
- SRV - [2010.09.07 11:46:56 | 000,072,280 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\XSrvSetup.exe -- (JMB36X)
- SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
- SRV - [2009.12.21 17:34:38 | 000,743,992 | ---- | M] (Infowatch) [Auto | Running] -- C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe -- (CSObjectsSrv)
- SRV - [2009.08.18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
- SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
- SRV - [2007.11.21 12:16:02 | 000,020,480 | ---- | M] () [Auto | Running] -- C:\Programme\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE -- (HerculesDJControlMP3)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV:[b]64bit:[/b] - [2012.09.25 20:14:23 | 000,025,216 | ---- | M] (Dev47Apps) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\droidcam.sys -- (DroidCam)
- DRV:[b]64bit:[/b] - [2012.09.04 12:16:00 | 000,147,472 | ---- | M] (<Turtle Entertainment>) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\ESLWireACD.sys -- (ESLWireAC)
- DRV:[b]64bit:[/b] - [2012.07.10 04:48:18 | 000,041,704 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\hssdrv6.sys -- (HssDRV6)
- DRV:[b]64bit:[/b] - [2012.05.19 12:43:38 | 000,639,280 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\SysNative\drivers\klif.sys -- (KLIF)
- DRV:[b]64bit:[/b] - [2012.04.18 19:08:03 | 000,188,736 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
- DRV:[b]64bit:[/b] - [2012.03.01 08:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
- DRV:[b]64bit:[/b] - [2012.02.15 11:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
- DRV:[b]64bit:[/b] - [2012.01.05 01:01:54 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\taphss.sys -- (taphss)
- DRV:[b]64bit:[/b] - [2011.10.20 11:48:00 | 000,458,032 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\kl1.sys -- (KL1)
- DRV:[b]64bit:[/b] - [2011.10.20 11:48:00 | 000,013,616 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kl2.sys -- (kl2)
- DRV:[b]64bit:[/b] - [2011.09.29 11:30:34 | 000,646,248 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
- DRV:[b]64bit:[/b] - [2011.08.22 17:07:58 | 000,062,064 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
- DRV:[b]64bit:[/b] - [2011.08.22 17:07:50 | 000,031,344 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\VMparport.sys -- (VMparport)
- DRV:[b]64bit:[/b] - [2011.08.22 17:06:14 | 000,030,320 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
- DRV:[b]64bit:[/b] - [2011.08.22 15:12:26 | 000,045,680 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
- DRV:[b]64bit:[/b] - [2011.08.22 15:12:26 | 000,020,080 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
- DRV:[b]64bit:[/b] - [2011.08.21 23:11:26 | 000,039,024 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
- DRV:[b]64bit:[/b] - [2011.08.08 14:59:12 | 000,116,336 | ---- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
- DRV:[b]64bit:[/b] - [2011.04.26 11:21:06 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
- DRV:[b]64bit:[/b] - [2011.03.11 08:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
- DRV:[b]64bit:[/b] - [2011.03.11 08:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
- DRV:[b]64bit:[/b] - [2011.03.10 18:36:24 | 000,029,488 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\klim6.sys -- (KLIM6)
- DRV:[b]64bit:[/b] - [2010.12.24 11:43:40 | 000,029,288 | -H-- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apowersoft_AudioDevice.sys -- (Apowersoft_AudioDevice)
- DRV:[b]64bit:[/b] - [2010.09.07 04:37:28 | 000,121,432 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID)
- DRV:[b]64bit:[/b] - [2009.12.14 12:44:24 | 000,085,048 | ---- | M] (Infowatch) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\CSCrySec.sys -- (CSCrySec)
- DRV:[b]64bit:[/b] - [2009.12.14 12:44:24 | 000,066,104 | ---- | M] (Infowatch) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys -- (CSVirtualDiskDrv)
- DRV:[b]64bit:[/b] - [2009.12.01 15:49:52 | 000,038,992 | ---- | M] (Screaming Bee LLC) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ScreamingBAudio64.sys -- (ScreamBAudioSvc)
- DRV:[b]64bit:[/b] - [2009.11.24 03:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
- DRV:[b]64bit:[/b] - [2009.11.23 17:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
- DRV:[b]64bit:[/b] - [2009.11.02 20:27:10 | 000,022,544 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klmouflt.sys -- (klmouflt)
- DRV:[b]64bit:[/b] - [2009.10.02 10:33:12 | 000,144,896 | ---- | M] (© Guillemot R&D, 2009. All rights reserved.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HDJMidi.sys -- (HDJMidi)
- DRV:[b]64bit:[/b] - [2009.10.02 10:33:06 | 000,154,112 | ---- | M] (© Guillemot R&D, 2009. All rights reserved.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HDJBulk.sys -- (Bulk)
- DRV:[b]64bit:[/b] - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
- DRV:[b]64bit:[/b] - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
- DRV:[b]64bit:[/b] - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
- DRV:[b]64bit:[/b] - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
- DRV:[b]64bit:[/b] - [2009.07.01 11:54:54 | 000,030,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGPBTDD.sys -- (LGPBTDD)
- DRV:[b]64bit:[/b] - [2009.06.22 20:01:16 | 000,132,608 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbnet.sys -- (ewusbnet)
- DRV:[b]64bit:[/b] - [2009.06.22 19:38:34 | 000,116,992 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
- DRV:[b]64bit:[/b] - [2009.06.22 19:26:40 | 000,113,792 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbdev.sys -- (hwusbdev)
- DRV:[b]64bit:[/b] - [2009.06.10 22:35:36 | 000,867,328 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr28ux.sys -- (netr28ux)
- DRV:[b]64bit:[/b] - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
- DRV:[b]64bit:[/b] - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
- DRV:[b]64bit:[/b] - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
- DRV:[b]64bit:[/b] - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
- DRV:[b]64bit:[/b] - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
- DRV:[b]64bit:[/b] - [2009.03.18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
- DRV - [2012.07.26 14:38:00 | 000,070,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys -- (VSPerfDrv110)
- DRV - [2012.07.23 16:18:42 | 000,072,856 | ---- | M] (BlueStack Systems) [Kernel | Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys -- (BstHdDrv)
- DRV - [2012.06.17 09:52:12 | 000,166,576 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- C:\Programme\Sandboxie\SbieDrv.sys -- (SbieDrv)
- DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- IE - HKLM\..\URLSearchHook: - No CLSID value found
- IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C7 A5 09 59 18 35 CD 01 [binary data]
- IE - HKCU\..\URLSearchHook: - No CLSID value found
- IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
- IE - HKCU\..\URLSearchHook: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - No CLSID value found
- IE - HKCU\..\SearchScopes,DefaultScope = {6552C7DD-90A4-4387-B795-F8F96747DE19}
- IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
- IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110819&tt=100512_2_&babsrc=SP_ss&mntrId=b6396a2c0000000000001c6f65468cdd
- IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
- IE - HKCU\..\SearchScopes\{86F14831-D88C-4BC8-B871-C8FB24D95D9B}: "URL" = http://www.questbasic.com/?prt=QstbscWD&keywords={searchTerms}
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8888;https=127.0.0.1:8888
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
- FF - prefs.js..browser.search.selectedEngine: "Google"
- FF - prefs.js..browser.startup.homepage: "http://google.de"
- FF - prefs.js..extensions.enabledAddons: afurladvisor@anchorfree.com:1.0
- FF - prefs.js..extensions.enabledAddons: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.2.2
- FF - prefs.js..extensions.enabledAddons: {800b5000-a755-47e1-992b-48a1c1357f07}:1.5.3
- FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q="
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
- FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
- FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
- FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
- FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB)
- FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.138.0: C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll (ESN Social Software AB)
- FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
- FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
- FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
- FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
- FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Kai\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Kai\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\linkfilter@kaspersky.ru [2012.06.13 16:08:31 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\virtualKeyboard@kaspersky.ru [2012.06.13 16:08:31 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\KavAntiBanner@Kaspersky.ru [2012.06.13 16:08:31 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.18 20:23:02 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.10.15 19:56:42 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
- FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.18 20:23:02 | 000,000,000 | ---D | M]
- FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
- [2012.05.18 19:38:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kai\AppData\Roaming\mozilla\Extensions
- [2012.10.17 14:06:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kai\AppData\Roaming\mozilla\Firefox\Profiles\4ik4zyhc.default\extensions
- [2012.10.17 14:06:20 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Kai\AppData\Roaming\mozilla\Firefox\Profiles\4ik4zyhc.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
- [2012.08.21 11:10:30 | 000,000,000 | ---D | M] (Hotspot Shield) -- C:\Users\Kai\AppData\Roaming\mozilla\Firefox\Profiles\4ik4zyhc.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}
- [2012.10.14 18:25:26 | 000,215,605 | ---- | M] () (No name found) -- C:\Users\Kai\AppData\Roaming\mozilla\firefox\profiles\4ik4zyhc.default\extensions\fbdislike@doweb.fr.xpi
- [2012.10.14 18:25:29 | 000,340,281 | ---- | M] () (No name found) -- C:\Users\Kai\AppData\Roaming\mozilla\firefox\profiles\4ik4zyhc.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
- [2012.09.25 20:24:51 | 000,269,659 | ---- | M] () (No name found) -- C:\Users\Kai\AppData\Roaming\mozilla\firefox\profiles\4ik4zyhc.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
- [2012.09.24 14:05:05 | 001,268,546 | ---- | M] () (No name found) -- C:\Users\Kai\AppData\Roaming\mozilla\firefox\profiles\4ik4zyhc.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
- [2012.09.26 16:09:37 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Kai\AppData\Roaming\mozilla\firefox\profiles\4ik4zyhc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- [2012.07.08 14:22:24 | 000,172,310 | ---- | M] () (No name found) -- C:\Users\Kai\AppData\Roaming\mozilla\firefox\profiles\4ik4zyhc.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
- [2012.07.24 14:48:30 | 000,000,168 | ---- | M] () -- C:\Users\Kai\AppData\Roaming\mozilla\firefox\profiles\4ik4zyhc.default\searchplugins\icqplugin.gif
- [2012.07.24 14:48:30 | 000,000,618 | ---- | M] () -- C:\Users\Kai\AppData\Roaming\mozilla\firefox\profiles\4ik4zyhc.default\searchplugins\icqplugin.src
- [2012.10.17 14:06:24 | 000,000,950 | ---- | M] () -- C:\Users\Kai\AppData\Roaming\mozilla\firefox\profiles\4ik4zyhc.default\searchplugins\icqplugin.xml
- [2012.08.18 22:20:06 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
- [2012.07.13 14:47:42 | 000,000,000 | ---D | M] (QuestBasic) -- C:\Program Files (x86)\mozilla firefox\extensions\{1CE72EFA-E2D1-48FA-A5EC-D7111C2C5BB6}
- [2012.07.13 14:45:13 | 000,000,000 | ---D | M] (z) -- C:\Program Files (x86)\mozilla firefox\extensions\{3e5ce861-0818-99c9-aa67-ac1c58fbaa8b}
- [2012.08.18 22:20:06 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com
- [2012.09.18 20:23:02 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
- [2012.07.14 02:45:08 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
- [2012.09.18 20:23:01 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
- [2012.07.14 02:45:08 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
- [2012.07.14 02:45:08 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
- [2012.07.14 02:45:08 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
- [2012.07.14 02:45:07 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
- [color=#E56717]========== Chrome ==========[/color]
- CHR - homepage: http://www.google.com/
- CHR - default_search_provider: Google (Enabled)
- CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
- CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
- CHR - homepage: http://www.google.com/
- CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
- CHR - plugin: Native Client (Enabled) = C:\Users\Kai\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
- CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Kai\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
- CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Kai\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
- CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
- CHR - plugin: Google Update (Enabled) = C:\Users\Kai\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
- CHR - Extension: di.slik.es = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\acmlfebmbccbmdaihmpefcfehaodlecb\1.3.0.3_0\
- CHR - Extension: Angry Birds = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
- CHR - Extension: StyleYourFacebook = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\baoldehlchpdgkdhlobagfmbdfbjoapd\2.2_0\
- CHR - Extension: YouTube = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
- CHR - Extension: Adblock Plus (Beta) = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
- CHR - Extension: Google-Suche = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
- CHR - Extension: Modul zur Link-Untersuchung = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.1.288_1\
- CHR - Extension: Stylish = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe\0.10_0\
- CHR - Extension: Dislike the web = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlbglppdmdnehajdanndnbdafoceoill\2.3_0\
- CHR - Extension: Virtuelle Tastatur = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.1.288_1\
- CHR - Extension: SweetIM for Facebook = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
- CHR - Extension: SweetIM for Facebook = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
- CHR - Extension: Dislike Anything = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpkgedojiglligeocnkladaopfejngao\0.4.2_0\
- CHR - Extension: Dislike FB 2.0 = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhelohobibckfhpgnamoidiofmfanjee\2.0_0\
- CHR - Extension: Skype Click to Call = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\
- CHR - Extension: Google Mail = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
- CHR - Extension: Anti-Banner = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.1.288_0\
- CHR - Extension: di.slik.es = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\acmlfebmbccbmdaihmpefcfehaodlecb\1.3.0.3_0\
- CHR - Extension: Angry Birds = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
- CHR - Extension: StyleYourFacebook = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\baoldehlchpdgkdhlobagfmbdfbjoapd\2.2_0\
- CHR - Extension: YouTube = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
- CHR - Extension: Adblock Plus (Beta) = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
- CHR - Extension: Google-Suche = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
- CHR - Extension: Modul zur Link-Untersuchung = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.1.288_1\
- CHR - Extension: Stylish = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe\0.10_0\
- CHR - Extension: Dislike the web = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlbglppdmdnehajdanndnbdafoceoill\2.3_0\
- CHR - Extension: Virtuelle Tastatur = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.1.288_1\
- CHR - Extension: SweetIM for Facebook = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
- CHR - Extension: SweetIM for Facebook = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
- CHR - Extension: Dislike Anything = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpkgedojiglligeocnkladaopfejngao\0.4.2_0\
- CHR - Extension: Dislike FB 2.0 = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhelohobibckfhpgnamoidiofmfanjee\2.0_0\
- CHR - Extension: Skype Click to Call = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\
- CHR - Extension: Google Mail = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
- CHR - Extension: Anti-Banner = C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.1.288_0\
- O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
- O2:[b]64bit:[/b] - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\ievkbd.dll (Kaspersky Lab ZAO)
- O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
- O2:[b]64bit:[/b] - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
- O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
- O2:[b]64bit:[/b] - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\klwtbbho.dll (Kaspersky Lab ZAO)
- O2:[b]64bit:[/b] - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
- O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ievkbd.dll (Kaspersky Lab ZAO)
- O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
- O2 - BHO: (Microsoft Web Test Recorder 10.0 Helper) - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
- O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
- O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\klwtbbho.dll (Kaspersky Lab ZAO)
- O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
- O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
- O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
- O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
- O3 - HKCU\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
- O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
- O4:[b]64bit:[/b] - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
- O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
- O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
- O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
- O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
- O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
- O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
- O4 - HKLM..\Run: [Hercules DJ Series] C:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe (Hercules®)
- O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
- O4 - HKCU..\Run: [AdobeBridge] File not found
- O4 - HKCU..\Run: [EADM] C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts)
- O4 - HKCU..\Run: [ESL Wire] C:\Program Files\EslWire\wire.exe (Turtle Entertainment GmbH)
- O4 - HKCU..\Run: [Firewall] C:\Program Files\Java\jre7\bin\javaw.exe (Oracle Corporation)
- O4 - HKCU..\Run: [ICQ] C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.)
- O4 - HKCU..\Run: [rfxsrvtray] C:\Program Files (x86)\Tobit Radio.fx\Client\rfx-tray.exe (Tobit.Software)
- O4 - HKCU..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe ()
- O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
- O4 - HKCU..\Run: [Spotify] C:\Users\Kai\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
- O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Kai\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
- O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
- O4 - Startup: C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Kai\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
- O4 - Startup: C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk = C:\Programme\Rainmeter\Rainmeter.exe ()
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O8:[b]64bit:[/b] - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ie_banner_deny.htm ()
- O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ie_banner_deny.htm ()
- O9:[b]64bit:[/b] - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\ievkbd.dll (Kaspersky Lab ZAO)
- O9:[b]64bit:[/b] - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\klwtbbho.dll (Kaspersky Lab ZAO)
- O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ievkbd.dll (Kaspersky Lab ZAO)
- O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.)
- O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.)
- O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\klwtbbho.dll (Kaspersky Lab ZAO)
- O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
- O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
- O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
- O13[b]64bit:[/b] - gopher Prefix: missing
- O13 - gopher Prefix: missing
- O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{541E9696-50F7-4625-BE7B-61BBFABB93EF}: DhcpNameServer = 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8DE44935-7CDD-4D36-A309-DA87C8AF0022}: DhcpNameServer = 139.7.30.125 139.7.30.126
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DB6BC001-7B78-41BA-A7B9-1386083E7AE2}: DhcpNameServer = 8.8.8.8
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EB49F06B-574A-44BB-9966-235274B663F3}: DhcpNameServer = 192.168.178.1
- O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data - No CLSID value found
- O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
- O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
- O20 - HKCU Winlogon: Shell - (expstart.exe) - C:\Windows\expstart.exe ()
- O20:[b]64bit:[/b] - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
- O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2012.08.18 10:45:33 | 000,041,425 | ---- | M] () - C:\autohaus1.amx -- [ NTFS ]
- O32 - AutoRun File - [2008.04.28 17:16:00 | 000,000,074 | R--- | M] () - G:\Autorun.inf -- [ CDFS ]
- O33 - MountPoints2\{420aa4e8-a10a-11e1-9c85-806e6f6e6963}\Shell - "" = AutoRun
- O33 - MountPoints2\{420aa4e8-a10a-11e1-9c85-806e6f6e6963}\Shell\AutoRun\command - "" = G:\0data\cobi.exe -- [2009.03.16 12:03:06 | 001,144,320 | R--- | M] (getanet.MEDIA)
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
- O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
- O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
- O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2012.10.18 14:32:24 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\.minecraft
- [2012.10.18 14:08:06 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\.spoutcraft
- [2012.10.16 19:11:50 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\SA-MP Audio Plugin
- [2012.10.16 17:10:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIX Networks
- [2012.10.16 13:06:43 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Local\Chromium
- [2012.10.16 13:04:46 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SA-MP Live
- [2012.10.16 13:02:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Rockstar Games
- [2012.10.15 16:37:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
- [2012.10.15 16:37:40 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
- [2012.10.15 13:22:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
- [2012.10.15 13:22:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
- [2012.10.15 12:10:22 | 000,000,000 | ---D | C] -- C:\Users\Kai\Desktop\Smoke-RL (c)
- [2012.10.14 20:43:22 | 000,000,000 | ---D | C] -- C:\Users\Kai\Desktop\LyL
- [2012.10.14 20:35:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7M
- [2012.10.14 20:35:02 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\ICQ Search
- [2012.10.14 20:34:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ICQ6Toolbar
- [2012.10.14 20:34:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Guard-ICQ
- [2012.10.14 20:34:42 | 000,000,000 | ---D | C] -- C:\ProgramData\ICQ
- [2012.10.14 20:34:09 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\ICQ
- [2012.10.14 20:34:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ICQ7M
- [2012.10.14 19:37:21 | 000,000,000 | ---D | C] -- C:\Users\Kai\Desktop\World of San Andreas 4.0.2
- [2012.10.06 12:14:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL
- [2012.10.06 12:14:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MySQL
- [2012.10.05 22:01:21 | 000,000,000 | ---D | C] -- C:\Users\Kai\Desktop\Hidden Ordner.{ED7BA470-8E54-465E-825C-99712043E01C}
- [2012.10.05 18:25:20 | 000,000,000 | --SD | C] -- C:\Users\Kai\AppData\Roaming\Frutas
- [2012.10.05 17:01:51 | 000,000,000 | ---D | C] -- C:\Users\Kai\Desktop\Script
- [2012.10.05 17:01:50 | 000,000,000 | ---D | C] -- C:\Users\Kai\Desktop\Pawno
- [2012.10.04 21:48:31 | 000,574,200 | -H-- | C] (Bytescout) -- C:\Windows\SysNative\BytescoutScreenCapturing.dll
- [2012.10.04 21:48:31 | 000,362,232 | -H-- | C] (Bytescout) -- C:\Windows\SysNative\BytescoutScreenCapturingFilter.dll
- [2012.10.04 21:48:31 | 000,231,672 | -H-- | C] (Bytescout) -- C:\Windows\SysNative\BytescoutVideoMixerFilter.dll
- [2012.10.04 21:48:31 | 000,175,864 | -H-- | C] (Bytescout) -- C:\Windows\SysWow64\BytescoutVideoMixerFilter.dll
- [2012.10.04 21:48:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apowersoft
- [2012.10.04 21:48:30 | 000,257,784 | -H-- | C] (Bytescout) -- C:\Windows\SysWow64\BytescoutScreenCapturingFilter.dll
- [2012.10.04 21:48:27 | 000,421,624 | -H-- | C] (Bytescout) -- C:\Windows\SysWow64\BytescoutScreenCapturing.dll
- [2012.10.04 21:48:27 | 000,029,288 | -H-- | C] (Wondershare) -- C:\Windows\SysNative\drivers\Apowersoft_AudioDevice.sys
- [2012.10.04 21:48:27 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\Apowersoft
- [2012.10.04 21:48:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apowersoft
- [2012.10.04 21:46:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GetFLV
- [2012.10.04 21:46:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GetFLV
- [2012.10.04 21:31:43 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\iFunbox_UserCache
- [2012.10.04 21:31:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\i-Funbox DevTeam
- [2012.10.04 21:31:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\i-Funbox DevTeam
- [2012.10.03 20:04:04 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\XnView
- [2012.10.03 20:04:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView
- [2012.10.03 20:03:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XnView
- [2012.10.03 17:33:24 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\MAXON
- [2012.10.03 14:30:47 | 000,000,000 | ---D | C] -- C:\Windows\pss
- [2012.10.03 14:20:02 | 000,000,000 | ---D | C] -- C:\bin
- [2012.10.03 14:20:02 | 000,000,000 | ---D | C] -- C:\backup
- [2012.09.30 16:41:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cinema 4D R12
- [2012.09.30 16:38:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cinema 4D R12
- [2012.09.28 16:59:20 | 000,000,000 | ---D | C] -- C:\Users\Kai\Desktop\Wheelman
- [2012.09.26 17:53:57 | 000,000,000 | ---D | C] -- C:\Users\Kai\Desktop\Super Spambot v3 by IQONMAN
- [2012.09.26 17:31:09 | 000,000,000 | ---D | C] -- C:\ProgramData\webcamXP 5
- [2012.09.26 17:31:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\webcamXP 5
- [2012.09.26 17:31:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\webcamXP 5
- [2012.09.25 20:14:21 | 000,025,216 | ---- | C] (Dev47Apps) -- C:\Windows\SysNative\drivers\droidcam.sys
- [2012.09.25 20:14:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DroidCam
- [2012.09.24 12:41:41 | 000,000,000 | ---D | C] -- C:\Encryption
- [2012.09.24 10:56:27 | 000,000,000 | R--D | C] -- C:\Users\Kai\Desktop\GFX
- [2012.09.23 21:47:01 | 000,000,000 | ---D | C] -- C:\Users\Kai\Documents\Cross Fire
- [2012.09.23 21:47:00 | 000,000,000 | ---D | C] -- C:\CFLog
- [2012.09.23 12:42:47 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Local\Play withSIX
- [2012.09.22 16:21:12 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\six-zsync
- [2012.09.22 16:20:45 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\Play withSIX
- [2012.09.22 16:20:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SIX Networks
- [2012.09.22 16:19:01 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Local\Downloaded Installations
- [2012.09.22 14:19:24 | 000,000,000 | ---D | C] -- C:\Users\Kai\Documents\ArmA 2 Other Profiles
- [2012.09.22 14:06:05 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Local\ArmA 2 OA
- [2012.09.22 14:06:05 | 000,000,000 | ---D | C] -- C:\Users\Kai\Documents\ArmA 2
- [2012.09.22 14:04:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Caphyon
- [2012.09.22 14:04:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DayZ
- [2012.09.22 14:04:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Arma 2
- [2012.09.22 14:04:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ArmA 2
- [2012.09.22 13:53:51 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\DayZ-Dev
- [2012.09.22 13:42:02 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
- [2012.09.22 13:41:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
- [2012.09.22 13:27:01 | 000,000,000 | ---D | C] -- C:\Program Files\Bohemia Interactive
- [2012.09.22 13:24:41 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Local\DayZCommander
- [2012.09.22 13:24:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dotjosh Studios
- [2012.09.21 21:09:20 | 000,000,000 | ---D | C] -- C:\Users\Kai\Desktop\Vorstellung
- [2012.09.21 19:13:53 | 000,000,000 | ---D | C] -- C:\Users\Kai\AppData\Local\__
- [2012.09.21 19:13:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Z8Games
- [2012.09.21 19:10:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Z8Games
- [2012.09.21 18:40:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BP DOWNLOADER
- [2012.09.19 22:12:51 | 000,000,000 | ---D | C] -- C:\Users\Kai\Desktop\Life Your Life RealLife
- [2012.09.18 18:00:17 | 000,000,000 | ---D | C] -- C:\Users\Kai\Desktop\Aktuellfrügiova
- [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2012.10.18 17:24:00 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2696722131-1725500217-3407015960-1001UA.job
- [2012.10.18 17:22:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
- [2012.10.18 17:13:55 | 000,014,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- [2012.10.18 17:13:55 | 000,014,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- [2012.10.18 17:08:53 | 010,537,064 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
- [2012.10.18 17:00:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2012.10.18 16:59:47 | 2140,790,783 | -HS- | M] () -- C:\hiberfil.sys
- [2012.10.18 14:26:30 | 001,625,922 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
- [2012.10.18 14:26:30 | 000,701,102 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
- [2012.10.18 14:26:30 | 000,656,180 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
- [2012.10.18 14:26:30 | 000,150,034 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
- [2012.10.18 14:26:30 | 000,122,818 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
- [2012.10.18 14:07:54 | 002,528,475 | ---- | M] () -- C:\Users\Kai\Desktop\Spoutcraft.exe
- [2012.10.17 16:24:00 | 000,001,060 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2696722131-1725500217-3407015960-1001Core.job
- [2012.10.16 15:47:14 | 002,147,328 | ---- | M] () -- C:\Users\Kai\Desktop\GRPLauncher.exe
- [2012.10.16 13:02:15 | 000,206,050 | ---- | M] () -- C:\Users\Kai\Desktop\samp-live_beta-1.2.4.exe
- [2012.10.15 16:37:41 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
- [2012.10.15 16:32:30 | 000,000,600 | ---- | M] () -- C:\Users\Kai\AppData\Local\PUTTY.RND
- [2012.10.15 15:09:08 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
- [2012.10.15 15:09:08 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
- [2012.10.15 12:09:27 | 002,620,225 | ---- | M] () -- C:\Users\Kai\Desktop\Smoke-RL (c).rar
- [2012.10.14 21:16:19 | 000,000,600 | ---- | M] () -- C:\Users\Kai\AppData\Roaming\winscp.rnd
- [2012.10.14 16:56:16 | 006,422,998 | ---- | M] () -- C:\Users\Kai\Desktop\LyL.rar
- [2012.10.14 04:37:16 | 229,172,310 | ---- | M] () -- C:\Users\Kai\Desktop\- Schriftarten -.rar
- [2012.10.14 03:17:50 | 405,367,689 | ---- | M] () -- C:\Users\Kai\Desktop\2000.rar
- [2012.10.06 12:14:47 | 001,652,610 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
- [2012.10.05 22:26:35 | 000,294,727 | ---- | M] () -- C:\Users\Kai\Documents\ts3_clientui-win64-1343657352-2012-10-05 22_26_34.622836.dmp
- [2012.10.05 15:41:48 | 005,376,539 | ---- | M] () -- C:\DRP.amx
- [2012.10.04 19:14:51 | 000,232,616 | ---- | M] () -- C:\Users\Kai\Desktop\Keybinder.rar
- [2012.10.04 15:43:45 | 001,288,520 | ---- | M] () -- C:\selfmade.amx
- [2012.10.04 15:12:18 | 000,001,738 | ---- | M] () -- C:\Windows\Sandboxie.ini
- [2012.10.03 20:53:13 | 000,000,132 | ---- | M] () -- C:\Users\Kai\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
- [2012.10.03 14:05:25 | 000,000,023 | ---- | M] () -- C:\Windows\ODBCINST.INI
- [2012.10.03 13:03:20 | 000,000,132 | ---- | M] () -- C:\Users\Kai\AppData\Roaming\Adobe CS6-GIF-Format - Voreinstellungen
- [2012.10.01 18:04:20 | 000,007,671 | ---- | M] () -- C:\Users\Kai\AppData\Local\Resmon.ResmonCfg
- [2012.09.26 17:37:07 | 000,000,034 | ---- | M] () -- C:\ProgramData\droidcam-settings
- [2012.09.25 21:59:28 | 000,307,059 | ---- | M] () -- C:\Users\Kai\Documents\ts3_clientui-win64-1343657352-2012-09-25 21_59_26.915381.dmp
- [2012.09.25 20:14:23 | 000,025,216 | ---- | M] (Dev47Apps) -- C:\Windows\SysNative\drivers\droidcam.sys
- [2012.09.24 12:39:22 | 000,003,383 | ---- | M] () -- C:\Users\Kai\Documents\hacker.pctl
- [2012.09.22 18:16:12 | 006,579,789 | ---- | M] () -- C:\Users\Kai\Documents\Time 4 You - Script.rar
- [2012.09.19 22:06:41 | 000,300,500 | ---- | M] () -- C:\Users\Kai\Documents\ts3_clientui-win64-1343657352-2012-09-19 22_06_40.266465.dmp
- [2012.09.19 16:18:43 | 000,005,003 | ---- | M] () -- C:\Users\Kai\Documents\[FS]Alkatraz.rar
- [2012.09.19 16:18:41 | 000,005,443 | ---- | M] () -- C:\Users\Kai\Documents\Ocean.rar
- [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2012.10.18 14:06:55 | 002,528,475 | ---- | C] () -- C:\Users\Kai\Desktop\Spoutcraft.exe
- [2012.10.16 15:47:06 | 002,147,328 | ---- | C] () -- C:\Users\Kai\Desktop\GRPLauncher.exe
- [2012.10.16 13:02:13 | 000,206,050 | ---- | C] () -- C:\Users\Kai\Desktop\samp-live_beta-1.2.4.exe
- [2012.10.15 16:37:41 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
- [2012.10.15 12:08:18 | 002,620,225 | ---- | C] () -- C:\Users\Kai\Desktop\Smoke-RL (c).rar
- [2012.10.14 18:28:39 | 229,172,310 | ---- | C] () -- C:\Users\Kai\Desktop\- Schriftarten -.rar
- [2012.10.14 18:28:27 | 405,367,689 | ---- | C] () -- C:\Users\Kai\Desktop\2000.rar
- [2012.10.14 18:23:13 | 006,422,998 | ---- | C] () -- C:\Users\Kai\Desktop\LyL.rar
- [2012.10.05 22:26:34 | 000,294,727 | ---- | C] () -- C:\Users\Kai\Documents\ts3_clientui-win64-1343657352-2012-10-05 22_26_34.622836.dmp
- [2012.10.05 15:41:48 | 005,376,539 | ---- | C] () -- C:\DRP.amx
- [2012.10.04 19:14:51 | 000,232,616 | ---- | C] () -- C:\Users\Kai\Desktop\Keybinder.rar
- [2012.10.03 14:18:32 | 005,498,995 | ---- | C] () -- C:\READ ME first !!.pdf
- [2012.10.03 14:18:32 | 000,035,328 | ---- | C] () -- C:\bspatch.exe
- [2012.10.03 14:18:32 | 000,002,802 | ---- | C] () -- C:\install.cmd
- [2012.10.03 14:18:32 | 000,001,448 | ---- | C] () -- C:\uninstall.cmd
- [2012.09.25 21:59:26 | 000,307,059 | ---- | C] () -- C:\Users\Kai\Documents\ts3_clientui-win64-1343657352-2012-09-25 21_59_26.915381.dmp
- [2012.09.25 20:16:11 | 000,000,034 | ---- | C] () -- C:\ProgramData\droidcam-settings
- [2012.09.25 20:15:27 | 000,001,056 | ---- | C] () -- C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DroidCam.lnk
- [2012.09.24 13:34:39 | 000,000,132 | ---- | C] () -- C:\Users\Kai\AppData\Roaming\Adobe CS6-GIF-Format - Voreinstellungen
- [2012.09.24 13:24:32 | 000,007,671 | ---- | C] () -- C:\Users\Kai\AppData\Local\Resmon.ResmonCfg
- [2012.09.24 12:39:22 | 000,003,383 | ---- | C] () -- C:\Users\Kai\Documents\hacker.pctl
- [2012.09.19 22:06:40 | 000,300,500 | ---- | C] () -- C:\Users\Kai\Documents\ts3_clientui-win64-1343657352-2012-09-19 22_06_40.266465.dmp
- [2012.09.19 16:18:41 | 000,005,003 | ---- | C] () -- C:\Users\Kai\Documents\[FS]Alkatraz.rar
- [2012.09.19 16:18:37 | 000,005,443 | ---- | C] () -- C:\Users\Kai\Documents\Ocean.rar
- [2012.09.16 17:20:12 | 000,925,184 | ---- | C] () -- C:\Windows\expstart.exe
- [2012.08.31 15:53:52 | 000,075,896 | ---- | C] () -- C:\Users\Kai\final_bstSnapshot_91792.jpg
- [2012.08.31 15:53:06 | 000,076,203 | ---- | C] () -- C:\Users\Kai\final_bstSnapshot_14588.jpg
- [2012.08.27 21:56:00 | 001,589,248 | ---- | C] () -- C:\Windows\SysWow64\libmysql_d.dll
- [2012.07.26 22:53:03 | 000,000,243 | ---- | C] () -- C:\Users\Kai\SciTE.session
- [2012.07.26 14:27:41 | 000,000,132 | ---- | C] () -- C:\Users\Kai\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
- [2012.07.13 14:45:14 | 000,075,118 | ---- | C] () -- C:\Windows\SysWow64\1b6f8cb.exe
- [2012.07.13 14:45:06 | 000,000,000 | ---- | C] () -- C:\ProgramData\f91865f3e006a0a23ca1478d1cd29a00_c
- [2012.07.12 16:22:48 | 000,001,738 | ---- | C] () -- C:\Windows\Sandboxie.ini
- [2012.07.11 16:34:23 | 003,146,960 | ---- | C] () -- C:\Users\Kai\ts3_recording_12_07_11_16_34_22.wav
- [2012.07.01 20:18:01 | 012,493,520 | ---- | C] () -- C:\Users\Kai\ts3_recording_12_07_01_20_18_0.wav
- [2012.06.28 18:07:15 | 000,168,864 | ---- | C] () -- C:\Program Files\Common Files\WireHelpSvc.exe
- [2012.06.24 11:50:51 | 000,000,023 | ---- | C] () -- C:\Windows\ODBCINST.INI
- [2012.06.23 16:38:48 | 000,000,600 | ---- | C] () -- C:\Users\Kai\AppData\Roaming\winscp.rnd
- [2012.05.27 13:31:52 | 001,652,610 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
- [2012.05.25 15:47:58 | 002,681,344 | ---- | C] () -- C:\Windows\SysWow64\dvmsg.dll
- [2012.05.19 18:26:19 | 000,000,600 | ---- | C] () -- C:\Users\Kai\AppData\Local\PUTTY.RND
- [2012.05.19 12:46:19 | 000,017,408 | ---- | C] () -- C:\Users\Kai\AppData\Local\WebpageIcons.db
- [2012.05.19 01:16:46 | 000,280,904 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
- [2012.05.19 01:16:45 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
- [2012.05.18 19:12:19 | 000,072,280 | ---- | C] () -- C:\Windows\SysWow64\XSrvSetup.exe
- [2012.05.15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
- [2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
- [2011.09.19 09:07:46 | 000,015,360 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll
- [2011.09.19 09:07:32 | 000,058,368 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
- [2011.07.03 00:00:00 | 000,026,622 | ---- | C] () -- C:\Users\Kai\logo.png
- [2010.10.27 11:10:27 | 000,007,764 | ---- | C] () -- C:\Windows\cadx2.ini
- [color=#E56717]========== ZeroAccess Check ==========[/color]
- [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
- [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- "" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:30:56 | 014,165,504 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
- "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Both
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
- [color=#E56717]========== LOP Check ==========[/color]
- [2012.10.18 14:32:24 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\.minecraft
- [2012.10.18 14:10:29 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\.spoutcraft
- [2012.06.26 18:44:14 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\.techniclauncher
- [2012.10.04 21:48:27 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Apowersoft
- [2012.09.11 19:19:00 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Audacity
- [2012.05.19 18:00:43 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Babylon
- [2012.09.08 14:36:26 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\BANDISOFT
- [2012.05.23 17:56:32 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Canneverbe Limited
- [2012.07.03 17:24:54 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
- [2012.07.18 22:53:51 | 000,000,000 | -HSD | M] -- C:\Users\Kai\AppData\Roaming\Common
- [2012.09.22 13:53:51 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\DayZ-Dev
- [2012.10.18 17:04:37 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Dropbox
- [2012.10.15 16:52:03 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\FileZilla
- [2012.10.05 18:25:20 | 000,000,000 | --SD | M] -- C:\Users\Kai\AppData\Roaming\Frutas
- [2012.10.18 17:04:50 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\ICQ
- [2012.10.14 20:35:02 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\ICQ Search
- [2012.10.04 21:31:43 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\iFunbox_UserCache
- [2012.08.25 11:41:10 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Lansoftware
- [2012.05.18 20:12:53 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Leadertech
- [2012.10.03 17:33:24 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\MAXON
- [2012.05.18 23:06:32 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Notepad++
- [2012.07.08 22:40:46 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\nspaces_bytesignals
- [2012.08.20 18:39:32 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\OpenOffice.org
- [2012.09.05 16:32:29 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Origin
- [2012.10.16 16:54:58 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Play withSIX
- [2012.05.20 12:59:04 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Publish Providers
- [2012.07.15 14:25:14 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Rainmeter
- [2012.10.16 19:16:50 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\SA-MP Audio Plugin
- [2012.08.30 20:27:24 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Screaming Bee
- [2012.09.22 16:21:12 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\six-zsync
- [2012.05.20 13:20:56 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Sony
- [2012.10.18 17:07:35 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Spotify
- [2012.06.10 13:42:16 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Steganos
- [2012.06.10 13:42:32 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Steganos VPN
- [2012.08.25 11:41:59 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Subversion
- [2012.05.24 19:07:51 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\TeamViewer
- [2012.07.16 13:25:20 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\TestApp
- [2012.09.11 21:57:27 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\The other Universe
- [2012.05.18 19:38:13 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Thunderbird
- [2012.05.25 15:48:34 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Tobit
- [2012.10.15 16:47:37 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\TS3Client
- [2012.07.16 16:43:00 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\ts3overlay
- [2012.05.19 18:07:47 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\Ubisoft
- [2012.06.03 20:30:42 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\WindSolutions
- [2012.10.03 20:04:35 | 000,000,000 | ---D | M] -- C:\Users\Kai\AppData\Roaming\XnView
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Alternate Data Streams ==========[/color]
- @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:8CE646EE
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement