OTL logfile created on: 22.09.2012 17:50:52 - Run 2 OTL by OldTimer - Version 3.2.65.0 Folder = C:\Dokumente und Einstellungen\Bene\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,43 Gb Available Physical Memory | 81,03% Memory free 4,85 Gb Paging File | 4,38 Gb Available in Paging File | 90,42% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 149,94 Gb Total Space | 3,22 Gb Free Space | 2,15% Space Free | Partition Type: NTFS Computer Name: B | User Name: Bene | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012.09.21 08:26:12 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Bene\Desktop\OTL.scr PRC - [2012.09.08 09:33:32 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2012.08.28 19:11:43 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.05.14 14:16:34 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2012.05.14 14:16:29 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2012.05.14 14:16:28 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2012.03.29 19:23:24 | 001,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2010.07.28 16:37:52 | 000,118,784 | ---- | M] () -- C:\Vision\Recorder\VAmpService.exe PRC - [2009.01.13 11:28:46 | 001,528,608 | ---- | M] (Cisco Systems, Inc.) -- C:\Programme\Cisco Systems\VPN Client\cvpnd.exe PRC - [2007.09.04 19:25:44 | 000,131,072 | ---- | M] (NVIDIA) -- C:\Programme\NVIDIA Corporation\nTune\nTuneService.exe PRC - [2006.08.02 16:08:52 | 000,237,620 | ---- | M] (Cherry GmbH) -- C:\Programme\Cherry\KeyMan\KeyMan.exe PRC - [2006.06.27 15:02:06 | 000,573,486 | ---- | M] (Cherry, Auerbach Germany, www.cherry.de) -- C:\Programme\Cherry\CDI\cdi.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012.09.08 09:33:31 | 002,244,064 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll MOD - [2012.08.29 09:02:57 | 009,813,704 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll MOD - [2012.05.14 14:16:35 | 000,398,288 | ---- | M] () -- C:\Programme\Avira\AntiVir Desktop\sqlite3.dll MOD - [2012.01.03 15:10:46 | 000,301,056 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.DEU MOD - [2010.07.28 16:37:52 | 000,118,784 | ---- | M] () -- C:\Vision\Recorder\VAmpService.exe MOD - [2009.10.03 16:42:26 | 000,094,208 | ---- | M] () -- C:\Programme\FileZilla FTP Client\fzshellext.dll MOD - [2009.01.13 11:29:00 | 000,197,408 | ---- | M] () -- C:\WINDOWS\system32\vpnapi.dll MOD - [2006.02.22 16:47:44 | 000,073,728 | ---- | M] () -- C:\Programme\Cherry\KeyMan\zlib1.dll MOD - [2006.02.22 16:47:16 | 000,114,688 | ---- | M] () -- C:\Programme\Cherry\KeyMan\libpng13.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - [2012.09.08 09:33:31 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.05.14 14:16:34 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.14 14:16:28 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.07.20 06:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv) SRV - [2010.07.28 16:37:52 | 000,118,784 | ---- | M] () [Auto | Running] -- C:\Vision\Recorder\VAmpService.exe -- (VAmpService) SRV - [2009.09.23 17:37:30 | 000,051,168 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Programme\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) SRV - [2009.01.13 11:28:46 | 001,528,608 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Programme\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND) SRV - [2007.11.08 00:58:18 | 003,004,416 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon90) SRV - [2007.09.04 19:25:44 | 000,131,072 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Programme\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService) SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose) SRV - [2006.06.27 15:02:06 | 000,573,486 | ---- | M] (Cherry, Auerbach Germany, www.cherry.de) [On_Demand | Running] -- C:\Programme\Cherry\CDI\cdi.exe -- (Cherry Device Interface) SRV - [2005.04.04 01:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\SjyPkt.sys -- (SjyPkt) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOKUME~1\Bene\LOKALE~1\Temp\pxtdqpow.sys -- (pxtdqpow) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\dgderdrv.sys -- (dgderdrv) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (agpjccme) DRV - [2012.05.14 14:16:35 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2012.05.14 14:16:35 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.10.11 15:00:01 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr) DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010.04.11 16:27:11 | 000,003,026 | ---- | M] (Logix4u) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\hwinterface.sys -- (hwinterface) DRV - [2010.01.19 19:36:48 | 005,818,400 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) DRV - [2009.11.18 20:39:08 | 000,279,712 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt) DRV - [2009.11.18 20:39:07 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt) DRV - [2009.11.18 08:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt) DRV - [2009.11.18 08:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt) DRV - [2009.01.13 11:27:38 | 000,306,811 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA) DRV - [2008.08.28 17:17:38 | 000,131,856 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE) DRV - [2008.05.27 20:31:18 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2007.12.17 13:30:44 | 000,269,824 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8187.sys -- (RTLWUSB) DRV - [2007.10.23 12:51:04 | 000,103,296 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2007.10.10 13:18:52 | 000,011,608 | ---- | M] (Dr.G.Schuhfried GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\IOXMGR.SYS -- (Ioxmgr) DRV - [2007.09.04 19:26:32 | 000,029,696 | ---- | M] (NVidia Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\nvoclock.sys -- (NVR0Dev) DRV - [2007.01.18 19:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA) DRV - [2006.07.24 04:52:04 | 000,071,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\StMp3Rec.sys -- (StMp3Rec) DRV - [2006.06.29 18:18:10 | 000,167,566 | R--- | M] (Cherry GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Ch2kUSB.sys -- (Ch2kUSB) DRV - [2006.04.28 09:59:10 | 000,072,149 | ---- | M] (Cherry GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Ch2kUSBm.sys -- (Ch2kUSBM) DRV - [2005.07.28 08:18:40 | 000,685,056 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock) DRV - [2005.07.20 18:08:28 | 000,100,096 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\aksusb.sys -- (aksusb) DRV - [2005.07.20 18:08:26 | 000,327,808 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\akshasp.sys -- (akshasp) DRV - [2002.04.09 17:00:10 | 000,004,480 | ---- | M] (Elaborate Bytes) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL) DRV - [2001.10.11 14:59:54 | 000,008,012 | ---- | M] (Sven Goers Software) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\TDLPT.SYS -- (TDLPT) DRV - [2001.08.17 14:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir) DRV - [2000.05.03 09:02:08 | 000,018,240 | ---- | M] (Dr.G.Schuhfried GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TDALLAS.SYS -- (Tdallas) DRV - [2000.05.02 06:54:08 | 000,021,472 | ---- | M] (Dr.G.Schuhfried GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SCHDNG.SYS -- (Schdng) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKCU\..\SearchScopes\{B2F5D5F4-5B6F-4639-BBBB-3CB3B1FB336F}: "URL" = http://www.google.de/search?q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "foxsearch" FF - prefs.js..browser.search.defaulturl: "http://suche.web.de/search/web/?origin=searchplugin&su=" FF - prefs.js..browser.search.order.1: "foxsearch" FF - prefs.js..browser.search.order.2: "GMX Suche mit Google" FF - prefs.js..browser.search.order.3: "1&1 Suche" FF - prefs.js..browser.search.searchEngine: "WEB.DE Suche" FF - prefs.js..browser.search.selectedEngine: "foxsearch" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "about:blank" FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1 FF - prefs.js..extensions.enabledItems: 6 FF - prefs.js..extensions.enabledItems: 2 FF - prefs.js..extensions.enabledItems: 48 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: VacuumPlacesImproved@lultimouomo-gmail.com:1.2 FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2 FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.9.3 FF - prefs.js..keyword.URL: "http://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q=" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll () FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Programme\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Programme\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Programme\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Programme\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Facebook\npfbplugin_1_0_3.dll ( ) FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Programme\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.09.08 09:33:32 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012.09.21 15:23:39 | 000,000,000 | ---D | M] [2009.04.11 14:52:54 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Mozilla\Extensions [2012.09.14 12:05:11 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Mozilla\Firefox\Profiles\cm2zeoj2.default\extensions [2010.06.25 08:17:09 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Mozilla\Firefox\Profiles\cm2zeoj2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010.07.08 20:56:45 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Mozilla\Firefox\Profiles\cm2zeoj2.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2009.11.06 20:19:01 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Mozilla\Firefox\Profiles\cm2zeoj2.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2011.01.14 15:16:34 | 000,000,000 | ---D | M] (Vacuum Places Improved) -- C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Mozilla\Firefox\Profiles\cm2zeoj2.default\extensions\VacuumPlacesImproved@lultimouomo-gmail.com [2012.08.28 19:13:43 | 000,340,132 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Mozilla\Firefox\Profiles\cm2zeoj2.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2012.09.14 12:05:11 | 000,270,876 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Mozilla\Firefox\Profiles\cm2zeoj2.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2012.09.08 09:32:53 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.09.08 09:33:32 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll [2010.07.17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll [2011.10.07 12:13:42 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.08.30 19:15:10 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml [2011.10.07 12:13:42 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml [2011.10.07 12:13:42 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml [2011.10.07 12:13:42 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml [2011.10.07 12:13:42 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2001.08.18 12:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found. O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [CherryKeyMan] C:\Programme\Cherry\KeyMan\KeyMan.exe (Cherry GmbH) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKCU..\Run: [NVIDIA nTune] C:\Programme\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0 O8 - Extra context menu item: Free YouTube Download - C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\DVDVideoSoftIEHelpers\youtubedownload.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\DVDVideoSoftIEHelpers\youtubetomp3.htm () O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab (Office Genuine Advantage Validation Tool) O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://static.pe.studivz.net/photouploader/ImageUploader5.cab?nocache=1220304077 (Image Uploader Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B52200EF-9678-49AD-B936-1DD40D3BD66A}: DhcpNameServer = 192.168.0.1 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Mozilla\Firefox\Desktop-Hintergrund.bmp O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Mozilla\Firefox\Desktop-Hintergrund.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008.03.29 06:36:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{c17c1b88-671f-11df-8ec5-0015af74ba29}\Shell\AutoRun\command - "" = F:\installer.exe O33 - MountPoints2\{cff8b6f4-02fc-11e0-9705-0019665c359c}\Shell - "" = AutoRun O33 - MountPoints2\{cff8b6f4-02fc-11e0-9705-0019665c359c}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{cff8b6f4-02fc-11e0-9705-0019665c359c}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) NetSvcs: 6to4 - File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found MsConfig - Services: "SQLWriter" MsConfig - Services: "odserv" MsConfig - Services: "MSSQL$SQLEXPRESS" MsConfig - Services: "aspnet_state" MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^NkbMonitor.exe.lnk - C:\Programme\Nikon\PictureProject\NkbMonitor.exe - (Nikon Corporation) MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^Bene^Startmenü^Programme^Autostart^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE - (Microsoft Corporation) MsConfig - StartUpReg: [b]Alcmtr[/b] - hkey= - key= - C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.) MsConfig - StartUpReg: [b]Anti-Blaxx Manager[/b] - hkey= - key= - C:\Programme\Anti-Blaxx\Anti-Blaxx.exe (MB-Soft) MsConfig - StartUpReg: [b]CheckPoint Cleanup[/b] - hkey= - key= - File not found MsConfig - StartUpReg: [b]CloneCDElbyCDFL[/b] - hkey= - key= - C:\Programme\Elaborate Bytes\CloneCD\ElbyCheck.exe (Elaborate Bytes) MsConfig - StartUpReg: [b]CTFMON.EXE[/b] - hkey= - key= - File not found MsConfig - StartUpReg: [b]nwiz[/b] - hkey= - key= - File not found MsConfig - StartUpReg: [b]QuickTime Task[/b] - hkey= - key= - C:\Programme\QuickTime\qttask.exe (Apple Computer, Inc.) MsConfig - State: "system.ini" - 0 MsConfig - State: "win.ini" - 0 MsConfig - State: "bootini" - 0 MsConfig - State: "services" - 2 MsConfig - State: "startup" - 2 SafeBootMin: 00850410.sys - Driver SafeBootMin: 62038374.sys - Driver SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vds - Service SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: 00850410.sys - Driver SafeBootNet: 62038374.sys - Driver SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: vsmon - Service SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install ActiveX: {9309DD7E-EBFE-3C95-8B47-30D3A012F606} - .NET Framework ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler) Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.) Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll () Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll () Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012.09.22 09:51:42 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\Bene\Recent [2012.09.22 09:17:07 | 000,000,000 | ---D | C] -- C:\_OTL [2012.09.21 19:09:45 | 000,000,000 | ---D | C] -- C:\Programme\ESET [2012.09.21 17:15:18 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine [2012.09.21 15:38:10 | 002,212,440 | ---- | C] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\Bene\Desktop\tdsskiller.exe [2012.09.21 15:15:48 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Malwarebytes [2012.09.21 15:15:25 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware [2012.09.21 15:15:24 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012.09.21 15:15:24 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware [2012.09.21 15:15:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes [2012.09.21 14:32:54 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Bene\Desktop\RK_Quarantine [2012.09.21 08:26:12 | 000,600,576 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Bene\Desktop\OTL.scr [2012.09.21 08:23:01 | 001,153,912 | ---- | C] (Emsi Software GmbH) -- C:\Dokumente und Einstellungen\Bene\Desktop\BlitzBlank.exe [2012.09.20 18:23:47 | 000,203,120 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTSD.sys [2012.09.20 18:23:47 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\PC Tools [2012.09.20 18:23:25 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP [2012.09.20 18:23:15 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Tools [2012.09.20 18:23:14 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\TestApp [2012.09.17 13:52:54 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Bene\Eigene Dateien\phd_toulouse [2012.09.12 20:01:18 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Bene\Lokale Einstellungen\Anwendungsdaten\Samsung [2012.09.12 20:01:13 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Bene\Anwendungsdaten\Samsung [2012.09.12 20:01:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Bene\Eigene Dateien\samsung [2012.09.12 20:00:22 | 000,010,472 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ssadcm.sys [2012.09.12 20:00:21 | 000,010,344 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ssadwh.sys [2012.09.12 19:59:34 | 004,659,712 | ---- | C] (Dmitry Streblechenko) -- C:\WINDOWS\System32\Redemption.dll [2012.09.12 19:59:23 | 000,000,000 | ---D | C] -- C:\Programme\MarkAny [2012.09.12 19:58:41 | 000,000,000 | ---D | C] -- C:\Programme\Samsung [2012.09.12 19:58:41 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Samsung [2012.09.12 19:58:21 | 000,016,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll [2012.09.12 19:57:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\umdf [2012.09.12 19:56:29 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Bene\Lokale Einstellungen\Anwendungsdaten\Downloaded Installations [2012.09.08 09:32:50 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox [2012.08.30 16:38:51 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\JPEG Lossless Rotator [2012.08.30 16:38:50 | 000,000,000 | ---D | C] -- C:\Programme\JPEG Lossless Rotator [2012.08.28 10:04:34 | 000,200,704 | ---- | C] ( (c) MusicCity) -- C:\WINDOWS\System32\muzwmts.dll [2012.08.28 10:04:34 | 000,172,032 | ---- | C] (Musiccity Co.Ltd.) -- C:\WINDOWS\System32\muzapp.exe [2012.08.28 10:04:34 | 000,135,168 | ---- | C] (Musiccity Co.Ltd.) -- C:\WINDOWS\System32\muzaf1.dll [2012.08.28 10:04:34 | 000,122,880 | ---- | C] ((c) MUSICCITY) -- C:\WINDOWS\System32\muzeffect.ax [2012.08.28 10:04:34 | 000,118,784 | ---- | C] ((주)마크애니) -- C:\WINDOWS\System32\MaDRM.dll [2012.08.28 10:04:34 | 000,110,592 | ---- | C] ((c) MusicCity) -- C:\WINDOWS\System32\muzmp4sp.ax [2012.08.28 10:04:34 | 000,049,152 | ---- | C] ((주) 마크애니) -- C:\WINDOWS\System32\MaJGUILib.dll [2012.08.28 10:04:34 | 000,045,056 | ---- | C] ((주) 마크애니) -- C:\WINDOWS\System32\MaXMLProto.dll [2012.08.28 10:04:34 | 000,040,960 | ---- | C] (Telechips Inc.,) -- C:\WINDOWS\System32\MTTELECHIP.dll [2012.08.28 10:04:32 | 000,569,344 | ---- | C] ((c) MusicCity) -- C:\WINDOWS\System32\muzdecode.ax [2012.08.28 10:04:32 | 000,491,520 | ---- | C] (Musiccity Co.Ltd.) -- C:\WINDOWS\System32\muzapp.dll [2012.08.28 10:04:32 | 000,352,256 | ---- | C] (Sample Corporation) -- C:\WINDOWS\System32\MSLUR71.dll [2012.08.28 10:04:32 | 000,258,048 | ---- | C] ((c) PeeringPortal) -- C:\WINDOWS\System32\muzoggsp.ax [2012.08.28 10:04:32 | 000,245,760 | ---- | C] (Teruten Inc.) -- C:\WINDOWS\System32\MSCLib.dll [2012.08.28 10:04:32 | 000,155,648 | ---- | C] (Teruten Inc.) -- C:\WINDOWS\System32\MSFLib.dll [2012.08.28 10:04:32 | 000,131,072 | ---- | C] ((c) MusicCity) -- C:\WINDOWS\System32\muzmpgsp.ax [2012.08.28 10:04:32 | 000,057,344 | ---- | C] (Marktek) -- C:\WINDOWS\System32\MK_Lyric.dll [2012.08.28 10:04:32 | 000,057,344 | ---- | C] (Marktek Inc.) -- C:\WINDOWS\System32\MTXSYNCICON.dll [2012.08.28 10:04:32 | 000,045,320 | ---- | C] (MARKANY) -- C:\WINDOWS\System32\MAMACExtract.dll [2012.08.28 10:04:32 | 000,045,056 | ---- | C] ((주) 마크애니) -- C:\WINDOWS\System32\MACXMLProto.dll [2012.08.28 10:04:32 | 000,024,576 | ---- | C] ((주)마크애니) -- C:\WINDOWS\System32\MASetupCleaner.exe [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012.09.22 17:47:40 | 000,000,000 | ---- | M] () -- C:\WINDOWS\TempFile [2012.09.22 17:47:32 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012.09.22 09:56:55 | 000,505,868 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat [2012.09.22 09:56:55 | 000,479,492 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012.09.22 09:56:55 | 000,104,178 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat [2012.09.22 09:56:55 | 000,085,382 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012.09.22 09:36:55 | 000,302,592 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\Desktop\qygpvo9l.exe [2012.09.22 09:29:22 | 000,000,283 | ---- | M] () -- C:\WINDOWS\matlab.ini [2012.09.21 19:16:10 | 000,881,724 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\Desktop\SecurityCheck.exe [2012.09.21 15:38:11 | 002,212,440 | ---- | M] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\Bene\Desktop\tdsskiller.exe [2012.09.21 14:31:46 | 001,387,520 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\Desktop\RogueKiller.exe [2012.09.21 08:26:12 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Bene\Desktop\OTL.scr [2012.09.21 08:23:02 | 001,153,912 | ---- | M] (Emsi Software GmbH) -- C:\Dokumente und Einstellungen\Bene\Desktop\BlitzBlank.exe [2012.09.20 18:24:35 | 000,691,393 | ---- | M] () -- C:\WINDOWS\System32\drivers\Cat.DB [2012.09.12 19:58:27 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012.09.12 19:58:26 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf [2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012.09.05 19:57:02 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012.09.02 10:48:03 | 000,000,034 | ---- | M] () -- C:\WINDOWS\cdplayer.ini [2012.08.29 11:14:59 | 000,248,696 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012.08.29 09:02:57 | 000,696,520 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2012.08.29 09:02:57 | 000,073,416 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2012.08.28 10:05:04 | 004,659,712 | ---- | M] (Dmitry Streblechenko) -- C:\WINDOWS\System32\Redemption.dll [2012.08.28 10:04:34 | 000,200,704 | ---- | M] ( (c) MusicCity) -- C:\WINDOWS\System32\muzwmts.dll [2012.08.28 10:04:34 | 000,172,032 | ---- | M] (Musiccity Co.Ltd.) -- C:\WINDOWS\System32\muzapp.exe [2012.08.28 10:04:34 | 000,143,360 | ---- | M] () -- C:\WINDOWS\System32\3DAudio.ax [2012.08.28 10:04:34 | 000,135,168 | ---- | M] (Musiccity Co.Ltd.) -- C:\WINDOWS\System32\muzaf1.dll [2012.08.28 10:04:34 | 000,122,880 | ---- | M] ((c) MUSICCITY) -- C:\WINDOWS\System32\muzeffect.ax [2012.08.28 10:04:34 | 000,118,784 | ---- | M] ((주)마크애니) -- C:\WINDOWS\System32\MaDRM.dll [2012.08.28 10:04:34 | 000,110,592 | ---- | M] ((c) MusicCity) -- C:\WINDOWS\System32\muzmp4sp.ax [2012.08.28 10:04:34 | 000,081,920 | ---- | M] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll [2012.08.28 10:04:34 | 000,065,536 | ---- | M] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll [2012.08.28 10:04:34 | 000,057,344 | ---- | M] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll [2012.08.28 10:04:34 | 000,049,152 | ---- | M] ((주) 마크애니) -- C:\WINDOWS\System32\MaJGUILib.dll [2012.08.28 10:04:34 | 000,045,056 | ---- | M] ((주) 마크애니) -- C:\WINDOWS\System32\MaXMLProto.dll [2012.08.28 10:04:34 | 000,040,960 | ---- | M] (Telechips Inc.,) -- C:\WINDOWS\System32\MTTELECHIP.dll [2012.08.28 10:04:32 | 000,974,848 | ---- | M] () -- C:\WINDOWS\System32\cis-2.4.dll [2012.08.28 10:04:32 | 000,569,344 | ---- | M] ((c) MusicCity) -- C:\WINDOWS\System32\muzdecode.ax [2012.08.28 10:04:32 | 000,491,520 | ---- | M] (Musiccity Co.Ltd.) -- C:\WINDOWS\System32\muzapp.dll [2012.08.28 10:04:32 | 000,352,256 | ---- | M] (Sample Corporation) -- C:\WINDOWS\System32\MSLUR71.dll [2012.08.28 10:04:32 | 000,258,048 | ---- | M] ((c) PeeringPortal) -- C:\WINDOWS\System32\muzoggsp.ax [2012.08.28 10:04:32 | 000,245,760 | ---- | M] (Teruten Inc.) -- C:\WINDOWS\System32\MSCLib.dll [2012.08.28 10:04:32 | 000,155,648 | ---- | M] (Teruten Inc.) -- C:\WINDOWS\System32\MSFLib.dll [2012.08.28 10:04:32 | 000,131,072 | ---- | M] ((c) MusicCity) -- C:\WINDOWS\System32\muzmpgsp.ax [2012.08.28 10:04:32 | 000,057,344 | ---- | M] (Marktek) -- C:\WINDOWS\System32\MK_Lyric.dll [2012.08.28 10:04:32 | 000,057,344 | ---- | M] (Marktek Inc.) -- C:\WINDOWS\System32\MTXSYNCICON.dll [2012.08.28 10:04:32 | 000,045,320 | ---- | M] (MARKANY) -- C:\WINDOWS\System32\MAMACExtract.dll [2012.08.28 10:04:32 | 000,045,056 | ---- | M] ((주) 마크애니) -- C:\WINDOWS\System32\MACXMLProto.dll [2012.08.28 10:04:32 | 000,024,576 | ---- | M] ((주)마크애니) -- C:\WINDOWS\System32\MASetupCleaner.exe [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012.09.22 09:36:55 | 000,302,592 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\Desktop\qygpvo9l.exe [2012.09.21 19:16:09 | 000,881,724 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\Desktop\SecurityCheck.exe [2012.09.21 14:31:45 | 001,387,520 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\Desktop\RogueKiller.exe [2012.09.20 18:24:08 | 000,691,393 | ---- | C] () -- C:\WINDOWS\System32\drivers\Cat.DB [2012.09.12 20:22:09 | 000,127,912 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat [2012.09.12 19:58:26 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf [2012.08.28 10:04:34 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\3DAudio.ax [2012.08.28 10:04:34 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll [2012.08.28 10:04:34 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll [2012.08.28 10:04:34 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll [2012.08.28 10:04:32 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll [2012.06.07 18:05:34 | 000,011,620 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\.recently-used.xbel [2012.02.15 10:07:01 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012.01.11 16:43:03 | 000,000,500 | RHS- | C] () -- C:\Dokumente und Einstellungen\Bene\ntuser.pol [2011.08.01 10:15:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Analyzer.INI [2011.02.24 13:10:31 | 000,034,045 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\report.bst [2011.02.24 13:00:23 | 000,018,131 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\report.dbj [2011.01.24 12:42:29 | 000,479,232 | ---- | C] () -- C:\WINDOWS\System32\VisionToolbox.dll [2011.01.24 12:42:17 | 000,004,608 | ---- | C] () -- C:\WINDOWS\System32\drivers\BrainAmpWDM.sys [2011.01.06 11:35:52 | 000,152,464 | ---- | C] () -- C:\WINDOWS\bwcc.dll [2011.01.06 11:35:52 | 000,000,394 | ---- | C] () -- C:\WINDOWS\dfcgen.ini [2010.11.19 22:06:16 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2010.11.19 22:06:14 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2010.11.19 22:06:14 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2010.11.19 22:06:14 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2010.11.19 22:06:13 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2010.11.15 11:44:41 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2010.02.06 20:00:01 | 000,034,283 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\lab.bst [2010.02.06 19:49:31 | 000,018,128 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\lab.dbj [2010.02.02 15:52:01 | 000,026,668 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\neuroreport.bst [2010.02.02 15:33:06 | 000,018,192 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\neuroreport.dbj [2009.07.29 20:00:06 | 000,026,755 | ---- | C] () -- C:\Programme\JoWooD.RPT [2009.06.02 18:19:33 | 000,000,800 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\.bash_history [2009.06.02 17:59:50 | 000,000,600 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\Lokale Einstellungen\Anwendungsdaten\PUTTY.RND [2009.05.29 15:55:35 | 000,001,113 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\_viminfo [2009.05.29 15:51:38 | 000,000,824 | -H-- | C] () -- C:\Dokumente und Einstellungen\Bene\.gitk [2009.01.27 19:50:36 | 000,011,704 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\gsview32.ini [2008.04.02 09:28:19 | 000,052,736 | ---- | C] () -- C:\Dokumente und Einstellungen\Bene\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008.03.31 19:15:10 | 000,000,020 | -H-- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLec.DAT [2008.03.30 08:55:46 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\addr_file.html [color=#E56717]========== ZeroAccess Check ==========[/color] [2009.07.27 17:27:12 | 000,263,222 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\Eigene Dateien\research\software\PyBCI\PyBCI\data\images\L.bmp [2012.02.12 21:17:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Bene\Lokale Einstellungen\Anwendungsdaten\Microsoft\Silverlight\is\osn3tfod.izn\xdcgm0gg.ano\1\l [2008.04.26 20:16:44 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color] [2012.09.21 19:12:21 | 000,002,966 | ---- | M] () -- C:\AdwCleaner[R1].txt [2012.09.22 09:31:11 | 000,002,888 | ---- | M] () -- C:\AdwCleaner[R2].txt [2012.09.22 09:31:32 | 000,002,980 | ---- | M] () -- C:\AdwCleaner[S1].txt [2008.03.29 06:36:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2012.02.27 13:20:38 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2001.08.18 12:00:00 | 000,004,952 | RHS- | M] () -- C:\bootfont.bin [2008.03.29 06:36:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2008.03.29 06:36:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2008.03.29 06:36:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2004.08.03 22:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2008.10.15 17:30:08 | 000,251,712 | RHS- | M] () -- C:\ntldr [2012.09.22 17:47:28 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys [color=#A23BEC]< %USERPROFILE%\*.* >[/color] [2009.10.09 16:05:38 | 000,000,800 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\.bash_history [2009.05.29 15:58:03 | 000,000,824 | -H-- | M] () -- C:\Dokumente und Einstellungen\Bene\.gitk [2012.06.07 18:05:34 | 000,011,620 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\.recently-used.xbel [2012.06.07 18:05:43 | 000,011,704 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\gsview32.ini [2010.02.06 20:08:20 | 000,034,283 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\lab.bst [2010.02.06 20:08:17 | 000,018,128 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\lab.dbj [2011.02.24 13:09:50 | 000,001,467 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\makebst.log [2010.05.17 16:54:18 | 000,000,222 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\mfput.log [2010.02.02 15:52:01 | 000,026,668 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\neuroreport.bst [2010.02.02 15:51:47 | 000,018,192 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\neuroreport.dbj [2012.09.22 09:51:51 | 009,961,472 | -H-- | M] () -- C:\Dokumente und Einstellungen\Bene\NTUSER.DAT [2012.09.22 17:56:06 | 000,001,024 | -H-- | M] () -- C:\Dokumente und Einstellungen\Bene\ntuser.dat.LOG [2012.03.29 19:25:47 | 000,000,190 | -HS- | M] () -- C:\Dokumente und Einstellungen\Bene\ntuser.ini [2012.01.11 16:43:03 | 000,000,500 | RHS- | M] () -- C:\Dokumente und Einstellungen\Bene\ntuser.pol [2011.02.24 13:10:31 | 000,034,045 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\report.bst [2011.02.24 13:08:44 | 000,018,131 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\report.dbj [2011.02.24 13:10:31 | 000,002,289 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\report.log [2009.05.29 15:57:00 | 000,001,113 | ---- | M] () -- C:\Dokumente und Einstellungen\Bene\_viminfo [color=#A23BEC]< %USERPROFILE%\Application Data\*.* >[/color] [color=#A23BEC]< %USERPROFILE%\Application Data\*. >[/color] [2008.04.11 10:29:51 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Bene\Application Data\Microsoft [2011.01.24 12:05:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Bene\Application Data\Syntrillium [color=#A23BEC]< %USERPROFILE%\Local Settings\*.* >[/color] [color=#A23BEC]< %USERPROFILE%\Local Settings\temp\*.exe >[/color] [color=#A23BEC]< %USERPROFILE%\Local Settings\Temporary Internet Files\*.exe >[/color] [color=#A23BEC]< %USERPROFILE%\Local Settings\Application Data\*.* >[/color] [color=#A23BEC]< %AllUsersProfile%\*.* >[/color] [color=#A23BEC]< %AllUsersProfile%\Application Data\*.* >[/color] [color=#A23BEC]< %AllUsersProfile%\Application Data\*. >[/color] [color=#A23BEC]< %AllUsersProfile%\Application Data\Local Settings\*.* >[/color] [color=#A23BEC]< %AllUsersProfile%\Application Data\Local Settings\Temp\*.exe >[/color] [color=#A23BEC]< %ALLUSERSPROFILE%\Documents\My Music\*.exe >[/color] [color=#A23BEC]< %ALLUSERSPROFILE%\Documents\My Pictures\*.exe >[/color] [color=#A23BEC]< %ALLUSERSPROFILE%\Documents\My Videos\*.exe >[/color] [color=#A23BEC]< %ALLUSERSPROFILE%\Documents\*.exe >[/color] [color=#A23BEC]< %USERPROFILE%\My Documents\*.* >[/color] [color=#A23BEC]< %CommonProgramFiles%\*.* >[/color] [color=#A23BEC]< %CommonProgramFiles%\ComObjects*.* >[/color] [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color] [2009.07.29 20:05:51 | 000,026,755 | ---- | M] () -- C:\Programme\JoWooD.RPT [color=#A23BEC]< %PROGRAMFILES%\*. >[/color] [2009.03.03 19:06:31 | 000,000,000 | ---D | M] -- C:\Programme\3DO [2010.02.12 17:02:54 | 000,000,000 | ---D | M] -- C:\Programme\AbiSuite2 [2012.03.04 16:04:53 | 000,000,000 | ---D | M] -- C:\Programme\Adobe [2010.01.27 18:24:38 | 000,000,000 | ---D | M] -- C:\Programme\AGEIA Technologies [2008.05.27 20:33:22 | 000,000,000 | ---D | M] -- C:\Programme\Anti-Blaxx [2009.01.04 13:28:12 | 000,000,000 | ---D | M] -- C:\Programme\ASCOMP Software [2008.03.30 10:47:12 | 000,000,000 | ---D | M] -- C:\Programme\Astonsoft [2010.07.08 21:42:46 | 000,000,000 | ---D | M] -- C:\Programme\Audacity 1.3 Beta (Unicode) [2009.09.28 18:09:17 | 000,000,000 | ---D | M] -- C:\Programme\Audiograbber [2011.10.16 10:37:32 | 000,000,000 | ---D | M] -- C:\Programme\Avira [2008.05.07 18:23:36 | 000,000,000 | ---D | M] -- C:\Programme\Business Objects [2008.05.07 18:03:20 | 000,000,000 | ---D | M] -- C:\Programme\CE Remote Tools [2010.08.05 10:11:47 | 000,000,000 | ---D | M] -- C:\Programme\CheckPoint [2008.03.29 08:35:45 | 000,000,000 | ---D | M] -- C:\Programme\Cherry [2009.10.21 13:54:55 | 000,000,000 | ---D | M] -- C:\Programme\Cisco Systems [2008.03.29 06:33:17 | 000,000,000 | ---D | M] -- C:\Programme\ComPlus Applications [2011.01.24 12:05:30 | 000,000,000 | ---D | M] -- C:\Programme\coolpro2 [2008.04.09 22:19:31 | 000,000,000 | ---D | M] -- C:\Programme\Creative Labs [2008.05.27 20:33:52 | 000,000,000 | ---D | M] -- C:\Programme\DAEMON Tools Lite [2010.08.05 10:53:25 | 000,000,000 | ---D | M] -- C:\Programme\DivX [2010.04.01 19:43:03 | 000,000,000 | ---D | M] -- C:\Programme\Dusco [2010.10.14 14:37:57 | 000,000,000 | ---D | M] -- C:\Programme\DVDVideoSoft [2008.03.30 14:28:51 | 000,000,000 | ---D | M] -- C:\Programme\Elaborate Bytes [2012.09.21 19:09:45 | 000,000,000 | ---D | M] -- C:\Programme\ESET [2008.04.07 19:51:00 | 000,000,000 | ---D | M] -- C:\Programme\ESTsoft [2009.10.05 11:03:30 | 000,000,000 | ---D | M] -- C:\Programme\FileZilla FTP Client [2009.09.29 19:17:16 | 000,000,000 | ---D | M] -- C:\Programme\Firaxis Games [2012.09.20 18:23:47 | 000,000,000 | ---D | M] -- C:\Programme\Gemeinsame Dateien [2009.01.27 19:50:36 | 000,000,000 | ---D | M] -- C:\Programme\Ghostgum [2009.02.08 10:36:20 | 000,000,000 | ---D | M] -- C:\Programme\GIMP-2.0 [2009.10.09 15:56:06 | 000,000,000 | ---D | M] -- C:\Programme\Git [2009.06.13 17:17:09 | 000,000,000 | ---D | M] -- C:\Programme\GnuPG [2010.02.12 18:37:24 | 000,000,000 | ---D | M] -- C:\Programme\GnuWin32 [2012.03.29 14:43:41 | 000,000,000 | ---D | M] -- C:\Programme\GridinSoft Trojan Killer [2009.01.27 19:44:58 | 000,000,000 | ---D | M] -- C:\Programme\gs [2010.04.21 17:16:12 | 000,000,000 | ---D | M] -- C:\Programme\HP [2009.07.29 09:44:14 | 000,000,000 | ---D | M] -- C:\Programme\HTML Help Workshop [2012.09.12 19:59:22 | 000,000,000 | -H-D | M] -- C:\Programme\InstallShield Installation Information [2008.03.29 08:26:40 | 000,000,000 | ---D | M] -- C:\Programme\Intel [2012.08.29 09:24:43 | 000,000,000 | ---D | M] -- C:\Programme\Internet Explorer [2008.03.30 13:50:40 | 000,000,000 | ---D | M] -- C:\Programme\JabRef [2010.08.05 10:26:52 | 000,000,000 | ---D | M] -- C:\Programme\Java [2012.08.30 16:38:51 | 000,000,000 | ---D | M] -- C:\Programme\JPEG Lossless Rotator [2010.11.19 22:06:14 | 000,000,000 | ---D | M] -- C:\Programme\K-Lite Codec Pack [2011.07.09 13:54:55 | 000,000,000 | ---D | M] -- C:\Programme\Kalypso [2009.01.27 19:42:14 | 000,000,000 | ---D | M] -- C:\Programme\LEd [2011.12.04 16:16:23 | 000,000,000 | ---D | M] -- C:\Programme\LilyPond [2012.09.21 15:15:26 | 000,000,000 | ---D | M] -- C:\Programme\Malwarebytes' Anti-Malware [2012.09.12 19:59:23 | 000,000,000 | ---D | M] -- C:\Programme\MarkAny [2008.03.29 09:03:04 | 000,000,000 | ---D | M] -- C:\Programme\MATLAB [2008.10.16 22:07:00 | 000,000,000 | ---D | M] -- C:\Programme\Messenger [2008.05.07 18:19:57 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Device Emulator [2008.03.30 08:50:37 | 000,000,000 | ---D | M] -- C:\Programme\microsoft frontpage [2011.06.29 17:53:20 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Office [2008.04.26 20:20:29 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft SDKs [2012.05.14 18:16:13 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Silverlight [2009.03.18 18:18:32 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft SQL Server [2008.05.07 18:18:27 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft SQL Server Compact Edition [2008.05.07 18:18:28 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Synchronization Services [2008.05.07 18:38:22 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Visual Studio 9.0 [2008.05.07 18:02:25 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Web Designer Tools [2009.12.22 17:19:56 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft Works [2008.05.07 18:21:40 | 000,000,000 | ---D | M] -- C:\Programme\Microsoft.NET [2009.05.30 16:09:43 | 000,000,000 | ---D | M] -- C:\Programme\MiKTeX 2.7 [2010.08.16 08:53:45 | 000,000,000 | ---D | M] -- C:\Programme\Movie Maker [2012.09.17 13:34:52 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox [2012.09.08 11:31:22 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Maintenance Service [2008.05.07 18:09:09 | 000,000,000 | ---D | M] -- C:\Programme\MSBuild [2008.05.28 09:34:05 | 000,000,000 | ---D | M] -- C:\Programme\MSECache [2008.03.29 06:32:20 | 000,000,000 | ---D | M] -- C:\Programme\MSN [2008.03.29 06:32:57 | 000,000,000 | ---D | M] -- C:\Programme\MSN Gaming Zone [2008.04.26 20:15:51 | 000,000,000 | ---D | M] -- C:\Programme\MSXML 6.0 [2011.11.26 14:59:42 | 000,000,000 | ---D | M] -- C:\Programme\MuseScore [2008.10.15 17:32:08 | 000,000,000 | ---D | M] -- C:\Programme\NetMeeting [2008.03.31 19:13:38 | 000,000,000 | ---D | M] -- C:\Programme\Nikon [2009.11.06 20:19:02 | 000,000,000 | ---D | M] -- C:\Programme\NOS [2008.05.16 23:40:10 | 000,000,000 | ---D | M] -- C:\Programme\NVIDIA Corporation [2008.05.16 23:39:33 | 000,000,000 | ---D | M] -- C:\Programme\NVIDIA nTune Performance Application [2008.03.30 09:02:54 | 000,000,000 | ---D | M] -- C:\Programme\OpenOffice.org 2.4 [2011.05.12 23:11:55 | 000,000,000 | ---D | M] -- C:\Programme\Outlook Express [2012.04.06 11:53:52 | 000,000,000 | ---D | M] -- C:\Programme\pdfsam [2011.04.25 17:40:57 | 000,000,000 | ---D | M] -- C:\Programme\Pixum [2009.06.02 18:26:00 | 000,000,000 | ---D | M] -- C:\Programme\PuTTY [2008.07.18 11:23:58 | 000,000,000 | ---D | M] -- C:\Programme\QuickTime [2008.03.30 13:28:01 | 000,000,000 | ---D | M] -- C:\Programme\R [2011.03.21 18:16:13 | 000,000,000 | ---D | M] -- C:\Programme\RadarSync [2008.03.30 20:19:06 | 000,000,000 | ---D | M] -- C:\Programme\Realtek [2008.04.26 20:17:44 | 000,000,000 | ---D | M] -- C:\Programme\Reference Assemblies [2012.09.12 20:00:10 | 000,000,000 | ---D | M] -- C:\Programme\Samsung [2012.05.01 09:29:15 | 000,000,000 | ---D | M] -- C:\Programme\Slicer3 3.6.2010-11-03 [2010.12.16 10:25:30 | 000,000,000 | ---D | M] -- C:\Programme\Spiele [2011.11.29 20:28:18 | 000,000,000 | ---D | M] -- C:\Programme\SPSSEV-DE [2011.01.04 20:52:01 | 000,000,000 | ---D | M] -- C:\Programme\Steam [2008.03.29 09:41:44 | 000,000,000 | ---D | M] -- C:\Programme\SYSTAT 11 [2011.07.09 17:23:57 | 000,000,000 | ---D | M] -- C:\Programme\Ubisoft [2008.03.29 06:41:39 | 000,000,000 | -H-D | M] -- C:\Programme\Uninstall Information [2011.01.04 12:38:51 | 000,000,000 | ---D | M] -- C:\Programme\VideoLAN [2010.04.01 19:48:20 | 000,000,000 | ---D | M] -- C:\Programme\VLCPortable [2009.05.30 16:14:10 | 000,000,000 | ---D | M] -- C:\Programme\Web Page Maker [2012.09.12 19:57:45 | 000,000,000 | ---D | M] -- C:\Programme\Windows Media Player [2008.05.07 18:19:37 | 000,000,000 | ---D | M] -- C:\Programme\Windows Mobile 5.0 SDK R2 [2008.10.15 17:32:05 | 000,000,000 | ---D | M] -- C:\Programme\Windows NT [2008.03.29 06:35:07 | 000,000,000 | -H-D | M] -- C:\Programme\WindowsUpdate [2008.03.29 06:36:18 | 000,000,000 | ---D | M] -- C:\Programme\xerox [2008.03.31 19:32:19 | 000,000,000 | ---D | M] -- C:\Programme\xp-AntiSpy [color=#A23BEC]< %systemroot%\system32\config\systemprofile\*.* >[/color] [color=#A23BEC]< %systemroot%\system32\config\systemprofile\Application Data\*.* >[/color] [color=#A23BEC]< %systemroot%\system32\config\systemprofile\\Local Settings\*.* >[/color] [color=#A23BEC]< %systemroot%\system32\config\systemprofile\\Local Settings\Application Data\*.* >[/color] [color=#A23BEC]< %systemroot%\system32\config\systemprofile\\Local Settings\Temp\*.exe >[/color] [color=#A23BEC]< %systemroot%\system32\config\systemprofile\\Local Settings\Temporary Internet Files\*.exe >[/color] [color=#A23BEC]< C:\Documents and Settings\LocalService\Application Data\*.* >[/color] [color=#A23BEC]< C:\Documents and Settings\LocalService\Local Settings\Application Data\*.* >[/color] [color=#A23BEC]< C:\Documents and Settings\LocalService\Local Settings\temp\*.exe >[/color] [color=#A23BEC]< C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\*.exe >[/color] [color=#A23BEC]< C:\Documents and Settings\LocalService\Local Settings\*.* >[/color] [color=#A23BEC]< C:\Documents and Settings\LocalService\*.* >[/color] [color=#A23BEC]< C:\Documents and Settings\NetworkService\Application Data\*.* >[/color] [color=#A23BEC]< C:\Documents and Settings\NetworkService\Local Settings\Application Data\*.* >[/color] [color=#A23BEC]< C:\Documents and Settings\NetworkService\Local Settings\temp\*.exe >[/color] [color=#A23BEC]< C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\*.exe >[/color] [color=#A23BEC]< C:\Documents and Settings\NetworkService\Local Settings\*.* >[/color] [color=#A23BEC]< C:\Documents and Settings\NetworkService\*.* >[/color] [color=#A23BEC]< %windir%\temp\*.exe >[/color] [color=#A23BEC]< %windir%\*. >[/color] [2012.08.29 09:26:07 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$hf_mig$ [2008.03.30 23:48:51 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$MSI31Uninstall_KB893803v2$ [2008.10.15 17:29:02 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtServicePackUninstall$ [2008.03.29 16:18:45 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$ [2008.03.29 16:18:36 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$ [2010.08.16 08:57:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2079403$ [2010.08.16 08:57:42 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2115168$ [2010.10.13 20:46:42 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2121546$ [2010.10.13 20:43:39 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2141007$ [2010.10.13 20:42:47 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2158563$ [2010.08.16 08:53:53 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2160329$ [2010.07.14 12:46:18 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2229593$ [2010.10.13 20:50:12 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2259922$ [2010.10.13 20:50:23 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2279986$ [2010.08.05 09:16:01 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2286198$ [2010.10.13 20:50:06 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2296011$ [2010.12.30 19:08:45 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2296199$ [2010.10.13 20:50:17 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2345886$ [2010.10.13 20:47:49 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2347290$ [2010.10.13 20:42:40 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2360937$ [2010.10.13 20:49:07 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2378111_WM9$ [2010.10.13 20:50:30 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2387149$ [2011.02.10 11:04:33 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2393802$ [2011.04.15 18:21:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2412687$ [2011.01.12 13:14:28 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2419632$ [2010.12.30 19:07:46 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2423089$ [2010.12.30 19:08:14 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2436673$ [2010.12.30 19:08:36 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2440591$ [2010.12.30 19:08:40 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2443105$ [2010.12.30 19:08:18 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2443685$ [2010.12.30 19:08:09 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2467659$ [2011.06.16 17:54:19 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2476490$ [2011.02.10 11:04:48 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2476687$ [2011.02.10 11:04:43 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2478960$ [2011.02.10 11:05:11 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2478971$ [2011.02.10 11:05:03 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2479628$ [2011.03.09 13:48:56 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2479943$ [2011.03.09 13:48:48 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2481109$ [2011.02.10 11:04:53 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2483185$ [2011.02.10 11:05:07 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2485376$ [2011.04.15 18:21:31 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2485663$ [2011.04.15 18:19:00 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2503658$ [2011.06.16 17:54:15 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2503665$ [2011.04.15 18:18:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2506212$ [2011.04.16 09:15:33 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2506223$ [2011.04.15 18:18:34 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2507618$ [2011.07.13 17:38:45 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2507938$ [2011.04.15 18:19:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2508272$ [2011.04.15 18:18:30 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2508429$ [2011.04.15 18:17:39 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2509553$ [2011.04.16 09:15:38 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2510581$ [2011.04.15 18:18:26 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2511455$ [2011.03.30 08:34:39 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2524375$ [2011.06.16 17:54:10 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2535512$ [2011.06.16 17:53:44 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2536276$ [2011.08.11 11:15:37 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2536276-v2$ [2011.06.29 17:50:59 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2541763$ [2011.06.16 17:53:36 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2544893$ [2011.07.13 17:38:34 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2555917$ [2011.08.11 11:14:51 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2562937$ [2011.10.12 16:17:37 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2564958$ [2011.08.11 11:14:59 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2566454$ [2011.10.12 16:15:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2567053$ [2011.08.11 11:15:42 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2567680$ [2011.08.11 11:15:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2570222$ [2011.08.24 11:23:16 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2570791$ [2011.09.15 09:11:33 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2570947$ [2012.01.11 13:22:46 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2584146$ [2012.01.26 13:34:57 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2585542$ [2011.10.12 13:47:02 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2592799$ [2012.01.11 13:22:59 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2598479$ [2012.01.11 13:22:54 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2603381$ [2011.09.07 16:42:58 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2607712$ [2011.09.15 09:12:10 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2616676$ [2011.12.14 10:23:02 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2618451$ [2011.12.14 10:23:21 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2619339$ [2011.12.14 10:22:35 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2620712$ [2012.03.14 16:29:50 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2621440$ [2011.12.14 10:24:10 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2624667$ [2012.01.11 13:23:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2631813$ [2011.12.14 10:22:25 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2633171$ [2011.12.14 10:23:25 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2633952$ [2011.12.14 10:24:16 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2639417$ [2012.03.14 16:29:56 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2641653$ [2011.11.11 19:14:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2641690$ [2012.01.11 13:23:12 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2646524$ [2012.03.14 16:29:41 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2647518$ [2012.04.11 10:08:51 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2653956$ [2012.08.28 19:14:33 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2655992$ [2012.05.14 14:46:28 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2659262$ [2012.02.15 10:16:10 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2660465$ [2012.02.15 10:15:40 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2661637$ [2012.05.14 14:40:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2676562$ [2012.06.13 17:02:38 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2685939$ [2012.05.14 14:42:33 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2686509$ [2012.08.28 19:14:41 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2691442$ [2012.05.14 14:42:00 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2695962$ [2012.08.28 19:13:58 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2698365$ [2012.08.29 09:26:03 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2705219$ [2012.06.13 17:05:23 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2707511$ [2012.06.13 17:00:13 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2709162$ [2012.08.29 09:26:41 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2712808$ [2012.06.04 16:18:38 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2718704$ [2012.08.28 19:14:09 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2719985$ [2012.08.29 09:25:36 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2723135$ [2012.08.29 09:26:10 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB2731847$ [2008.03.31 10:51:15 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB873339$ [2008.03.31 10:52:50 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB885835$ [2008.03.31 10:52:47 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB885836$ [2008.03.31 10:48:01 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB886185$ [2008.03.31 10:51:07 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB887472$ [2008.03.29 08:28:42 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB888111WXPSP2$ [2008.03.31 23:23:45 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB888302$ [2008.03.31 10:50:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB890046$ [2008.03.31 08:52:17 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB890859$ [2008.03.31 10:50:19 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB891781$ [2008.03.31 10:52:06 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB893756$ [2008.03.31 08:52:38 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB894391$ [2008.03.31 10:50:57 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB896358$ [2008.03.31 10:51:41 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB896423$ [2008.03.31 10:47:38 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB896428$ [2008.03.30 23:48:17 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB898461$ [2008.03.31 10:53:15 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB899587$ [2008.03.31 10:52:14 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB899591$ [2008.03.31 10:51:37 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB900485$ [2012.09.21 15:23:39 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB900725$ [2008.03.31 10:52:18 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB901017$ [2008.03.31 10:49:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB901214$ [2008.03.31 10:50:09 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB902400$ [2008.06.01 13:09:02 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB904942$ [2008.03.31 10:49:08 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB905414$ [2008.03.31 10:47:46 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB905749$ [2008.03.31 08:52:34 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB908519$ [2008.03.31 10:47:50 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB908531$ [2008.03.31 10:50:42 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB910437$ [2008.03.31 10:51:57 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB911280$ [2008.03.31 10:51:49 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB911562$ [2008.03.31 10:50:38 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB911564$ [2008.03.31 10:52:22 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB911927$ [2008.03.31 10:47:42 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB913580$ [2008.03.31 10:49:43 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB914388$ [2008.03.31 08:52:27 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB914389$ [2008.06.01 13:09:09 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB914440$ [2008.03.29 16:18:20 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB915865$ [2008.03.31 10:47:59 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB916595$ [2008.03.31 10:48:47 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB918118$ [2008.03.31 10:50:16 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB918439$ [2008.03.31 10:49:47 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB919007$ [2008.03.31 10:48:13 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB920213$ [2008.03.31 10:50:24 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB920670$ [2008.03.31 08:52:30 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB920683$ [2008.03.31 10:52:10 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB920685$ [2008.03.31 23:23:59 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB920872$ [2008.03.31 10:48:56 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB922582$ [2008.03.31 10:52:55 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB922819$ [2008.03.31 10:49:00 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB923191$ [2008.03.31 23:24:27 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB923414$ [2009.04.15 21:38:45 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB923561$ [2008.03.31 10:52:01 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB923980$ [2008.03.31 10:51:32 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB924270$ [2008.03.31 23:24:17 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB924667$ [2008.03.31 10:50:53 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB925398_WMP64$ [2008.04.27 17:51:50 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB925720$ [2008.03.31 23:24:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB925902$ [2008.03.31 10:48:43 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB926255$ [2008.03.31 10:50:00 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB926436$ [2008.03.31 10:53:10 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB927779$ [2008.03.31 10:53:06 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB927802$ [2008.03.31 23:24:14 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB927891$ [2008.03.31 10:52:37 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB928255$ [2008.03.31 08:52:10 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB928843$ [2008.03.31 10:50:28 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB929123$ [2012.09.14 11:55:27 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB929399$ [2008.03.31 10:49:51 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB930178$ [2008.03.31 23:23:37 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB930916$ [2008.03.31 10:51:29 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB931261$ [2008.03.31 10:52:31 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB931784$ [2008.03.31 23:23:50 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB932168$ [2008.05.29 09:45:56 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB932823-v3$ [2008.03.31 23:24:23 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB933729$ [2008.03.31 10:52:26 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB935448$ [2008.03.31 10:47:34 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB935839$ [2008.03.31 10:48:09 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB935840$ [2008.03.31 10:51:53 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB936021$ [2008.03.31 23:24:09 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB936357$ [2008.03.31 10:51:25 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB936782_WMP9$ [2008.03.31 10:52:42 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB937894$ [2008.10.15 17:37:00 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB938464$ [2009.03.11 18:30:37 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB938464-v2$ [2008.09.10 15:22:12 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB938464_0$ [2008.03.31 10:51:45 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB938828$ [2008.03.31 10:51:01 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB938829$ [2008.03.31 10:48:51 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB941202$ [2008.03.31 10:48:39 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB941568$ [2008.03.31 10:49:18 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB941569$ [2008.03.31 10:51:12 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB941644$ [2008.04.09 09:15:49 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB941693$ [2008.03.31 10:49:55 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB942763$ [2008.03.31 10:47:30 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB943055$ [2008.06.01 13:09:15 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB943460$ [2008.03.31 10:53:00 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB943460_0$ [2008.03.31 10:48:06 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB943485$ [2008.03.31 08:52:23 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB944653$ [2008.04.09 09:14:50 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB945553$ [2008.03.31 10:51:05 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB946026$ [2008.10.16 22:06:59 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB946648$ [2008.04.09 09:15:26 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB948590$ [2008.04.09 09:15:53 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB948881$ [2008.05.14 07:46:55 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB950749$ [2008.06.11 00:02:00 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB950760$ [2008.10.15 17:37:07 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB950762$ [2008.06.11 00:02:04 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB950762_0$ [2008.10.15 17:37:13 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB950974$ [2008.08.14 23:57:11 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB950974_0$ [2008.10.15 17:37:19 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB951066$ [2008.08.14 11:50:11 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB951066_0$ [2008.08.14 11:50:25 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB951072-v2$ [2008.10.15 17:37:25 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB951376$ [2008.10.15 17:37:31 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB951376-v2$ [2008.06.20 19:00:13 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB951376-v2_0$ [2008.06.11 00:01:51 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB951376_0$ [2008.10.15 17:37:37 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB951698$ [2008.06.11 00:02:08 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB951698_0$ [2008.10.16 22:06:49 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB951978$ [2009.04.15 21:39:03 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB952004$ [2008.12.11 11:51:53 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB952069_WM9$ [2008.10.15 17:37:42 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB952287$ [2008.08.14 11:50:18 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB952287_0$ [2008.10.15 17:37:48 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB952954$ [2008.08.14 23:57:18 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB952954_0$ [2008.08.14 11:50:29 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB953839$ [2009.10.14 16:42:27 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB954155_WM9$ [2008.10.15 20:43:51 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB954211$ [2008.11.12 19:45:29 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB954459$ [2008.12.11 11:51:49 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB954600$ [2008.11.12 19:45:21 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB955069$ [2009.12.21 21:58:54 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB955759$ [2008.12.11 11:52:34 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB955839$ [2008.10.15 20:44:20 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB956391$ [2009.04.15 21:39:16 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB956572$ [2009.08.13 10:02:13 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB956744$ [2008.12.11 11:51:40 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB956802$ [2009.02.21 20:48:25 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB956803$ [2008.10.15 20:43:41 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB956841$ [2009.09.09 23:19:32 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB956844$ [2008.10.15 20:44:15 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB957095$ [2008.11.12 19:45:34 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB957097$ [2008.10.24 19:30:55 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB958644$ [2009.01.14 15:24:40 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB958687$ [2009.03.11 18:30:30 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB958690$ [2009.10.14 16:42:37 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB958869$ [2009.04.15 21:39:34 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB959426$ [2009.03.11 18:30:43 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB960225$ [2009.02.12 10:10:22 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB960715$ [2009.04.15 21:38:56 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB960803$ [2009.08.13 10:02:27 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB960859$ [2009.08.09 08:42:24 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB961118$ [2009.07.15 21:21:48 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB961371$ [2009.04.15 21:39:28 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB961373$ [2009.06.10 21:09:25 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB961501$ [2009.02.25 09:54:56 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB967715$ [2009.09.28 21:15:42 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB968389$ [2009.06.10 21:09:06 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB968537$ [2009.09.09 23:19:36 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB968816_WM9$ [2009.10.14 16:42:33 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB969059$ [2009.06.10 21:09:20 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB969898$ [2009.06.10 21:09:15 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB970238$ [2009.12.09 14:58:13 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB970430$ [2009.08.26 21:29:13 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB970653-v3$ [2011.03.15 22:46:57 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB971029$ [2010.02.10 11:51:14 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB971468$ [2009.10.14 16:41:56 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB971486$ [2009.08.13 10:02:18 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB971557$ [2009.07.15 21:21:57 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB971633$ [2009.08.13 10:02:23 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB971657$ [2009.12.09 14:57:24 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB971737$ [2009.09.09 23:19:23 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB971961$ [2010.01.13 13:38:49 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB972270$ [2009.07.15 21:22:02 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB973346$ [2009.08.13 10:01:57 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB973354$ [2009.08.13 10:02:02 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB973507$ [2009.10.14 16:41:48 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB973525$ [2009.08.13 10:01:51 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB973540_WM9$ [2009.11.24 22:00:03 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB973687$ [2009.08.13 10:01:43 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB973815$ [2009.08.13 10:02:07 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB973869$ [2009.12.09 14:58:02 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB973904$ [2009.10.14 16:42:24 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB974112$ [2009.12.09 14:58:08 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB974318$ [2009.12.09 14:57:32 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB974392$ [2009.10.14 16:42:14 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB974571$ [2009.10.14 16:42:19 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB975025$ [2009.10.14 16:38:03 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB975467$ [2010.10.13 20:49:19 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB975558_WM8$ [2010.02.10 11:50:52 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB975560$ [2010.03.10 20:17:16 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB975561$ [2010.06.11 00:43:29 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB975562$ [2010.02.10 11:51:03 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB975713$ [2009.11.24 22:00:11 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB976098-v2$ [2010.02.10 11:50:26 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB977165$ [2010.04.14 13:42:38 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB977816$ [2010.02.10 11:50:45 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB977914$ [2010.02.10 11:51:08 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB978037$ [2010.02.10 11:50:58 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB978251$ [2010.02.10 11:51:20 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB978262$ [2010.04.14 13:42:43 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB978338$ [2010.05.12 14:30:32 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB978542$ [2010.04.14 13:42:32 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB978601$ [2010.06.11 00:43:59 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB978695_WM9$ [2010.02.10 11:50:38 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB978706$ [2010.02.28 02:25:32 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB979306$ [2010.04.14 13:42:23 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB979309$ [2010.06.11 00:43:50 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB979482$ [2010.06.11 00:44:05 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB979559$ [2010.04.14 13:43:27 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB979683$ [2010.10.13 20:46:55 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB979687$ [2010.06.11 00:45:20 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB980195$ [2010.06.11 00:45:25 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB980218$ [2010.04.14 13:43:19 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB980232$ [2010.08.16 08:53:48 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB980436$ [2010.10.13 20:43:54 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB981322$ [2010.04.14 13:43:13 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB981349$ [2010.05.26 14:14:03 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB981793$ [2010.08.16 08:57:26 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB981852$ [2010.10.13 20:43:50 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB981957$ [2010.08.16 08:53:44 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB981997$ [2010.10.13 20:48:32 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB982132$ [2010.08.16 08:57:47 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB982214$ [2010.08.16 08:53:36 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallKB982665$ [2008.04.26 20:15:55 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallWIC$ [2012.09.12 19:57:36 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallWMFDist11$ [2012.09.12 19:58:16 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallWudf01000$ [2008.04.26 20:19:22 | 000,000,000 | -H-D | M] -- C:\WINDOWS\$NtUninstallXPSEPSCLP$ [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\addins [2009.12.22 08:35:51 | 000,000,000 | ---D | M] -- C:\WINDOWS\AppPatch [2012.06.14 08:45:35 | 000,000,000 | R-SD | M] -- C:\WINDOWS\assembly [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\Config [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\Connection Wizard [2008.03.29 06:32:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\Cursors [2008.08.27 15:30:03 | 000,000,000 | ---D | M] -- C:\WINDOWS\Debug [2009.08.26 17:59:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\Downloaded Installations [2008.09.01 23:21:21 | 000,000,000 | --SD | M] -- C:\WINDOWS\Downloaded Program Files [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\Driver Cache [2008.10.15 17:34:26 | 000,000,000 | ---D | M] -- C:\WINDOWS\ehome [2011.11.26 14:57:05 | 000,000,000 | R-SD | M] -- C:\WINDOWS\Fonts [2012.07.03 13:15:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\Help [2008.03.29 16:19:37 | 000,000,000 | -H-D | M] -- C:\WINDOWS\ie7 [2012.02.15 10:15:48 | 000,000,000 | ---D | M] -- C:\WINDOWS\ie7updates [2012.02.18 14:08:14 | 000,000,000 | -H-D | M] -- C:\WINDOWS\ie8 [2012.08.29 09:24:30 | 000,000,000 | ---D | M] -- C:\WINDOWS\ie8updates [2008.10.15 17:34:24 | 000,000,000 | ---D | M] -- C:\WINDOWS\ime [2012.09.20 12:42:55 | 000,000,000 | -H-D | M] -- C:\WINDOWS\inf [2012.09.20 18:28:07 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\java [2008.10.15 17:34:13 | 000,000,000 | ---D | M] -- C:\WINDOWS\l2schemas [2008.08.13 20:42:49 | 000,000,000 | ---D | M] -- C:\WINDOWS\Logs [2012.02.18 18:01:17 | 000,000,000 | ---D | M] -- C:\WINDOWS\Media [2012.06.14 08:45:37 | 000,000,000 | ---D | M] -- C:\WINDOWS\Microsoft.NET [2008.05.17 17:33:15 | 000,000,000 | ---D | M] -- C:\WINDOWS\Minidump [2011.01.10 13:17:09 | 000,000,000 | ---D | M] -- C:\WINDOWS\MRI-Prefs [2008.10.15 17:32:10 | 000,000,000 | ---D | M] -- C:\WINDOWS\msagent [2008.03.30 08:50:37 | 000,000,000 | ---D | M] -- C:\WINDOWS\msapps [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\mui [2008.10.15 17:34:24 | 000,000,000 | ---D | M] -- C:\WINDOWS\network diagnostic [2008.03.29 08:33:52 | 000,000,000 | ---D | M] -- C:\WINDOWS\nview [2008.03.29 06:35:14 | 000,000,000 | R--D | M] -- C:\WINDOWS\Offline Web Pages [2008.03.29 08:30:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\OPTIONS [2008.04.26 20:16:26 | 000,000,000 | ---D | M] -- C:\WINDOWS\pchealth [2008.10.15 17:34:12 | 000,000,000 | ---D | M] -- C:\WINDOWS\PeerNet [2008.05.27 20:27:09 | 000,000,000 | -H-D | M] -- C:\WINDOWS\PIF [2012.09.22 17:48:34 | 000,000,000 | ---D | M] -- C:\WINDOWS\Prefetch [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\Provisioning [2012.02.27 13:20:37 | 000,000,000 | ---D | M] -- C:\WINDOWS\pss [2010.01.28 20:31:44 | 000,000,000 | ---D | M] -- C:\WINDOWS\RegisteredPackages [2012.09.20 18:53:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\Registration [2011.10.16 10:40:01 | 000,000,000 | ---D | M] -- C:\WINDOWS\repair [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\Resources [2012.09.22 09:51:50 | 000,000,000 | ---D | M] -- C:\WINDOWS\security [2008.10.15 17:34:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\ServicePackFiles [2008.05.08 08:40:12 | 000,000,000 | ---D | M] -- C:\WINDOWS\ShellNew [2008.05.07 18:29:49 | 000,000,000 | ---D | M] -- C:\WINDOWS\SoftwareDistribution [2008.07.09 22:04:43 | 000,000,000 | ---D | M] -- C:\WINDOWS\SQL9_KB948109_ENU [2008.07.11 09:11:01 | 000,000,000 | ---D | M] -- C:\WINDOWS\SQLTools9_KB948109_ENU [2008.12.12 14:15:48 | 000,000,000 | ---D | M] -- C:\WINDOWS\SQLTools9_KB954606_ENU [2009.02.12 10:09:52 | 000,000,000 | ---D | M] -- C:\WINDOWS\SQLTools9_KB960089_ENU [2008.10.15 17:32:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\srchasst [2008.05.06 18:46:06 | 000,000,000 | ---D | M] -- C:\WINDOWS\Sun [2011.06.18 10:06:14 | 000,000,000 | ---D | M] -- C:\WINDOWS\SxsCaPendDel [2008.05.07 18:08:13 | 000,000,000 | ---D | M] -- C:\WINDOWS\symbols [2008.10.15 17:31:43 | 000,000,000 | ---D | M] -- C:\WINDOWS\system [2012.09.22 09:56:55 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32 [2012.06.12 12:48:26 | 000,000,000 | --SD | M] -- C:\WINDOWS\Tasks [2012.09.22 17:51:59 | 000,000,000 | ---D | M] -- C:\WINDOWS\Temp [2008.03.29 07:20:02 | 000,000,000 | ---D | M] -- C:\WINDOWS\twain_32 [2008.03.29 16:19:49 | 000,000,000 | ---D | M] -- C:\WINDOWS\WBEM [2008.03.29 06:35:16 | 000,000,000 | R--D | M] -- C:\WINDOWS\Web [2012.09.20 18:27:59 | 000,000,000 | ---D | M] -- C:\WINDOWS\WinSxS [color=#A23BEC]< %windir%\installer\*. >[/color] [2008.04.26 20:16:25 | 000,000,000 | -HSD | M] -- C:\WINDOWS\installer\$PatchCache$ [2008.10.15 17:34:13 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\tsclientmsitrans [2008.05.07 18:22:45 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{028ED9C4-25EE-4DEE-9CF4-91034BC89B18} [2010.11.03 16:07:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3} [2009.03.18 18:17:28 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{07629207-FAA0-4F1A-8092-BF5085BE511F} [2008.04.26 20:21:00 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{07FCBED5-94C3-4F94-B9D3-360FA27C7B06} [2008.04.26 20:15:51 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E} [2008.05.07 18:18:29 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{159098AF-4EB8-4C10-B0C6-24CDA32B45F9} [2008.03.30 09:04:07 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{1B14B0C3-2D60-477C-A1FE-B88E60948854} [2008.05.07 18:18:45 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{1C3ADB5F-750E-4453-AC98-B75C5323845C} [2010.05.14 13:28:46 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{26A24AE4-039D-4CA4-87B4-2F83216020FF} [2009.10.09 14:54:17 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{2E0DFC24-7C4B-4DCF-BCC7-81C513BED3BC} [2008.03.30 13:57:16 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{3248F0A8-6813-11D6-A77B-00B0D0160050} [2008.03.29 06:41:45 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227} [2009.10.14 16:39:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{445174EA-3D3A-308E-84AD-446127E71441} [2008.03.30 13:48:30 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{49C69876-0196-4620-B237-EA334C2E40B5} [2008.05.07 18:21:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{5C759B74-34F4-43C6-A5D9-039CB754C5E9} [2008.05.07 18:27:29 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{64c5b887-b5ee-42b8-8596-78905a6b5f1f} [2008.04.07 19:54:44 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{6D9B9CF3-1E9C-45B6-B41E-5CF568605556} [2008.05.07 18:17:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{72CCBEA1-8D57-4981-A337-81019F28C5BA} [2008.05.16 23:40:16 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF} [2009.03.18 18:16:51 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{7FB12670-0F93-4E1E-B2F5-4F339199A03A} [2008.04.26 20:20:53 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{842FAF7C-50EF-4463-9B8F-6222E1384D7D} [2012.05.14 14:39:06 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} [2008.05.07 18:02:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{90120000-0021-0000-0000-0000000FF1CE} [2012.03.02 13:04:51 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{90120000-006E-0407-0000-0000000FF1CE} [2008.05.28 09:34:12 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{90120000-00B2-0407-0000-0000000FF1CE} [2012.08.29 09:26:34 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{91120000-002F-0000-0000-0000000FF1CE} [2010.01.27 18:24:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{95FC26FB-19FD-4A96-BBB1-B1062E8648F5} [2008.05.07 18:28:35 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD} [2008.04.26 20:20:09 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{A1071AEB-B0EF-3F5F-BC84-83A270EBE496} [2010.04.21 17:16:23 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{AC60C8C1-855E-45AB-8D95-1D16F8A38E78} [2012.03.04 16:05:43 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{AC76BA86-7AD7-1031-7B44-AA1000000001} [2009.05.16 16:23:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{AC76BA86-7AD7-5464-3428-800000000003} [2010.10.17 12:05:19 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{AC76BA86-7AD7-5760-0000-800000000003} [2008.05.07 18:17:19 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{B1060346-9388-4C5B-AA52-176C39819E43} [2008.05.07 18:27:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{B268E9A1-04A9-40D0-9866-846BE2B74BA7} [2010.04.21 17:16:13 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{BA7A3288-228D-4031-A93A-B5F6B3415E15} [2009.03.18 18:18:49 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{BBAAAD82-6242-420F-86D4-BD72BB5E6C86} [2008.05.07 18:27:12 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{CAA376AF-0DE8-4FCA-942E-C6AC579B94B3} [2008.03.29 08:36:00 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{DC627AE5-A2B1-4D16-AF56-178D10EC3E81} [2008.05.07 18:18:34 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{E32260E7-0B10-43C7-9B77-AB9F4184676D} [2010.04.21 17:16:20 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{F1CD25A0-5401-40B2-BAA9-E267408B16DF} [2009.10.21 13:55:56 | 000,000,000 | ---D | M] -- C:\WINDOWS\installer\{F3C1DE9E-5E16-4BA9-B854-7B53A45E3579} [color=#A23BEC]< %windir%\system32\*. >[/color] [2010.01.28 20:18:36 | 000,000,000 | -H-D | M] -- C:\WINDOWS\system32\$DXE_V2$ [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1025 [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1028 [2008.05.07 18:07:19 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1031 [2008.03.29 07:19:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1033 [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1037 [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1041 [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1042 [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1054 [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\2052 [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\3076 [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\3com_dmi [2010.01.27 18:24:27 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\AGEIA [2008.06.16 18:23:11 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\appmgmt [2008.10.15 17:34:12 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\bits [2012.09.14 11:56:51 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\CatRoot [2012.09.22 17:49:21 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\CatRoot2 [2008.10.15 17:32:07 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Com [2008.05.08 08:38:32 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config [2008.05.07 18:23:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\css [2008.10.15 17:34:13 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\de [2012.02.18 18:01:20 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\de-de [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\dhcp [2011.07.09 17:25:59 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DirectX [2012.09.14 11:55:55 | 000,000,000 | RHSD | M] -- C:\WINDOWS\system32\dllcache [2012.09.22 09:36:24 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\drivers [2012.09.20 12:42:55 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DRVSTORE [2009.08.07 19:24:31 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\en-us [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\export [2012.01.11 16:42:29 | 000,000,000 | -H-D | M] -- C:\WINDOWS\system32\GroupPolicy [2008.05.07 18:23:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\html [2008.03.29 07:19:27 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ias [2008.03.29 07:19:52 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\icsxml [2008.05.07 18:23:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\images [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\IME [2011.04.09 12:15:37 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\inetsrv [2008.05.07 18:23:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\js [2008.03.29 08:59:45 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Lang [2012.09.12 19:58:26 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\LogFiles [2008.03.29 06:34:11 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Macromed [2008.03.29 06:40:42 | 000,000,000 | --SD | M] -- C:\WINDOWS\system32\Microsoft [2008.03.29 06:33:10 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\MsDtc [2008.04.26 20:18:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\mui [2008.10.15 17:32:10 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\npp [2012.09.20 21:30:19 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\NtmsData [2008.10.15 17:31:45 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\oobe [2008.03.30 23:48:19 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\PreInstall [2008.07.18 11:23:58 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\QuickTime [2008.03.29 07:19:56 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ras [2011.08.01 08:57:34 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ReinstallBackups [2008.10.31 17:00:03 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Restore [2010.01.28 16:43:39 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\RTCOM [2011.01.24 12:42:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Setup [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ShellExt [2008.03.30 23:32:52 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\SoftwareDistribution [2008.04.26 20:17:27 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\spool [2008.10.15 17:34:14 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\usmt [2008.09.10 15:23:49 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Visual Studio 2008 [2008.09.10 15:23:49 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Visual Studio 2008Templates [2009.04.16 17:48:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\wbem [2008.03.29 07:18:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\wins [2008.03.29 06:36:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\xircom [2012.05.14 14:45:58 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\XPSViewer [color=#A23BEC]< %Temp%\smtmp\1\*.* >[/color] [color=#A23BEC]< %Temp%\smtmp\2\*.* >[/color] [color=#A23BEC]< %Temp%\smtmp\3\*.* >[/color] [color=#A23BEC]< %Temp%\smtmp\4\*.* >[/color] [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color] [color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color] [color=#A23BEC]< %systemroot%\system32\drivers\*.sys /90 >[/color] [2012.09.21 17:16:35 | 000,188,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\acpi.sys [2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys [2012.07.04 16:05:05 | 000,139,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\rdpwd.sys [2012.06.27 10:37:56 | 000,010,472 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\drivers\ssadcm.sys [2012.06.27 10:37:56 | 000,010,344 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\drivers\ssadwh.sys [color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color] [2008.05.27 20:31:18 | 000,717,296 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\drivers\sptd.sys [color=#A23BEC]< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >[/color] [2008.07.06 14:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll [2005.09.01 16:14:44 | 000,069,120 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\hpzpp40m.dll [2006.10.26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\msonpppr.dll [color=#A23BEC]< %systemroot%\*. /rp /s >[/color] [color=#A23BEC]< %systemroot%\assembly\tmp\*.* /S /MD5 >[/color] [color=#A23BEC]< %systemroot%\assembly\temp\*.* /S /MD5 >[/color] [color=#A23BEC]< %systemroot%\assembly\GAC\*.ini >[/color] [color=#A23BEC]< %systemroot%\assembly\GAC_32\*.ini >[/color] [color=#A23BEC]< %SystemRoot%\assembly\GAC_MSIL\*.ini >[/color] [color=#A23BEC]< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >[/color] [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} /s >[/color] "" = PSFactoryBuffer [HKEY_CLASSES_ROOT\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemsvc.dll -- [2008.04.14 04:22:32 | 000,043,520 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s >[/color] "" = Microsoft WBEM New Event Subsystem [HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 04:22:32 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#A23BEC]< HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s >[/color] [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s >[/color] "" = Microsoft WBEM New Event Subsystem [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 04:22:32 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s >[/color] "" = MruPidlList [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 04:22:25 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} /s >[/color] "" = Start Menu Pin [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}\InProcServer32] "" = %SystemRoot%\system32\SHELL32.dll -- [2012.06.08 16:25:14 | 008,503,808 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} /s >[/color] "" = PSFactoryBuffer [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemsvc.dll -- [2008.04.14 04:22:32 | 000,043,520 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#A23BEC]< HKEY_CLASSES_ROOT\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F} /s >[/color] "" = Microsoft WBEM _WbemFetchRefresherMgr Proxy Helper [HKEY_CLASSES_ROOT\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 12:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [color=#A23BEC]< HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9} /s >[/color] "" = ShellFolder for CD Burning [HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32] "" = C:\WINDOWS\system32\shell32.dll -- [2012.06.08 16:25:14 | 008,503,808 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\MergedFolder] "Attributes" = 0x0 "AttributeMask" = 0xffffffff "Location" = @shell32.dll,-12589 -- [2012.06.08 16:25:14 | 008,503,808 | ---- | M] (Microsoft Corporation) "ConflictOverlayIcon" = %SystemRoot%\system32\SHELL32.dll,-232 -- [2012.06.08 16:25:14 | 008,503,808 | ---- | M] (Microsoft Corporation) [color=#A23BEC]< HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9} /s >[/color] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32] "ThreadingModel" = Both "" = C:\WINDOWS\system32\shell32.dll -- [2012.06.08 16:25:14 | 008,503,808 | ---- | M] (Microsoft Corporation) [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F} /s >[/color] "" = Microsoft WBEM _WbemFetchRefresherMgr Proxy Helper [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 12:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [color=#A23BEC]< HKEY_CURRENT_USER\Software\MSOLoad /s >[/color] [color=#A23BEC]< type c:\diskreport.txt /c >[/color] Microsoft DiskPart Version 5.1.3565 Copyright (C) 1999-2003 Microsoft Corporation. Auf Computer: B Volume Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- Volume 0 D DVD 0 B Volume 1 E DVD 0 B Volume 2 C NTFS Partition 150 GB OK System [color=#A23BEC]< MD5 for: AFD.SYS >[/color] [2011.08.17 15:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\dllcache\afd.sys [2011.08.17 15:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\drivers\afd.sys [2008.04.13 21:19:23 | 000,138,112 | ---- | M] (Microsoft Corporation) MD5=322D0E36693D6E24A2398BEE62A268CD -- C:\WINDOWS\$NtUninstallKB956803$\afd.sys [2008.04.13 21:19:23 | 000,138,112 | ---- | M] (Microsoft Corporation) MD5=322D0E36693D6E24A2398BEE62A268CD -- C:\WINDOWS\ServicePackFiles\i386\afd.sys [2011.02.16 15:22:48 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=355556D9E580915118CD7EF736653A89 -- C:\WINDOWS\$NtUninstallKB2592799$\afd.sys [2008.10.16 17:07:58 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=38D7B715504DA4741DF35E3594FE2099 -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\afd.sys [2008.08.14 12:34:26 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=4D43E74F2A1239D53929B82600F1971C -- C:\WINDOWS\$hf_mig$\KB956803\SP3QFE\afd.sys [2004.08.03 23:14:16 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=5AC495F4CB807B2B98AD2AD591E6D92E -- C:\WINDOWS\$NtServicePackUninstall$\afd.sys [2008.10.16 16:43:01 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7618D5218F2A614672EC61A80D854A37 -- C:\WINDOWS\$NtUninstallKB2503665$\afd.sys [2008.08.14 12:04:36 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 -- C:\WINDOWS\$NtUninstallKB2509553$\afd.sys [2011.02.16 15:25:05 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=8D499B1276012EB907E7A9E0F4D8FDA4 -- C:\WINDOWS\$hf_mig$\KB2503665\SP3QFE\afd.sys [2011.08.17 15:41:46 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=F6B7B1ECD7B41736BDB6FF4B092BCB79 -- C:\WINDOWS\$hf_mig$\KB2592799\SP3QFE\afd.sys [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color] [2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys [2008.10.11 17:33:44 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2008.10.11 17:33:44 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys [2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys [2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys [2004.08.03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys [2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys [2004.08.03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys [color=#A23BEC]< MD5 for: DISK.SYS >[/color] [2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys [2008.10.11 17:33:44 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys [2008.10.11 17:33:44 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys [2004.08.03 22:59:56 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys [2008.04.13 20:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys [2008.04.13 20:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys [color=#A23BEC]< MD5 for: EVENTLOG.DLL >[/color] [2008.01.10 11:43:00 | 000,028,791 | R--- | M] () MD5=01CE8D74F220AC757728906DADA2E0C7 -- C:\Perl\lib\auto\Win32\EventLog\EventLog.dll [2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll [2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll [1999.10.02 10:24:46 | 000,017,408 | ---- | M] () MD5=1363337A5301619F00F8033835EF30E9 -- C:\Programme\MATLAB\R2007a\sys\perl\win32\site\lib\auto\Win32\EventLog\EventLog.dll [2004.08.04 00:57:20 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll [color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color] [2004.08.04 00:57:54 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=22FE1BE02EADDE1632E478E4125639E0 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe [2007.06.13 15:10:08 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=331ED93570BAF3CFE30340298762CD56 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe [2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe [2007.06.13 15:21:45 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=64D320C0E301EEDC5A4ADBBDC5024F7F -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe [2012.03.29 19:23:24 | 001,037,824 | ---- | M] (Microsoft Corporation) MD5=F2317622D29F9FF0F88AEECD5F60F0DD -- C:\WINDOWS\explorer.exe [color=#A23BEC]< MD5 for: I8042PRT.SYS >[/color] [2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:i8042prt.sys [2008.10.11 17:33:44 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:i8042prt.sys [2008.10.11 17:33:44 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:i8042prt.sys [2004.08.04 00:42:26 | 000,053,248 | ---- | M] (Microsoft Corporation) MD5=7C575018D0413440D75432A78B88C899 -- C:\WINDOWS\$NtServicePackUninstall$\i8042prt.sys [2008.04.14 03:55:34 | 000,052,992 | ---- | M] (Microsoft Corporation) MD5=E283B97CFBEB86C1D86BAED5F7846A92 -- C:\WINDOWS\ServicePackFiles\i386\i8042prt.sys [2008.04.14 03:55:34 | 000,052,992 | ---- | M] (Microsoft Corporation) MD5=E283B97CFBEB86C1D86BAED5F7846A92 -- C:\WINDOWS\system32\drivers\i8042prt.sys [color=#A23BEC]< MD5 for: IPSEC.SYS >[/color] [2008.04.13 21:19:42 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=23C74D75E36E7158768DD63D92789A91 -- C:\WINDOWS\ServicePackFiles\i386\ipsec.sys [2008.04.13 21:19:42 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=23C74D75E36E7158768DD63D92789A91 -- C:\WINDOWS\system32\drivers\ipsec.sys [2004.08.03 23:14:30 | 000,074,752 | ---- | M] (Microsoft Corporation) MD5=64537AA5C003A6AFEEE1DF819062D0D1 -- C:\WINDOWS\$NtServicePackUninstall$\ipsec.sys [color=#A23BEC]< MD5 for: LSASS.EXE >[/color] [2004.08.04 00:58:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=183805EB05BCA5A1E4AAAED4D2BE3690 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe [2008.04.14 04:22:51 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=AFB8261B56CBA0D86AEB6DF682AF9785 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe [2008.04.14 04:22:51 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=AFB8261B56CBA0D86AEB6DF682AF9785 -- C:\WINDOWS\system32\lsass.exe [color=#A23BEC]< MD5 for: NETBT.SYS >[/color] [2004.08.03 23:14:38 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=0C80E410CD2F47134407EE7DD19CC86B -- C:\WINDOWS\$NtServicePackUninstall$\netbt.sys [2008.04.13 21:21:00 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D -- C:\WINDOWS\ServicePackFiles\i386\netbt.sys [2008.04.13 21:21:00 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D -- C:\WINDOWS\system32\drivers\netbt.sys [color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color] [2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll [2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll [2004.08.04 00:57:32 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll [color=#A23BEC]< MD5 for: REDBOOK.SYS >[/color] [2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:redbook.sys [2008.10.11 17:33:44 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:redbook.sys [2008.10.11 17:33:44 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:redbook.sys [2004.08.04 01:40:08 | 000,057,600 | ---- | M] (Microsoft Corporation) MD5=AA56702E230860565CB8D43680F57F33 -- C:\WINDOWS\$NtServicePackUninstall$\redbook.sys [2008.04.14 03:52:51 | 000,057,728 | ---- | M] (Microsoft Corporation) MD5=ED761D453856F795A7FE056E42C36365 -- C:\WINDOWS\ServicePackFiles\i386\redbook.sys [2008.04.14 03:52:51 | 000,057,728 | ---- | M] (Microsoft Corporation) MD5=ED761D453856F795A7FE056E42C36365 -- C:\WINDOWS\system32\drivers\redbook.sys [color=#A23BEC]< MD5 for: SCECLI.DLL >[/color] [2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll [2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll [2004.08.04 00:57:34 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll [color=#A23BEC]< MD5 for: SERIAL.SYS >[/color] [2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:serial.sys [2008.10.11 17:33:44 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:serial.sys [2008.10.11 17:33:44 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:serial.sys [2004.08.04 00:42:26 | 000,065,920 | ---- | M] (Microsoft Corporation) MD5=CD5B9995AFCDB466C9EFC048D167E3BE -- C:\WINDOWS\$NtServicePackUninstall$\serial.sys [2008.04.14 03:54:59 | 000,065,536 | ---- | M] (Microsoft Corporation) MD5=CF24EB4F0412C82BCD1F4F35A025E31D -- C:\WINDOWS\ServicePackFiles\i386\serial.sys [2008.04.14 03:54:59 | 000,065,536 | ---- | M] (Microsoft Corporation) MD5=CF24EB4F0412C82BCD1F4F35A025E31D -- C:\WINDOWS\system32\drivers\serial.sys [color=#A23BEC]< MD5 for: SERVICES.EXE >[/color] [2008.04.14 04:22:59 | 000,109,056 | ---- | M] (Microsoft Corporation) MD5=4BB6A83640F1D1792AD21CE767B621C6 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe [2008.04.14 04:22:59 | 000,109,056 | ---- | M] (Microsoft Corporation) MD5=4BB6A83640F1D1792AD21CE767B621C6 -- C:\WINDOWS\ServicePackFiles\i386\services.exe [2009.02.09 13:21:35 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=A3EDBE9053889FB24AB22492472B39DC -- C:\WINDOWS\system32\dllcache\services.exe [2009.02.09 13:21:35 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=A3EDBE9053889FB24AB22492472B39DC -- C:\WINDOWS\system32\services.exe [2004.08.04 00:58:12 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=EDB6B81761BD60F32F740BBC40AFB676 -- C:\WINDOWS\$NtServicePackUninstall$\services.exe [2009.02.09 13:14:22 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=F0A7D59AF279326528715B206669B86C -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe [color=#A23BEC]< MD5 for: SMSS.EXE >[/color] [2008.04.14 04:23:01 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=B3EFDE4B2CC3AC949BCDE7A89712AFCF -- C:\WINDOWS\ServicePackFiles\i386\smss.exe [2008.04.14 04:23:01 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=B3EFDE4B2CC3AC949BCDE7A89712AFCF -- C:\WINDOWS\system32\smss.exe [2004.08.04 00:58:14 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=F529C489BF4A8921DFED80638ECDA656 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe [color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color] [2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Programme\Malwarebytes' Anti-Malware\Chameleon\svchost.exe [2008.04.14 04:23:02 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=4FBC75B74479C7A6F829E0CA19DF3366 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe [2008.04.14 04:23:02 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=4FBC75B74479C7A6F829E0CA19DF3366 -- C:\WINDOWS\system32\svchost.exe [2004.08.04 00:58:16 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=65A819B121EB6FDAB4400EA42BDFFE64 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe [color=#A23BEC]< MD5 for: TCPIP.SYS >[/color] [2007.10.30 18:53:32 | 000,360,832 | ---- | M] (Microsoft Corporation) MD5=64798ECFA43D78C7178375FCDD16D8C8 -- C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys [2007.10.30 19:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys [2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB2509553$\tcpip.sys [2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys [2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys [2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys [2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys [2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys [color=#A23BEC]< MD5 for: USERINIT.EXE >[/color] [2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe [2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe [2004.08.04 00:58:18 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe [color=#A23BEC]< MD5 for: VOLSNAP.SYS >[/color] [2008.04.14 03:52:02 | 000,053,760 | ---- | M] (Microsoft Corporation) MD5=A5A712F4E880874A477AF790B5186E1D -- C:\WINDOWS\ServicePackFiles\i386\volsnap.sys [2008.04.14 03:52:02 | 000,053,760 | ---- | M] (Microsoft Corporation) MD5=A5A712F4E880874A477AF790B5186E1D -- C:\WINDOWS\system32\drivers\volsnap.sys [2004.08.04 00:44:50 | 000,053,760 | ---- | M] (Microsoft Corporation) MD5=D6888520FF56D72A50437E371CA25FC9 -- C:\WINDOWS\$NtServicePackUninstall$\volsnap.sys [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color] [2004.08.04 00:58:20 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe [2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Programme\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe [2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe [2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe [color=#E56717]========== Files - Unicode (All) ==========[/color] [2011.11.04 16:40:06 | 000,158,633 | ---- | M] ()(C:\Dokumente und Einstellungen\All Users\Dokumente\?????????1.pptx) -- C:\Dokumente und Einstellungen\All Users\Dokumente\งานนำเสนอ1.pptx [2011.11.04 15:40:36 | 000,158,633 | ---- | C] ()(C:\Dokumente und Einstellungen\All Users\Dokumente\?????????1.pptx) -- C:\Dokumente und Einstellungen\All Users\Dokumente\งานนำเสนอ1.pptx [color=#E56717]========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========[/color] [C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction [C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction [C:\WINDOWS\assembly\GAC_MSIL\WcfSvcHost\9.0.0.0__31bf3856ad364e35] -> C:\WINDOWS\WinSxS\MSIL_WcfSvcHost_31bf3856ad364e35_9.0.0.0_x-ww_e0abf5ea -> Junction [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 127 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:430C6D84 @Alternate Data Stream - 105 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:DFC5A2B2 < End of report >