OTL logfile created on: 10/8/2012 20:48:01 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rux\Downloads
Windows Vista Ultimate Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.65 Gb Available Physical Memory | 55.19% Memory free
6.17 Gb Paging File | 4.52 Gb Available in Paging File | 73.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 78.12 Gb Total Space | 28.76 Gb Free Space | 36.81% Space Free | Partition Type: NTFS
Drive D: | 108.18 Gb Total Space | 70.14 Gb Free Space | 64.83% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Computer Name: RUX-PC | User Name: Rux | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Rux\Downloads\OTL.com (OldTimer Tools)
PRC - C:\Users\Rux\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\G Data\InternetSecurity\AVKTray\AVKTray.exe (G Data Software AG)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\G Data\InternetSecurity\AVK\AVKWCtl.exe (G Data Software AG)
PRC - C:\Program Files\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG)
PRC - C:\Program Files\Photodex\ProShow Gold\scsiaccess.exe ()
PRC - C:\Program Files\G Data\InternetSecurity\Firewall\GDFirewallTray.exe (G Data Software AG)
PRC - C:\Program Files\G Data\InternetSecurity\AVK\AVKService.exe (G Data Software AG)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Windows\System32\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
PRC - C:\Windows\System32\dlbccoms.exe ( )
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Yahoo!\Messenger\yui.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
========== Services (SafeList) ==========
SRV - (sprtsvc_dellsupportcenter) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter File not found
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AVKWCtl) -- C:\Program Files\G Data\InternetSecurity\AVK\AVKWCtl.exe (G Data Software AG)
SRV - (AVKProxy) -- C:\Program Files\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Skype C2C Service) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (Browser Defender Update Service) -- C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (GDFwSvc) -- C:\Program Files\G Data\InternetSecurity\Firewall\GDFwSvc.exe (G Data Software AG)
SRV - (GDScan) -- C:\Program Files\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG)
SRV - (ScsiAccess) -- C:\Program Files\Photodex\ProShow Gold\scsiaccess.exe ()
SRV - (AVKService) -- C:\Program Files\G Data\InternetSecurity\AVK\AVKService.exe (G Data Software AG)
SRV - (AESTFilters) -- C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (STacSV) -- C:\Windows\System32\stacsv.exe (IDT, Inc.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (dlbc_device) -- C:\Windows\System32\dlbccoms.exe ( )
========== Driver Services (SafeList) ==========
DRV - (USBModem) -- system32\DRIVERS\lgusbmodem.sys File not found
DRV - (usbbus) -- system32\DRIVERS\lgusbbus.sys File not found
DRV - (rwrwaxnd) -- C:\Program Files\Common Files\Microsoft Shared\rwrwaxnd.dll File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (hwusbfake) -- system32\DRIVERS\ewusbfake.sys File not found
DRV - (hwdatacard) -- system32\DRIVERS\ewusbmdm.sys File not found
DRV - (ewusbnet) -- system32\DRIVERS\ewusbnet.sys File not found
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (GDPkIcpt) -- C:\Windows\System32\drivers\PktIcpt.sys (G Data Software AG)
DRV - (GDMnIcpt) -- C:\Windows\System32\drivers\MiniIcpt.sys (G Data Software AG)
DRV - (HookCentre) -- C:\Windows\System32\drivers\HookCentre.sys (G Data Software AG)
DRV - (GDBehave) -- C:\Windows\System32\drivers\GDBehave.sys (G Data Software AG)
DRV - (gdwfpcd) -- C:\Windows\System32\drivers\gdwfpcd32.sys (G Data Software AG)
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (GRD) -- C:\Windows\System32\drivers\GRD.sys (G Data Software)
DRV - (PCTBD) -- C:\Windows\System32\drivers\PCTBD.sys (PC Tools)
DRV - (ANDModem) -- C:\Windows\System32\drivers\lgandmodem.sys (LG Electronics Inc.)
DRV - (AndGps) -- C:\Windows\System32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (AndDiag) -- C:\Windows\System32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (Andbus) -- C:\Windows\System32\drivers\lgandbus.sys (LG Electronics Inc.)
DRV - (SSPORT) -- C:\Windows\System32\drivers\SSPORT.sys (Samsung Electronics)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (DgiVecp) -- C:\Windows\System32\drivers\DgivEcp.sys (Samsung Electronics Co., Ltd.)
DRV - (BCM42RLY) -- C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (OEM02Dev) -- C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (OEM02Vfx) -- C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (adusbser) -- C:\Windows\System32\drivers\adusbser.sys (QUALCOMM Incorporated)
DRV - (bcm4sbxp) -- C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (btusbflt) -- C:\Windows\System32\drivers\btusbflt.sys (Broadcom Corporation.)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.ro
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.ro
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.google.ro
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.ro
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.ro
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2790392
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.ro
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.ro
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.ro
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.ro
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ro/
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...q={searchTerms}
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask...8A-27F1ABBBFFD1
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\SearchScopes\{19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}: "URL" = http://www.fastbrows...3-78E4F39F7BC3}
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\SearchScopes\{2F99AC55-281F-4C3F-8455-0964E3569A57}: "URL" = http://search.yahoo....=utf-8&fr=b1ie7
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.de/"
FF - prefs.js..extensions.enabledAddons: {906305f7-aafc-45e9-8bbd-941950a84dad}:1.1.11215.1124
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.6.117
FF - prefs.js..keyword.URL: "http://dts.search-re...id=406&sr=0&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools\PC Tools Security\BDT\Firefox\ [2012/07/19 23:37:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/11 00:56:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/22 19:16:45 | 000,000,000 | ---D | M]
[2012/05/06 17:49:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rux\AppData\Roaming\Mozilla\Extensions
[2012/10/03 02:59:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rux\AppData\Roaming\Mozilla\Firefox\Profiles\foerfg0y.default\extensions
[2012/08/30 20:50:49 | 000,000,000 | ---D | M] (BitTorrentBar Community Toolbar) -- C:\Users\Rux\AppData\Roaming\Mozilla\Firefox\Profiles\foerfg0y.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/02/20 11:30:18 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Rux\AppData\Roaming\Mozilla\Firefox\Profiles\foerfg0y.default\extensions\[email protected]
[2012/10/03 02:59:03 | 000,000,000 | ---D | M] ("TimeLineRemove.Com") -- C:\Users\Rux\AppData\Roaming\Mozilla\Firefox\Profiles\foerfg0y.default\extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack
[2010/06/27 23:27:25 | 000,002,384 | ---- | M] () -- C:\Users\Rux\AppData\Roaming\Mozilla\Firefox\Profiles\foerfg0y.default\searchplugins\askcom.xml
[2012/04/29 21:23:02 | 000,002,519 | ---- | M] () -- C:\Users\Rux\AppData\Roaming\Mozilla\Firefox\Profiles\foerfg0y.default\searchplugins\Search_Results.xml
[2012/10/08 06:10:21 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/07/19 08:16:03 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/10/08 06:10:22 | 000,000,000 | ---D | M] (G Data BankGuard) -- C:\Program Files\Mozilla Firefox\extensions\{906305f7-aafc-45e9-8bbd-941950a84dad}
[2012/08/12 08:44:30 | 000,000,000 | ---D | M] (G Data WebFilter) -- C:\Program Files\Mozilla Firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}
[2011/03/17 21:18:12 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/09/11 00:56:10 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/06/28 18:55:41 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/08/31 18:38:37 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/29 21:23:02 | 000,002,519 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2012/08/31 18:38:37 | 000,002,253 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage: http://www.google.com/
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\8.0.552.215\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\8.0.552.215\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\8.0.552.215\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U20 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: DNA Plug-in (Enabled) = C:\Program Files\DNA\plugins\npbtdna.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.6.0 (Enabled) = C:\Users\Rux\AppData\Local\Yahoo!\BrowserPlus\2.6.0\Plugins\npybrowserplus_2.6.0.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
O1 HOSTS File: ([2012/09/02 12:17:00 | 000,001,692 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 4 more lines...
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (BHO) - {BA3295CF-17ED-4F49-9E95-D999A0ADBFDC} - C:\Program Files\Common Files\G Data\AVKProxy\BanksafeBHO.dll (G Data Software AG)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [G Data AntiVirus Tray Application] C:\Program Files\G Data\InternetSecurity\AVKTray\AVKTray.exe (G Data Software AG)
O4 - HKLM..\Run: [GDFirewallTray] C:\Program Files\G Data\InternetSecurity\Firewall\GDFirewallTray.exe (G Data Software AG)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000..\Run: [Ehewniru] C:\Windows\explorer.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000..\Run: [ehTray.exe] C:\Windows\explorer.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000..\Run: [JustVoip] "C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe" -nosplash -minimized File not found
O4 - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\S-1-5-21-3576319258-3730388377-3009755145-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...tes/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3BD70C58-F99C-4269-9AA0-411D7A51AF1C}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (\\.\globalroot\systemroot\system32\userinit.exe) - \\.\globalroot\systemroot\system32\userinit.exe ()
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\System32\DreamScene.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Rux\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Rux\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{21c052e7-e242-11de-9257-ea1163804fd7}\Shell - "" = AutoRun
O33 - MountPoints2\{21c052e7-e242-11de-9257-ea1163804fd7}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{238f1340-a838-11dd-9a67-93735652b166}\Shell\AutoRun\command - "" = hni.cmd
O33 - MountPoints2\{238f1340-a838-11dd-9a67-93735652b166}\Shell\explore\Command - "" = hni.cmd
O33 - MountPoints2\{238f1340-a838-11dd-9a67-93735652b166}\Shell\open\Command - "" = hni.cmd
O33 - MountPoints2\{4fc79bdd-1528-11e1-a393-cf6076231f4a}\Shell - "" = AutoRun
O33 - MountPoints2\{4fc79bdd-1528-11e1-a393-cf6076231f4a}\Shell\AutoRun\command - "" = F:\setup.exe /autorun
O33 - MountPoints2\{7f1d2503-d8b2-11e0-9038-9c72073efa11}\Shell - "" = AutoRun
O33 - MountPoints2\{7f1d2503-d8b2-11e0-9038-9c72073efa11}\Shell\AutoRun\command - "" = F:\.\Setup.exe AUTORUN=1
O33 - MountPoints2\{8d04cf13-ba94-11de-b6de-b698a2e0dbc6}\Shell\AutoRun\command - "" = system32/rundll.exe
O33 - MountPoints2\{8d04cf13-ba94-11de-b6de-b698a2e0dbc6}\Shell\explore\command - "" = system32/rundll.exe
O33 - MountPoints2\{8d04cf13-ba94-11de-b6de-b698a2e0dbc6}\Shell\open\command - "" = system32/rundll.exe
O33 - MountPoints2\{db820478-d594-11de-82b1-fdafffb5bd3b}\Shell\AutoRun\command - "" = F:\GODINA/cure.exe
O33 - MountPoints2\{db820478-d594-11de-82b1-fdafffb5bd3b}\Shell\explore\command - "" = F:\GODINA/cure.exe
O33 - MountPoints2\{db820478-d594-11de-82b1-fdafffb5bd3b}\Shell\open\command - "" = F:\GODINA/cure.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = explorer.exe Start.html
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 360 Days ==========
[2012/10/08 06:10:28 | 001,836,568 | ---- | C] (G Data Software AG) -- C:\Windows\System32\GdScrSv.scr
[2012/10/08 06:10:28 | 000,010,792 | ---- | C] (G Data Software AG) -- C:\Windows\System32\GdScrSv.en.dll
[2012/10/07 23:21:29 | 000,000,000 | ---D | C] -- C:\Users\Public\Desktop\CC Support
[2012/10/07 22:56:00 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\DriverCure
[2012/10/07 22:55:59 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\SpeedyPC Software
[2012/10/07 22:55:26 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedyPC Software
[2012/10/07 22:36:57 | 000,000,000 | ---D | C] -- C:\Program Files\BitLocker
[2012/10/04 17:08:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/04 17:08:50 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/10/04 17:08:50 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/09/22 19:51:14 | 000,000,000 | ---D | C] -- C:\Users\Rux\Desktop\fahrradtour
[2012/09/06 13:03:33 | 000,000,000 | ---D | C] -- C:\Users\Rux\Desktop\Regim
[2012/09/05 20:11:20 | 000,000,000 | ---D | C] -- C:\Users\Rux\Desktop\Tarantino Collection
[2012/09/02 12:06:23 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe Media Player
[2012/09/02 12:06:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
[2012/09/02 12:00:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
[2012/09/02 11:43:34 | 000,000,000 | ---D | C] -- C:\Users\Rux\Desktop\Burg Vischering
[2012/08/30 16:49:08 | 000,000,000 | ---D | C] -- C:\Users\Rux\Desktop\New Folder
[2012/08/18 21:59:19 | 000,000,000 | ---D | C] -- C:\Users\Rux\Desktop\Drensteinfurt
[2012/08/16 11:01:22 | 000,000,000 | ---D | C] -- C:\tmpDownload
[2012/08/13 08:48:49 | 000,000,000 | ---D | C] -- C:\Users\Rux\Desktop\Ruxandra
[2012/08/12 15:33:58 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Local\G DATA
[2012/08/12 10:03:49 | 000,030,256 | ---- | C] (G Data Software) -- C:\Windows\System32\drivers\GRD.sys
[2012/08/12 08:44:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G Data InternetSecurity
[2012/08/12 08:44:24 | 000,045,944 | ---- | C] (G Data Software AG) -- C:\Windows\System32\drivers\HookCentre.sys
[2012/08/12 08:44:23 | 000,041,888 | ---- | C] (G Data Software AG) -- C:\Windows\System32\drivers\GDBehave.sys
[2012/08/12 08:44:21 | 000,053,664 | ---- | C] (G Data Software AG) -- C:\Windows\System32\drivers\gdwfpcd32.sys
[2012/08/11 18:00:47 | 000,050,080 | ---- | C] (G Data Software AG) -- C:\Windows\System32\drivers\PktIcpt.sys
[2012/08/11 17:59:55 | 000,093,728 | ---- | C] (G Data Software AG) -- C:\Windows\System32\drivers\MiniIcpt.sys
[2012/08/11 17:59:31 | 000,000,000 | ---D | C] -- C:\ProgramData\G DATA
[2012/08/11 17:59:31 | 000,000,000 | ---D | C] -- C:\Program Files\G Data
[2012/08/11 17:59:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\G Data
[2012/08/11 17:47:26 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Local\Downloaded Installations
[2012/07/20 10:25:53 | 000,000,000 | ---D | C] -- C:\Users\Rux\Desktop\Lebenslauf Stefan
[2012/07/20 09:26:30 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools Security
[2012/07/20 09:20:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2012/07/19 23:37:13 | 000,070,768 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTBD.sys
[2012/07/19 23:37:12 | 002,267,096 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2012/07/19 23:37:12 | 001,681,368 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2012/07/19 23:37:12 | 000,149,464 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2012/07/19 08:19:10 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2012/07/19 08:15:30 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Local\Threat Expert
[2012/07/19 07:16:10 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\Malwarebytes
[2012/07/19 07:16:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/07/18 21:12:48 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools
[2012/07/18 21:08:17 | 000,203,088 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys
[2012/07/18 21:08:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2012/07/18 21:07:58 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2012/07/18 21:07:57 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\TestApp
[2012/07/18 21:07:57 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2012/07/18 20:38:39 | 000,000,000 | ---D | C] -- C:\ProgramData\036DFF61000112BF0053707FC2E33D86
[2012/07/18 20:37:20 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\Epeg
[2012/07/18 20:37:20 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\Cotu
[2012/06/01 22:56:03 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012/06/01 22:56:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012/05/10 19:36:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/05/10 19:36:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2012/04/30 20:56:29 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2012/04/29 21:24:32 | 000,000,000 | ---D | C] -- C:\USERS\RUX\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SopCast
[2012/04/29 21:24:32 | 000,000,000 | ---D | C] -- C:\Program Files\SopCast
[2012/04/29 21:12:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\skin
[2012/04/29 21:12:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\languages
[2012/04/29 21:12:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\codec
[2012/04/29 21:12:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\adv
[2012/03/01 20:36:56 | 000,000,000 | ---D | C] -- C:\Users\Rux\Desktop\Casa Lahr
[2012/02/24 20:28:44 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\JustVoip
[2012/02/23 22:26:27 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Local\Babylon
[2012/02/23 22:26:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2012/02/23 22:08:43 | 000,000,000 | -H-D | C] -- C:\Windows\PIF
[2012/02/23 15:10:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProShow Gold
[2012/02/23 15:10:34 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\Netscape
[2012/02/23 15:10:14 | 000,000,000 | ---D | C] -- C:\Program Files\Photodex
[2012/02/23 14:59:23 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\Photodex
[2012/02/23 14:59:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Photodex
[2012/02/23 14:09:50 | 000,000,000 | ---D | C] -- C:\Users\Rux\Documents\SMP
[2012/02/02 14:25:35 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\Yahoo!
[2011/12/26 21:09:05 | 000,000,000 | -H-D | C] -- C:\$AVG
[2011/12/26 17:24:29 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2011/12/26 17:11:19 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2011/12/17 15:04:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Support Center
[2011/12/14 21:07:31 | 000,000,000 | ---D | C] -- C:\Users\Rux\resuscitare
[2011/11/27 15:53:38 | 000,000,000 | ---D | C] -- C:\Users\Rux\doctorat
[2011/11/14 15:47:33 | 000,000,000 | ---D | C] -- C:\USERS\RUX\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\IrfanView
[2011/11/14 15:47:22 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView
[2011/11/14 15:44:47 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\IrfanView
[2011/11/06 10:57:11 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2011/10/28 12:51:20 | 000,000,000 | ---D | C] -- C:\Users\Rux\AppData\Roaming\PrimoPDF
[2011/10/28 12:17:10 | 000,000,000 | ---D | C] -- C:\Program Files\Nitro PDF
[2011/10/26 18:29:25 | 000,000,000 | ---D | C] -- C:\Program Files\LG Electronics
[2011/10/21 12:34:50 | 000,000,000 | R--D | C] -- C:\Users\Rux\Documents\Scanned Documents
[2011/10/21 12:34:50 | 000,000,000 | ---D | C] -- C:\Users\Rux\Documents\Fax
[2009/12/06 14:52:44 | 028,868,320 | ---- | C] (Microsoft Corporation) -- C:\Program Files\FileFormatConverters.exe
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 360 Days ==========
[2012/10/08 21:01:04 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{A9DBD632-500B-4C93-8C4B-977756834674}.job
[2012/10/08 20:55:04 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/08 20:25:01 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\Registry Reviver-Rux-Startup.job
[2012/10/08 20:25:00 | 000,000,876 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/08 20:24:50 | 000,031,681 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2012/10/08 20:24:50 | 000,031,681 | ---- | M] () -- C:\ProgramData\nvModes.001
[2012/10/08 20:24:44 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/08 20:24:44 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/08 20:24:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/10/08 20:24:39 | 3219,173,376 | -HS- | M] () -- C:\hiberfil.sys
[2012/10/08 20:22:52 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/10/08 17:10:55 | 000,819,056 | ---- | M] () -- C:\Windows\System32\sig.bin
[2012/10/08 17:10:55 | 000,044,736 | ---- | M] () -- C:\Windows\System32\nmp.map
[2012/10/08 06:11:06 | 000,050,080 | ---- | M] (G Data Software AG) -- C:\Windows\System32\drivers\PktIcpt.sys
[2012/10/08 06:10:34 | 000,093,728 | ---- | M] (G Data Software AG) -- C:\Windows\System32\drivers\MiniIcpt.sys
[2012/10/08 06:10:34 | 000,045,944 | ---- | M] (G Data Software AG) -- C:\Windows\System32\drivers\HookCentre.sys
[2012/10/08 06:10:34 | 000,041,888 | ---- | M] (G Data Software AG) -- C:\Windows\System32\drivers\GDBehave.sys
[2012/10/08 06:10:29 | 000,053,664 | ---- | M] (G Data Software AG) -- C:\Windows\System32\drivers\gdwfpcd32.sys
[2012/10/05 06:47:49 | 000,618,648 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/10/05 06:47:49 | 000,104,024 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/10/04 17:09:41 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/25 14:47:24 | 000,010,792 | ---- | M] (G Data Software AG) -- C:\Windows\System32\GdScrSv.en.dll
[2012/09/11 21:01:38 | 003,792,763 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2505.JPG
[2012/09/11 20:58:02 | 004,402,551 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2476.JPG
[2012/09/11 20:51:16 | 004,440,972 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2468.JPG
[2012/09/11 20:42:09 | 001,015,713 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2464.JPG
[2012/09/11 20:38:01 | 000,700,664 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2489.JPG
[2012/09/11 20:21:38 | 000,569,181 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2520.jpg
[2012/09/11 20:19:22 | 000,771,193 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2518.jpg
[2012/09/11 20:18:00 | 000,613,099 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2517.jpg
[2012/09/11 20:16:39 | 000,768,243 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2519.jpg
[2012/09/11 20:04:57 | 004,832,553 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2544.JPG
[2012/09/09 15:42:52 | 003,031,908 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2471.JPG
[2012/09/07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/09/07 06:34:46 | 002,195,400 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/09/02 14:28:21 | 000,003,584 | ---- | M] () -- C:\Users\Rux\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/02 13:57:27 | 003,673,710 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2279.JPG
[2012/09/02 13:04:02 | 005,696,432 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2373.JPG
[2012/09/02 13:02:28 | 004,825,795 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2426.JPG
[2012/09/02 12:49:34 | 004,791,311 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2397.JPG
[2012/09/02 12:34:54 | 004,204,361 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2366.JPG
[2012/09/02 12:34:02 | 005,520,932 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2365.JPG
[2012/08/21 16:30:27 | 004,971,499 | ---- | M] () -- C:\Users\Rux\Desktop\IMG_2159.JPG
[2012/08/12 20:02:33 | 277,343,645 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/08/12 10:03:49 | 000,030,256 | ---- | M] (G Data Software) -- C:\Windows\System32\drivers\GRD.sys
[2012/08/12 08:41:57 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/08/11 19:59:35 | 000,000,336 | ---- | M] () -- C:\Windows\tasks\FixIt_F66956F4-B17B-4115-BBB0-D431EB5C3051.job
[2012/08/11 19:59:31 | 000,002,268 | ---- | M] () -- C:\FixitRegBackup.reg
[2012/07/20 09:27:21 | 001,942,839 | ---- | M] () -- C:\Windows\System32\drivers\Cat.DB
[2012/07/19 08:29:15 | 000,003,836 | ---- | M] () -- C:\Windows\System32\.crusader
[2012/06/14 12:31:38 | 000,070,768 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\PCTBD.sys
[2012/06/14 12:31:22 | 002,267,096 | ---- | M] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2012/06/14 12:31:22 | 001,681,368 | ---- | M] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2012/06/14 12:31:22 | 000,149,464 | ---- | M] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2012/06/14 12:31:00 | 000,767,960 | ---- | M] () -- C:\Windows\BDTSupport.dll
[2012/06/14 11:03:42 | 000,003,488 | ---- | M] () -- C:\Windows\UDB.zip
[2012/06/14 11:03:42 | 000,000,882 | ---- | M] () -- C:\Windows\RegSDImport.xml
[2012/06/14 11:03:42 | 000,000,879 | ---- | M] () -- C:\Windows\RegISSImport.xml
[2012/06/14 11:03:42 | 000,000,131 | ---- | M] () -- C:\Windows\IDB.zip
[2012/05/25 05:37:24 | 001,836,568 | ---- | M] (G Data Software AG) -- C:\Windows\System32\GdScrSv.scr
[2012/05/11 11:14:20 | 000,203,088 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys
[2012/04/29 21:12:44 | 000,075,938 | ---- | M] () -- C:\Windows\System32\Uninstall-TvPlugin-5.4
[2012/02/24 00:06:43 | 229,884,344 | ---- | M] () -- C:\Users\Rux\Desktop\ProShow Slideshow.avi
[2012/02/23 22:26:41 | 000,000,474 | ---- | M] () -- C:\user.js
[2012/02/23 15:10:39 | 000,001,902 | ---- | M] () -- C:\Users\Rux\Application Data\Microsoft\Internet Explorer\Quick Launch\ProShow Gold.lnk
[2012/02/23 15:10:39 | 000,001,878 | ---- | M] () -- C:\Users\Public\Desktop\ProShow Gold.lnk
[2012/02/22 19:21:48 | 000,001,887 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2012/02/11 19:16:09 | 040,918,773 | ---- | M] () -- C:\Users\Rux\Desktop\Snow Feldberg.wmv
[2012/02/07 18:00:25 | 000,274,277 | ---- | M] () -- C:\Users\Rux\Documents\2.JPG
[2012/01/31 05:59:04 | 000,237,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2012/01/26 21:07:55 | 000,000,870 | ---- | M] () -- C:\Users\Rux\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/26 21:07:55 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/01/26 21:03:49 | 000,000,943 | ---- | M] () -- C:\Users\Rux\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/11 09:44:11 | 000,100,446 | ---- | M] () -- C:\Users\Rux\Documents\cc_20120111_084401.reg
[2011/11/30 21:57:53 | 001,023,604 | ---- | M] () -- C:\Users\Rux\Documents\IMAG0912.jpg
[2011/11/30 21:55:28 | 000,739,378 | ---- | M] () -- C:\Users\Rux\Documents\IMAG0906.jpg
[2011/11/30 21:55:04 | 001,115,643 | ---- | M] () -- C:\Users\Rux\Documents\IMAG0502.jpg
[2011/11/22 19:09:42 | 000,017,408 | ---- | M] () -- C:\Users\Rux\AppData\Local\WebpageIcons.db
[2011/11/14 15:47:33 | 000,000,807 | ---- | M] () -- C:\Users\Rux\Desktop\IrfanView.lnk
[2011/11/06 10:57:30 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/05 06:46:06 | 000,031,681 | ---- | C] () -- C:\ProgramData\nvModes.001
[2012/10/04 18:34:02 | 000,031,681 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2012/10/04 18:33:47 | 3219,173,376 | -HS- | C] () -- C:\hiberfil.sys
[2012/10/04 17:09:41 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/11 21:00:56 | 003,792,763 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2505.JPG
[2012/09/11 20:36:46 | 004,402,551 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2476.JPG
[2012/09/11 20:36:45 | 000,700,664 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2489.JPG
[2012/09/11 20:35:51 | 004,440,972 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2468.JPG
[2012/09/11 20:35:50 | 001,015,713 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2464.JPG
[2012/09/11 20:35:49 | 003,031,908 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2471.JPG
[2012/09/11 20:21:36 | 000,569,181 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2520.jpg
[2012/09/11 20:19:21 | 000,771,193 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2518.jpg
[2012/09/11 20:17:59 | 000,613,099 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2517.jpg
[2012/09/11 20:16:16 | 000,768,243 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2519.jpg
[2012/09/11 19:54:58 | 004,832,553 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2544.JPG
[2012/09/02 13:43:21 | 003,673,710 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2279.JPG
[2012/09/02 13:25:06 | 005,520,932 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2365.JPG
[2012/09/02 13:04:24 | 005,696,432 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2373.JPG
[2012/09/02 13:04:24 | 004,825,795 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2426.JPG
[2012/09/02 13:04:24 | 004,791,311 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2397.JPG
[2012/09/02 13:04:24 | 004,204,361 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2366.JPG
[2012/09/02 12:08:55 | 000,001,002 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS4.lnk
[2012/09/02 12:08:02 | 000,000,964 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS4.lnk
[2012/09/02 12:07:35 | 000,001,293 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Drive CS4.lnk
[2012/09/02 12:05:25 | 000,001,057 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS4.lnk
[2012/09/02 12:02:50 | 000,001,268 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS4.lnk
[2012/09/02 12:02:06 | 000,001,148 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS4.lnk
[2012/08/21 16:26:22 | 004,971,499 | ---- | C] () -- C:\Users\Rux\Desktop\IMG_2159.JPG
[2012/08/12 20:02:02 | 277,343,645 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/08/12 11:57:13 | 000,819,056 | ---- | C] () -- C:\Windows\System32\sig.bin
[2012/08/12 11:57:13 | 000,044,736 | ---- | C] () -- C:\Windows\System32\nmp.map
[2012/08/11 19:59:31 | 000,002,268 | ---- | C] () -- C:\FixitRegBackup.reg
[2012/08/11 19:59:31 | 000,000,336 | ---- | C] () -- C:\Windows\tasks\FixIt_F66956F4-B17B-4115-BBB0-D431EB5C3051.job
[2012/08/02 21:14:51 | 000,003,584 | ---- | C] () -- C:\Users\Rux\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/20 09:26:57 | 001,942,839 | ---- | C] () -- C:\Windows\System32\drivers\Cat.DB
[2012/07/19 23:37:13 | 000,767,960 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2012/07/19 23:37:12 | 000,003,488 | ---- | C] () -- C:\Windows\UDB.zip
[2012/07/19 23:37:12 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2012/07/19 23:37:12 | 000,000,879 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2012/07/19 23:37:12 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2012/07/19 08:29:15 | 000,003,836 | ---- | C] () -- C:\Windows\System32\.crusader
[2012/04/29 21:12:42 | 000,075,938 | ---- | C] () -- C:\Windows\System32\Uninstall-TvPlugin-5.4
[2012/02/23 23:36:59 | 229,884,344 | ---- | C] () -- C:\Users\Rux\Desktop\ProShow Slideshow.avi
[2012/02/23 22:26:34 | 000,000,474 | ---- | C] () -- C:\user.js
[2012/02/23 15:10:39 | 000,001,902 | ---- | C] () -- C:\Users\Rux\Application Data\Microsoft\Internet Explorer\Quick Launch\ProShow Gold.lnk
[2012/02/23 15:10:39 | 000,001,878 | ---- | C] () -- C:\Users\Public\Desktop\ProShow Gold.lnk
[2012/02/22 19:16:45 | 000,001,887 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2012/02/11 19:09:46 | 040,918,773 | ---- | C] () -- C:\Users\Rux\Desktop\Snow Feldberg.wmv
[2012/02/07 18:00:12 | 000,274,277 | ---- | C] () -- C:\Users\Rux\Documents\2.JPG
[2012/01/26 21:07:55 | 000,000,870 | ---- | C] () -- C:\Users\Rux\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/26 21:07:55 | 000,000,858 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/01/26 21:07:55 | 000,000,846 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/01/26 21:03:49 | 000,000,943 | ---- | C] () -- C:\Users\Rux\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/11 09:44:07 | 000,100,446 | ---- | C] () -- C:\Users\Rux\Documents\cc_20120111_084401.reg
[2011/11/30 21:57:43 | 001,023,604 | ---- | C] () -- C:\Users\Rux\Documents\IMAG0912.jpg
[2011/11/30 21:55:21 | 000,739,378 | ---- | C] () -- C:\Users\Rux\Documents\IMAG0906.jpg
[2011/11/30 21:54:53 | 001,115,643 | ---- | C] () -- C:\Users\Rux\Documents\IMAG0502.jpg
[2011/11/22 19:09:39 | 000,017,408 | ---- | C] () -- C:\Users\Rux\AppData\Local\WebpageIcons.db
[2011/11/14 15:47:33 | 000,000,807 | ---- | C] () -- C:\Users\Rux\Desktop\IrfanView.lnk
[2011/10/28 12:17:12 | 000,180,624 | ---- | C] () -- C:\Windows\System32\Primomonnt.dll
[2011/06/24 14:09:38 | 000,175,616 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011/06/24 14:09:38 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/06/24 14:09:35 | 000,644,608 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011/06/24 14:09:35 | 000,243,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011/06/24 14:09:35 | 000,073,216 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011/05/24 17:58:15 | 000,003,584 | ---- | C] () -- C:\Windows\System32\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/17 23:11:56 | 000,000,251 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2009/03/11 06:46:38 | 000,162,304 | ---- | C] () -- C:\Program Files\UNWISE.EXE
========== ZeroAccess Check ==========
[2010/05/24 07:08:18 | 000,000,064 | ---- | M] () -- C:\$Recycle.bin\S-1-5-21-3576319258-3730388377-3009755145-1000\$R3C0WVT\Data\l.xml
[2010/05/24 07:08:18 | 000,000,064 | ---- | M] () -- C:\$Recycle.bin\S-1-5-21-3576319258-3730388377-3009755145-1000\$R3C0WVT\Data\n.xml
[2010/05/24 07:08:18 | 000,000,064 | ---- | M] () -- C:\$Recycle.bin\S-1-5-21-3576319258-3730388377-3009755145-1000\$R3C0WVT\Data\u.xml
[2006/11/02 14:53:06 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2008/11/06 14:57:06 | 011,315,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/03/03 06:16:12 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2006/11/02 11:46:13 | 000,348,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/04/27 14:26:21 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\ApexDC++
[2009/11/17 22:52:14 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\Autodesk
[2011/06/24 12:22:50 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\BSplayer
[2008/06/21 15:12:55 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\BSplayer Pro
[2008/07/11 17:12:15 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\ConceptDraw MINDMAP
[2008/07/11 17:12:02 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\ConceptDraw MindMap 6
[2008/07/11 16:55:42 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\ConceptDraw Project 5
[2012/07/18 20:37:20 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\Cotu
[2008/07/11 16:47:53 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\CSOdessa
[2011/04/07 16:24:49 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\DAEMON Tools Lite
[2011/06/24 12:30:39 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\DNA
[2012/10/07 22:56:00 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\DriverCure
[2012/07/19 08:14:33 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\Epeg
[2011/06/21 20:19:04 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\FreeBurner
[2011/08/21 00:26:35 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\Garden Planner
[2011/06/24 13:16:09 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\ImgBurn
[2011/11/14 15:47:23 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\IrfanView
[2008/06/20 20:53:26 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\iSilo
[2012/02/24 20:55:17 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\JustVoip
[2008/07/11 19:00:31 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\LGSync
[2012/02/23 15:10:34 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\Netscape
[2010/06/28 18:59:52 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\OpenOffice.org
[2009/12/17 17:39:55 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\Opera
[2011/02/20 11:19:08 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\PCDr
[2012/02/23 14:59:23 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\Photodex
[2011/10/28 12:51:20 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\PrimoPDF
[2012/10/07 22:55:59 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\SpeedyPC Software
[2012/07/18 21:07:57 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\TestApp
[2010/03/17 14:56:07 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\Thinstall
[2009/12/06 12:43:44 | 000,000,000 | ---D | M] -- C:\Users\Rux\AppData\Roaming\Vodafone
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
< End of report >
I hope that you can help me.
Thank you in advance