~Snoopy~ | 16.08.2011 16:58 | ui sorry Code:
OTL logfile created on: 16.08.2011 15:35:11 - Run 1
OTL by OldTimer - Version 3.2.26.4 Folder = C:\Users\-SchwarzesBlut-\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,75 Gb Total Physical Memory | 1,76 Gb Available Physical Memory | 63,98% Memory free
5,50 Gb Paging File | 4,47 Gb Available in Paging File | 81,31% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297,99 Gb Total Space | 246,70 Gb Free Space | 82,79% Space Free | Partition Type: NTFS
Computer Name: SCHWARZESBLUT | User Name: -SchwarzesBlut- | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\-SchwarzesBlut-\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Programme\Norton 360\Engine\5.1.0.29\ccsvchst.exe (Symantec Corporation)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Programme\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Modules (No Company Name) ==========
MOD - C:\Users\-SchwarzesBlut-\AppData\Local\Google\Chrome\Application\13.0.782.112\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\-SchwarzesBlut-\AppData\Local\Google\Chrome\Application\13.0.782.112\pdf.dll ()
MOD - C:\Users\-SchwarzesBlut-\AppData\Local\Google\Chrome\Application\13.0.782.112\libglesv2.dll ()
MOD - C:\Users\-SchwarzesBlut-\AppData\Local\Google\Chrome\Application\13.0.782.112\libegl.dll ()
MOD - C:\Users\-SchwarzesBlut-\AppData\Local\Google\Chrome\Application\13.0.782.112\avutil-50.dll ()
MOD - C:\Users\-SchwarzesBlut-\AppData\Local\Google\Chrome\Application\13.0.782.112\avformat-52.dll ()
MOD - C:\Users\-SchwarzesBlut-\AppData\Local\Google\Chrome\Application\13.0.782.112\avcodec-52.dll ()
MOD - C:\Users\-SchwarzesBlut-\AppData\Local\Google\Chrome\Application\13.0.782.112\gcswf32.dll ()
MOD - C:\Users\-SCHWA~1\AppData\Local\Google\Chrome\APPLIC~1\130782~1.112\gcswf32.dll ()
========== Win32 Services (SafeList) ==========
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TeamViewer6) -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (N360) -- C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SBSDWSCService) -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Driver Services (SafeList) ==========
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20110815.034\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20110815.034\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Programme\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Programme\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVix86) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110815.030\IDSvix86.sys (Symantec Corporation)
DRV - (BHDrvx86) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110812.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SymNetS) -- C:\Windows\System32\Drivers\N360\0501000.01D\SYMNETS.SYS (Symantec Corporation)
DRV - (SRTSP) -- C:\Windows\System32\Drivers\N360\0501000.01D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\Windows\system32\drivers\N360\0501000.01D\SRTSPX.SYS (Symantec Corporation)
DRV - (SymEFA) -- C:\Windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) -- C:\Windows\system32\drivers\N360\0501000.01D\SYMDS.SYS (Symantec Corporation)
DRV - (SymIRON) -- C:\Windows\system32\drivers\N360\0501000.01D\Ironx86.SYS (Symantec Corporation)
DRV - (SipIMNDI) -- C:\Windows\System32\drivers\SipIMNDI.sys (T-Systems International GmbH)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 60 B7 E7 C0 B9 30 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\-SchwarzesBlut-\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\-SchwarzesBlut-\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2011.08.11 07:38:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_0_8 [2011.08.16 15:03:22 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2011.08.16 00:32:47 | 000,436,434 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15019 more lines...
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programme\Norton 360\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programme\Norton 360\Engine\5.1.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programme\Norton 360\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.08.15 21:10:45 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011.08.15 20:50:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011.08.15 20:50:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011.08.15 20:50:50 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011.08.15 14:43:44 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{71465EDE-D6D2-4440-A2CE-2AFCBA07798F}
[2011.08.15 14:43:34 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{5F04E09A-2001-4446-AB45-F421E7F5F88E}
[2011.08.14 10:21:55 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{8EAC7273-0CB3-4359-BA38-FC2F69ABD087}
[2011.08.14 10:21:42 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{44E7E797-2820-410A-AB2C-67A9529751AC}
[2011.08.13 22:21:16 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{F1B3544B-225A-47F8-8E5F-C71215177EF7}
[2011.08.13 22:21:03 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{F757EAE7-DDC4-4A20-817F-4D9D92BEE418}
[2011.08.13 10:20:30 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{310B1F38-C137-4A64-89C1-07D3A0E2ED66}
[2011.08.13 10:20:18 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{61E7F08B-0209-4D84-87C2-74FE2D9D60B8}
[2011.08.12 20:17:47 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{76F6F492-70AD-4591-A28C-CB05847DFFF0}
[2011.08.12 20:17:36 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{F4A35A10-C87C-4B97-9D8A-D81DAD0E88D5}
[2011.08.12 07:45:00 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{3C5BDDDD-592F-48C2-A302-64855C72FA73}
[2011.08.12 07:44:48 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{472D3EEC-C74C-458A-B9F2-6312C2199BC4}
[2011.08.11 19:39:25 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{2BC14A13-DD9C-49B4-9FD7-AD7B152AED99}
[2011.08.11 19:39:12 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{25D71E6C-D4E4-4B42-8F8F-5D1CEA21363A}
[2011.08.11 07:38:33 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{6A3F92FB-1542-4B55-8A99-958CF2A5BD17}
[2011.08.11 07:38:15 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{FEBC45AD-4ECB-4AAB-95BA-60F72D56F763}
[2011.08.10 13:16:20 | 003,957,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2011.08.10 13:16:19 | 003,902,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2011.08.10 13:16:05 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2011.08.10 13:16:05 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011.08.10 13:16:05 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011.08.10 13:16:05 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011.08.10 13:16:05 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011.08.10 13:16:05 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011.08.10 13:16:05 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011.08.10 13:16:05 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2011.08.10 13:16:05 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011.08.10 13:16:05 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011.08.10 13:16:05 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011.08.10 13:16:04 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.08.10 13:15:59 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2011.08.10 13:15:59 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2011.08.10 13:15:58 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2011.08.10 13:15:58 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2011.08.10 13:15:58 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2011.08.10 13:15:58 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2011.08.10 13:15:58 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2011.08.10 13:15:58 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2011.08.10 13:15:58 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2011.08.10 13:15:58 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2011.08.10 13:15:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2011.08.10 13:15:57 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2011.08.10 13:15:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2011.08.10 13:15:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2011.08.10 13:15:55 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcjt32.dll
[2011.08.10 13:15:55 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccp32.dll
[2011.08.10 13:15:55 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccu32.dll
[2011.08.10 13:15:55 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccr32.dll
[2011.08.10 13:15:54 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbctrac.dll
[2011.08.10 13:09:43 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{F4747E92-4260-4B4F-ACFB-06CD89A4162A}
[2011.08.10 13:09:13 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{3C4BBA55-79C7-454B-967D-43499F8F129F}
[2011.08.10 07:37:44 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{81F5F85A-D9F3-4E1C-A91B-1FB924ABB4B5}
[2011.08.10 07:37:31 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{A6655295-AA76-48F6-8B4D-9CB865AFFBF4}
[2011.08.09 20:45:44 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\Documents\ICQ
[2011.08.09 17:14:57 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\Documents\Meine empfangenen Dateien
[2011.08.09 16:41:46 | 000,744,568 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0501000.01D\symefa.sys
[2011.08.09 16:41:46 | 000,516,216 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0501000.01D\srtsp.sys
[2011.08.09 16:41:46 | 000,340,088 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0501000.01D\symds.sys
[2011.08.09 16:41:46 | 000,299,640 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0501000.01D\symnets.sys
[2011.08.09 16:41:46 | 000,136,312 | R--- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0501000.01D\ironx86.sys
[2011.08.09 16:41:46 | 000,050,168 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0501000.01D\srtspx.sys
[2011.08.09 16:41:22 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\N360\0501000.01D
[2011.08.09 12:46:05 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{14991B8C-A524-4FAB-A641-8F8BA9E0E6DB}
[2011.08.09 12:45:50 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{955F5FA9-D8CE-409F-A7DC-66CE1C6EBC13}
[2011.08.08 19:19:53 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.08.08 19:19:53 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2011.08.08 18:56:11 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{236C0F46-82B3-4FEE-8DF3-FBB4CA5F29FF}
[2011.08.08 18:55:45 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{78A625D1-0C9F-4967-8C4D-22D681DBD571}
[2011.08.08 18:52:37 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2011.08.08 18:52:34 | 000,126,584 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
[2011.08.08 18:52:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2011.08.08 18:52:34 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2011.08.08 18:52:15 | 000,106,928 | ---- | C] (GEAR Software Inc.) -- C:\Windows\System32\GEARAspi.dll
[2011.08.08 18:52:02 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\N360
[2011.08.08 18:51:59 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2011.08.08 18:51:59 | 000,000,000 | ---D | C] -- C:\Program Files\Norton 360
[2011.08.08 18:51:53 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2011.08.08 07:19:37 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{D7E4C236-FD52-40C8-B8B2-0703520E7F0E}
[2011.08.08 07:19:26 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{0D3950BD-09D8-4E51-AC53-E575FD27850D}
[2011.08.07 19:40:43 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\CrashDumps
[2011.08.07 19:32:07 | 000,024,352 | ---- | C] (T-Systems International GmbH) -- C:\Windows\System32\drivers\SipIMNDI.sys
[2011.08.07 15:46:15 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{DDE713F8-60BB-4E93-9802-706A0F019CDD}
[2011.08.07 15:46:01 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{5C071188-6C68-489D-BDD0-E0CC78566405}
[2011.08.07 11:16:29 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{D724F1C2-71AA-4B2B-A09A-6CAF69792F88}
[2011.08.07 11:16:18 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{62B6A4FE-FAFD-4FB3-86AE-BE22F93B5D1B}
[2011.08.01 09:02:24 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{4C538F0A-899E-4EF4-9D8E-3A0A0F12DD6E}
[2011.07.30 19:15:57 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SAM Broadcaster
[2011.07.30 19:15:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAM Broadcaster
[2011.07.30 19:15:50 | 000,000,000 | ---D | C] -- C:\Program Files\SpacialAudio
[2011.07.30 19:15:50 | 000,000,000 | ---D | C] -- C:\ProgramData\firebird
[2011.07.30 19:15:35 | 000,000,000 | ---D | C] -- C:\Program Files\Firebird
[2011.07.30 10:31:05 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{1CF0AAE8-EA31-450E-ABDE-904C9F376020}
[2011.07.29 22:18:48 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Roaming\Skype
[2011.07.29 22:18:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2011.07.29 09:43:17 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{C7C37057-A382-4073-A84C-8EE287E5A117}
[2011.07.27 10:26:46 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{4B63E05E-8EDF-4793-812B-CB8FC0B2E5D0}
[2011.07.27 10:26:45 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{A1E9F4A7-5EAA-4ABE-8E56-4BEAC3EAD90B}
[2011.07.26 10:11:54 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{D9C52188-01B5-45D3-AA89-64C5054C0739}
[2011.07.25 09:58:21 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{E393949E-1C1D-461C-B2FE-B3BFD586F2DA}
[2011.07.24 21:57:57 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\{D0E1CC8B-D3A5-423F-8FC8-3546533C554E}
[2011.07.24 21:57:43 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\Tracing
[2011.07.24 21:45:34 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2011.07.24 21:44:30 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2011.07.24 21:43:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011.07.24 21:43:02 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2011.07.24 21:38:49 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\Windows Live
[2011.07.24 21:38:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2011.07.24 20:53:18 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Roaming\WinRAR
[2011.07.24 20:53:17 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011.07.24 20:53:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011.07.24 20:53:05 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2011.07.24 19:53:58 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2011.07.24 19:42:37 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Roaming\ts3overlay
[2011.07.24 19:41:21 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Roaming\TS3Client
[2011.07.24 19:40:36 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
[2011.07.24 19:40:31 | 000,000,000 | ---D | C] -- C:\Users\-SchwarzesBlut-\AppData\Local\TeamSpeak 3 Client
[2011.07.23 11:14:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2011.07.23 11:10:16 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
========== Files - Modified Within 30 Days ==========
[2011.08.16 15:36:00 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.08.16 15:08:25 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.08.16 15:08:25 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.08.16 15:03:45 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.08.16 15:03:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.08.16 15:03:09 | 2213,351,424 | -HS- | M] () -- C:\hiberfil.sys
[2011.08.16 15:01:07 | 000,001,160 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4143225004-3801396974-2412421755-1000UA.job
[2011.08.16 00:32:47 | 000,436,434 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011.08.15 15:36:28 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.08.15 15:36:28 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.08.15 15:36:28 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.08.15 15:36:28 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.08.15 09:49:01 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4143225004-3801396974-2412421755-1000Core.job
[2011.08.11 07:48:57 | 001,299,404 | ---- | M] () -- C:\Windows\System32\drivers\N360\0501000.01D\Cat.DB
[2011.08.09 16:41:47 | 000,126,584 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
[2011.08.09 16:41:47 | 000,007,468 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
[2011.08.09 16:41:47 | 000,000,806 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.INF
[2011.08.08 19:19:53 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.07.22 06:56:17 | 001,638,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
========== Files Created - No Company Name ==========
[2011.08.10 07:35:49 | 001,299,404 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\Cat.DB
[2011.08.09 16:41:46 | 000,007,528 | R--- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\iron.cat
[2011.08.09 16:41:46 | 000,007,458 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\symnet.cat
[2011.08.09 16:41:46 | 000,007,456 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\symefa.cat
[2011.08.09 16:41:46 | 000,007,454 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\srtspx.cat
[2011.08.09 16:41:46 | 000,007,450 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\srtsp.cat
[2011.08.09 16:41:46 | 000,003,373 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\symefa.inf
[2011.08.09 16:41:46 | 000,002,792 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\symds.inf
[2011.08.09 16:41:46 | 000,001,446 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\symnet.inf
[2011.08.09 16:41:46 | 000,001,389 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\srtspx.inf
[2011.08.09 16:41:46 | 000,001,383 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\srtsp.inf
[2011.08.09 16:41:46 | 000,000,742 | R--- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\iron.inf
[2011.08.09 16:41:26 | 000,000,000 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\symds.cat
[2011.08.09 16:41:22 | 000,000,172 | ---- | C] () -- C:\Windows\System32\drivers\N360\0501000.01D\isolate.ini
[2011.08.08 18:52:34 | 000,007,468 | ---- | C] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
[2011.08.08 18:52:34 | 000,000,806 | ---- | C] () -- C:\Windows\System32\drivers\SYMEVENT.INF
[2011.07.24 21:47:50 | 000,001,404 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2011.07.24 21:47:20 | 000,002,432 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011.07.24 19:54:03 | 000,001,136 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 6.lnk
[2011.06.23 15:12:36 | 000,017,408 | ---- | C] () -- C:\Users\-SchwarzesBlut-\AppData\Local\WebpageIcons.db
[2009.07.14 10:47:43 | 000,654,166 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 10:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 10:47:43 | 000,130,006 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 10:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 06:33:53 | 000,265,640 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 04:05:48 | 000,616,008 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 04:05:48 | 000,106,388 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 02:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009.07.14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat |