Vivid_Sky | 02.09.2013 20:41 | Ohje da hab ich aber wirklich was grob übersehen, tut mir leid !
Jetzt aber :
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-09-2013
Ran by Beyond The Empty Sky (administrator) on BEYONDALLSKIES on 02-09-2013 01:38:15
Running from C:\Users\Beyond The Empty Sky\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Iminent) C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe
() C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
() C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Windows\AsScrPro.exe
() C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiSeAgnt.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
() C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Iminent) C:\Program Files (x86)\Iminent\Iminent.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
(Iminent) C:\Program Files (x86)\Iminent\Iminent.Messengers.exe
(Dropbox, Inc.) C:\Users\Beyond The Empty Sky\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
(Windows Net) C:\Users\Beyond The Empty Sky\AppData\Roaming\Windows Net Data\net.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ASUS WebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-16] ()
HKLM\...\Run: [Trend Micro Titanium] - C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe [1111568 2011-10-08] (Trend Micro Inc.)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2189416 2011-03-01] (Realtek Semiconductor)
HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324096 2010-08-11] (Alcor Micro Corp.)
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-13] (ELAN Microelectronics Corp.)
HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] ()
HKLM\...\Run: [Trend Micro Client Framework] - C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [197152 2011-02-10] (Trend Micro Inc.)
HKLM\...\Policies\Explorer: [NoActiveDesktop] 1
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564016 2013-07-26] (Samsung)
HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe [578560 2013-07-18] (Samsung Electronics)
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-07-26] (Samsung)
HKCU\...\Run: [GoogleChromeAutoLaunch_87301C057DF59987BD329160C015DF91] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [829392 2013-08-24] (Google Inc.)
HKCU\...\Run: [icq] - C:\Users\Beyond The Empty Sky\AppData\Roaming\ICQM\icq.exe [26606072 2013-01-10] (ICQ)
HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] ()
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-07-26] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] - C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [1666560 2012-02-20] (AimerSoft)
HKLM-x32\...\Run: [UIExec] - C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe [156448 2012-05-04] ()
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-18] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM-x32\...\Run: [Iminent] - C:\Program Files (x86)\Iminent\Iminent.exe [1074736 2013-08-28] (Iminent)
HKLM-x32\...\Run: [IminentMessenger] - C:\Program Files (x86)\Iminent\Iminent.Messengers.exe [884784 2013-08-28] (Iminent)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [226920 2011-02-08] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [192616 2011-02-08] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Beyond The Empty Sky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Beyond The Empty Sky\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Beyond The Empty Sky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.0.lnk
ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
Startup: C:\Users\Beyond The Empty Sky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk
ShortcutTarget: net.lnk -> C:\Users\Beyond The Empty Sky\AppData\Roaming\Windows Net Data\net.exe (Windows Net)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
BHO: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe64.dll (Trend Micro Inc.)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\TmIEPlg32.dll (Trend Micro Inc.)
BHO-x32: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files (x86)\Iminent\Iminent.WebBooster.InternetExplorer.dll (Iminent)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
BHO-x32: Web Check - {E155F23C-9931-47c6-A619-20E6FCA86D75} - C:\Program Files (x86)\Web Check\WebCheck.dll (Web Check)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe64.dll (Trend Micro Inc.)
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\TmIEPlg32.dll (Trend Micro Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Beyond The Empty Sky\AppData\Roaming\Mozilla\Firefox\Profiles\rpplbwut.default
FF user.js: detected! => C:\Users\Beyond The Empty Sky\AppData\Roaming\Mozilla\Firefox\Profiles\rpplbwut.default\user.js
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20url.indexOf('.brightcove.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1%20%26%26%20url.indexOf('.png')%20%3D%3D%20-1)%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20ab-us21.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000%3B%20PROXY%20ab-us20.personalitycores.com%3A8000%3B%20PROXY%20ab-us14.personalitycores.com%3A8000%3B%20PROXY%20ab-us17.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us16.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us22.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000%3B%20PROXY%20ab-us15.personalitycores.com%3A8000%3B%20PROXY%20ab-us18.personalitycores.com%3A8000%3B%20PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @millisecond.com/npInquisit,version=3.0 - C:\Program Files (x86)\Millisecond Software\Inquisit 3.0 Mozilla Plugin\npInquisit_3060.dll (Millisecond Software)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @millisecond.com/npInquisit,version=3.0 - C:\Program Files (x86)\Millisecond Software\Inquisit 3.0 Mozilla Plugin\npInquisit_3060.dll (Millisecond Software)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: 714cb7478d98b1cb51d1f5f515f060c7 - C:\Users\Beyond The Empty Sky\AppData\Roaming\Mozilla\Firefox\Profiles\rpplbwut.default\Extensions\714cb7478d98b1cb51d1f5f515f060c7@link.codefisher.org.xpi
FF Extension: jid1-QpHD8URtZWJC2A - C:\Users\Beyond The Empty Sky\AppData\Roaming\Mozilla\Firefox\Profiles\rpplbwut.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi
FF Extension: No Name - C:\Users\Beyond The Empty Sky\AppData\Roaming\Mozilla\Firefox\Profiles\rpplbwut.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: No Name - C:\Users\Beyond The Empty Sky\AppData\Roaming\Mozilla\Firefox\Profiles\rpplbwut.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\firefoxextension\
FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\firefoxextension\
FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF Extension: No Name - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF HKLM-x32\...\Firefox\Extensions: [{52b0f3db-f988-4788-b9dc-861d016f4487}] C:\Program Files (x86)\Web Check\WebCheck.xpi
FF Extension: No Name - C:\Program Files (x86)\Web Check\WebCheck.xpi
Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\pdf.dll ()
CHR Plugin: (Skype Click to Call) - C:\Users\Beyond The Empty Sky\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0\npSkypeChromePlugin.dll (Skype Technologies S.A.)
CHR Plugin: (Free Studio) - C:\Users\Beyond The Empty Sky\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\np_dvs_plugin.dll (DVDVideoSoft Ltd.)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Inquisit Web Edition) - C:\Program Files (x86)\Millisecond Software\Inquisit 3.0 Mozilla Plugin\npInquisit_3060.dll (Millisecond Software)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll No File
CHR Extension: (ProxTube) - C:\Users\BEYOND~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.4_0
CHR Extension: (Google Drive) - C:\Users\BEYOND~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\BEYOND~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\BEYOND~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Web Check) - C:\Users\BEYOND~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dacechnliklhcacondhhkkfobapdopee\0.1_0
CHR Extension: (Iminent) - C:\Users\BEYOND~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.35.1.1_0
CHR Extension: (Skype Click to Call) - C:\Users\BEYOND~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0
CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\BEYOND~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\BEYOND~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (Gmail) - C:\Users\BEYOND~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [aakchaleigkohafkfjfjbblobjifikek] - C:\Users\Beyond The Empty Sky\AppData\LocalLow\proxtube\CHROME\proxtube.crx
CHR HKLM-x32\...\Chrome\Extension: [dacechnliklhcacondhhkkfobapdopee] - C:\Program Files (x86)\Web Check\WebCheck.crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-18] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-18] (Avira Operations GmbH & Co. KG)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
R2 SProtection; C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe [2868544 2013-08-07] (Iminent)
R2 UI Assistant Service; C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe [274208 2012-05-04] ()
R2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [x]
==================== Drivers (Whitelisted) ====================
R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17024 2010-07-26] (ASUS)
R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17024 2010-07-26] (ASUS)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-07-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-07-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-06] (Avira Operations GmbH & Co. KG)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-07-18] ()
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-07-18] ()
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R2 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [90704 2010-09-17] (Trend Micro Inc.)
R2 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [144464 2010-09-17] (Trend Micro Inc.)
R2 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [67664 2010-09-17] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105552 2010-09-17] (Trend Micro Inc.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-02 01:37 - 2013-09-02 01:37 - 01951926 _____ (Farbar) C:\Users\Beyond The Empty Sky\Desktop\FRST64.exe
2013-08-31 15:20 - 2013-08-31 15:20 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\freepdf
2013-08-31 15:20 - 2013-08-31 15:20 - 00000000 ____D C:\Program Files (x86)\Web Check
2013-08-31 15:19 - 2013-08-31 15:19 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\Iminent
2013-08-31 15:18 - 2013-08-31 15:19 - 00000000 ____D C:\Program Files (x86)\Iminent
2013-08-31 15:18 - 2013-08-31 15:18 - 00000635 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-31 15:18 - 2013-08-31 15:18 - 00000000 ____D C:\ProgramData\Iminent
2013-08-31 15:17 - 2013-08-31 15:17 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\Windows Net Data
2013-08-31 01:21 - 2013-08-31 01:23 - 00000000 ____D C:\Users\BEYOND~1\AppData\Local\DownloadGuide
2013-08-31 01:21 - 2013-08-31 01:21 - 00444400 _____ C:\Users\Beyond The Empty Sky\Desktop\DLG_free-pdf-perfect_chip_de-DE10.exe
2013-08-30 23:05 - 2013-08-30 23:22 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\Neuer Ordner
2013-08-30 22:47 - 2013-08-30 22:56 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\Thinspo
2013-08-30 14:54 - 2013-08-30 14:54 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\Bewrbungskram - Kopie
2013-08-29 00:09 - 2013-08-31 22:46 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\Japan, März '13
2013-08-25 23:13 - 2013-08-25 23:13 - 00003158 _____ C:\Windows\System32\Tasks\YourFile DownloaderUpdate
2013-08-25 23:13 - 2013-08-25 23:13 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\YourFileDownloader
2013-08-25 16:05 - 2013-08-25 16:05 - 06617383 _____ C:\Users\Beyond The Empty Sky\Desktop\20130823_screens_export.zip
2013-08-22 23:27 - 2013-08-22 23:27 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\kk
2013-08-22 22:41 - 2013-08-22 22:41 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2013-08-22 21:57 - 2013-08-22 23:26 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-08-22 21:52 - 2013-07-18 07:34 - 00233472 _____ (Teruten) C:\Windows\SysWOW64\FsUsbExService.Exe
2013-08-22 21:52 - 2013-07-18 07:34 - 00037344 _____ C:\Windows\SysWOW64\FsUsbExDisk.Sys
2013-08-22 21:52 - 2013-07-18 07:34 - 00037344 _____ C:\Windows\SysWOW64\FsUsbExDisk.Sy_
2013-08-22 21:52 - 2012-09-26 21:57 - 00110592 _____ () C:\Windows\SysWOW64\FsUsbExDevice.Dll
2013-08-22 18:47 - 2013-08-22 18:47 - 00237568 _____ (www.CompulsiveCode.com) C:\Users\Beyond The Empty Sky\Desktop\JPEGtoPDF37.exe
2013-08-21 01:04 - 2013-08-30 01:47 - 00024130 _____ C:\Users\Beyond The Empty Sky\Documents\dptext.txt
2013-08-20 23:06 - 2013-08-20 23:06 - 00001785 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-08-20 23:05 - 2013-08-20 23:06 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-08-20 23:05 - 2013-08-20 23:06 - 00000000 ____D C:\Program Files\iTunes
2013-08-20 23:05 - 2013-08-20 23:06 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-08-20 23:05 - 2013-08-20 23:05 - 00000000 ____D C:\Program Files\iPod
2013-08-20 07:02 - 2013-08-20 07:02 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll
2013-08-20 07:02 - 2013-08-20 07:02 - 00708168 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller.dll
2013-08-20 07:02 - 2013-08-20 07:02 - 00204568 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2013-08-20 07:02 - 2013-08-20 07:02 - 00103576 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2013-08-18 03:52 - 2013-08-18 03:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-15 03:09 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-15 03:09 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-15 03:09 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-15 03:09 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-15 03:09 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-15 03:09 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-15 03:09 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-15 03:09 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-15 03:09 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-15 03:09 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-15 03:09 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-15 03:09 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-15 03:09 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-15 03:09 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-15 03:09 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-15 03:09 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-15 03:09 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-15 03:09 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-15 03:09 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-15 03:09 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-15 03:09 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-15 03:09 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-15 03:09 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-15 03:09 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-15 03:09 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-15 03:09 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-15 03:09 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-15 03:09 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-15 03:09 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-15 03:09 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-15 03:09 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-15 03:01 - 2013-08-15 03:04 - 00000000 ____D C:\Windows\system32\MRT
2013-08-15 00:18 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-15 00:18 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-15 00:18 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-15 00:18 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-15 00:18 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-15 00:18 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-15 00:18 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-15 00:18 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-15 00:17 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-15 00:17 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-15 00:17 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-15 00:17 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-15 00:17 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-15 00:17 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-15 00:17 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-15 00:17 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-15 00:17 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-15 00:17 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-15 00:17 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-15 00:17 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-15 00:17 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-15 00:17 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-15 00:17 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-15 00:17 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-15 00:17 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-15 00:17 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-15 00:17 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-13 03:02 - 2013-08-22 18:37 - 00000000 ____D C:\Users\BEYOND~1\AppData\Local\Kingsoft
2013-08-13 02:57 - 2013-08-13 02:57 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\Kingsoft
2013-08-13 02:57 - 2013-08-13 02:57 - 00000000 ____D C:\ProgramData\Kingsoft
2013-08-13 02:57 - 2013-08-13 02:57 - 00000000 ____D C:\Program Files (x86)\Kingsoft
2013-08-13 02:49 - 2013-08-13 02:50 - 63363736 _____ (Microsoft Corporation) C:\Users\Beyond The Empty Sky\Desktop\PowerPointViewer.exe
2013-08-13 02:49 - 2013-08-13 02:50 - 25755856 _____ (Microsoft Corporation) C:\Users\Beyond The Empty Sky\Desktop\wordview_de-de.exe
2013-08-13 02:44 - 2013-08-13 02:50 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-08-13 02:38 - 2013-08-13 02:38 - 05242880 _____ C:\Users\Beyond The Empty Sky\Desktop\Universum._.pps
2013-08-12 01:01 - 2013-08-30 03:31 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\Japan, Sep. '12
2013-08-11 01:23 - 2013-08-29 00:13 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\blabilder
2013-08-11 01:02 - 2013-08-11 01:21 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\LINEcamera
==================== One Month Modified Files and Folders =======
2013-09-02 01:38 - 2013-09-02 01:38 - 00000000 ____D C:\FRST
2013-09-02 01:37 - 2013-09-02 01:37 - 01951926 _____ (Farbar) C:\Users\Beyond The Empty Sky\Desktop\FRST64.exe
2013-09-02 01:35 - 2013-01-21 02:37 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-02 01:35 - 2011-05-27 14:05 - 01173909 _____ C:\Windows\WindowsUpdate.log
2013-09-02 01:35 - 2011-01-12 17:50 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-02 01:35 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-02 01:35 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-01 04:07 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\tracing
2013-09-01 03:42 - 2011-01-12 17:50 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-01 03:29 - 2009-08-04 11:51 - 00666256 _____ C:\Windows\system32\perfh007.dat
2013-09-01 03:29 - 2009-08-04 11:51 - 00134178 _____ C:\Windows\system32\perfc007.dat
2013-09-01 03:29 - 2009-07-14 07:13 - 01531218 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-01 01:41 - 2012-03-11 12:19 - 00033140 _____ C:\Windows\setupact.log
2013-08-31 22:46 - 2013-08-29 00:09 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\Japan, März '13
2013-08-31 22:46 - 2012-11-15 05:47 - 00000000 ___RD C:\Users\Beyond The Empty Sky\Dropbox
2013-08-31 22:46 - 2012-11-15 05:45 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\Dropbox
2013-08-31 22:45 - 2012-02-21 21:42 - 00000000 ___HD C:\ASUS.DAT
2013-08-31 22:45 - 2011-05-27 14:31 - 00002426 _____ C:\Windows\system32\AutoRunFilter.ini
2013-08-31 22:45 - 2011-05-27 14:31 - 00001406 _____ C:\Windows\system32\ServiceFilter.ini
2013-08-31 22:44 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-31 22:44 - 2009-07-14 06:45 - 00276600 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-31 22:43 - 2012-04-27 02:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-31 22:43 - 2012-03-12 05:44 - 00147250 _____ C:\Windows\PFRO.log
2013-08-31 22:42 - 2012-04-27 21:41 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\SoftGrid Client
2013-08-31 22:33 - 2013-01-06 03:06 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\Skype
2013-08-31 16:09 - 2012-03-03 03:34 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\vlc
2013-08-31 15:51 - 2013-01-21 02:37 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-31 15:51 - 2012-08-10 23:56 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-31 15:51 - 2012-08-10 23:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-31 15:21 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-08-31 15:20 - 2013-08-31 15:20 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\freepdf
2013-08-31 15:20 - 2013-08-31 15:20 - 00000000 ____D C:\Program Files (x86)\Web Check
2013-08-31 15:19 - 2013-08-31 15:19 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\Iminent
2013-08-31 15:19 - 2013-08-31 15:18 - 00000000 ____D C:\Program Files (x86)\Iminent
2013-08-31 15:18 - 2013-08-31 15:18 - 00000635 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-31 15:18 - 2013-08-31 15:18 - 00000000 ____D C:\ProgramData\Iminent
2013-08-31 15:17 - 2013-08-31 15:17 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\Windows Net Data
2013-08-31 15:17 - 2012-02-21 21:43 - 00000000 ___RD C:\Users\Beyond The Empty Sky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-31 01:23 - 2013-08-31 01:21 - 00000000 ____D C:\Users\BEYOND~1\AppData\Local\DownloadGuide
2013-08-31 01:21 - 2013-08-31 01:21 - 00444400 _____ C:\Users\Beyond The Empty Sky\Desktop\DLG_free-pdf-perfect_chip_de-DE10.exe
2013-08-30 23:22 - 2013-08-30 23:05 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\Neuer Ordner
2013-08-30 22:56 - 2013-08-30 22:47 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\Thinspo
2013-08-30 14:54 - 2013-08-30 14:54 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\Bewrbungskram - Kopie
2013-08-30 14:52 - 2013-04-18 20:19 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\Bewrbungskram
2013-08-30 03:31 - 2013-08-12 01:01 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\Japan, Sep. '12
2013-08-30 03:31 - 2012-02-21 21:44 - 00058520 _____ C:\Users\BEYOND~1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-30 01:47 - 2013-08-21 01:04 - 00024130 _____ C:\Users\Beyond The Empty Sky\Documents\dptext.txt
2013-08-30 01:34 - 2009-07-14 09:45 - 00000000 ____D C:\Windows\ShellNew
2013-08-29 00:13 - 2013-08-11 01:23 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\blabilder
2013-08-25 23:13 - 2013-08-25 23:13 - 00003158 _____ C:\Windows\System32\Tasks\YourFile DownloaderUpdate
2013-08-25 23:13 - 2013-08-25 23:13 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\YourFileDownloader
2013-08-25 16:05 - 2013-08-25 16:05 - 06617383 _____ C:\Users\Beyond The Empty Sky\Desktop\20130823_screens_export.zip
2013-08-22 23:27 - 2013-08-22 23:27 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\kk
2013-08-22 23:26 - 2013-08-22 21:57 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-08-22 22:41 - 2013-08-22 22:41 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2013-08-22 21:56 - 2011-01-12 17:48 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-08-22 21:55 - 2012-11-14 03:31 - 00000000 ____D C:\Program Files (x86)\Samsung
2013-08-22 21:55 - 2012-11-14 03:12 - 00000000 ____D C:\Users\BEYOND~1\AppData\Local\Downloaded Installations
2013-08-22 18:47 - 2013-08-22 18:47 - 00237568 _____ (www.CompulsiveCode.com) C:\Users\Beyond The Empty Sky\Desktop\JPEGtoPDF37.exe
2013-08-22 18:37 - 2013-08-13 03:02 - 00000000 ____D C:\Users\BEYOND~1\AppData\Local\Kingsoft
2013-08-20 23:06 - 2013-08-20 23:06 - 00001785 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-08-20 23:06 - 2013-08-20 23:05 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-08-20 23:06 - 2013-08-20 23:05 - 00000000 ____D C:\Program Files\iTunes
2013-08-20 23:06 - 2013-08-20 23:05 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-08-20 23:05 - 2013-08-20 23:05 - 00000000 ____D C:\Program Files\iPod
2013-08-20 07:02 - 2013-08-20 07:02 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll
2013-08-20 07:02 - 2013-08-20 07:02 - 00708168 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller.dll
2013-08-20 07:02 - 2013-08-20 07:02 - 00204568 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2013-08-20 07:02 - 2013-08-20 07:02 - 00103576 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2013-08-18 03:52 - 2013-08-18 03:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-18 03:07 - 2011-05-27 14:33 - 00045056 _____ C:\Windows\SysWOW64\acovcnt.exe
2013-08-16 15:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-15 03:04 - 2013-08-15 03:01 - 00000000 ____D C:\Windows\system32\MRT
2013-08-15 03:01 - 2012-04-12 01:14 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-15 01:31 - 2012-03-03 03:34 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\dvdcss
2013-08-13 02:57 - 2013-08-13 02:57 - 00000000 ____D C:\Users\Beyond The Empty Sky\AppData\Roaming\Kingsoft
2013-08-13 02:57 - 2013-08-13 02:57 - 00000000 ____D C:\ProgramData\Kingsoft
2013-08-13 02:57 - 2013-08-13 02:57 - 00000000 ____D C:\Program Files (x86)\Kingsoft
2013-08-13 02:51 - 2011-01-12 17:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-08-13 02:50 - 2013-08-13 02:49 - 63363736 _____ (Microsoft Corporation) C:\Users\Beyond The Empty Sky\Desktop\PowerPointViewer.exe
2013-08-13 02:50 - 2013-08-13 02:49 - 25755856 _____ (Microsoft Corporation) C:\Users\Beyond The Empty Sky\Desktop\wordview_de-de.exe
2013-08-13 02:50 - 2013-08-13 02:44 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-08-13 02:38 - 2013-08-13 02:38 - 05242880 _____ C:\Users\Beyond The Empty Sky\Desktop\Universum._.pps
2013-08-11 01:21 - 2013-08-11 01:02 - 00000000 ____D C:\Users\Beyond The Empty Sky\Desktop\LINEcamera
Files to move or delete:
====================
C:\Users\BEYOND~1\AppData\Local\Temp\0cw-kigm.dll
C:\Users\BEYOND~1\AppData\Local\Temp\contentDATs.exe
C:\Users\BEYOND~1\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\BEYOND~1\AppData\Local\Temp\htmlayout.dll
C:\Users\BEYOND~1\AppData\Local\Temp\SecurityScan_Release.exe
C:\Users\BEYOND~1\AppData\Local\Temp\SkypeSetup.exe
C:\Users\BEYOND~1\AppData\Local\Temp\toolbar677168359.exe
C:\Users\BEYOND~1\AppData\Local\Temp\uninstall677292583.exe
C:\Users\BEYOND~1\AppData\Local\Temp\{EAC200CF-94CC-44DE-96A8-9984F0CE2AAF}\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}\difxapi.dll
C:\Users\BEYOND~1\AppData\Local\Temp\{CC36BB50-FC3F-42A0-8CC9-686B09391EFA}\InstallFlashPlayer.exe
C:\Users\BEYOND~1\AppData\Local\Temp\{AC76BA86-7AD7-1041-7B44-AB0000000001}\FixTransforms.exe
C:\Users\BEYOND~1\AppData\Local\Temp\RarSFX0\Binaries\IExploreInstaller.exe
C:\Users\BEYOND~1\AppData\Local\Temp\nsy161C.tmp\DropboxNSISTools.dll
C:\Users\BEYOND~1\AppData\Local\Temp\nswFC2C.tmp\DropboxNSISTools.dll
C:\Users\BEYOND~1\AppData\Local\Temp\nsi22E.tmp\DropboxNSISTools.dll
C:\Users\BEYOND~1\AppData\Local\Temp\nsc763A.tmp\DropboxNSISTools.dll
C:\Users\BEYOND~1\AppData\Local\Temp\nsc763A.tmp\UAC.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MaAgent.exe
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MAAuthProc.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MACLICX13.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MACLicX15.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MACSMANAGER.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MaCSMgr.exe
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MaCSProHook.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\mapshapi.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\mapwij10.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MaSyncP.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MaWAMP.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MAWebControl.exe
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MaWMP.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MPXBox.exe
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\MtpAccess.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\UserShare.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\XSYNCClt.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAFileUpdate.dll
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAUpdate.exe
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAUpdateBoot.exe
C:\Users\BEYOND~1\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MaUpdateClient.exe
C:\Users\BEYOND~1\AppData\Local\Temp\InstallShare4143\bab_setup.exe
C:\Users\BEYOND~1\AppData\Local\Temp\InstallShare25473\bab_setup.exe
C:\Users\BEYOND~1\AppData\Local\Temp\c3d576a3-923f-483e-9285-c1487497175a\CliSecureRT.dll
C:\Users\BEYOND~1\AppData\Local\Temp\5eb7a3db-8621-4131-b849-4f59e4b7e373\CliSecureRT.dll
C:\Users\BEYOND~1\AppData\Local\Temp\51dcc584-8329-4198-a7d3-3588a70ffbd0\CliSecureRT.dll
C:\Users\BEYOND~1\AppData\Local\Temp\3d083b50-7f3e-4293-bc13-1f4d16bd927c\CliSecureRT.dll
C:\Users\BEYOND~1\AppData\Local\Temp\28b64586-8ca8-47a1-aa7a-b34872124d3e\CliSecureRT.dll
C:\Users\BEYOND~1\AppData\Local\Temp\22775de3-904c-421e-8a03-b7b6cac921fa\CliSecureRT.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-22 14:00
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-09-2013
Ran by Beyond The Empty Sky at 2013-09-02 01:39:06
Running from C:\Users\Beyond The Empty Sky\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
1&1 Surf-Stick (x32 Version: 1.0.0.2)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03)
Aimersoft Video Converter Ultimate(Build 4.2.4.0) (x32)
Alcor Micro USB Card Reader (x32 Version: 1.8.17.26026)
Apple Application Support (x32 Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
ASUS AI Recovery (x32 Version: 1.0.13)
ASUS FancyStart (x32 Version: 1.1.0)
ASUS LifeFrame3 (x32 Version: 3.0.30)
ASUS Live Update (x32 Version: 2.5.9)
ASUS Power4Gear Hybrid (Version: 1.1.43)
ASUS SmartLogon (x32 Version: 1.0.0011)
ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0031)
ASUS Virtual Camera (x32 Version: 1.0.21)
ASUS WebStorage (x32 Version: 2.0.46.1429)
AsusScr_K3 Series_ENG_Basic (x32 Version: 1.0.0001)
AsusVibe2.0 (x32 Version: 2.0.3.585)
ATK Package (x32 Version: 1.0.0008)
Avira Free Antivirus (x32 Version: 13.0.0.3885)
AVS Update Manager 1.0 (x32)
AVS Video Converter 8 (x32)
AVS4YOU Software Navigator 1.4 (x32)
Bonjour (Version: 3.0.0.10)
Bookworm Deluxe (x32)
Canon iP4300
Canon MG5200 series MP Drivers
Cisco EAP-FAST Module (x32 Version: 2.2.14)
Cisco LEAP Module (x32 Version: 1.0.19)
Cisco PEAP Module (x32 Version: 1.1.6)
Collage Maker (x32 Version: 3.00)
Control ActiveX de Windows Live Mesh para conexiones remotas (x32 Version: 15.4.5722.2)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2)
Cooking Dash (x32)
CyberLink LabelPrint (x32 Version: 2.5.1908)
CyberLink Power2Go (x32 Version: 6.1.3602c)
Dropbox (HKCU Version: 2.0.22)
Extended Asian Language font pack for Adobe Reader XI (x32 Version: 11.0.0)
Fast Boot (Version: 1.0.8)
Free YouTube to MP3 Converter version 3.11.37.1212 (x32 Version: 3.11.37.1212)
Game Park Console (x32 Version: 6.2.1.1)
GIMP 2.6.12 (x32 Version: 2.6.12)
Google Chrome (x32 Version: 29.0.1547.62)
Google Update Helper (x32 Version: 1.3.21.153)
GUILD WARS (x32)
Hotel Dash Suite Success (x32)
ICQ 8.0 (build 5981, für aktuellen Benutzer) (HKCU Version: 8.0.5981.0)
Iminent (x32 Version: 6.35.31.0)
Intel(R) Control Center (x32 Version: 1.2.1.1007)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1118)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2291)
Intel(R) Turbo Boost Technology Monitor 2.0 (Version: 2.1.23.0)
iTunes (Version: 11.0.5.5)
Jewel Quest 3 (x32)
Luxor 3 (x32)
Mahjongg dimensions (x32)
McAfee Security Scan Plus (x32 Version: 3.0.318.3)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000)
Microsoft Office Word Viewer 2003 (x32 Version: 11.0.8173.0)
Microsoft PowerPoint Viewer (x32 Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1)
Mozilla Maintenance Service (x32 Version: 23.0.1)
Mp3tag v2.54 (x32 Version: v2.54)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0)
MyFreeCodec (HKCU)
NVIDIA Control Panel 266.86 (Version: 266.86)
NVIDIA Graphics Driver 266.86 (Version: 266.86)
NVIDIA Install Application (Version: 2.265.39.0)
NVIDIA Optimus 1.0.18 (Version: 1.0.18)
NVIDIA Update Components (Version: 1.0.18)
Path of Exile (x32 Version: 0.10.7.24409)
PhotoScape (x32)
Picture Collage Maker Free 2.1.2 (x32)
Picture Collage Maker Pro 3.3.7 (x32 Version: 3.3.7)
Plants vs Zombies (x32)
Ralink RT2860 Wireless LAN Card (x32 Version: 1.5.9.0)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6324)
Samsung Kies (x32 Version: 2.5.0.12094_28)
Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0)
Skype Click to Call (x32 Version: 6.3.11079)
Skype™ 6.6 (x32 Version: 6.6.106)
syncables desktop SE (x32 Version: 5.5.746.11492)
Trend Micro Titanium Internet Security (Version: 3.00)
Trend Micro Titanium Internet Security (Version: 3.1.1109)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
VLC media player 2.0.0 (x32 Version: 2.0.0)
Ware PS/2-X64 8.0.5.0_WHQL (Version: 8.0.5.0)
Web Check (x32)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2)
Windows Utils (x32)
WinFlash (x32 Version: 2.31.1)
WinRAR Archivierer (x32)
Wireless Console 3 (x32 Version: 3.0.19)
World of Goo (x32)
Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (x32 Version: 15.4.5722.2)
פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (x32 Version: 15.4.5722.2)
適用遠端連線的 Windows Live Mesh ActiveX 控制項 (x32 Version: 15.4.5722.2)
==================== Restore Points =========================
22-08-2013 19:55:35 Installiert Samsung Story Album Viewer
29-08-2013 23:05:15 Geplanter Prüfpunkt
31-08-2013 13:18:59 Free Pdf Perfect Prereq
31-08-2013 20:37:35 Free Pdf Perfect Prereq
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => start w32time task_started
Task: {26B5803A-56C6-4682-B4EF-B2293FA11216} - System32\Tasks\YourFile DownloaderUpdate => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe No File
Task: {31E3737D-85DB-4E1E-8D13-0173A1D6E75E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {386FAD27-212C-4FD1-9C54-3CA881555077} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => start osppsvc
Task: {5F62521A-DC2B-4494-89A5-CD06084CC344} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-02] (ASUS)
Task: {6454799E-A467-4F70-881E-4C5B66B78103} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-12] (Google Inc.)
Task: {811BC62A-E1CB-4AA3-8739-2711665D5076} - System32\Tasks\AIRecoveryRemind => C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe [2010-12-18] (ASUSTek Computer Inc.)
Task: {941FE5C0-D809-4DBE-9FD2-20E830975FB0} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] ()
Task: {BDA2AFE9-00E9-42A0-833C-4FBB44086965} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1679623340-2199165571-2730880989-1002 => C:\Windows\System32\portabledeviceapi.dll [2010-11-20] (Microsoft Corporation)
Task: {C12012C5-397F-4104-98C2-396321DCF603} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-12] (Google Inc.)
Task: {CDF94A65-BFBC-44A1-8D90-E81DA44D066D} - System32\Tasks\User_Feed_Synchronization-{18CED222-E37C-4B2C-B74F-2699F2AB84EB} => C:\Windows\system32\msfeedssync.exe [2013-04-30] (Microsoft Corporation)
Task: {D1D10E3E-6A64-4CBE-B46F-577371A6CA1E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-31] (Adobe Systems Incorporated)
Task: {DF4D4999-1398-43C5-A3D0-DDD6F8950614} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2010-08-02] (ASUS)
Task: {E251D727-1E78-462B-A4AF-872082821139} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation)
Task: {E4D34A1C-A74E-46C5-93BE-CEB6E7A7FC33} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS)
Task: {E6E17FA8-718A-489F-AEC9-B42E221A5F10} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2011-05-27 14:27 - 2011-02-08 04:55 - 00226920 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2009-07-14 02:22 - 2009-07-14 03:38 - 00081408 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\System32\l3codeca.acm
2009-07-14 01:19 - 2009-07-14 03:41 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\ktmw32.dll
2009-07-14 01:46 - 2009-07-14 03:41 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\tschannel.dll
2011-04-20 10:18 - 2011-01-27 02:47 - 07386112 _____ (Intel Corporation) C:\Windows\system32\igd10umd64.dll
2009-11-26 07:49 - 2009-11-26 07:49 - 00070656 _____ (eCareme Technologies, Inc.) C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll
2013-05-25 02:36 - 2013-05-25 02:36 - 00164016 _____ (Dropbox, Inc.) C:\Users\Beyond The Empty Sky\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
2011-04-20 10:18 - 2011-01-27 02:25 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrDEU.lrc
2013-07-11 22:48 - 2013-04-24 00:56 - 09991832 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
2013-07-12 22:34 - 2013-07-12 22:34 - 15577088 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\88744044294787b99dd4a8704ab75a79\mscorlib.ni.dll
2009-07-13 22:37 - 2009-06-10 22:39 - 00085312 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsec.dll
2010-03-16 03:48 - 2010-03-16 03:48 - 04273488 _____ (Ecareme) C:\Program Files (x86)\ASUS\ASUS WebStorage\XPClient.dll
2009-03-02 04:07 - 2009-03-02 04:07 - 00200704 _____ ( ) C:\Program Files (x86)\ASUS\ASUS WebStorage\LogicNP.EZShellExtensions.dll
2013-01-09 18:18 - 2012-10-05 12:52 - 01574496 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
2013-08-16 00:59 - 2013-08-16 00:59 - 10655744 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System\af0a0b96a02f9925eb84392ee65a5cfa\System.ni.dll
2013-08-16 11:40 - 2013-08-16 11:40 - 02131968 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\d15d14098d2ac24115f6b7dbd377eea3\Microsoft.VisualBasic.ni.dll
2010-03-16 03:48 - 2010-03-16 03:48 - 00148816 _____ () C:\Program Files (x86)\ASUS\ASUS WebStorage\EcaremeDLL.dll
2011-01-12 18:01 - 2011-01-12 18:01 - 00030032 _____ () C:\Windows\assembly\GAC_MSIL\SqliteShared\1.0.3726.20828__0d0f4b69e50e559b\SqliteShared.dll
2013-08-16 01:00 - 2013-08-16 01:00 - 02320384 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\868d117286ad259249f31d3fe813d39a\System.Drawing.ni.dll
2013-08-16 01:01 - 2013-08-16 01:01 - 17383424 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\95674cb72317e3a5380ea450b913786f\System.Windows.Forms.ni.dll
2013-08-16 00:59 - 2013-08-16 00:59 - 06964736 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\3975acf49313ceea1280da91f0383480\System.Xml.ni.dll
2011-01-12 18:01 - 2011-01-12 18:01 - 00931840 _____ () C:\Windows\assembly\GAC_64\System.Data.SQLite\1.0.60.0__db937bc2d44ff139\System.Data.SQLite.dll
2013-08-16 01:02 - 2013-08-16 01:02 - 08682496 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\5e957216f11830cbc49b4b30314e0e10\System.Data.ni.dll
2012-02-25 21:50 - 2010-11-05 03:56 - 03095552 _____ (Microsoft Corporation) C:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
2013-08-16 01:02 - 2013-08-16 01:02 - 00921600 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\aedc9c10f3875976af459b0209a8d09f\System.Transactions.ni.dll
2009-07-13 22:37 - 2009-06-10 22:40 - 00283136 _____ (Microsoft Corporation) C:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
2013-08-16 00:59 - 2013-08-16 00:59 - 01320448 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\1031b311ee568364d4ca1c4db634eaf0\System.Configuration.ni.dll
2013-08-16 01:02 - 2013-08-16 01:02 - 01081344 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\1163a3233beb99d037b873460fb0cea8\System.EnterpriseServices.ni.dll
2011-05-27 14:27 - 2011-02-08 04:55 - 02204776 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2011-01-29 02:34 - 2011-01-29 02:34 - 00053864 _____ (NVIDIA Corporation) C:\Windows\system32\Nv3DAppShExtR.dll
2009-07-14 01:41 - 2009-07-14 03:41 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2013-07-30 01:36 - 2013-07-18 08:01 - 00231480 _____ (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll
2009-10-26 05:38 - 2009-10-26 05:38 - 00221184 _____ ( ) C:\Program Files (x86)\ASUS\ASUS WebStorage\LogicNP.EZNamespaceExtensions.dll
2006-03-30 07:24 - 2006-03-30 07:24 - 00270336 _____ (The Apache Software Foundation) C:\Program Files (x86)\ASUS\ASUS WebStorage\log4net.dll
2012-02-25 21:48 - 2010-11-20 15:27 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll
2011-08-31 00:05 - 2011-08-31 00:05 - 00132968 _____ (Apple Inc.) C:\Program Files\Bonjour\mdnsNSP.dll
2009-07-14 02:31 - 2009-07-14 03:41 - 02137600 _____ (Microsoft Corporation) C:\Windows\System32\NLSData0007.dll
2012-02-25 21:49 - 2010-11-20 15:26 - 00116224 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\fms.dll
2012-02-21 22:08 - 2011-02-10 16:03 - 00144616 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\tmdshell.dll
2013-07-30 01:36 - 2013-07-18 08:02 - 02288184 _____ (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\shlext64.dll
2012-12-22 16:48 - 2012-12-22 16:48 - 00331776 _____ (Florian Heidenreich) C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll
2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll
2010-09-20 20:07 - 2010-09-20 20:07 - 00044160 _____ (ASUS) C:\Program Files\P4G\OvrClk.dll
2009-07-03 02:36 - 2009-07-03 02:36 - 00126520 _____ (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\AGFNEX64.dll
2005-06-03 10:39 - 2006-09-12 01:46 - 00035840 _____ (ASUSTek) C:\Program Files (x86)\ASUS\Splendid\OVS.dll
2010-04-03 04:21 - 2008-10-01 08:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2005-04-08 06:38 - 2006-10-10 04:15 - 00011264 _____ (ASUSTeK) C:\Program Files (x86)\ASUS\Splendid\Chameleon.dll
2013-08-16 11:40 - 2013-08-16 11:40 - 01472000 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\7e1a0f53a8580321c5902b6867c3f7da\System.Management.ni.dll
2012-02-25 21:49 - 2010-11-05 03:57 - 00042328 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\wminet_utils.dll
2006-03-30 07:24 - 2006-03-30 07:24 - 00270336 _____ (The Apache Software Foundation) C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\log4net.dll
2009-10-29 05:02 - 2009-10-29 05:02 - 00004096 _____ ( ) C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\Interop.SIMPLEAESLib.dll
2009-11-06 20:18 - 2009-11-06 20:18 - 00004096 _____ ( ) C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\Interop.SimpleAES64Lib.dll
2009-11-25 12:46 - 2009-11-25 12:46 - 00056832 _____ (eCareme Technologies, Inc.) C:\Program Files (x86)\ASUS\ASUS WebStorage\service\SimpleAES64.dll
2012-04-12 21:54 - 2010-11-13 02:08 - 00315392 _____ (Microsoft Corporation) C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
2012-04-12 21:54 - 2010-11-13 02:08 - 00434176 _____ (Microsoft Corporation) C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll
2011-04-20 10:18 - 2011-01-27 02:23 - 00109056 _____ (Intel Corporation) C:\Windows\System32\hccutils.DLL
2011-04-20 10:18 - 2011-01-27 02:24 - 00062464 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll
2011-04-20 10:18 - 2011-01-27 02:22 - 09014784 _____ (Intel Corporation) C:\Windows\System32\igfxress.dll
2011-04-20 10:18 - 2011-01-27 02:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-05-27 14:29 - 2010-11-03 12:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2011-05-27 14:29 - 2011-03-03 11:48 - 02839656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll
2009-07-14 02:18 - 2009-07-14 03:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\audioeng.dll
2011-05-27 14:29 - 2010-07-22 10:48 - 00081232 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\system32\SFCom64.dll
2011-04-20 10:20 - 2010-12-13 15:12 - 00351016 _____ (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDFavorite.dll
2011-04-20 10:20 - 2010-12-13 15:12 - 00335144 _____ (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDApix.dll
2011-04-20 10:20 - 2010-12-13 15:12 - 00369960 _____ (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCmds.dll
2013-08-15 03:09 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2009-07-14 02:00 - 2009-07-14 03:41 - 00283648 _____ (Microsoft Corporation) C:\Windows\System32\LocationApi.dll
2009-07-14 02:00 - 2009-07-14 03:41 - 00174592 _____ (Microsoft Corporation) C:\Windows\System32\SensorsApi.dll
2009-07-14 01:28 - 2009-07-14 03:41 - 00271360 _____ (Microsoft Corporation) C:\Windows\System32\WDSCORE.dll
2013-02-28 09:50 - 2013-01-13 21:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\D3D10Warp.dll
2013-04-30 03:06 - 2013-04-30 03:06 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2009-07-14 01:56 - 2009-07-14 03:41 - 00163328 _____ (Microsoft Corporation) C:\Program Files\Windows Sidebar\wlsrvc.dll
2013-04-30 03:06 - 2013-04-30 03:06 - 00281600 _____ (Microsoft Corporation) C:\Windows\System32\Dxtrans.dll
2009-07-14 01:41 - 2009-07-14 03:40 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\ddrawex.dll
2013-04-30 03:06 - 2013-04-30 03:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\System32\Dxtmsft.dll
2011-01-12 18:05 - 2011-02-16 16:34 - 00060896 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilDebugLog.dll
2011-01-12 18:05 - 2010-09-17 10:52 - 00047104 _____ () C:\Program Files\Trend Micro\AMSP\boost_thread-vc80-mt-1_36.dll
2011-01-12 18:05 - 2010-09-17 10:52 - 00042496 _____ () C:\Program Files\Trend Micro\AMSP\boost_date_time-vc80-mt-1_36.dll
2011-01-12 18:05 - 2010-09-17 10:52 - 00091104 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilMsgBuffer.dll
2011-01-12 18:05 - 2011-07-28 16:16 - 00144832 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilJsonHandle.dll
2011-01-12 18:05 - 2010-09-17 10:52 - 00376408 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\outer_AMSP_ClientLibrary.dll
2011-01-12 18:05 - 2010-09-17 10:52 - 00107584 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilIPC.dll
2011-01-12 18:05 - 2010-09-17 10:52 - 00024672 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilThread.dll
2011-01-12 18:05 - 2010-09-17 10:52 - 00137448 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilRPC.dll
2011-01-12 18:05 - 2010-09-17 10:52 - 00032912 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilAccessControl.dll
2011-01-12 18:05 - 2011-02-16 16:34 - 00531088 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilInstallation.dll
2011-01-12 18:05 - 2010-09-17 10:52 - 00095224 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilComponentInfo.dll
2011-01-12 18:05 - 2010-09-17 10:52 - 00030864 _____ (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\utilGenericLoader.dll
2012-02-24 04:05 - 2012-02-24 04:05 - 00054272 _____ (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_bc20f59b0bdd1acd\MFC80DEU.DLL
2010-11-30 00:00 - 2010-11-30 00:00 - 00018944 _____ (Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandCommon.dll
2013-08-16 10:42 - 2013-08-16 10:42 - 01022976 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\5d7208467b0ffffee644a83f4e76fa12\System.Runtime.Remoting.ni.dll
2013-08-16 01:00 - 2013-08-16 01:00 - 04962816 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\ae3db946d20bb0ad28cf588eef06ecf0\WindowsBase.ni.dll
2013-08-16 01:00 - 2013-08-16 01:00 - 16542720 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\455f1bf19319ef1c59b3e0c1e45c1c9c\PresentationCore.ni.dll
2013-08-16 01:02 - 2013-08-16 01:02 - 19197952 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\90ad207864957bd667f551bdd1c39ada\PresentationFramework.ni.dll
2013-07-11 22:48 - 2013-04-20 00:54 - 02256032 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\wpfgfx_v0300.dll
2010-11-30 00:04 - 2010-11-30 00:04 - 00403968 _____ () C:\Program Files\Intel\TurboBoost\de\SignalIslandUi.resources.dll
2008-05-08 22:37 - 2008-05-08 22:37 - 00070720 _____ (Microsoft Corporation) C:\Program Files\Intel\TurboBoost\Microsoft.Practices.Unity.dll
2008-05-08 22:37 - 2008-05-08 22:37 - 00070720 _____ (Microsoft Corporation) C:\Program Files\Intel\TurboBoost\Microsoft.Practices.ObjectBuilder2.dll
2009-09-23 19:51 - 2009-09-23 19:51 - 00012288 _____ ( ) C:\Program Files\Intel\TurboBoost\DHLogInterfaces.Interop.dll
2013-08-16 11:40 - 2013-08-16 11:40 - 03315712 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\296ad113496c7e97a1689ffef9550b19\System.Core.ni.dll
2012-02-25 21:48 - 2010-11-05 03:56 - 00797016 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\diasymreader.dll
2011-04-20 10:18 - 2011-01-27 02:57 - 07470080 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll
2013-07-12 22:38 - 2013-07-12 22:38 - 00463360 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\56d7206478a1eb28089a8efbdf921bf2\PresentationFramework.Aero.ni.dll
2012-12-31 07:24 - 2012-12-31 07:24 - 00546976 _____ (Microsoft) C:\Windows\assembly\GAC_MSIL\Microsoft.WindowsAPICodePack.Shell\1.1.0.0__31bf3856ad364e35\Microsoft.WindowsAPICodePack.Shell.dll
2012-12-31 07:24 - 2012-12-31 07:24 - 00110240 _____ (Microsoft) C:\Windows\assembly\GAC_MSIL\Microsoft.WindowsAPICodePack\1.1.0.0__31bf3856ad364e35\Microsoft.WindowsAPICodePack.dll
2009-08-04 11:50 - 2009-08-04 11:50 - 00110592 _____ (Microsoft Corporation) C:\Windows\assembly\GAC_MSIL\PresentationCore.resources\3.0.0.0_de_31bf3856ad364e35\PresentationCore.resources.dll
2009-07-14 03:01 - 2009-06-10 22:31 - 01165664 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2009-07-14 01:39 - 2009-07-14 03:41 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\msctfui.dll
==================== Alternate Data Streams (whitelisted) ==========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/02/2013 01:34:47 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 76827591
Error: (09/02/2013 01:34:47 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 76827591
Error: (09/02/2013 01:34:47 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/02/2013 01:34:46 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 76826577
Error: (09/02/2013 01:34:46 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 76826577
Error: (09/02/2013 01:34:46 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/01/2013 04:14:33 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 13151
Error: (09/01/2013 04:14:33 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 13151
Error: (09/01/2013 04:14:33 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/01/2013 04:14:32 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 12152
System errors:
=============
Error: (08/31/2013 10:49:06 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTLOKALER DIENSTS-1-5-19LocalHost (unter Verwendung von LRPC)
Error: (08/31/2013 10:46:11 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (08/31/2013 10:44:56 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "ATKGFNEX Service" ist von folgendem Dienst abhängig: ASMMAP64. Dieser Dienst ist eventuell nicht installiert.
Error: (08/31/2013 10:36:46 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Update diamondata" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (08/31/2013 03:18:25 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SProtection" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (08/29/2013 10:03:54 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Netman erreicht.
Error: (08/28/2013 11:18:52 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
Error: (08/28/2013 11:18:52 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
Error: (08/28/2013 11:18:52 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
Error: (08/28/2013 11:18:52 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
Microsoft Office Sessions:
=========================
Error: (09/02/2013 01:34:47 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 76827591
Error: (09/02/2013 01:34:47 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 76827591
Error: (09/02/2013 01:34:47 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/02/2013 01:34:46 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 76826577
Error: (09/02/2013 01:34:46 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 76826577
Error: (09/02/2013 01:34:46 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/01/2013 04:14:33 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 13151
Error: (09/01/2013 04:14:33 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 13151
Error: (09/01/2013 04:14:33 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/01/2013 04:14:32 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 12152
CodeIntegrity Errors:
===================================
Date: 2013-08-22 21:52:42.854
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-08-22 21:52:42.701
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-08-22 21:52:40.098
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-08-22 21:52:39.916
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-08-22 21:52:37.704
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-08-22 21:52:37.550
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-08-22 21:52:35.256
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sy_" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-08-22 21:52:35.121
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sy_" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-08-22 21:52:32.961
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-08-22 21:52:32.841
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 67%
Total physical RAM: 6056.16 MB
Available physical RAM: 1990.94 MB
Total Pagefile: 12110.5 MB
Available Pagefile: 7654.22 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:75.54 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:254.45 GB) (Free:254.36 GB) NTFS
Drive e: (INTERVIEW_WITH_THE_VAMPIRE) (CDROM) (Total:7 GB) (Free:0 GB) UDF
Drive g: () (Removable) (Total:3.83 GB) (Free:1.05 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 343771F7)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=186 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=254 GB) - (Type=OF Extended)
========================================================
Disk: 1 (Size: 4 GB) (Disk ID: 00000000)
Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)
==================== End Of Log ============================ |