FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013
Ran by kamilla (administrator) on 15-06-2013 21:42:45
Running from C:\Users\kamilla\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CSIS Security Group) C:\Program Files (x86)\Heimdal\Client\HeimdalAgent.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\WISO\Steuersoftware 2013\mshaktuell.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(CSIS Security Group) C:\Program Files (x86)\Heimdal\Service\HeimdalAgentService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft) C:\Program Files (x86)\Heimdal\HeimdalSecureDNS\DnsService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [8123936 2009-09-29] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-27] (Microsoft Corporation)
HKCU\...\Winlogon: [Shell] explorer.exe <==== ATTENTION
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-11-28] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152544 2012-12-12] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Heimdal.lnk
ShortcutTarget: Heimdal.lnk -> C:\Program Files (x86)\Heimdal\Client\HeimdalAgent.exe (CSIS Security Group)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
ShortcutTarget: Logitech Desktop Messenger.lnk -> C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
ShortcutTarget: WISO Mein Steuer-Sparbuch heute.lnk -> C:\Program Files (x86)\WISO\Steuersoftware 2013\mshaktuell.exe ()
Startup: C:\Users\kamilla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={1B3EA98D-6F9F-4FB3-A230-E08778D04FBA}
HKCU SearchScopes: DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=113749&tt=010712_3&babsrc=SP_ss&mntrId=9e9962350000000000000624d2f0bf57
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=113749&tt=010712_3&babsrc=SP_ss&mntrId=9e9962350000000000000624d2f0bf57
SearchScopes: HKCU - {7D78640F-4BE7-43C9-BC30-8EA395E8DEB5} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7SKPT_de
SearchScopes: HKCU - {88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6} URL = hxxp://www.search-results.com/web?q={searchTerms}&o=15868&l=dis&prt=BDIE&chn=retail&geo=DE&ver=4.0.0.0
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{BB51DB52-65BF-4D10-91F3-E3EBA90F718B}: [NameServer]127.0.0.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\kamilla\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\kamilla\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\kamilla\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Gmail) - C:\Users\kamilla\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 HeimdalSecureDNS; C:\Program Files (x86)\Heimdal\HeimdalSecureDNS\DnsService.exe [94368 2013-06-04] (Microsoft)
R2 HeimdalService; C:\Program Files (x86)\Heimdal\Service\HeimdalAgentService.exe [134304 2013-06-04] (CSIS Security Group)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)
S2 SkypeUpdate; C:\Program Files (x86)\Program Files\Skype\Updater\Updater.exe [161384 2013-02-28] (Skype Technologies)
==================== Drivers (Whitelisted) ====================
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-06-15] (Duplex Secure Ltd.)
S1 fhxghaft; \??\C:\Windows\system32\drivers\fhxghaft.sys [x]
S1 fojjzjiq; \??\C:\Windows\system32\drivers\fojjzjiq.sys [x]
S1 nnxayzrc; \??\C:\Windows\system32\drivers\nnxayzrc.sys [x]
S0 TfFsMon; system32\drivers\TfFsMon.sys [x]
S3 TfNetMon; \??\C:\Windows\system32\drivers\TfNetMon.sys [x]
S0 TFSysMon; system32\drivers\TfSysMon.sys [x]
U3 pwliafod; \??\C:\Users\kamilla\AppData\Local\Temp\pwliafod.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-15 21:42 - 2013-06-15 21:42 - 00000000 ____D C:\FRST
2013-06-15 21:41 - 2013-06-15 21:41 - 01920546 ____A (Farbar) C:\Users\kamilla\Desktop\FRST64.exe
2013-06-15 21:06 - 2013-06-15 21:22 - 00000000 ____D C:\troja
2013-06-15 21:04 - 2013-06-15 21:04 - 00377856 ____A C:\Users\kamilla\Desktop\gmer_2.1.19163.exe
2013-06-15 20:59 - 2013-06-15 20:59 - 00068414 ____A C:\Users\kamilla\Desktop\Extras.Txt
2013-06-15 20:57 - 2013-06-15 20:57 - 00092376 ____A C:\Users\kamilla\Desktop\OTL.Txt
2013-06-15 20:48 - 2013-06-15 20:48 - 00602112 ____A (OldTimer Tools) C:\Users\kamilla\Desktop\OTL.exe
2013-06-15 20:41 - 2013-06-15 20:41 - 00000586 ____A C:\Users\kamilla\Desktop\defogger_disable.log
2013-06-15 20:41 - 2013-06-15 20:41 - 00000020 ____A C:\Users\kamilla\defogger_reenable
2013-06-15 20:40 - 2013-06-15 20:40 - 00050477 ____A C:\Users\kamilla\Desktop\Defogger.exe
2013-06-15 18:35 - 2013-06-15 18:52 - 127231689 ____A (Igor Pavlov) C:\Users\kamilla\Desktop\OTLPENet.exe
2013-06-15 18:02 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-15 18:02 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-15 18:02 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-15 18:02 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-15 18:02 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-15 18:02 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-15 18:02 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-15 18:02 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-15 18:02 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-15 18:02 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-15 18:02 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-15 18:02 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-15 18:02 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-15 18:02 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-15 18:02 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-15 18:01 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-15 18:01 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-15 18:01 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-15 18:01 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-15 18:01 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-15 18:01 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-15 18:01 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-15 18:01 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-15 18:01 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-15 18:01 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-15 18:01 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-15 18:01 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-15 18:01 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-15 18:01 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-15 18:01 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-15 18:01 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-15 17:58 - 2013-06-15 17:58 - 00834544 ____A (Duplex Secure Ltd.) C:\Windows\System32\Drivers\sptd.sys
2013-06-15 17:57 - 2013-06-15 17:57 - 00000000 ____D C:\Program Files (x86)\LSoft Technologies
2013-06-15 10:08 - 2013-06-15 10:08 - 00000000 ____D C:\Users\kamilla\AppData\Local\{A051121E-1164-44EA-9E8E-2CE88D63D09D}
2013-06-13 17:23 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-13 17:18 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-13 17:18 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-13 17:18 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-13 17:18 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-13 17:17 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-13 17:17 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-13 17:17 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-13 17:17 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-13 17:17 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-13 17:17 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-13 17:17 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-13 17:17 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-13 17:17 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-13 17:17 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-13 17:17 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-13 17:17 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-13 17:16 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-13 17:16 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-13 17:03 - 2013-06-13 17:03 - 00000000 ____D C:\Users\kamilla\AppData\Local\{F0444DB9-8C06-4618-A6B8-786E06D89243}
2013-06-11 22:39 - 2013-06-11 22:39 - 00000000 ____D C:\Users\kamilla\AppData\Local\{166BC79A-D81A-4838-9C30-32B71C2FAA26}
2013-06-10 22:58 - 2013-06-10 22:59 - 00000000 ____D C:\Users\kamilla\AppData\Local\{693C0949-0890-4D5F-9D83-7E54E61C9EAA}
2013-06-08 14:38 - 2013-06-08 14:38 - 00000000 ____D C:\Users\kamilla\AppData\Local\{7ACB839C-A848-49A8-87D9-AEEE60129492}
2013-06-07 21:44 - 2013-06-07 21:44 - 00000000 ____D C:\Users\kamilla\AppData\Local\{DAE4DC4F-2CC7-41F4-9CAA-B079EB8EB09B}
2013-06-06 19:55 - 2013-06-06 19:55 - 00000000 ____D C:\Users\kamilla\AppData\Local\{15357813-265A-4A7B-8BBE-6FE9DC19C788}
2013-06-05 16:40 - 2013-06-05 16:40 - 00000000 ____D C:\Users\kamilla\AppData\Local\{AC174280-3D7C-4AF7-97BD-5AA2FE1C7465}
2013-06-04 19:40 - 2013-06-04 19:40 - 00000000 ____D C:\Users\kamilla\AppData\Local\{BA0BA70A-C2A8-45B3-8C19-1C0AF102EC79}
2013-06-03 15:50 - 2013-06-03 15:50 - 00000000 ____D C:\Users\kamilla\AppData\Local\{F1265978-D5D1-4E98-8D36-219AD5EDA750}
2013-06-02 19:38 - 2013-06-02 19:38 - 00000000 ____D C:\Users\kamilla\AppData\Local\{2ECD3ABE-3F43-4C7E-BAB7-F105A31D3FE5}
2013-05-28 19:02 - 2013-05-28 19:03 - 00000000 ____D C:\Users\kamilla\AppData\Local\{129B7F22-C58F-4443-A3BD-F03EE1875AFD}
2013-05-26 16:49 - 2013-05-26 16:49 - 00000000 ____D C:\Users\kamilla\AppData\Local\{B835DCF9-70B7-4E68-9D32-D5810C2098EB}
2013-05-22 16:11 - 2013-05-22 16:11 - 00000000 ____D C:\Users\kamilla\AppData\Local\{B4380F9D-D2C2-496B-BAC7-979B9FFB2275}
2013-05-21 22:47 - 2013-05-21 22:48 - 00000000 ____D C:\Users\kamilla\AppData\Local\{84049EC0-D6D1-46C5-BA5E-8376274219DB}
2013-05-20 19:41 - 2013-05-20 19:41 - 00000000 ____D C:\Users\kamilla\AppData\Local\{9B23C5C4-4FD2-4746-8F68-CD141BFDA594}
2013-05-17 23:35 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-17 23:35 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-17 23:35 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-17 23:35 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-17 23:35 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-17 23:35 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-17 23:35 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-17 23:35 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-05-17 23:12 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-17 23:12 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-05-17 23:12 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
2013-05-17 23:11 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-17 23:11 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-05-17 23:11 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-05-17 23:08 - 2013-05-17 23:07 - 00477616 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2013-05-17 23:08 - 2013-05-17 23:07 - 00162224 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2013-05-17 23:08 - 2013-05-17 23:07 - 00149936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2013-05-17 23:08 - 2013-05-17 23:07 - 00149936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2013-05-17 23:07 - 2013-05-17 23:07 - 00000000 ____D C:\Program Files (x86)\Java
2013-05-17 23:03 - 2013-06-04 19:25 - 00000000 ____D C:\Program Files (x86)\Heimdal
2013-05-17 23:03 - 2013-05-17 23:03 - 00000000 ____D C:\ProgramData\CSIS
2013-05-17 22:19 - 2013-05-17 22:19 - 00000488 ____A C:\Windows\System32\.crusader
2013-05-17 21:03 - 2013-05-17 21:03 - 00000000 ____D C:\Windows\pss
2013-05-17 19:51 - 2013-05-17 22:23 - 00000000 ____D C:\ProgramData\HitmanPro
2013-05-16 17:19 - 2013-05-17 21:17 - 00000004 ____A C:\Users\kamilla\AppData\Roaming\skype.ini
==================== One Month Modified Files and Folders =======
2013-06-15 21:42 - 2013-06-15 21:42 - 00000000 ____D C:\FRST
2013-06-15 21:41 - 2013-06-15 21:41 - 01920546 ____A (Farbar) C:\Users\kamilla\Desktop\FRST64.exe
2013-06-15 21:34 - 2012-12-03 15:24 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-15 21:31 - 2011-07-23 09:59 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-15 21:22 - 2013-06-15 21:06 - 00000000 ____D C:\troja
2013-06-15 21:04 - 2013-06-15 21:04 - 00377856 ____A C:\Users\kamilla\Desktop\gmer_2.1.19163.exe
2013-06-15 20:59 - 2013-06-15 20:59 - 00068414 ____A C:\Users\kamilla\Desktop\Extras.Txt
2013-06-15 20:57 - 2013-06-15 20:57 - 00092376 ____A C:\Users\kamilla\Desktop\OTL.Txt
2013-06-15 20:51 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-15 20:51 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-15 20:48 - 2013-06-15 20:48 - 00602112 ____A (OldTimer Tools) C:\Users\kamilla\Desktop\OTL.exe
2013-06-15 20:47 - 2011-07-03 20:49 - 01579949 ____A C:\Windows\WindowsUpdate.log
2013-06-15 20:43 - 2011-07-23 09:59 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-15 20:43 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-15 20:43 - 2009-07-14 06:51 - 00059662 ____A C:\Windows\setupact.log
2013-06-15 20:41 - 2013-06-15 20:41 - 00000586 ____A C:\Users\kamilla\Desktop\defogger_disable.log
2013-06-15 20:41 - 2013-06-15 20:41 - 00000020 ____A C:\Users\kamilla\defogger_reenable
2013-06-15 20:41 - 2011-07-03 21:04 - 00000000 ____D C:\users\kamilla
2013-06-15 20:40 - 2013-06-15 20:40 - 00050477 ____A C:\Users\kamilla\Desktop\Defogger.exe
2013-06-15 20:25 - 2012-09-23 10:38 - 00000474 ____A C:\Users\kamilla\Desktop\tt-info Home.website
2013-06-15 19:17 - 2012-08-10 19:12 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4188504125-4069441578-2337564504-1000UA.job
2013-06-15 19:17 - 2012-08-10 19:12 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4188504125-4069441578-2337564504-1000Core.job
2013-06-15 18:52 - 2013-06-15 18:35 - 127231689 ____A (Igor Pavlov) C:\Users\kamilla\Desktop\OTLPENet.exe
2013-06-15 18:39 - 2009-10-24 17:51 - 00654166 ____A C:\Windows\System32\perfh007.dat
2013-06-15 18:39 - 2009-10-24 17:51 - 00130006 ____A C:\Windows\System32\perfc007.dat
2013-06-15 18:39 - 2009-07-14 07:13 - 01498506 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-15 18:03 - 2011-07-24 11:13 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-15 17:58 - 2013-06-15 17:58 - 00834544 ____A (Duplex Secure Ltd.) C:\Windows\System32\Drivers\sptd.sys
2013-06-15 17:57 - 2013-06-15 17:57 - 00000000 ____D C:\Program Files (x86)\LSoft Technologies
2013-06-15 17:57 - 2011-07-23 15:35 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-06-15 10:08 - 2013-06-15 10:08 - 00000000 ____D C:\Users\kamilla\AppData\Local\{A051121E-1164-44EA-9E8E-2CE88D63D09D}
2013-06-13 17:03 - 2013-06-13 17:03 - 00000000 ____D C:\Users\kamilla\AppData\Local\{F0444DB9-8C06-4618-A6B8-786E06D89243}
2013-06-11 22:40 - 2012-04-12 02:54 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-11 22:40 - 2011-07-23 15:11 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-11 22:39 - 2013-06-11 22:39 - 00000000 ____D C:\Users\kamilla\AppData\Local\{166BC79A-D81A-4838-9C30-32B71C2FAA26}
2013-06-10 22:59 - 2013-06-10 22:58 - 00000000 ____D C:\Users\kamilla\AppData\Local\{693C0949-0890-4D5F-9D83-7E54E61C9EAA}
2013-06-10 22:58 - 2012-09-13 21:46 - 00000000 ____D C:\Users\kamilla\Documents\Schule
2013-06-09 18:10 - 2012-09-15 14:21 - 00000000 ____D C:\SCHULE
2013-06-09 15:08 - 2012-10-26 22:02 - 00000000 ____D C:\Users\kamilla\AppData\Local\Microsoft Help
2013-06-08 16:08 - 2013-06-15 18:01 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-15 18:01 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-15 18:01 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-15 18:01 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-15 18:01 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:38 - 2013-06-08 14:38 - 00000000 ____D C:\Users\kamilla\AppData\Local\{7ACB839C-A848-49A8-87D9-AEEE60129492}
2013-06-08 14:28 - 2013-06-15 18:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-15 18:01 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-15 18:01 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-15 18:01 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-15 18:01 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-15 18:01 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-15 18:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-07 21:44 - 2013-06-07 21:44 - 00000000 ____D C:\Users\kamilla\AppData\Local\{DAE4DC4F-2CC7-41F4-9CAA-B079EB8EB09B}
2013-06-07 08:35 - 2012-09-02 09:49 - 00002185 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-06 19:55 - 2013-06-06 19:55 - 00000000 ____D C:\Users\kamilla\AppData\Local\{15357813-265A-4A7B-8BBE-6FE9DC19C788}
2013-06-05 16:40 - 2013-06-05 16:40 - 00000000 ____D C:\Users\kamilla\AppData\Local\{AC174280-3D7C-4AF7-97BD-5AA2FE1C7465}
2013-06-04 19:40 - 2013-06-04 19:40 - 00000000 ____D C:\Users\kamilla\AppData\Local\{BA0BA70A-C2A8-45B3-8C19-1C0AF102EC79}
2013-06-04 19:25 - 2013-05-17 23:03 - 00000000 ____D C:\Program Files (x86)\Heimdal
2013-06-03 20:27 - 2011-07-23 10:54 - 00026070 ____A C:\Windows\PFRO.log
2013-06-03 20:19 - 2011-07-03 21:12 - 00000000 ____D C:\Users\kamilla\AppData\Roaming\Skype
2013-06-03 15:50 - 2013-06-03 15:50 - 00000000 ____D C:\Users\kamilla\AppData\Local\{F1265978-D5D1-4E98-8D36-219AD5EDA750}
2013-06-02 19:38 - 2013-06-02 19:38 - 00000000 ____D C:\Users\kamilla\AppData\Local\{2ECD3ABE-3F43-4C7E-BAB7-F105A31D3FE5}
2013-06-02 09:43 - 2011-07-23 09:07 - 00000000 ____D C:\ProgramData\Skype
2013-05-28 19:03 - 2013-05-28 19:02 - 00000000 ____D C:\Users\kamilla\AppData\Local\{129B7F22-C58F-4443-A3BD-F03EE1875AFD}
2013-05-26 16:49 - 2013-05-26 16:49 - 00000000 ____D C:\Users\kamilla\AppData\Local\{B835DCF9-70B7-4E68-9D32-D5810C2098EB}
2013-05-22 16:11 - 2013-05-22 16:11 - 00000000 ____D C:\Users\kamilla\AppData\Local\{B4380F9D-D2C2-496B-BAC7-979B9FFB2275}
2013-05-21 22:48 - 2013-05-21 22:47 - 00000000 ____D C:\Users\kamilla\AppData\Local\{84049EC0-D6D1-46C5-BA5E-8376274219DB}
2013-05-20 19:41 - 2013-05-20 19:41 - 00000000 ____D C:\Users\kamilla\AppData\Local\{9B23C5C4-4FD2-4746-8F68-CD141BFDA594}
2013-05-18 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-05-18 09:16 - 2009-07-14 06:45 - 00435568 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-18 08:49 - 2012-10-26 22:01 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-05-17 23:07 - 2013-05-17 23:08 - 00477616 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2013-05-17 23:07 - 2013-05-17 23:08 - 00162224 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2013-05-17 23:07 - 2013-05-17 23:08 - 00149936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2013-05-17 23:07 - 2013-05-17 23:08 - 00149936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2013-05-17 23:07 - 2013-05-17 23:07 - 00000000 ____D C:\Program Files (x86)\Java
2013-05-17 23:07 - 2011-07-23 18:39 - 00473520 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2013-05-17 23:03 - 2013-05-17 23:03 - 00000000 ____D C:\ProgramData\CSIS
2013-05-17 22:33 - 2011-07-24 15:23 - 00000000 ____D C:\ProgramData\Adobe
2013-05-17 22:23 - 2013-05-17 19:51 - 00000000 ____D C:\ProgramData\HitmanPro
2013-05-17 22:19 - 2013-05-17 22:19 - 00000488 ____A C:\Windows\System32\.crusader
2013-05-17 21:17 - 2013-05-16 17:19 - 00000004 ____A C:\Users\kamilla\AppData\Roaming\skype.ini
2013-05-17 21:03 - 2013-05-17 21:03 - 00000000 ____D C:\Windows\pss
2013-05-17 03:25 - 2013-06-15 18:02 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-05-17 03:25 - 2013-06-15 18:02 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-05-17 03:25 - 2013-06-15 18:02 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-05-17 03:25 - 2013-06-15 18:02 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-05-17 03:25 - 2013-06-15 18:02 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-05-17 03:25 - 2013-06-15 18:02 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-05-17 03:25 - 2013-06-15 18:01 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-05-17 03:25 - 2013-06-15 18:01 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-05-17 02:59 - 2013-06-15 18:02 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-05-17 02:59 - 2013-06-15 18:01 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-05-17 02:58 - 2013-06-15 18:02 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-05-17 02:58 - 2013-06-15 18:01 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
Files to move or delete:
====================
C:\Users\kamilla\AppData\Roaming\skype.ini
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-06-13 18:00
==================== End Of Log ============================
--- --- ---
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-06-2013
Ran by kamilla at 2013-06-15 21:43:44 Run:
Running from C:\Users\kamilla\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Active@ ISO Burner (Version: 2.5.1)
Adobe Flash Player 11 ActiveX (Version: 11.7.700.224)
Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7)
Apple Application Support (Version: 2.3.2)
Apple Mobile Device Support (Version: 6.0.1.3)
Apple Software Update (Version: 2.1.3.127)
Audiograbber 1.83 SE (Version: 1.83 SE)
Bing Bar (Version: 7.0.619.0)
Bonjour (Version: 3.0.0.10)
D3DX10 (Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
Facebook Video Calling 1.2.0.287 (Version: 1.2.287)
Google Chrome (Version: 27.0.1453.110)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.4.3607.2246)
Google Update Helper (Version: 1.3.21.145)
Heimdal (Version: 1.8.0.500)
Icy Tower v1.5
iLivid (Version: 1.92.0.115185)
iTunes (Version: 11.0.1.12)
Java(TM) 6 Update 45 (Version: 6.0.450)
Junk Mail filter update (Version: 15.4.3502.0922)
Logitech Desktop Messenger (Version: 2.54.11)
Logitech Harmony Remote Software 7 (Version: 7.6.0.8)
Logitech Harmony Remote Software 7 (Version: 7.7.0.0)
Mesh Runtime (Version: 15.4.5722.2)
Messenger Companion (Version: 15.4.3502.0922)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Home and Business 2010 (Version: 14.0.6029.1000)
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Security Client (Version: 4.2.0223.1)
Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0)
Microsoft Security Essentials (Version: 4.2.223.1)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
OpenOffice.org 3.3 (Version: 3.3.9567)
Realtek High Definition Audio Driver (Version: 6.0.1.5948)
Remote Control USB Driver (Version: 2.3.2.317)
Skype Click to Call (Version: 6.3.11079)
Skype™ 6.3 (Version: 6.3.105)
Total Commander (Remove or Repair) (Version: 7.50)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553378) 64-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition
Update for Microsoft Outlook 2010 (KB2597090) 64-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2598240) 64-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition
VideoLAN VLC media player 0.8.6d (Version: 0.8.6d)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live Fotogalerie (Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (Version: 15.4.5722.2)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
WinRAR Archivierer
WISO Steuer-Sparbuch 2012 (Version: 19.00.7303)
WISO Steuer-Sparbuch 2013 (Version: 20.00.8137)
==================== Restore Points =========================
18-02-2013 20:03:35 Windows Update
23-02-2013 13:35:21 Windows Update
02-03-2013 12:56:02 Windows Update
05-03-2013 19:09:55 Windows Update
08-03-2013 19:46:41 Windows Update
12-03-2013 17:58:02 Windows Update
17-03-2013 19:49:39 Windows Update
18-03-2013 16:59:25 Windows Update
24-03-2013 09:42:20 Windows Update
25-03-2013 10:40:12 Windows Modules Installer
27-03-2013 10:12:48 Windows Update
02-04-2013 08:06:57 Windows Update
06-04-2013 08:29:17 Windows Update
09-04-2013 19:42:21 Windows Update
13-04-2013 20:17:26 Windows Update
13-04-2013 21:02:47 Windows Update
18-04-2013 16:14:05 Windows Update
24-04-2013 19:47:24 Windows Update
24-04-2013 19:59:11 Windows Update
29-04-2013 14:52:24 Windows Update
05-05-2013 12:27:18 Windows Update
09-05-2013 20:14:41 Windows Update
12-05-2013 21:25:29 Windows Update
17-05-2013 20:25:27 Windows Update
18-05-2013 06:40:34 Windows Modules Installer
21-05-2013 19:24:02 Windows Update
25-05-2013 08:26:43 Windows Update
28-05-2013 17:14:20 Windows Update
01-06-2013 07:54:56 Windows Update
04-06-2013 17:34:32 Windows Update
09-06-2013 10:07:52 Windows Update
12-06-2013 14:33:44 Windows Update
15-06-2013 15:57:10 Installed Active@ ISO Burner
15-06-2013 15:58:13 SPTD setup V1.62
15-06-2013 15:59:31 Windows Update
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (06/15/2013 04:47:52 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Error: (06/15/2013 04:30:50 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Error: (06/14/2013 00:52:09 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 21616075
Error: (06/14/2013 00:52:09 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 21616075
Error: (06/14/2013 00:52:09 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/12/2013 10:40:58 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 21617308
Error: (06/12/2013 10:40:58 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 21617308
Error: (06/12/2013 10:40:58 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/12/2013 04:42:29 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 21615577
Error: (06/12/2013 04:42:29 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 21615577
System errors:
=============
Error: (06/15/2013 08:44:01 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
TfFsMon
TFSysMon
Error: (06/15/2013 08:44:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows-Bilderfassung (WIA)" ist vom Dienst "Shellhardwareerkennung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058
Error: (06/15/2013 08:43:55 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Heimdal Secure DNS Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (06/15/2013 08:43:55 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Heimdal Secure DNS Service erreicht.
Error: (06/15/2013 08:43:00 PM) (Source: atikmdag) (User: )
Description: Display is not active
Error: (06/15/2013 08:43:00 PM) (Source: atikmdag) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (06/15/2013 06:10:21 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
TfFsMon
TFSysMon
Error: (06/15/2013 06:10:19 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows-Bilderfassung (WIA)" ist vom Dienst "Shellhardwareerkennung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058
Error: (06/15/2013 06:09:21 PM) (Source: atikmdag) (User: )
Description: Display is not active
Error: (06/15/2013 06:09:21 PM) (Source: atikmdag) (User: )
Description: CPLIB :: General - Invalid Parameter
Microsoft Office Sessions:
=========================
Error: (06/15/2013 04:47:52 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestE:\SoftonicDownloader_fuer_malwarebytes-anti-malware.exe
Error: (06/15/2013 04:30:50 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestE:\SoftonicDownloader_fuer_malwarebytes-anti-malware.exe
Error: (06/14/2013 00:52:09 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 21616075
Error: (06/14/2013 00:52:09 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 21616075
Error: (06/14/2013 00:52:09 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/12/2013 10:40:58 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 21617308
Error: (06/12/2013 10:40:58 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 21617308
Error: (06/12/2013 10:40:58 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/12/2013 04:42:29 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 21615577
Error: (06/12/2013 04:42:29 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 21615577
CodeIntegrity Errors:
===================================
Date: 2012-10-30 00:31:18.252
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\bakupmobfest\Windows.old\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-10-30 00:31:18.143
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\bakupmobfest\Windows.old\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-10-30 00:31:18.018
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\bakupmobfest\Windows.old\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-10-30 00:31:17.893
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\bakupmobfest\Windows.old\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-10-29 23:54:10.926
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\bakupmobfest\Windows.old\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-10-29 23:54:10.802
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\bakupmobfest\Windows.old\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-10-29 23:54:10.677
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\bakupmobfest\Windows.old\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-10-29 23:54:10.568
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\bakupmobfest\Windows.old\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-10-29 23:50:32.308
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\bakupmobfest\Windows.old\Windows\System32\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-10-29 23:50:32.183
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\bakupmobfest\Windows.old\Windows\System32\bcrypt.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 44%
Total physical RAM: 4060.61 MB
Available physical RAM: 2255.91 MB
Total Pagefile: 8119.41 MB
Available Pagefile: 6423.19 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:452.76 GB) (Free:151.96 GB) NTFS (Disk=0 Partition=2) ==>[Drive with boot components (obtained from BCD)]
Drive f: () (Removable) (Total:7.41 GB) (Free:2.8 GB) FAT32 (Disk=1 Partition=1)
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 7407B56E)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=453 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 7 GB) (Disk ID: 00000000)
Partition 1: (Not Active) - (Size=7 GB) - (Type=0B)
==================== End Of Log ============================
[/CODE]