OTL
OTL
OTL
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.startup.homepage: "www.google.de"
FF - prefs.js..extensions.enabledItems: {b749fc7c-e949-447f-926c-3f4eed6accfe}:0
.6.12
FF - prefs.js..extensions.enabledItems: linky@gemal.dk:3.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6
.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6
.0.24
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1
.0.1
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.1.400
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 4444
FF - prefs.js..network.proxy.ssl: "127.0.0.1"
FF - prefs.js..network.proxy.ssl_port: 4445
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Ma
cromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program File
s\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jr
e6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wa
t\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program
Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PR
OGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PRO
GRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program
Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\
Users\simon\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google In
c.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\
Users\simon\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google In
c.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users
\simon\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (
Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program F
iles\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Compo
nents: C:\Program Files\Mozilla Firefox\components [2011.10.02 00:39:29 | 000,00
0,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugi
ns: C:\Program Files\Mozilla Firefox\plugins [2011.07.27 20:02:05 | 000,000,000
| ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\C
omponents: C:\Program Files\Mozilla Thunderbird\components [2011.09.12 14:16:13
| 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\P
lugins: C:\Program Files\Mozilla Thunderbird\plugins
peAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentProm
ptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA =
0
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\
Programme\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36
D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110}
- C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky L
ab ZAO)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5}
- C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technol
ogies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC
46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Sk
ype Technologies S.A.)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky La
b ZAO)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common F
iles\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common F
iles\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Bonjour\
mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6
.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6
.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6
.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.
com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{046C2B54-0589-4818-9
107-9F2E94A65FB3}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D4D8C0B3-5031-4503-B
553-601F9E846CAA}: DhcpNameServer = 80.67.0.2 91.213.246.2
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Progr
amme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Use
rs\simon\Downloads\Ant Videos\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8
} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Techn
ologies S.A.)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Progr
amme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) -C:\Programme\Ka
spersky Lab\Kaspersky Anti-Virus 2011\mzvkbd3.dll (Kaspersky Lab ZAO)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft
Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\S
ystem32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\Sy
stem32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Wi
verlight
[2011.10.02 19:05:45 | 000,000,000 | ---D | C] -- C:\Windows\symbols
[2011.10.02 19:05:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\
Merge Modules
[2011.10.01 22:07:57 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming
\Microsoft\Windows\Start Menu\Programs\Anvil-Soft
[2011.10.01 22:07:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windo
ws\Start Menu\Programs\Anvil-Soft
[2011.10.01 22:07:54 | 000,000,000 | ---D | C] -- C:\Program Files\Klomanager
[2011.09.29 22:22:20 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Local\v
pntunnel
[2011.09.28 22:50:16 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAP
ICOM 2.1.0.2
[2011.09.28 18:44:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windo
ws\Start Menu\Programs\Microsoft Office
[2011.09.28 18:43:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\
DESIGNER
[2011.09.28 18:41:01 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Off
ice
[2011.09.28 18:40:49 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2011.09.28 16:50:56 | 000,000,000 | -HSD | C] -- C:\ProgramData\DSS
[2011.09.28 16:50:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Codemasters
[2011.09.28 16:44:15 | 000,000,000 | ---D | C] -- C:\Windows\System32\xlive
[2011.09.28 16:44:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windo
ws\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2011.09.28 16:44:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Gam
es for Windows - LIVE
[2011.09.28 16:41:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windo
ws\Start Menu\Programs\Blue Ripple Sound
[2011.09.28 16:41:37 | 001,417,216 | ---- | C] (Blue Ripple Sound Limited) -- C:
\Windows\System32\rapture3d_oal.dll
[2011.09.28 16:41:36 | 000,000,000 | ---D | C] -- C:\Program Files\BRS
[2011.09.28 16:30:41 | 000,000,000 | ---D | C] -- C:\Program Files\Codemasters
[2011.09.27 20:31:55 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming
\VPNTunnel
[2011.09.27 20:29:55 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming
\Microsoft\Windows\Start Menu\Programs\VPNTunnel
[2011.09.27 20:29:50 | 000,000,000 | ---D | C] -- C:\Program Files\VPNTunnel
[2011.05.20 17:44:31 | 000,438,272 | ---- | C] ( ) -- C:\Windows\System32\lxdohc
p.dll
[2011.05.20 17:44:31 | 000,360,448 | ---- | C] ( ) -- C:\Windows\System32\lxdoin
pa.dll
[2011.05.20 17:44:30 | 001,069,056 | ---- | C] ( ) -- C:\Windows\System32\lxdose
rv.dll
[2011.05.20 17:44:30 | 000,954,368 | ---- | C] ( ) -- C:\Windows\System32\lxdous
b1.dll
[2011.05.20 17:44:30 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxdopm
ui.dll
[2011.05.20 17:44:30 | 000,339,968 | ---- | C] ( ) -- C:\Windows\System32\lxdoie
sc.dll
[2011.05.20 17:44:30 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\lxdopr
ox.dll
[2011.05.20 17:44:29 | 000,569,344 | ---- | C] ( ) -- C:\Windows\System32\lxdolm
pm.dll
[2011.05.20 17:44:29 | 000,315,392 | ---- | C] ( ) -- C:\Windows\System32\lxdoih
.exe
[2011.05.20 17:44:28 | 000,663,552 | ---- | C] ( ) -- C:\Windows\System32\lxdohb
n3.dll
[2011.05.20 17:44:27 | 000,851,968 | ---- | C] ( ) -- C:\Windows\System32\lxdoco
mc.dll
9.dat
[2011.10.14 17:54:46 | 005,905,816 | ---- | M] () -- C:\Users\simon\Desktop\Morp
hVOXPro4_Install-4.3.13.de.exe
[2011.10.10 21:00:22 | 000,001,029 | ---- | M] () -- C:\Users\Public\Desktop\Dis
playFusion.lnk
[2011.10.10 20:50:54 | 001,440,220 | ---- | M] () -- C:\Users\simon\Desktop\rain
bow_nyan_nyan_pop_tart_cat_by_zaithy-d3e8u2k.jpg
[2011.10.10 17:14:27 | 000,002,016 | ---- | M] () -- C:\Users\Public\Desktop\Avi
ra Control Center.lnk
[2011.10.10 16:26:47 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCl
eaner.lnk
[2011.10.09 22:09:32 | 007,910,991 | R--- | M] () -- C:\Users\simon\Desktop\Germ
anLetsPlay ft. Fr3akyZockt YTITTY STYLE.mp3
[2011.10.09 21:17:05 | 000,001,258 | ---- | M] () -- C:\Users\Public\Desktop\Hex
Workshop Hex Editor (32 bit).lnk
[2011.10.09 18:51:06 | 000,021,859 | ---- | M] () -- C:\Users\simon\Desktop\gpot
ato.jpg
[2011.10.09 18:39:01 | 000,106,435 | ---- | M] () -- C:\Users\simon\Desktop\flyf
f_logo.png
[2011.10.09 11:02:28 | 000,106,733 | ---- | M] () -- C:\Users\simon\Desktop\Stea
m-logo.png
[2011.10.09 00:08:11 | 035,997,815 | ---- | M] () -- C:\Users\simon\Desktop\Luci
dDreaming.mp3
[2011.10.08 18:25:01 | 000,081,664 | ---- | M] (GMER) -- C:\aujasnkj.sys
[2011.10.07 18:27:05 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTu
nes.lnk
[2011.10.06 21:43:45 | 000,175,104 | ---- | M] () -- C:\Users\simon\Desktop\sqli
te3.dll
[2011.10.05 21:17:56 | 024,355,582 | ---- | M] () -- C:\Users\simon\Desktop\Gori
llaz_Feel_good_inc_DUBSTEP_REMIX.flv
[2011.10.05 15:13:52 | 000,002,401 | ---- | M] () -- C:\Users\simon\Desktop\Goog
le Chrome.lnk
[2011.10.03 16:59:32 | 008,782,367 | R--- | M] () -- C:\Users\simon\Desktop\va10
0dbstp.part6.rar
[2011.10.03 16:57:54 | 250,000,000 | ---- | M] () -- C:\Users\simon\Desktop\va10
0dbstp.part5.rar
[2011.10.03 16:19:47 | 000,000,600 | ---- | M] () -- C:\Users\simon\AppData\Roam
ing\winscp.rnd
[2011.10.03 16:19:40 | 000,000,600 | ---- | M] () -- C:\Users\simon\AppData\Loca
l\PUTTY.RND
[2011.10.03 16:02:46 | 250,000,000 | ---- | M] () -- C:\Users\simon\Desktop\va10
0dbstp.part4.rar
[2011.10.03 15:58:00 | 000,001,799 | ---- | M] () -- C:\Users\simon\Desktop\WinS
CP.lnk
[2011.10.03 13:13:54 | 250,000,000 | ---- | M] () -- C:\Users\simon\Desktop\va10
0dbstp.part3.rar
[2011.10.03 12:25:31 | 250,000,000 | ---- | M] () -- C:\Users\simon\Desktop\va10
0dbstp.part2.rar
[2011.10.03 11:40:19 | 250,000,000 | ---- | M] () -- C:\Users\simon\Desktop\va10
0dbstp.part1.rar
[2011.09.30 22:49:08 | 009,539,324 | ---- | M] () -- C:\Users\simon\Desktop\Esca
pe Island v5.1.zip
[2011.09.28 16:41:32 | 000,444,952 | ---- | M] (Creative Labs) -- C:\Windows\Sys
tem32\wrap_oal.dll
[2011.09.27 20:31:15 | 000,001,071 | ---- | M] () -- C:\Users\simon\Desktop\VPNT
unnel GUI.lnk
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
-- C:\Users\simon\defogger_ree
-- C:\Users\simon\Desktop\Defo
-- C:\Users\simon\ts3_recordin
-- C:\ProgramData\Microsoft\Wi
-- C:\Users\simon\Desktop\Auda
-- C:\Users\simon\Desktop\SWF
-- C:\Windows\System32\drivers
-- C:\Users\Public\Desktop\Sky
-- C:\Users\simon\Desktop\hs_e
-- C:\Users\simon\Desktop\brai
-- C:\Users\Public\Desktop\Mal
-- C:\Users\simon\Desktop\Prak
-- C:\Users\simon\Desktop\Morp
-- C:\Users\simon\Desktop\Syst
-- C:\Users\simon\Desktop\Syst
-- C:\Users\simon\Desktop\Skyp
-- C:\Users\simon\Desktop\JSNe
-- C:\Users\Public\Desktop\Dis
-- C:\Users\simon\Desktop\rain
-- C:\Users\Public\Desktop\Avi
-- C:\Users\Public\Desktop\CCl
-- C:\Users\simon\Desktop\Germ
-- C:\Users\Public\Desktop\Hex
-- C:\Users\simon\Desktop\Hex
-- C:\Users\simon\Desktop\gpot
-- C:\Users\simon\Desktop\flyf
-- C:\Users\simon\Desktop\Secr
-- C:\Users\simon\Desktop\Secr
-- C:\Users\simon\Desktop\Stea
-- C:\Users\simon\Desktop\Luci
dDreaming.mp3
[2011.10.07 18:27:05 | 000,001,753 | ---- | C]
nes.lnk
[2011.10.06 21:43:45 | 000,175,104 | ---- | C]
te3.dll
[2011.10.05 21:17:53 | 024,355,582 | ---- | C]
llaz_Feel_good_inc_DUBSTEP_REMIX.flv
[2011.10.03 16:58:48 | 008,782,367 | R--- | C]
0dbstp.part6.rar
[2011.10.03 16:30:33 | 250,000,000 | ---- | C]
0dbstp.part5.rar
[2011.10.03 15:58:00 | 000,001,799 | ---- | C]
CP.lnk
[2011.10.03 15:42:30 | 250,000,000 | ---- | C]
0dbstp.part4.rar
[2011.10.03 12:54:44 | 250,000,000 | ---- | C]
0dbstp.part3.rar
[2011.10.03 11:55:00 | 250,000,000 | ---- | C]
0dbstp.part2.rar
[2011.10.03 11:05:27 | 250,000,000 | ---- | C]
0dbstp.part1.rar
[2011.09.30 21:43:29 | 009,539,324 | ---- | C]
pe Island v5.1.zip
[2011.09.28 16:43:38 | 000,001,338 | ---- | C]
ndows\Start Menu\Programs\Windows Live ID.lnk
[2011.09.27 20:31:15 | 000,001,071 | ---- | C]
unnel GUI.lnk
[2011.09.25 15:23:54 | 001,589,248 | ---- | C]
l_d.dll
[2011.09.25 15:19:18 | 000,000,232 | ---- | C]
[2011.07.20 19:40:51 | 000,000,000 | ---- | C]
l\census.cache
[2011.07.20 19:40:51 | 000,000,000 | ---- | C]
l\ars.cache
[2011.07.20 19:38:37 | 000,000,036 | ---- | C]
l\housecall.guid.cache
[2011.07.10 10:14:32 | 000,115,369 | ---- | C]
\klin.dat
[2011.07.10 10:14:32 | 000,097,961 | ---- | C]
\klick.dat
[2011.07.08 21:18:59 | 000,000,132 | ---- | C]
ing\Adobe PNG Format CS5 Prefs
[2011.06.12 12:12:14 | 000,045,286 | ---- | C]
ing\room_v3.dat
[2011.05.23 21:30:59 | 000,000,193 | ---- | C]
[2011.05.23 20:08:29 | 000,043,520 | ---- | C]
Ext03.dll
[2011.05.20 17:50:02 | 000,348,160 | ---- | C]
n.dll
[2011.05.20 17:49:03 | 000,045,056 | ---- | C]
N.DLL
[2011.05.20 17:49:03 | 000,032,768 | ---- | C]
U.DLL
[2011.05.20 17:48:43 | 000,069,632 | ---- | C]
.dll
[2011.05.20 17:45:26 | 000,028,672 | ---- | C]
[2011.05.20 17:45:26 | 000,011,776 | ---- | C]
2.dll
[2011.05.20 17:44:51 | 000,000,060 | -H-- | C]
d.ini
() -- C:\Users\Public\Desktop\iTu
() -- C:\Users\simon\Desktop\sqli
() -- C:\Users\simon\Desktop\Gori
() -- C:\Users\simon\Desktop\va10
() -- C:\Users\simon\Desktop\va10
() -- C:\Users\simon\Desktop\WinS
() -- C:\Users\simon\Desktop\va10
() -- C:\Users\simon\Desktop\va10
() -- C:\Users\simon\Desktop\va10
() -- C:\Users\simon\Desktop\va10
() -- C:\Users\simon\Desktop\Esca
() -- C:\ProgramData\Microsoft\Wi
() -- C:\Users\simon\Desktop\VPNT
() -- C:\Windows\System32\libmysq
() -- C:\Windows\ODBCINST.INI
() -- C:\Users\simon\AppData\Loca
() -- C:\Users\simon\AppData\Loca
() -- C:\Users\simon\AppData\Loca
() -- C:\Windows\System32\drivers
() -- C:\Windows\System32\drivers
() -- C:\Users\simon\AppData\Roam
() -- C:\Users\simon\AppData\Roam
() -- C:\Windows\WORDPAD.INI
() -- C:\Windows\System32\CmdLine
() -- C:\Windows\System32\lxdocoi
() -- C:\Windows\System32\LXDOPMO
() -- C:\Windows\System32\LXDOFXP
() -- C:\Windows\System32\lxdooem
() -- C:\Windows\hookdllX.dll
() -- C:\Windows\System32\pmsbfn3
() -- C:\Windows\System32\lxdorwr
C] () -- C:\Windows\System32\lxdoins
C] () -- C:\Windows\System32\lxdogrd
C] () -- C:\Windows\System32\atipbla
C] () -- C:\Windows\System32\atiicdx
C] () -- C:\Windows\System32\mlfcach
C] () -- C:\Users\simon\AppData\Roam
C] () -- C:\Windows\System32\Access.
C] () -- C:\Windows\System32\ezsidmv
C] () -- C:\Windows\System32\xlive.d
C] () -- C:\Users\simon\AppData\Roam
C] () -- C:\Windows\CD_Start.INI
C] () -- C:\Windows\System32\OVDecod
C] () -- C:\Windows\ODBC.INI
C] () -- C:\Users\simon\AppData\Loca
C] () -- C:\Users\simon\AppData\Loca
C] () -- C:\Users\simon\AppData\Loca
C] () -- C:\Users\simon\AppData\Loca
C] () -- C:\Users\simon\AppData\Roam
C] () -- C:\Users\simon\AppData\Loca
C] () -- C:\Windows\System32\UpdateD
C] () -- C:\Windows\System32\ucuiinf
C] () -- C:\Windows\System32\drivers
C] () -- C:\Windows\System32\PnkBstr
C] () -- C:\Windows\System32\PnkBstr
C] () -- C:\Windows\ativpsrm.bin
C] () -- C:\Windows\System32\Airfoil
C] () -- C:\Windows\System32\drivers
C] () -- C:\Windows\System32\perfh00
C] () -- C:\Windows\System32\perfi00
C] () -- C:\Windows\System32\perfc00
C] () -- C:\Windows\System32\perfd00
C] () -- C:\Windows\bootstat.dat
| ---- | C] () -- C:\Windows\System32\FNTCACH
| ---- | C] () -- C:\Windows\System32\perfh00
| ---- | C] () -- C:\Windows\System32\perfi00
| ---- | C] () -- C:\Windows\System32\perfc00
| ---- | C] () -- C:\Windows\System32\perfd00
| ---- | C] () -- C:\Windows\System32\NOISE.D
| ---- | C] () -- C:\Windows\System32\dssec.d
| ---- | C] () -- C:\Windows\mib.bin
| ---- | C] () -- C:\Windows\System32\BthpanC
| ---- | C] () -- C:\Windows\System32\BWConte
| ---- | C] () -- C:\Windows\System32\sccls.d
| ---- | C] () -- C:\Windows\System32\devmgr.
| ---- | C] () -- C:\Windows\System32\mlang.d
| ---- | C] () -- C:\Windows\System32\physxcu
| ---- | C] () -- C:\Windows\System32\AgCPane
| ---- | C] () -- C:\Windows\System32\AgCPane
| ---- | C] () -- C:\Windows\System32\AgCPane
| ---- | C] () -- C:\Windows\System32\AgCPane
| ---- | C] () -- C:\Windows\System32\AgCPane
| ---- | C] () -- C:\Windows\System32\AgCPane
| ---- | C] () -- C:\Windows\System32\AgCPane
| ---- | C] () -- C:\Windows\System32\AgCPane
| ---- | C] () -- C:\Windows\System32\AgCPane
| ---- | C] () -- C:\Windows\System32\lxdodrs
| ---- | C] () -- C:\Windows\System32\lxdocnv
| ---- | C] () -- C:\Windows\System32\lxdocap
| ---- | C] () -- C:\Windows\System32\lxdovs.
| ---- | C] () -- C:\Windows\sel3110.exe
| ---- | C] () -- C:\Windows\CleanDev.exe
| ---- | C] () -- C:\Windows\amcap.exe
\.minecraft
[2011.02.19 13:57:54 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\.Nitrous
[2011.09.24 15:23:23 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\9500 Series
[2011.05.23 20:08:37 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Atari
[2011.10.14 17:50:41 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Avnex
[2011.07.01 22:07:57 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011.02.28 20:59:47 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Cycling '74
[2011.10.22 10:22:06 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\DAEMON Tools Lite
[2011.05.30 20:28:21 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\de.myphotobook.creator.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1
[2011.10.10 19:37:57 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Dev-Cpp
[2011.10.10 21:05:09 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\DisplayFusion
[2011.10.26 18:01:02 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Dropbox
[2011.09.09 21:11:42 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\DVDVideoSoft
[2011.02.21 14:50:21 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\DVDVideoSoftIEHelpers
[2011.10.09 11:43:20 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\EvaBox
[2011.10.26 17:58:04 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\FileZilla
[2011.04.22 17:10:37 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\GetRightToGo
[2011.02.16 22:46:20 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\GHISLER
[2011.09.10 17:35:10 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\gtk-2.0
[2011.10.06 19:59:37 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\I2P
[2011.10.06 22:08:44 | 000,000,000 | RHSD | M] -- C:\Users\simon\AppData\Roaming
\InstallDir
[2011.05.23 20:16:06 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Leadertech
[2011.05.21 10:30:30 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Lexmark Productivity Studio
[2011.04.13 18:03:34 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\LolClient
[2011.07.06 19:40:31 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\ManyCam
[2011.07.08 17:31:25 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Mavituna Security Ltd
[2011.07.09 22:00:56 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Metasploit
[2011.09.25 15:22:47 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\MySQL
[2011.05.23 20:21:16 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\NewSoft
[2011.07.18 18:55:56 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Notepad++
[2011.02.28 20:59:47 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\PACE Anti-Piracy
[2011.10.09 22:02:47 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\redsn0w
[2011.10.14 17:56:56 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Screaming Bee
[2011.07.02 22:36:42 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.07.20 20:18:00 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\TeamViewer
[2011.02.28 20:17:22 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Teeworlds
[2011.07.19 17:19:51 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Thunderbird
[2011.10.25 14:42:09 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\TS3Client
[2011.07.11 20:19:02 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\ts3overlay
[2011.07.23 17:51:51 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\TuneUp Software
[2011.06.12 12:50:42 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Tunngle
[2011.03.19 15:15:06 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\Ubisoft
[2011.10.26 11:05:17 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\VPNTunnel
[2011.10.05 21:29:50 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\WindSolutions
[2011.10.08 21:59:44 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming
\X-Chat 2
[2011.10.09 21:37:56 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.T
XT
[color=#E56717]========== Purity Check ==========[/color]
M]
M]
M]
M]
M]
M]
M]
M]
M]
M]
M]
M]
M]
M]
M]
M]
M]
M]
M]
M]
---------------------
C:\$Recycle.Bin
C:\Belkin
C:\Capture
C:\Dev-Cpp
C:\Documents and Settings
C:\Dokumente und Einstellungen
C:\found.000
C:\Fraps
C:\HammerAutosave
C:\inetpub
C:\logs
C:\MSOCache
C:\P-Book
C:\PerfLogs
C:\Perl
C:\Program Files
C:\ProgramData
C:\Programme
C:\Recovery
C:\rsit
[2011.08.06
[2011.08.06
[2011.10.26
[2011.06.24
[2011.10.17
[2011.10.24
[2011.10.09
[2011.09.24
[2011.08.06
12:58:06
12:55:44
18:14:26
21:19:11
21:51:07
11:30:02
21:37:43
16:23:41
16:22:59
|
|
|
|
|
|
|
|
|
000,000,000
000,000,000
000,000,000
000,000,000
000,000,000
000,000,000
000,000,000
000,000,000
000,000,000
|
|
|
|
|
|
|
|
|
---D
---D
-HSD
---D
R--D
---D
-HSD
---D
---D
|
|
|
|
|
|
|
|
|
M]
M]
M]
M]
M]
M]
M]
M]
M]
----------
C:\Ruby192
C:\Ruby192l
C:\System Volume Information
C:\temp
C:\Users
C:\Windows
C:\Windupdt
C:\WinSetupFromUSB
C:\xampp