Sorry about the long-winded explanation below, not sure of any way around it.
I first noticed a problem when my Avast was inactive. Couldn't get it to activate (message said damaged path or something similar if I remember correctly). Tried to reinstall, didn't help. Had no other problems that I was aware of; my son didn't tell me of any (if he would even recognize them as such). Called Avast for help, they told me they found all kinds of stuff & would kindly fix it for a price that was much more than this computer is worth. (Although they told me my machine was 'in great shape' -- not sure if there are diagnostics tha would tell them that in 5 minutes or was that all smoke?) But you folks have previously helped and are great so here I am.
One thing I did remember that they found to be problematic was InternetSecurity2010 folder under programs. (This machine was bought in Germany & thinks it is still there so most programs are in the C:/Programme folder but this one did land in the C:/Program Files folder. BTW, any advice on how to let the computer know that it is now indeed in the US? OTL, for instance, automatically downloaded in German.)
Wasn't sure how best to proceed as they indicated multiple problems,ultimately decided to follow the "normal malware removal procedure" instructions but the new virus protection software showed 2 things but didn't let me remove them, so I went to your internet security removal instructions, then proceed all the way through the "normal malware removal procedure" instructions.
Therefore, I ran
1)Malewarebytes, which found 1 problem, let it fix it.
2)downloaded & ran a new virus protector program (Avira)after uninstalling a)Avast and b) McAfee. I am not sure if McAfee was real or a virus as I didn't download or install it but maybe my son did. Avira hung at searching for hidden objects. I stopped it and it ran again but not sure if it searched for hidden objects. Found 2 problems but wouldn't let me remove them so decided to try specific InternetSecurity removal instructions.
3) ran OTL with the special instructions under 'fix' mode. One thing I did change -- I noticed it was for only a short time period. As the Avast people indicated that there were problems there for a long time, I increased that timeframe to the max (360-? days).
4)ran Malewarebytes again
5) ran Avira again which again froze at searching for hidden objects. (I even tried letting it run overnight this time) I stopped it and it ran again but, again, not sure if it searched for hidden objects. It did let me fix the problems on this run-through.
6)ran GMER
7)ran OTL again w/ Quickfix, special instructions, left at 90 days.
Logs posted below & in next posts. I can gladly upload them if that is easier for you.
GMER log:
GMER 1.0.15.15319 - http://www.gmer.net
Rootkit scan 2010-10-17 20:59:55
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOKUME~1\THEFAM~1\LOKALE~1\Temp\fwliikoc.sys
---- System - GMER 1.0.15 ----
SSDT F7A6B8AE ZwCreateKey
SSDT F7A6B8A4 ZwCreateThread
SSDT F7A6B8B3 ZwDeleteKey
SSDT F7A6B8BD ZwDeleteValueKey
SSDT F7A6B8C2 ZwLoadKey
SSDT F7A6B890 ZwOpenProcess
SSDT F7A6B895 ZwOpenThread
SSDT F7A6B8CC ZwReplaceKey
SSDT F7A6B8C7 ZwRestoreKey
SSDT F7A6B8B8 ZwSetValueKey
SSDT \??\C:\Programme\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB896A620]
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] C:\Programme\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\196592[email protected] 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C5[email protected] 0x59 0x5E 0xE7 0x0A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\[email protected] 0x7C 0x66 0x56 0x0E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\[email protected] 0xDF 0x2D 0xB0 0x63 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\[email protected] C:\Programme\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\1965923922[email protected] 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x59 0x5E 0xE7 0x0A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\[email protected] 0x7C 0x66 0x56 0x0E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\[email protected] 0xDF 0x2D 0xB0 0x63 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\[email protected] C:\Programme\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\1965923922[email protected] 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x59 0x5E 0xE7 0x0A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\[email protected] 0x7C 0x66 0x56 0x0E ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\[email protected] 0xDF 0x2D 0xB0 0x63 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\[email protected] C:\Programme\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\1965923922[email protected] 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x59 0x5E 0xE7 0x0A ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\[email protected] 0x7C 0x66 0x56 0x0E ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\[email protected] 0xDF 0x2D 0xB0 0x63 ...
---- EOF - GMER 1.0.15 ----
Latest OTL logs:
OTL.txt:
OTL logfile created on: 17.10.2010 21:02:29 - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Dokumente und Einstellungen\The Family\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 75.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 256 256 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 74.50 Gb Total Space | 4.52 Gb Free Space | 6.07% Space Free | Partition Type: NTFS
Drive D: | 65.73 Gb Total Space | 19.91 Gb Free Space | 30.28% Space Free | Partition Type: NTFS
Drive E: | 8.79 Gb Total Space | 5.53 Gb Free Space | 62.94% Space Free | Partition Type: FAT32
Drive N: | 465.76 Gb Total Space | 178.79 Gb Free Space | 38.39% Space Free | Partition Type: NTFS
Computer Name: CHAPMAN-03 | User Name: The Family | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days
========== Processes (SafeList) ==========
PRC - [2010.10.16 01:11:33 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\The Family\Desktop\OTL.exe
PRC - [2010.10.16 00:48:56 | 002,424,560 | ---- | M] (SUPERAntiSpyware.com) -- C:\Programme\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2010.09.21 14:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe
PRC - [2010.04.01 13:33:19 | 000,267,432 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2010.03.19 10:49:20 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010.03.05 02:31:41 | 000,524,632 | ---- | M] (Lavasoft) -- C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010.03.05 02:31:39 | 001,029,456 | ---- | M] (Lavasoft) -- C:\Programme\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010.03.02 11:28:31 | 000,282,792 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.02.24 10:28:09 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2010.02.02 17:31:56 | 000,279,296 | ---- | M] (Motorola) -- C:\Programme\Motorola\MotoConnectService\MotoConnect.exe
PRC - [2010.01.27 11:37:22 | 000,091,392 | ---- | M] () -- C:\Programme\Motorola\MotoConnectService\MotoConnectService.exe
PRC - [2010.01.14 22:11:00 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2010.01.11 16:21:52 | 000,246,504 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
PRC - [2009.06.23 11:55:24 | 000,188,736 | ---- | M] (Nitro PDF Software) -- C:\Programme\Nitro PDF\Professional\NitroPDFDriverService.exe
PRC - [2009.06.23 11:54:18 | 000,061,760 | ---- | M] (Nalpeiron Ltd.) -- C:\WINDOWS\system32\ASTSRV.EXE
PRC - [2008.10.28 17:42:30 | 000,156,968 | ---- | M] (Seagate Technology LLC) -- C:\Programme\Seagate\SeagateManager\Sync\FreeAgentService.exe
PRC - [2008.04.13 22:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.12.01 03:16:54 | 000,594,600 | ---- | M] ( ) -- C:\WINDOWS\system32\lxdpcoms.exe
PRC - [2007.12.01 03:16:47 | 000,098,984 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdpserv.exe
PRC - [2007.01.04 17:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Programme\Viewpoint\Common\ViewpointService.exe
PRC - [2006.09.11 04:40:32 | 000,218,032 | ---- | M] (Macrovision Corporation) -- C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\ISUSPM.exe
PRC - [2003.06.19 17:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
PRC - [2002.10.31 04:35:58 | 000,065,536 | ---- | M] (America Online, Inc.) -- C:\WINDOWS\wanmpsvc.exe
========== Modules (SafeList) ==========
MOD - [2010.10.16 01:11:33 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\The Family\Desktop\OTL.exe
MOD - [2008.04.13 22:21:06 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010.04.01 13:33:19 | 000,267,432 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010.03.19 10:49:20 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010.03.05 02:31:39 | 001,029,456 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Programme\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010.02.24 10:28:09 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.01.27 11:37:22 | 000,091,392 | ---- | M] () [Auto | Running] -- C:\Programme\Motorola\MotoConnectService\MotoConnectService.exe -- (MotoConnect Service)
SRV - [2009.06.23 11:55:24 | 000,188,736 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Programme\Nitro PDF\Professional\NitroPDFDriverService.exe -- (NitroDriverReadSpool)
SRV - [2009.06.23 11:54:18 | 000,061,760 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\WINDOWS\system32\ASTSRV.EXE -- (astcc)
SRV - [2008.10.28 17:42:30 | 000,156,968 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Programme\Seagate\SeagateManager\Sync\FreeAgentService.exe -- (FreeAgentGoNext Service)
SRV - [2008.08.08 23:44:19 | 000,354,560 | ---- | M] (TuneUp Software GmbH) [On_Demand | Stopped] -- C:\WINDOWS\system32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2008.05.01 12:24:16 | 000,313,840 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Programme\Gemeinsame Dateien\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe -- (RoxLiveShare9)
SRV - [2008.05.01 12:24:12 | 000,170,480 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Programme\Gemeinsame Dateien\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe -- (RoxWatch9)
SRV - [2008.05.01 12:23:54 | 001,108,464 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe -- (RoxMediaDB9)
SRV - [2008.04.04 14:51:32 | 000,028,416 | ---- | M] (TuneUp Software GmbH) [On_Demand | Stopped] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2007.12.01 03:16:54 | 000,594,600 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\System32\lxdpcoms.exe -- (lxdp_device)
SRV - [2007.12.01 03:16:47 | 000,098,984 | ---- | M] () [Auto | Running] -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdpserv.exe -- (lxdpCATSCustConnectService)
SRV - [2007.01.04 17:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Running] -- C:\Programme\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - [2006.10.23 08:50:35 | 000,046,640 | R--- | M] (AOL LLC) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe -- (AOL ACS)
SRV - [2004.10.21 21:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2003.06.19 17:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe -- (MDM)
SRV - [2002.10.31 04:35:58 | 000,065,536 | ---- | M] (America Online, Inc.) [Auto | Running] -- C:\WINDOWS\wanmpsvc.exe -- (WANMiniportService) WAN Miniport (ATW)
SRV - [2001.11.12 08:31:48 | 000,020,480 | ---- | M] (X10) [On_Demand | Stopped] -- C:\Programme\Common Files\X10\Common\X10nets.exe -- (x10nets)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Dokumente und Einstellungen\Besitzer\Desktop\MD8008_1120\Biosupdate\WinFlash.sys -- (WINFLASH)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\iiusbisp.sys -- (IIUSBISP)
DRV - [2010.08.31 13:54:03 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010.03.01 10:05:24 | 000,124,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2010.02.26 21:07:15 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2010.02.26 21:07:15 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Programme\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010.02.16 14:24:01 | 000,060,936 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.02.11 08:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2010.01.10 21:14:55 | 000,016,694 | ---- | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PalmUSBD.sys -- (PalmUSBD)
DRV - [2009.10.27 12:02:14 | 000,023,936 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motmodem.sys -- (motmodem)
DRV - [2009.05.11 12:49:19 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009.05.11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.04.24 01:31:44 | 000,064,160 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2008.04.13 14:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008.04.13 14:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008.04.13 14:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008.02.27 13:49:00 | 000,003,840 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\BANTExt.sys -- (BANTExt)
DRV - [2007.12.19 21:02:56 | 000,715,248 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2007.03.11 17:37:20 | 000,018,003 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- C:\Programme\Common Files\Motive\MRENDIS5.sys -- (MRENDIS5)
DRV - [2007.03.11 17:37:19 | 000,019,345 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- C:\Programme\Common Files\Motive\MREMPR5.sys -- (MREMPR5)
DRV - [2004.08.04 01:29:54 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2003.07.18 04:58:20 | 000,036,992 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\SISAGPX.sys -- (SISAGP)
DRV - [2003.05.22 11:44:44 | 000,670,203 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctxs51.sys -- (Intels51)
DRV - [2003.03.20 10:21:24 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2003.02.09 17:33:14 | 000,028,164 | ---- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\MxlW2k.sys -- (MxlW2k)
DRV - [2003.01.10 17:13:04 | 000,033,588 | R--- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2002.11.04 10:32:00 | 000,027,520 | ---- | M] (Philips Semiconductors) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PhTVTune.sys -- (PhTVTune)
DRV - [2002.11.04 10:29:42 | 000,422,976 | ---- | M] (Philips Semiconductors) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Cap7134.sys -- (Cap7134) MEDION (7134)
DRV - [2002.10.28 02:38:06 | 000,947,884 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2002.08.29 08:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2002.08.29 08:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2002.08.14 15:03:36 | 000,017,005 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
DRV - [2002.07.10 11:39:34 | 000,032,256 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisnic.sys -- (SISNIC)
DRV - [2002.04.17 14:27:02 | 000,011,264 | ---- | M] (VOB Computersysteme GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\asapiW2k.sys -- (asapiW2k)
DRV - [2002.03.22 02:43:58 | 000,321,394 | ---- | M] (GlobeSpan Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\GLAPCI.SYS -- (glapci)
DRV - [2002.03.20 12:38:20 | 000,019,140 | ---- | M] (America Online) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atwpkt.sys -- (ATWPKT)
DRV - [2001.11.14 13:07:42 | 000,010,761 | ---- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\x10uif.sys -- (X10UIF)
DRV - [2001.08.17 13:53:42 | 000,004,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\loop.sys -- (msloop)
DRV - [2001.08.17 12:11:18 | 000,020,160 | ---- | M] (ADMtek Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ADM8511.SYS -- (ADM8511)
DRV - [2001.08.17 09:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/2...ions/index.html
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:2.0.1
FF - prefs.js..extensions.enabledItems: [email protected]:4.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:3.20
FF - prefs.js..extensions.enabledItems: [email protected]:5.0.1
FF - prefs.js..extensions.enabledItems: {bcd47b5a-43be-433f-9051-7ce2cdf94ac0}:3.1.3
FF - prefs.js..extensions.enabledItems: {FDE3FEE9-893E-4cc7-A814-60E0DE7B2E01}:3.6
FF - prefs.js..extensions.enabledItems: {e213bb8f-8ebd-11db-96b7-005056c00008}:3.0.0.91
FF - prefs.js..keyword.URL: "http://www.google.co...-8&oe=UTF-8&q="
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Programme\Real\RealPlayer\browserrecord [2007.12.07 22:11:10 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Programme\Mozilla Firefox\components [2010.10.15 19:19:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2010.09.26 12:10:02 | 000,000,000 | ---D | M]
[2008.08.14 22:43:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Extensions
[2010.10.16 14:41:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\extensions
[2010.09.26 15:41:54 | 000,000,000 | ---D | M] (Forecastfox Weather) -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010.09.26 15:42:31 | 000,000,000 | ---D | M] (ActiveInbox for Gmail and Google Apps) -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\extensions\{bcd47b5a-43be-433f-9051-7ce2cdf94ac0}
[2010.09.26 15:41:54 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.08.08 12:26:35 | 000,000,000 | ---D | M] (myFireFox) -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008}
[2010.08.08 12:26:03 | 000,000,000 | ---D | M] (Aeon Clouds) -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\extensions\{FDE3FEE9-893E-4cc7-A814-60E0DE7B2E01}
[2010.03.14 00:32:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\extensions\[email protected]
[2010.09.26 15:41:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\extensions\[email protected]
[2010.03.14 00:32:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\extensions\[email protected]
[2010.09.26 15:42:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\extensions\[email protected]
[2010.08.08 12:26:35 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008}\chrome\mozapps\extensions
[2008.06.02 20:41:50 | 000,001,193 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\searchplugins\altavista.xml
[2010.10.10 21:15:23 | 000,001,968 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\searchplugins\bremende.xml
[2007.09.07 03:14:21 | 000,000,953 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\searchplugins\businesscom.xml
[2010.09.26 12:21:45 | 000,001,728 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\searchplugins\canoonet-inflection.xml
[2010.10.10 21:15:25 | 000,004,267 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\searchplugins\deutscher-wortschatz.xml
[2010.10.10 21:15:25 | 000,001,137 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\searchplugins\dictionarycom.xml
[2010.10.10 21:15:25 | 000,002,008 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\searchplugins\leo-de-en.xml
[2008.08.02 08:02:19 | 000,001,173 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\searchplugins\referencecom---encyclopedia.xml
[2010.10.10 21:15:26 | 000,005,124 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\searchplugins\spiegel-wissen.xml
[2008.06.25 09:14:37 | 000,000,681 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Mozilla\Firefox\Profiles\gnzvcelx.default\searchplugins\webster.xml
[2010.10.16 14:41:32 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2008.09.03 20:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npbittorrent.dll
[2005.12.05 16:31:00 | 000,114,688 | ---- | M] () -- C:\Programme\Mozilla Firefox\plugins\npmozax.dll
[2008.04.13 20:40:09 | 000,163,840 | ---- | M] (CNN) -- C:\Programme\Mozilla Firefox\plugins\NPTURNMED.dll
[2007.04.16 13:07:12 | 000,180,293 | ---- | M] () -- C:\Programme\Mozilla Firefox\plugins\npViewpoint.dll
[2007.04.16 13:07:12 | 000,180,293 | ---- | M] () -- C:\Programme\Mozilla Firefox\plugins\npViewpoint_.dll
O1 HOSTS File: ([2010.10.16 10:19:34 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programme\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programme\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Programme\Gemeinsame Dateien\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [ISUSPM] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [XdriveTray] C:\Programme\xdrive\xdrive desktop\xdrive.exe File not found
O4 - HKCU..\Run: [XdriveTrayIcon] C:\Programme\Xdrive\Xdrive Desktop\XdriveTray.exe File not found
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Alarm Manager.LNK = C:\Programme\palmOne\AlarmApp.exe (Palm, Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\HotSync Manager.lnk = C:\Programme\palmOne\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Dokumente und Einstellungen\The Family\Startmenü\Programme\Autostart\Dropbox.lnk = C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Dokumente und Einstellungen\The Family\Startmenü\Programme\Autostart\PowerReg Scheduler.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MaxRecentDocs = 21
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Programme\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programme\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} http://www.xdrive.co...stall/setup.exe ()
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1186325003218 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1186325760765 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupd...7657.0299189815 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://driveragent.c...driveragent.cab (Driver Agent ActiveX Control)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: vzTCPConfig http://www2.verizon....vzTCPConfig.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Programme\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Programme\SUPERAntiSpyware\SASWINLO.dll - C:\Programme\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\The Family\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\The Family\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Programme\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003.02.05 03:31:27 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - Unable to obtain root file information for disk N:\
O33 - MountPoints2\{40003803-403d-11df-9d88-00038a000015}\Shell\AutoRun\command - "" = J:\setupSNK.exe -- File not found
O33 - MountPoints2\{b65e5658-d2e5-11df-9dc9-00038a000015}\Shell\AutoRun\command - "" = H:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{b65e5658-d2e5-11df-9dc9-00038a000015}\Shell\install\command - "" = H:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{b65e5658-d2e5-11df-9dc9-00038a000015}\Shell\usermanualEnglish\command - "" = H:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{b65e5658-d2e5-11df-9dc9-00038a000015}\Shell\usermanualFrench\command - "" = H:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{b65e5658-d2e5-11df-9dc9-00038a000015}\Shell\usermanualSpanish\command - "" = H:\rcaeasyrip_setup.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH)
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16620634377289728)
========== Files/Folders - Created Within 90 Days ==========
[2010.10.16 10:17:28 | 000,000,000 | ---D | C] -- C:\_OTL
[2010.10.16 09:45:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Avira
[2010.10.16 01:11:30 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\The Family\Desktop\OTL.exe
[2010.10.16 01:04:31 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Avira
[2010.10.16 01:00:46 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010.10.16 01:00:45 | 000,124,784 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2010.10.16 01:00:45 | 000,060,936 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2010.10.16 01:00:45 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2010.10.16 01:00:45 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010.10.16 01:00:44 | 000,000,000 | ---D | C] -- C:\Programme\Avira
[2010.10.16 01:00:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira
[2010.10.15 13:16:26 | 000,000,000 | ---D | C] -- C:\Programme\ERUNT
[2010.10.15 13:14:57 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Dokumente und Einstellungen\The Family\Desktop\erunt-setup.exe
[2010.10.14 22:49:50 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\The Family\Desktop\mbam-setup-1.46.exe
[2010.10.14 18:47:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\The Family\Local Settings
[2010.10.14 18:47:18 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Software Update Utility
[2010.10.14 18:13:11 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\ICS
[2010.10.14 12:24:26 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\HamsterSoft
[2010.10.13 16:44:28 | 000,000,000 | ---D | C] -- C:\Programme\NCH Software
[2010.10.11 08:52:38 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\The Family\Desktop\My Dropbox
[2010.10.11 08:48:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Dropbox
[2010.10.05 23:14:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\The Family\Desktop\Adam Mesh
[2010.10.03 21:50:41 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\The Family\Desktop\Mash Season 8 DVDRip
[2010.09.27 18:52:32 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\The Family\Desktop\Neuer Ordner
[2010.09.26 22:29:07 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\The Family\Desktop\Season 7
[2010.09.01 20:18:17 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\The Family\Lokale Einstellungen\Anwendungsdaten\AIM
[2010.09.01 20:18:17 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AIM
[2010.09.01 20:16:35 | 000,000,000 | ---D | C] -- C:\Programme\AIM
[2010.08.11 12:41:51 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\McAfee
[2010.08.08 12:32:13 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Abine
[2010.08.08 10:54:51 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\McAfee
[2010.08.04 10:39:45 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Macromedia
[2010.08.04 10:39:41 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Adobe
[2010.07.21 10:21:17 | 000,000,000 | ---D | C] -- C:\Programme\Tracker Software
[2009.04.01 08:29:13 | 000,438,272 | ---- | C] ( ) -- C:\WINDOWS\System32\LXDPhcp.dll
[2009.04.01 08:29:13 | 000,364,544 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdpinpa.dll
[2009.04.01 08:29:13 | 000,339,968 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdpiesc.dll
[2009.04.01 08:29:12 | 001,101,824 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdpserv.dll
[2009.04.01 08:29:12 | 000,843,776 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdpusb1.dll
[2009.04.01 08:29:12 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdpprox.dll
[2009.04.01 08:29:11 | 000,647,168 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdppmui.dll
[2009.04.01 08:29:11 | 000,569,344 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdplmpm.dll
[2009.04.01 08:29:10 | 000,663,552 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdphbn3.dll
[2009.04.01 08:29:08 | 000,851,968 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdpcomc.dll
[2009.04.01 08:29:08 | 000,376,832 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdpcomm.dll
[2009.03.19 15:07:22 | 037,452,296 | ---- | C] (Lavasoft ) -- C:\Programme\Ad-AwareAE.exe
[2008.05.27 16:30:45 | 001,282,759 | ---- | C] (Alexander van Kaam ) -- C:\Programme\MotherboardMonitor.exe
[2008.05.27 14:54:01 | 014,782,496 | ---- | C] (Microsoft Corporation) -- C:\Programme\IE7-WindowsXP-x86-deu.exe
[2008.04.27 22:51:12 | 000,399,000 | ---- | C] (NCH Software) -- C:\Programme\switchsetup.exe
[2007.07.16 10:53:02 | 000,728,624 | ---- | C] (AOL LLC) -- C:\Programme\aolsetup.exe
[2 C:\Dokumente und Einstellungen\The Family\Desktop\*.tmp files -> C:\Dokumente und Einstellungen\The Family\Desktop\*.tmp -> ]
[1 C:\Dokumente und Einstellungen\The Family\Eigene Dateien\*.tmp files -> C:\Dokumente und Einstellungen\The Family\Eigene Dateien\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010.10.17 21:00:00 | 000,000,488 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2010.10.17 18:17:33 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.10.17 13:24:05 | 000,285,230 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\gmer.zip
[2010.10.17 13:14:09 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.10.16 11:31:03 | 000,293,376 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\qmcz98to.exe
[2010.10.16 10:19:34 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2010.10.16 01:16:02 | 000,033,792 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Download OTL to your Desktop.doc
[2010.10.16 01:11:33 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\The Family\Desktop\OTL.exe
[2010.10.16 01:01:04 | 000,001,675 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010.10.15 19:18:18 | 000,002,953 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010.10.15 19:07:41 | 000,025,600 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\cleaning PC log.doc
[2010.10.15 19:07:41 | 000,000,162 | -H-- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\~$eaning PC log.doc
[2010.10.15 18:13:15 | 000,000,359 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Eigene Dateien.lnk
[2010.10.15 16:42:13 | 000,082,944 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.10.15 13:16:26 | 000,000,595 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\NTREGOPT.lnk
[2010.10.15 13:16:26 | 000,000,576 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\ERUNT.lnk
[2010.10.15 13:14:57 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Dokumente und Einstellungen\The Family\Desktop\erunt-setup.exe
[2010.10.15 12:01:31 | 044,089,904 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\avira_antivir_personal_en.exe
[2010.10.15 01:32:25 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010.10.14 22:50:49 | 000,000,680 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.10.14 22:49:58 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\The Family\Desktop\mbam-setup-1.46.exe
[2010.10.14 20:12:54 | 000,024,576 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Honors VocabWk7.doc
[2010.10.14 19:33:52 | 000,040,448 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\English 9 Vocabulary.doc
[2010.10.14 19:33:17 | 000,000,162 | -H-- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\~$nors VocabWk7.doc
[2010.10.14 18:47:29 | 000,000,731 | -H-- | M] () -- C:\IPH.PH
[2010.10.14 18:47:27 | 000,001,544 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\AIM.lnk
[2010.10.14 15:13:14 | 050,594,264 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\setup_av_free.exe
[2010.10.14 12:23:51 | 000,000,526 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Hamster Free Video Converter.lnk
[2010.10.13 23:11:37 | 000,025,600 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\Journal Entry 9.doc
[2010.10.13 16:47:06 | 000,000,782 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\WavePad Sound Editor.lnk
[2010.10.13 16:44:28 | 000,000,745 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Prism Video Converter.lnk
[2010.10.12 17:08:08 | 000,021,504 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\DayAllotment.xls
[2010.10.11 08:52:39 | 000,001,027 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Startmenü\Programme\Autostart\Dropbox.lnk
[2010.10.11 08:52:38 | 000,001,027 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Dropbox.lnk
[2010.10.11 01:32:39 | 000,000,054 | ---- | M] () -- C:\WINDOWS\System32\rp_stats.dat
[2010.10.11 01:32:39 | 000,000,039 | ---- | M] () -- C:\WINDOWS\System32\rp_rules.dat
[2010.10.05 17:27:16 | 019,248,337 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Owensonradio-short.mp3
[2010.10.05 17:23:47 | 106,100,768 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Owensonradio-short.wav
[2010.09.26 13:59:22 | 000,000,162 | -H-- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\~$ghtTummy.doc
[2010.09.26 13:59:17 | 000,000,162 | -H-- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\~$use-Org-Storage.doc
[2010.09.26 12:07:54 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.09.07 00:52:40 | 000,136,704 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\The Wal.doc
[2010.09.07 00:52:40 | 000,000,162 | -H-- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\~$he Wal.doc
[2010.09.04 19:07:54 | 000,000,162 | -H-- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\~$crosoft OUTLOOK 2007.doc
[2010.09.04 19:07:53 | 000,033,792 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\Microsoft OUTLOOK 2007.doc
[2010.09.04 18:54:40 | 000,439,443 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Bike rack_2009NewF6InstructionsV1.pdf
[2010.08.31 16:05:05 | 000,293,272 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.08.31 13:26:40 | 000,540,964 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Elevate_America_User_Guide.pdf
[2010.08.31 12:57:23 | 000,001,713 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2010.08.16 12:49:52 | 000,028,160 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\East WHeeling.doc
[2010.08.06 09:19:44 | 000,000,655 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Alarm Manager.LNK
[2010.08.03 08:58:25 | 000,029,696 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\Scrabble.doc
[2010.07.28 21:55:02 | 000,001,404 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Verknüpfung mit Wallpaper.lnk
[2010.07.27 00:08:46 | 000,099,328 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\GTD_Tools for Thought.doc
[2010.07.27 00:08:46 | 000,000,162 | -H-- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\~$D_Tools for Thought.doc
[2010.07.23 00:39:15 | 000,075,264 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\2010 picnic.doc
[2010.07.21 23:55:17 | 000,226,816 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Dem vs Rep Talking Points_toni.doc
[2010.07.21 23:35:31 | 000,000,162 | -H-- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\~$e Power of Concentration.doc
[2010.07.21 10:28:03 | 000,419,136 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\print_averagejoe.pdf
[2010.07.21 10:21:22 | 000,000,760 | ---- | M] () -- C:\Dokumente und Einstellungen\The Family\Desktop\PDF-Viewer.lnk
[2 C:\Dokumente und Einstellungen\The Family\Desktop\*.tmp files -> C:\Dokumente und Einstellungen\The Family\Desktop\*.tmp -> ]
[1 C:\Dokumente und Einstellungen\The Family\Eigene Dateien\*.tmp files -> C:\Dokumente und Einstellungen\The Family\Eigene Dateien\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.10.17 13:24:02 | 000,285,230 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\gmer.zip
[2010.10.16 11:31:00 | 000,293,376 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\qmcz98to.exe
[2010.10.16 01:13:50 | 000,033,792 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Download OTL to your Desktop.doc
[2010.10.16 01:01:03 | 000,001,675 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010.10.15 19:07:41 | 000,000,162 | -H-- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\~$eaning PC log.doc
[2010.10.15 19:07:40 | 000,025,600 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\cleaning PC log.doc
[2010.10.15 18:13:15 | 000,000,359 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Eigene Dateien.lnk
[2010.10.15 13:16:26 | 000,000,595 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\NTREGOPT.lnk
[2010.10.15 13:16:26 | 000,000,576 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\ERUNT.lnk
[2010.10.15 11:52:13 | 044,089,904 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\avira_antivir_personal_en.exe
[2010.10.14 19:33:52 | 000,040,448 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\English 9 Vocabulary.doc
[2010.10.14 19:33:17 | 000,024,576 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Honors VocabWk7.doc
[2010.10.14 19:33:17 | 000,000,162 | -H-- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\~$nors VocabWk7.doc
[2010.10.14 15:10:51 | 050,594,264 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\setup_av_free.exe
[2010.10.14 12:23:51 | 000,000,526 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Hamster Free Video Converter.lnk
[2010.10.13 23:11:37 | 000,025,600 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\Journal Entry 9.doc
[2010.10.13 16:47:06 | 000,000,782 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\WavePad Sound Editor.lnk
[2010.10.13 16:44:28 | 000,000,745 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Prism Video Converter.lnk
[2010.10.11 08:52:39 | 000,001,027 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Startmenü\Programme\Autostart\Dropbox.lnk
[2010.10.11 08:52:38 | 000,001,027 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Dropbox.lnk
[2010.10.11 01:32:39 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2010.10.11 01:32:39 | 000,000,039 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2010.10.10 14:46:48 | 000,021,504 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\DayAllotment.xls
[2010.10.05 23:13:43 | 000,024,002 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\earningstheory.pdf
[2010.10.05 17:24:00 | 019,248,337 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Owensonradio-short.mp3
[2010.10.05 17:23:31 | 106,100,768 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Owensonradio-short.wav
[2010.09.26 13:59:22 | 000,000,162 | -H-- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\~$ghtTummy.doc
[2010.09.26 13:59:17 | 000,000,162 | -H-- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\~$use-Org-Storage.doc
[2010.09.07 00:52:40 | 000,000,162 | -H-- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\~$he Wal.doc
[2010.09.07 00:52:39 | 000,136,704 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\The Wal.doc
[2010.09.04 19:07:54 | 000,000,162 | -H-- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\~$crosoft OUTLOOK 2007.doc
[2010.09.04 19:07:53 | 000,033,792 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\Microsoft OUTLOOK 2007.doc
[2010.09.04 18:54:40 | 000,439,443 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Bike rack_2009NewF6InstructionsV1.pdf
[2010.09.01 20:18:14 | 000,001,544 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\AIM.lnk
[2010.09.01 20:15:40 | 000,000,731 | -H-- | C] () -- C:\IPH.PH
[2010.08.31 13:26:38 | 000,540,964 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Elevate_America_User_Guide.pdf
[2010.08.14 13:52:47 | 000,028,160 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\East WHeeling.doc
[2010.08.06 09:19:44 | 000,000,655 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Alarm Manager.LNK
[2010.08.03 08:58:24 | 000,029,696 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\Scrabble.doc
[2010.07.27 00:08:46 | 000,000,162 | -H-- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\~$D_Tools for Thought.doc
[2010.07.27 00:08:45 | 000,099,328 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\GTD_Tools for Thought.doc
[2010.07.23 00:39:15 | 000,075,264 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\2010 picnic.doc
[2010.07.21 23:35:31 | 000,000,162 | -H-- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\~$e Power of Concentration.doc
[2010.07.21 10:28:03 | 000,419,136 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Eigene Dateien\print_averagejoe.pdf
[2010.07.21 10:21:22 | 000,000,760 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\PDF-Viewer.lnk
[2010.07.21 09:20:35 | 000,226,816 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Desktop\Dem vs Rep Talking Points_toni.doc
[2010.03.27 23:30:41 | 000,020,992 | ---- | C] () -- C:\WINDOWS\jestertb.dll
[2009.04.03 12:30:08 | 000,003,776 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2009.04.01 08:49:01 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxdpvs.dll
[2009.04.01 08:48:49 | 000,348,160 | ---- | C] () -- C:\WINDOWS\System32\lxdpcoin.dll
[2009.04.01 08:29:37 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\lxdprwrd.ini
[2009.04.01 08:29:13 | 000,348,160 | ---- | C] () -- C:\WINDOWS\System32\LXDPinst.dll
[2009.04.01 08:29:10 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lxdpgrd.dll
[2008.09.23 14:36:26 | 000,000,112 | ---- | C] () -- C:\WINDOWS\ActiveSkin.INI
[2008.09.14 03:15:54 | 000,021,579 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Comma Separated Values (Windows).ADR
[2008.09.11 16:28:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2008.08.09 08:21:19 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2008.08.05 02:07:20 | 000,065,216 | ---- | C] () -- C:\WINDOWS\System32\PDFreDirectMonNT.dll
[2008.07.13 05:06:17 | 000,000,021 | ---- | C] () -- C:\WINDOWS\atid.ini
[2008.05.31 11:46:34 | 000,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
[2008.05.31 10:09:49 | 001,500,168 | ---- | C] () -- C:\Programme\advisor.exe
[2008.05.31 09:20:30 | 000,688,638 | ---- | C] () -- C:\Programme\PC-Decrapifier-1.9.1.exe
[2008.05.30 07:25:57 | 000,948,113 | ---- | C] () -- C:\Programme\EFRCSetup.exe
[2008.05.28 07:47:08 | 001,324,633 | ---- | C] () -- C:\Programme\siw.zip
[2008.05.28 07:42:38 | 001,567,713 | ---- | C] () -- C:\Programme\revosetup.exe
[2008.05.27 11:38:04 | 006,439,960 | ---- | C] () -- C:\Programme\SUPERAntiSpyware.exe
[2008.04.29 14:42:24 | 000,503,808 | ---- | C] () -- C:\WINDOWS\System32\ICCProfiles.dll
[2008.04.12 11:49:44 | 000,000,063 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2008.04.12 11:49:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2008.04.06 10:17:46 | 014,574,336 | ---- | C] () -- C:\Programme\TU2008TrialEN.exe
[2008.01.18 11:52:09 | 000,860,391 | ---- | C] () -- C:\Programme\unzipRAR-7z457.exe
[2007.12.26 17:12:22 | 000,000,032 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ezsid.dat
[2007.12.08 21:45:10 | 000,000,534 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007.09.20 01:38:10 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2007.09.19 11:36:09 | 000,000,048 | ---- | C] () -- C:\WINDOWS\FileNamesinQueue.ini
[2007.09.17 18:24:53 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2007.09.13 20:49:26 | 000,001,825 | ---- | C] () -- C:\Programme\Ad-AwareAd-Aware update.log
[2007.09.02 01:31:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2007.08.22 10:21:17 | 000,000,220 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2007.08.21 05:35:40 | 000,259,341 | R--- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\hosts.bak
[2007.08.21 05:35:40 | 000,003,002 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Config.nt.bak
[2007.08.21 05:35:40 | 000,001,806 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Autoexec.nt.bak
[2007.08.07 03:16:14 | 000,003,363 | ---- | C] () -- C:\Programme\Ad-AwareAdAware event.log
[2007.07.16 10:53:02 | 000,004,424 | ---- | C] () -- C:\Programme\aolsetup.bin
[2007.07.16 10:53:02 | 000,001,592 | ---- | C] () -- C:\Programme\main.ini
[2004.08.31 13:59:42 | 000,082,944 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004.06.03 15:16:13 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
[2004.06.03 15:16:13 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2004.06.03 15:16:13 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2004.06.03 15:16:13 | 000,000,205 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2004.06.03 15:16:13 | 000,000,073 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
[2004.06.02 15:18:15 | 000,000,143 | ---- | C] () -- C:\Dokumente und Einstellungen\The Family\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2004.06.01 13:14:54 | 000,003,548 | ---- | C] () -- C:\WINDOWS\System32\drivers\WinFlash.sys
[2004.06.01 12:56:41 | 000,000,184 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2003.03.01 14:04:26 | 000,000,200 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003.02.09 18:44:52 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003.02.09 17:29:19 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2003.02.05 11:23:47 | 000,000,830 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003.02.05 05:22:22 | 000,000,748 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003.02.05 04:39:28 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003.02.05 04:23:14 | 000,065,536 | ---- | C] () -- C:\WINDOWS\Dit.DLL
[2003.02.05 04:23:14 | 000,000,208 | ---- | C] () -- C:\WINDOWS\Dit.INI
[2003.02.05 04:05:46 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2003.02.05 03:56:43 | 000,003,072 | ---- | C] () -- C:\WINDOWS\winio.sys
[2003.02.05 03:34:32 | 000,000,863 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003.02.05 03:27:21 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2002.03.26 15:18:27 | 000,091,136 | ---- | C] () -- C:\WINDOWS\System32\mp4fil32.dll
[1999.01.22 14:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2008.07.21 19:17:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\acccore
[2009.10.13 09:50:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\agi
[2010.09.01 20:18:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AIM
[2010.10.15 19:18:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Alwil Software
[2010.03.28 20:13:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BVRP Software
[2007.09.02 02:31:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DataViz
[2009.04.09 17:05:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\G DATA
[2007.08.06 11:05:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft
[2010.01.10 20:29:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\HotSync
[2008.04.19 11:20:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Musicnotes
[2010.10.13 16:47:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NCH Swift Sound
[2009.08.14 23:12:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Nitro PDF
[2009.07.18 17:49:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PopCap
[2009.08.26 18:30:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RingCentral
[2009.02.07 14:14:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Seagate
[2010.01.19 09:01:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
[2008.04.06 21:39:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2008.07.21 19:17:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Viewpoint
[2010.03.31 13:47:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009.03.19 15:10:06 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2010.10.17 21:00:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Abine
[2007.09.28 21:48:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\acccore
[2010.01.18 23:43:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Auslogics
[2010.10.14 20:28:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\BitTorrent
[2008.05.28 08:55:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\BizFormBar
[2007.12.30 23:06:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\DAEMON Tools
[2009.04.09 13:33:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\DNA
[2009.08.14 10:55:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Downloaded Installations
[2010.10.17 13:15:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Dropbox
[2008.05.31 00:20:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\gtopala
[2010.10.14 12:24:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\HamsterSoft
[2010.01.10 20:16:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\HotSync
[2003.02.05 04:15:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\InterTrust
[2007.09.02 01:27:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Leadertech
[2010.01.16 10:59:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\MailWasherPro
[2008.04.27 22:57:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\NCH Swift Sound
[2010.07.25 23:19:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Nitro PDF
[2009.07.30 09:46:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\PDF reDirect
[2008.07.13 05:07:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\QQ Games Plugin
[2010.03.04 14:46:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\SanDisk
[2008.04.06 21:40:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\TuneUp Software
[2007.10.15 20:31:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Viewpoint
[2007.09.20 02:07:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\The Family\Anwendungsdaten\Xdrive
[2010.10.17 21:00:00 | 000,000,488 | ---- | M] () -- C:\WINDOWS\Tasks\1-Click Maintenance.job
[2010.10.15 01:32:25 | 000,000,456 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010.10.17 13:13:59 | 000,068,092 | ---- | M] () -- C:\aaw7boot.log
[2008.04.02 21:49:18 | 000,000,006 | ---- | M] () -- C:\agreed.txt
[2007.09.19 13:54:18 | 000,010,920 | ---- | M] () -- C:\aolconnfix.exe
[2007.09.19 13:54:18 | 000,001,039 | ---- | M] () -- C:\aolconnfix.txt
[2003.02.05 03:31:27 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2005.10.12 09:24:44 | 045,971,964 | ---- | M] () -- C:\BackupBeforeLOPfix.reg
[2009.04.10 13:14:30 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010.01.17 10:08:52 | 000,000,281 | -HS- | M] () -- C:\boot.ini
[2002.08.29 08:00:00 | 000,004,952 | RHS- | M] () -- C:\bootfont.bin
[2004.08.04 00:00:10 | 000,262,448 | ---- | M] () -- C:\cmldr
[2003.02.05 03:31:27 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2004.08.31 14:02:56 | 000,000,000 | ---- | M] () -- C:\EPG_Chan.log
[2004.07.04 01:04:40 | 000,004,379 | -HS- | M] () -- C:\ffastun.ffa
[2004.07.04 01:04:40 | 000,180,224 | -HS- | M] () -- C:\ffastun.ffl
[2004.07.04 01:04:40 | 000,077,824 | -H-- | M] () -- C:\ffastun.ffo
[2004.07.04 01:04:40 | 000,712,704 | -HS- | M] () -- C:\ffastun0.ffx
[2010.01.10 21:20:44 | 003,844,510 | ---- | M] () -- C:\HuskyInstallerLog.txt
[2008.09.23 14:36:48 | 000,001,119 | ---- | M] () -- C:\INSTALL.LOG
[2003.02.05 03:31:27 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010.10.14 18:47:29 | 000,000,731 | -H-- | M] () -- C:\IPH.PH
[2009.02.11 21:02:56 | 000,000,028 | ---- | M] () -- C:\liberror.txt
[2003.02.05 03:31:27 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2007.08.05 13:23:03 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009.04.05 11:54:09 | 000,251,712 | RHS- | M] () -- C:\ntldr
[2010.10.17 13:14:01 | 268,435,456 | -HS- | M] () -- C:\pagefile.sys
[2004.08.31 14:02:11 | 000,000,184 | ---- | M] () -- C:\Setup.log
[2004.06.02 17:38:08 | 000,001,736 | ---- | M] () -- C:\TDSLCheck.txt
[2001.01.10 12:23:58 | 000,162,304 | ---- | M] () -- C:\UNWISE.EXE
[2007.04.28 07:24:07 | 000,000,282 | ---- | M] () -- C:\Verknüpfung mit Recover ©.lnk
[2009.04.10 20:05:12 | 027,262,976 | ---- | M] () -- C:\VIRTPART.DAT
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2003.02.05 04:26:10 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2003.02.05 04:26:10 | 000,606,208 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2003.02.05 04:26:10 | 000,405,504 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-31 18:30:50
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:B623B5B8
< End of report >