OTL EXTRAS Logfile: Code:
OTL Extras logfile created on: 4/15/2012 7:30:54 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\*******\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 2.05 Gb Available Physical Memory | 68.55% Memory free
5.99 Gb Paging File | 5.20 Gb Available in Paging File | 86.80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 226.53 Gb Total Space | 87.42 Gb Free Space | 38.59% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 465.40 Gb Free Space | 99.92% Space Free | Partition Type: NTFS
Drive E: | 223.00 Gb Total Space | 222.90 Gb Free Space | 99.95% Space Free | Partition Type: NTFS
Computer Name: ******-PC | User Name: ******* | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1" = Allgemeine Runtime Files (x86)
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83217000FF}" = Java(TM) 7
"{2A3A4BD6-6CE0-4E2A-80D2-1D0FF6ACBFBA}" = LG United Mobile Driver
"{2C3CE8F0-F4AD-4D54-A520-975309C617E2}" = LG PC Suite III
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{4539863D-69F5-457B-901A-6A36C46AB2BD}" = XPlay 3
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6E5A0256-C1BB-4A4E-99CE-B87CC4383744}" = HP Photosmart Plus B210 series Basic Device Software
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F5FDEA1-D0AC-4D80-9D95-59775FCCFA40}" = HP Photosmart Plus B210 series Help
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{8729E65B-8C12-4A42-B1FE-E4DA7ED52855}_is1" = DirectX 9.0c Extra Files (x86, x64)
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.2) - Deutsch
"{AF145F8997B44EE9B106D018EF1DB58B}" = DivX Converter Mobile
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C0E18DC4-C74A-4889-AE3A-933471023787}" = LG PC Suite III
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}" = iTunes
"{F7BBA5F2-64EE-4BA0-B578-25256753A2A1}" = iDumpPod2iTunesDEMO
"{FDF7187F-3960-4BEC-916D-98C9A83E3A68}_is1" = DirectX for Managed Code
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"Age of Mythology Expansion Pack 1.0" = Age of Mythology Gold
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9
"Free YouTube Download_is1" = Free YouTube Download version 3.0.22.221
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.17.221
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 11.0 (x86 de)" = Mozilla Firefox 11.0 (x86 de)
"Office14.SingleImage" = Microsoft Office Home and Student 2010
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Spotify" = Spotify
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 13.04.2012 05:59:24 | Computer Name = ******-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2246
Error - 13.04.2012 06:30:34 | Computer Name = *******-PC | Source = Application Error | ID = 1000
Description = Faulting application name: autorun.exe_unknown, version: 0.0.0.0,
time stamp: 0x3bcf10d3 Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xffffffff Faulting process id:
0xeb0 Faulting application start time: 0x01cd195f12a9d8cb Faulting application path:
F:\autorun.exe Faulting module path: unknown Report Id: b34d4774-8553-11e1-9462-00a0d1ae6671
Error - 13.04.2012 06:31:39 | Computer Name = *******-PC | Source = Application Error | ID = 1000
Description = Faulting application name: autorun.exe_EMPIRE EARTH - Autorun-Anwendung,
version: 1.0.0.1, time stamp: 0x3bcf10d3 Faulting module name: unknown, version:
0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0060001e
Faulting
process id: 0xeb0 Faulting application start time: 0x01cd195f12a9d8cb Faulting application
path: F:\autorun.exe Faulting module path: unknown Report Id: d9c56838-8553-11e1-9462-00a0d1ae6671
Error - 13.04.2012 13:53:08 | Computer Name = *******-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 13.04.2012 13:53:08 | Computer Name = ********-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1029
Error - 13.04.2012 13:53:08 | Computer Name = *******-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1029
Error - 13.04.2012 13:53:09 | Computer Name = ******-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 13.04.2012 13:53:09 | Computer Name = *******-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2028
Error - 13.04.2012 13:53:09 | Computer Name = *******-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2028
Error - 14.04.2012 07:46:45 | Computer Name = *******-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
[ System Events ]
Error - 13.04.2012 10:02:32 | Computer Name = *******-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 13.04.2012 10:02:37 | Computer Name = ******-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 13.04.2012 10:02:42 | Computer Name = ******-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 13.04.2012 10:02:46 | Computer Name = ********-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 13.04.2012 10:02:51 | Computer Name = ********-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 13.04.2012 10:02:56 | Computer Name = *******-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 13.04.2012 10:03:01 | Computer Name = *******-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 13.04.2012 10:03:06 | Computer Name = *******-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 13.04.2012 10:03:10 | Computer Name = *******-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 14.04.2012 06:37:36 | Computer Name = ******-PC | Source = DCOM | ID = 10001
Description =
< End of report > --- --- ---
OTL Logfile: Code:
OTL logfile created on: 4/15/2012 7:30:53 PM - Run OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\*******\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 2.05 Gb Available Physical Memory | 68.55% Memory free
5.99 Gb Paging File | 5.20 Gb Available in Paging File | 86.80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 226.53 Gb Total Space | 87.42 Gb Free Space | 38.59% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 465.40 Gb Free Space | 99.92% Space Free | Partition Type: NTFS
Drive E: | 223.00 Gb Total Space | 222.90 Gb Free Space | 99.95% Space Free | Partition Type: NTFS
Computer Name: ******-PC | User Name: ****** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/04/15 19:30:40 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\*******\Downloads\OTL (3).exe
PRC - [2012/04/14 14:11:44 | 000,244,736 | -H-- | M] ( ) -- C:\ProgramData\UJGyQniXPhdjNN.exe
PRC - [2012/04/14 13:57:19 | 000,324,608 | -H-- | M] ( ) -- C:\ProgramData\gDgSIUpPNve.exe
PRC - [2012/01/03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/07/16 06:31:12 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011/02/26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/11/15 16:50:58 | 000,300,544 | ---- | M] (Mediafour Corporation) -- C:\Program Files\Mediafour\XPlay 3\XPlay.exe
PRC - [2010/11/15 16:50:58 | 000,211,968 | ---- | M] (Mediafour Corporation) -- C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe
PRC - [2010/10/16 06:41:02 | 000,101,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
PRC - [2009/07/14 03:14:46 | 000,115,200 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE
PRC - [2009/07/14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/14 03:14:12 | 000,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2009/07/14 03:14:12 | 000,016,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\attrib.exe
========== Modules (No Company Name) ==========
MOD - [2012/04/11 18:38:06 | 018,684,416 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\ehshell\60daffc3b5a5cfe07df3db9f1282c419\ehshell.ni.dll
MOD - [2012/04/11 18:37:50 | 002,035,712 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mcstore\f82d7a5f5ece82fcc49bc56031f10935\mcstore.ni.dll
MOD - [2012/04/11 18:37:48 | 006,499,840 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\7132ee88ae7232372954772ad7de3778\Microsoft.MediaCenter.UI.ni.dll
MOD - [2012/04/11 18:37:44 | 001,009,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\5d0ad8da43da340b3473bca66ac6cd0a\Microsoft.MediaCenter.ni.dll
MOD - [2012/02/18 02:02:36 | 000,107,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\MCESidebarCtrl\c758d6c0f34d9d5468e9b49dd64ad625\MCESidebarCtrl.ni.dll
MOD - [2012/02/18 02:02:17 | 000,705,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\0a9c32ac2e34bed2911c2d0d5e0d68de\Microsoft.MediaCenter.Sports.ni.dll
MOD - [2012/02/18 02:02:14 | 000,849,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\42b6b49c22c79b5cb11394dd9e070f34\Microsoft.MediaCenter.Shell.ni.dll
MOD - [2012/02/18 02:02:11 | 000,364,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\2aa4e27292ee3bb5eb469162491ca79c\mcstoredb.ni.dll
MOD - [2012/02/18 02:02:09 | 003,326,976 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mcepg\3eb09c85a77ef81cd54e6613a85faf3d\mcepg.ni.dll
MOD - [2012/02/18 01:56:32 | 007,952,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\1f14b3e1ee0847f8662f513e67f92547\System.ni.dll
MOD - [2012/01/19 15:05:30 | 000,442,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\d7cb05bc1b3ae306de88a42c372abb60\ehiProxy.ni.dll
MOD - [2012/01/19 15:04:05 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll
MOD - [2011/11/02 00:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/11/02 00:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009/07/14 03:20:04 | 000,134,656 | ---- | M] () -- C:\Windows\assembly\GAC_32\mcstoredb\6.1.0.0__31bf3856ad364e35\mcstoredb.dll
========== Win32 Services (SafeList) ==========
SRV - [2012/03/09 18:02:51 | 001,343,400 | -H-- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2012/01/03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/11/15 16:50:58 | 000,211,968 | ---- | M] (Mediafour Corporation) [Auto | Running] -- C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe -- (M4iPodWPDService)
SRV - [2009/07/14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - [2011/02/14 03:42:36 | 000,020,864 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2011/02/14 03:42:34 | 000,025,216 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2011/02/14 03:42:32 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2010/12/07 15:23:00 | 000,025,088 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgandmodem.sys -- (ANDModem)
DRV - [2010/12/07 15:23:00 | 000,020,736 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lganddiag.sys -- (AndDiag)
DRV - [2010/12/07 15:23:00 | 000,020,096 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgandgps.sys -- (AndGps)
DRV - [2010/12/07 15:22:58 | 000,014,336 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgandbus.sys -- (Andbus)
DRV - [2010/11/15 16:50:56 | 000,145,504 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\cbfs.sys -- (CbFs)
DRV - [2010/07/13 10:56:36 | 000,065,640 | ---- | M] (ITE Tech. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\itecir.sys -- (itecir)
DRV - [2009/09/28 14:02:18 | 000,259,176 | ---- | M] (Mediafour Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\MDFSYSNT.SYS -- (MDFSYSNT)
DRV - [2009/07/14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009/07/14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009/07/14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009/07/14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/14 00:13:48 | 001,035,776 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2009/07/14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R)
DRV - [2009/07/14 00:02:47 | 000,047,104 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1E62x86.sys -- (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Google [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Hotmail, Skype Download und Messenger sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3B 3E CE 84 39 1A CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/18 18:08:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012/02/16 14:33:39 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\******\AppData\Roaming\Mozilla\Extensions
[2012/03/06 14:25:33 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\yo1kqp3c.default\extensions
[2012/03/06 14:25:33 | 000,000,000 | -H-D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\yo1kqp3c.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/03/19 13:29:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/03/18 18:08:37 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/02/08 19:36:16 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/02/08 19:21:19 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/08 19:36:16 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012/02/08 19:36:16 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/02/08 19:36:16 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/02/08 19:36:16 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009/06/10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Reg Error: Value error.) - {4907C0AD-874D-44D9-B13E-7B0A4D8B9D3E} - C:\Program Files\Mediafour\XPlay 3\XPBHO.DLL (Mediafour Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [{914C5BF8-EEDD-4F3A-A8BE-34EE71CF1B29}] C:\Program Files\Mediafour\XPlay 3\XPlay.exe (Mediafour Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKCU..\Run: [gDgSIUpPNve.exe] C:\ProgramData\gDgSIUpPNve.exe ( )
O4 - HKCU..\Run: [Spotify] C:\Users\******\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: An OneNote s&enden - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube Download - C:\Users\******\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\******\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 10.0.0)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60449FEE-589B-43BB-B57A-4C4C66269D1F}: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/04/13 15:58:04 | 000,000,000 | ---D | C] -- C:\Sierra
[2012.04.14 20:06:52 | 000,000,000 | ---D | C] -- C:\Users\******\AppData\Local\ElevatedDiagnostics
[2012.04.14 14:12:15 | 000,000,000 | -H-D | C] -- C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SMART HDD
[2012.04.12 18:09:43 | 000,000,000 | -H-D | C] -- C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2012.04.12 18:08:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
[2012.04.12 17:43:51 | 000,000,000 | ---D | C] -- C:\Windows\Watson
[2012.04.12 15:28:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2012.04.12 15:27:53 | 000,000,000 | -H-D | C] -- C:\ProgramData\HP
[2012.04.12 15:27:52 | 000,000,000 | ---D | C] -- C:\Program Files\HP
[2012.04.12 15:27:40 | 000,000,000 | -H-D | C] -- C:\Users\******\AppData\Local\HP
[2012.04.10 15:05:23 | 000,000,000 | -H-D | C] -- C:\Users\******\AppData\Local\Spotify
[2012.04.10 15:03:41 | 000,000,000 | -H-D | C] -- C:\Users\******\AppData\Roaming\Spotify
[2012.03.31 18:40:02 | 000,121,376 | -H-- | C] (Martin Pesch) -- C:\Users\******\Desktop\mp3DirectCut.exe
[2012.03.31 18:40:02 | 000,000,000 | -H-D | C] -- C:\Users\******\Desktop\Languages
[2012.03.30 13:24:07 | 000,000,000 | -H-D | C] -- C:\Users\******\Desktop\AlphaCD
[2012.03.24 22:01:35 | 000,000,000 | -H-D | C] -- C:\Users\******\Desktop\New folder
[2012.03.20 22:05:25 | 000,000,000 | -H-D | C] -- C:\Users\******\Desktop\5pkpräsis
========== Files - Modified Within 30 Days ==========
[2012.04.15 19:32:11 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.04.15 19:32:11 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.04.15 19:24:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.04.15 19:24:43 | 2413,522,944 | -HS- | M] () -- C:\hiberfil.sys
[2012.04.14 19:29:43 | 000,000,359 | -H-- | M] () -- C:\Users\******\Desktop\Recycle Bin - Shortcut.lnk
[2012.04.14 14:12:16 | 000,000,168 | -H-- | M] () -- C:\ProgramData\-UJGyQniXPhdjNNr
[2012.04.14 14:12:16 | 000,000,000 | -H-- | M] () -- C:\ProgramData\-UJGyQniXPhdjNN
[2012.04.14 14:12:15 | 000,000,675 | -H-- | M] () -- C:\Users\******\Application Data\Microsoft\Internet Explorer\Quick Launch\SMART_HDD.lnk
[2012.04.14 14:12:15 | 000,000,651 | -H-- | M] () -- C:\Users\******\Desktop\SMART_HDD.lnk
[2012.04.14 14:12:13 | 000,000,256 | -H-- | M] () -- C:\ProgramData\UJGyQniXPhdjNN
[2012.04.14 14:11:44 | 000,244,736 | -H-- | M] ( ) -- C:\ProgramData\UJGyQniXPhdjNN.exe
[2012.04.14 13:57:19 | 000,324,608 | -H-- | M] ( ) -- C:\ProgramData\gDgSIUpPNve.exe
[2012.04.13 16:06:28 | 000,000,025 | ---- | M] () -- C:\Windows\SIERRA.INI
[2012.04.13 14:39:20 | 000,005,570 | -H-- | M] () -- C:\Users\******\Documents\Stationen der Machtergreifung und Gleichschaltung.odt
[2012.04.13 11:26:05 | 000,435,912 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.04.12 17:28:51 | 000,000,694 | -H-- | M] () -- C:\Windows\tasks\hpwebreg_CN0832M66S05J9.job
[2012.04.12 15:42:08 | 000,144,181 | -H-- | M] () -- C:\Users\******\Documents\Geschichte Abitur.Machtergreifung.odt
[2012.04.11 18:31:19 | 350,196,069 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.04.11 18:07:19 | 000,492,467 | -H-- | M] () -- C:\Users\******\Documents\Geschichte Abitur.Wiedervereinigung.odt
[2012.04.11 14:27:41 | 000,035,840 | -H-- | M] () -- C:\Users\******\Documents\Geschichte Abitur.Machtergreifung.dot
[2012.04.10 17:14:16 | 000,011,902 | -H-- | M] () -- C:\Users\******\Documents\Biologie-abiturÖkologie.odt
[2012.04.10 15:05:22 | 000,001,851 | -H-- | M] () -- C:\Users\******\Desktop\Spotify.lnk
[2012.04.08 19:58:18 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.04.08 19:58:18 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.31 19:24:29 | 000,002,332 | -H-- | M] () -- C:\Users\******\Desktop\mp3DirectCut.ini
[2012.03.31 19:21:12 | 000,622,793 | -H-- | M] () -- C:\Users\******\Documents\Seeed-Wonderful Life(abi30sek)2.mp3
[2012.03.31 19:21:12 | 000,622,793 | -H-- | M] () -- C:\Users\******\Desktop\Seeed-Wonderful Life(abi30sek)2.mp3
[2012.03.31 19:12:06 | 000,618,846 | -H-- | M] () -- C:\Users\******\Documents\Seeed-Wonderful Life(abi30sek).mp3
[2012.03.30 13:22:54 | 000,007,485 | -H-- | M] () -- C:\Users\******\Documents\Sprache.odt
[2012.03.28 23:46:02 | 000,005,278 | -H-- | M] () -- C:\Users\******\Documents\Liste4SemDeutsch.odt
[2012.03.26 18:00:22 | 000,004,746 | -H-- | M] () -- C:\Users\******\Documents\Fischer Abiturwissen.odt
[2012.03.24 12:51:04 | 000,005,043 | -H-- | M] () -- C:\Users\******\Documents\Abiturvorbereitung 1.odt
[2012.03.20 21:48:38 | 007,322,112 | -H-- | M] () -- C:\Users\******\Documents\Präsenationsentwurf15pk(pp2003) bilderstick.pot
[2012.03.20 21:46:32 | 007,949,457 | -H-- | M] () -- C:\Users\******\Documents\Präsenationsentwurf15pk(pp2003) bilderstick2openoffice.odp
[2012.03.18 18:07:43 | 006,520,203 | -H-- | M] () -- C:\Users\******\Documents\Präsenationsentwurf15pk3(20min)nummerduo.odp
========== Files Created - No Company Name ==========
[2012/02/17 16:26:20 | 000,000,127 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2012/01/29 22:20:13 | 000,053,248 | ---- | C] () -- C:\Windows\System32\CommonDL.dll
[2012/01/29 22:20:13 | 000,002,413 | ---- | C] () -- C:\Windows\System32\lgAxconfig.ini
[2012/01/15 19:10:31 | 000,162,304 | ---- | C] () -- C:\Windows\System32\libpng13.dll
[2012/01/15 19:10:30 | 000,394,752 | ---- | C] () -- C:\Windows\System32\cygwinb19.dll
[2012.04.14 19:29:43 | 000,000,359 | -H-- | C] () -- C:\Users\******\Desktop\Recycle Bin - Shortcut.lnk
[2012.04.14 14:12:16 | 000,000,168 | -H-- | C] () -- C:\ProgramData\-UJGyQniXPhdjNNr
[2012.04.14 14:12:16 | 000,000,000 | -H-- | C] () -- C:\ProgramData\-UJGyQniXPhdjNN
[2012.04.14 14:12:15 | 000,000,675 | -H-- | C] () -- C:\Users\******\Application Data\Microsoft\Internet Explorer\Quick Launch\SMART_HDD.lnk
[2012.04.14 14:12:15 | 000,000,651 | -H-- | C] () -- C:\Users\******\Desktop\SMART_HDD.lnk
[2012.04.14 14:11:50 | 000,000,256 | -H-- | C] () -- C:\ProgramData\UJGyQniXPhdjNN
[2012.04.14 14:11:44 | 000,244,736 | -H-- | C] ( ) -- C:\ProgramData\UJGyQniXPhdjNN.exe
[2012.04.14 13:59:29 | 000,324,608 | -H-- | C] ( ) -- C:\ProgramData\gDgSIUpPNve.exe
[2012.04.13 14:32:10 | 000,005,570 | -H-- | C] () -- C:\Users\******\Documents\Stationen der Machtergreifung und Gleichschaltung.odt
[2012.04.13 12:21:19 | 000,000,025 | ---- | C] () -- C:\Windows\SIERRA.INI
[2012.04.12 15:29:06 | 000,000,694 | -H-- | C] () -- C:\Windows\tasks\hpwebreg_CN0832M66S05J9.job
[2012.04.11 14:57:12 | 000,492,467 | -H-- | C] () -- C:\Users\******\Documents\Geschichte Abitur.Wiedervereinigung.odt
[2012.04.11 13:49:31 | 000,035,840 | -H-- | C] () -- C:\Users\******\Documents\Geschichte Abitur.Machtergreifung.dot
[2012.04.10 16:57:48 | 000,011,902 | -H-- | C] () -- C:\Users\******\Documents\Biologie-abiturÖkologie.odt
[2012.04.10 15:42:06 | 000,144,181 | -H-- | C] () -- C:\Users\******\Documents\Geschichte Abitur.Machtergreifung.odt
[2012.04.10 15:05:22 | 000,001,851 | -H-- | C] () -- C:\Users\******\Desktop\Spotify.lnk
[2012.04.10 15:05:22 | 000,001,837 | -H-- | C] () -- C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2012.03.31 19:50:46 | 000,622,793 | -H-- | C] () -- C:\Users\******\Desktop\Seeed-Wonderful Life(abi30sek)2.mp3
[2012.03.31 19:21:12 | 000,622,793 | -H-- | C] () -- C:\Users\******\Documents\Seeed-Wonderful Life(abi30sek)2.mp3
[2012.03.31 19:12:06 | 000,618,846 | -H-- | C] () -- C:\Users\******\Documents\Seeed-Wonderful Life(abi30sek).mp3
[2012.03.31 18:40:12 | 000,002,332 | -H-- | C] () -- C:\Users\******\Desktop\mp3DirectCut.ini
[2012.03.31 18:40:02 | 000,026,881 | -H-- | C] () -- C:\Users\******\Desktop\Manual.htm
[2012.03.31 18:40:02 | 000,015,099 | -H-- | C] () -- C:\Users\******\Desktop\FAQ.htm
[2012.03.29 15:20:53 | 000,007,485 | -H-- | C] () -- C:\Users\******\Documents\Sprache.odt
[2012.03.28 23:44:25 | 000,005,278 | -H-- | C] () -- C:\Users\******\Documents\Liste4SemDeutsch.odt
[2012.03.26 18:00:19 | 000,004,746 | -H-- | C] () -- C:\Users\******\Documents\Fischer Abiturwissen.odt
[2012.03.24 12:51:03 | 000,005,043 | -H-- | C] () -- C:\Users\******\Documents\Abiturvorbereitung 1.odt
[2012.03.20 21:48:26 | 007,322,112 | -H-- | C] () -- C:\Users\******\Documents\Präsenationsentwurf15pk(pp2003) bilderstick.pot
[2012.03.20 21:46:23 | 007,949,457 | -H-- | C] () -- C:\Users\******\Documents\Präsenationsentwurf15pk(pp2003) bilderstick2openoffice.odp
[2012.01.15 19:10:32 | 000,100,352 | ---- | C] () -- C:\Windows\System32\zlib1.dll
[2012.01.15 19:10:29 | 001,202,763 | ---- | C] () -- C:\Windows\unins002.exe
[2012.01.15 19:10:29 | 000,012,770 | ---- | C] () -- C:\Windows\unins002.dat
[2012.01.15 19:10:25 | 001,199,175 | ---- | C] () -- C:\Windows\unins001.exe
[2012.01.15 19:10:25 | 000,709,719 | ---- | C] () -- C:\Windows\unins000.exe
[2012.01.15 19:10:25 | 000,012,191 | ---- | C] () -- C:\Windows\unins001.dat
[2012.01.15 19:10:25 | 000,007,972 | ---- | C] () -- C:\Windows\unins000.dat
========== LOP Check ==========
[2012.03.03 14:22:32 | 000,000,000 | -H-D | M] -- C:\Users\******\AppData\Roaming\Amazon
[2012.03.06 14:26:50 | 000,000,000 | -H-D | M] -- C:\Users\******\AppData\Roaming\DVDVideoSoft
[2012.03.06 14:26:45 | 000,000,000 | -H-D | M] -- C:\Users\******\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.01.29 21:59:19 | 000,000,000 | -H-D | M] -- C:\Users\******\AppData\Roaming\LG Electronics
[2012.03.06 14:36:07 | 000,000,000 | -H-D | M] -- C:\Users\******\AppData\Roaming\OpenOffice.org
[2012.04.15 19:25:18 | 000,000,000 | -H-D | M] -- C:\Users\******\AppData\Roaming\Spotify
[2012.04.14 14:19:53 | 000,032,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > --- --- ---
Das ist jetzt das, was raus kam ohne dein script :) |