Trader99 | 20.07.2013 17:29 | Hi, schonmal jetzt danke für deine Hilfe!
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-07-2013
Ran by Zarelli (administrator) on 20-07-2013 18:19:14
Running from C:\Users\Zarelli\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(Agere Systems) C:\Windows\system32\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(NETGATE Technologies s.r.o.) C:\Program Files\NETGATE\FortKnox Personal Firewall\FortKnox.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
(NETGATE Technologies s.r.o.) C:\Program Files\NETGATE\FortKnox Personal Firewall\FortKnoxGUI.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
==================== Registry (Whitelisted) ==================
...\Run: [LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [52256 2007-01-08] ()
HKLM\...\Run: [FortKnoxPersonalFirewall] - C:\Program Files\NETGATE\FortKnox Personal Firewall\FortKnoxGUI.exe [1776280 2010-06-02] (NETGATE Technologies s.r.o.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdSync.exe [215552 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-01] (Avira Operations GmbH & Co. KG)
HKCU\...\Run: [Power2GoExpress] - NA [x]
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
Startup: C:\Users\Zarelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
BootExecute: autocheck autochk * bootdelete
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.sport1.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKCU - DefaultScope {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=51911376-B593-4F28-BFEB-8C388F273BA7&apn_sauid=F2957BE5-B8A9-4FBE-9979-664290AE20AA&
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=51911376-B593-4F28-BFEB-8C388F273BA7&apn_sauid=F2957BE5-B8A9-4FBE-9979-664290AE20AA&
SearchScopes: HKCU - {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://www.ask.com/web?l=dis&o=APN10020&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^US&apn_ptnrs=^A4G &apn_uid=4370136398234086&p2=^A4G ^YYYYYY^YY^US&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - DVD Video Soft Toolbar - {cd8812d4-e5b8-41c6-94d4-59872a484bf1} - C:\Program Files\dvdvideosofttoolbar\dvdvideosofttoolbarX.dll ()
Toolbar: HKCU -No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Zarelli\AppData\Roaming\Mozilla\Firefox\Profiles\ylb8aagz.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\ask.xml
FF Extension: No Name - C:\Users\Zarelli\AppData\Roaming\Mozilla\Firefox\Profiles\ylb8aagz.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF Extension: DVD Video Soft Toolbar - C:\Users\Zarelli\AppData\Roaming\Mozilla\Firefox\Profiles\ylb8aagz.default\Extensions\{cd8812d4-e5b8-41c6-94d4-59872a484bf1}
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{77BEC163-D389-42c1-91A4-C758846296A5}] C:\Program Files\Video downloader\Firefox
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-01] (Avira Operations GmbH & Co. KG)
R2 fortknox; C:\Program Files\NETGATE\FortKnox Personal Firewall\FortKnox.exe [514640 2010-02-04] (NETGATE Technologies s.r.o.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2006-12-19] ()
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-04-01] (Avira Operations GmbH & Co. KG)
R3 Fkndisf; C:\Windows\System32\DRIVERS\fortknoxfw_ndisim.sys [23120 2009-09-17] (NETGATE Technologies s.r.o.)
R1 fortknox_drv; C:\Windows\System32\drivers\fortknoxfw.sys [57808 2009-11-15] (NETGATE Technologies s.r.o.)
S3 hitmanpro35; C:\Windows\system32\drivers\hitmanpro36.sys [26400 2012-04-22] ()
R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2006-11-14] (SAMSUNG ELECTRONICS CO., LTD.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 PRSBDrvr; C:\Windows\System32\DRIVERS\PRSBDrvr.sys [28424 2012-01-17] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-03-24] (Avira GmbH)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
U1 ntq96ne7; \??\C:\Windows\system32\ntq96ne7.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-20 18:18 - 2013-07-20 18:18 - 00000000 ____D C:\FRST
2013-07-20 18:16 - 2013-07-20 18:16 - 01219758 _____ (Farbar) C:\Users\Zarelli\Desktop\FRST.exe
2013-07-19 23:31 - 2013-07-19 23:31 - 00000906 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-19 23:31 - 2013-07-19 23:31 - 00000000 ____D C:\Users\Zarelli\AppData\Roaming\Malwarebytes
2013-07-19 23:31 - 2013-07-19 23:31 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-19 23:31 - 2013-07-19 23:31 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-19 23:31 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-07-11 21:58 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 21:58 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 21:58 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-07-11 21:58 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 21:58 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 21:58 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-07-11 21:58 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 21:58 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-07-11 21:58 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-07-11 21:58 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 21:58 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 21:58 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 21:58 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 21:58 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-07-11 21:58 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 21:57 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 18:18 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 18:18 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 18:18 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 18:18 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-07-11 18:18 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-07-11 18:18 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-07-11 18:18 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-07-11 18:18 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-07-11 18:18 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-07-11 18:18 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-07-11 18:18 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-11 18:18 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-07-01 15:37 - 2013-07-01 16:01 - 00000000 ____D C:\Users\Zarelli\Desktop\mukk
2013-07-01 15:30 - 2013-07-01 15:30 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-07-01 15:29 - 2013-07-01 15:29 - 25328416 _____ (DVDVideoSoft Ltd. ) C:\Users\Zarelli\Downloads\FreeYouTubeToMP3Converter.exe
2013-07-01 15:27 - 2013-07-01 15:27 - 00000000 ____D C:\Program Files\BearShare Applications
2013-06-23 11:10 - 2013-06-23 11:10 - 00008284 _____ C:\Windows\system32\eps_icon.avi
2013-06-23 11:10 - 2013-06-23 11:10 - 00000031 _____ C:\Windows\EPSMTL32.TXT
==================== One Month Modified Files and Folders =======
2013-07-20 18:18 - 2013-07-20 18:18 - 00000000 ____D C:\FRST
2013-07-20 18:17 - 2011-12-26 13:24 - 00000000 ___RD C:\Users\Zarelli\Desktop
2013-07-20 18:16 - 2013-07-20 18:16 - 01219758 _____ (Farbar) C:\Users\Zarelli\Desktop\FRST.exe
2013-07-20 17:57 - 2012-05-09 18:28 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-20 17:56 - 2011-12-26 13:47 - 00000000 ____D C:\Users\Zarelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2013-07-20 17:55 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-20 17:55 - 2006-11-02 14:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-20 17:55 - 2006-11-02 14:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-20 07:55 - 2006-11-02 15:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-20 07:55 - 2006-11-02 14:52 - 01973465 _____ C:\Windows\WindowsUpdate.log
2013-07-20 01:08 - 2011-12-26 20:36 - 00149662 _____ C:\Windows\PFRO.log
2013-07-20 00:03 - 2011-12-26 13:24 - 00000000 ____D C:\Users\Zarelli
2013-07-19 23:31 - 2013-07-19 23:31 - 00000906 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-19 23:31 - 2013-07-19 23:31 - 00000000 ____D C:\Users\Zarelli\AppData\Roaming\Malwarebytes
2013-07-19 23:31 - 2013-07-19 23:31 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-19 23:31 - 2013-07-19 23:31 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-19 23:31 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Public\Desktop
2013-07-14 23:05 - 2006-11-02 12:33 - 01445352 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-14 08:50 - 2011-12-27 16:44 - 00000000 ____D C:\Users\Zarelli\AppData\Local\Adobe
2013-07-14 08:49 - 2012-05-09 18:28 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-07-14 08:49 - 2011-12-26 17:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-07-13 21:40 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-12 21:02 - 2006-11-02 14:47 - 00278000 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-12 21:00 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2013-07-11 22:00 - 2006-11-02 12:24 - 75699896 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-07-11 21:49 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-11 21:07 - 2013-05-01 19:21 - 00000000 ____D C:\Users\Zarelli\Downloads\Unfall Mazda
2013-07-07 23:02 - 2011-12-26 11:14 - 00048640 _____ C:\Users\Zarelli\Desktop\todo.xls
2013-07-01 16:01 - 2013-07-01 15:37 - 00000000 ____D C:\Users\Zarelli\Desktop\mukk
2013-07-01 15:49 - 2011-12-27 13:42 - 00000000 ____D C:\Users\Zarelli\Downloads\Musik
2013-07-01 15:30 - 2013-07-01 15:30 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-07-01 15:30 - 2013-05-09 18:37 - 00001032 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2013-07-01 15:30 - 2013-05-09 18:37 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-07-01 15:30 - 2012-02-12 20:41 - 00000000 ____D C:\Users\Zarelli\AppData\Roaming\DVDVideoSoft
2013-07-01 15:29 - 2013-07-01 15:29 - 25328416 _____ (DVDVideoSoft Ltd. ) C:\Users\Zarelli\Downloads\FreeYouTubeToMP3Converter.exe
2013-07-01 15:27 - 2013-07-01 15:27 - 00000000 ____D C:\Program Files\BearShare Applications
2013-06-27 18:20 - 2012-12-16 19:30 - 00000000 ____D C:\Pokal
2013-06-23 11:10 - 2013-06-23 11:10 - 00008284 _____ C:\Windows\system32\eps_icon.avi
2013-06-23 11:10 - 2013-06-23 11:10 - 00000031 _____ C:\Windows\EPSMTL32.TXT
2013-06-23 11:10 - 2011-12-29 21:16 - 00000000 ____D C:\Program Files\EPSON
2013-06-23 11:08 - 2011-12-26 13:41 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-06-23 10:37 - 2012-01-06 19:43 - 00002623 _____ C:\Users\Zarelli\Desktop\Microsoft Word.lnk
Files to move or delete:
====================
C:\ProgramData\1oleej.pad
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-20 18:04
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-07-2013
Ran by Zarelli at 2013-07-20 18:27:26
Running from C:\Users\Zarelli\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Adobe Flash Player 11 ActiveX (Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (Version: 11.7.700.224)
Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7)
Agere Systems HDA Modem
Atheros WLAN Client (Version: 1.00.000)
ATI Catalyst Install Manager (Version: 3.0.641.0)
Avira Free Antivirus (Version: 13.0.0.3737)
Catalyst Control Center Core Implementation (Version: 2007.0621.1715.28924)
Catalyst Control Center Graphics Full Existing (Version: 2007.0621.1715.28924)
Catalyst Control Center Graphics Full New (Version: 2007.0621.1715.28924)
Catalyst Control Center Graphics Light (Version: 2007.0621.1715.28924)
Catalyst Control Center Graphics Previews Vista (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Chinese Standard (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Chinese Traditional (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Czech (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Danish (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Dutch (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Finnish (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization French (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization German (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Greek (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Hungarian (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Italian (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Japanese (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Korean (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Norwegian (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Polish (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Portuguese (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Russian (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Spanish (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Swedish (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Thai (Version: 2007.0621.1715.28924)
Catalyst Control Center Localization Turkish (Version: 2007.0621.1715.28924)
CCC Help Chinese Standard (Version: 2007.0621.1714.28924)
CCC Help Chinese Traditional (Version: 2007.0621.1714.28924)
CCC Help Czech (Version: 2007.0621.1714.28924)
CCC Help Danish (Version: 2007.0621.1714.28924)
CCC Help Dutch (Version: 2007.0621.1714.28924)
CCC Help English (Version: 2007.0621.1714.28924)
CCC Help Finnish (Version: 2007.0621.1714.28924)
CCC Help French (Version: 2007.0621.1714.28924)
CCC Help German (Version: 2007.0621.1714.28924)
CCC Help Greek (Version: 2007.0621.1714.28924)
CCC Help Hungarian (Version: 2007.0621.1714.28924)
CCC Help Italian (Version: 2007.0621.1714.28924)
CCC Help Japanese (Version: 2007.0621.1714.28924)
CCC Help Korean (Version: 2007.0621.1714.28924)
CCC Help Norwegian (Version: 2007.0621.1714.28924)
CCC Help Polish (Version: 2007.0621.1714.28924)
CCC Help Portuguese (Version: 2007.0621.1714.28924)
CCC Help Russian (Version: 2007.0621.1714.28924)
CCC Help Spanish (Version: 2007.0621.1714.28924)
CCC Help Swedish (Version: 2007.0621.1714.28924)
CCC Help Thai (Version: 2007.0621.1714.28924)
CCC Help Turkish (Version: 2007.0621.1714.28924)
ccc-core-static (Version: 2007.0621.1715.28924)
ccc-utility (Version: 2007.0621.1715.28924)
DVD Suite (Version: 5.0.1603)
DVD Video Soft Toolbar (Version: 1.0.0.12)
Easy Display Manager (Version: 2.0.0.0)
ElsterFormular (Version: 14.0.0.10899)
EPSON Copy Utility 3 (Version: 3.1.5.0)
EPSON Scan
EPSON-Drucker-Software
FortKnox Personal Firewall
Free YouTube to MP3 Converter version 3.12.5.628 (Version: 3.12.5.628)
ICQ7.7 (Version: 7.7)
Ipswitch WS_FTP Pro
Java Auto Updater (Version: 2.1.9.0)
Java(TM) 6 Update 22 (Version: 6.0.220)
JavaFX 2.1.1 (Version: 2.1.1)
LabelPrint 2.0
LightScribe 1.4.124.1 (Version: 1.4.124.1)
LM98Free 2.2a
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
MediaShow (Version: 3.0.3927)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Office XP Professional mit FrontPage (Version: 10.0.2701.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mozilla Firefox 21.0 (x86 en-US) (Version: 21.0)
Mozilla Maintenance Service (Version: 21.0)
Mozilla Thunderbird 17.0.5 (x86 de) (Version: 17.0.5)
OpenOffice.org 3.3 (Version: 3.3.9567)
PhotoNow! 1.0 (Version: 3.0.3127)
Power2Go 5.0
PowerDirector
PowerDVD (Version: 7.0.2802.0)
PowerProducer
Realtek High Definition Audio Driver (Version: 6.0.1.5433)
Samsung Recovery Solution II (Version: 2.0)
Skins (Version: 2007.0621.1715.28924)
Synaptics Pointing Device Driver (Version: 9.1.22.0)
Update for Microsoft .NET Framework 3.5 SP1 (KB2836940) (Version: 1)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
VLC media player 1.1.11 (Version: 1.1.11)
VSO Image Resizer 4.0.3.6 (Version: 4.0.3.6)
WinRAR 4.01 (32-Bit) (Version: 4.01.0)
==================== Restore Points =========================
13-07-2013 20:17:36 Geplanter Prüfpunkt
18-07-2013 18:51:51 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {0FA9E7D7-A43F-4173-A927-AFF44C9F6C3C} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\VistaSP1CEIP => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {2A79832B-DFF4-4E32-9F2F-0C42A373161E} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2007-06-01] (SAMSUNG Electronics)
Task: {35ECB8CC-95A5-4D48-A2DA-527CB8672A07} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation)
Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation)
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation)
Task: {CC747871-3F21-4520-A643-99C7A42CA689} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-14] (Adobe Systems Incorporated)
Task: {CD2F536E-028D-4E00-A4B9-8D162374569B} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2011-12-26] (Microsoft Corporation)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/20/2013 01:01:00 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy40,0xc0000000,0x00000003,...)". hr = 0x80070005.
Error: (07/20/2013 01:00:52 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy40,0xc0000000,0x00000003,...)". hr = 0x80070005.
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (07/20/2013 01:00:51 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy40,0xc0000000,0x00000003,...)". hr = 0x80070005.
Error: (07/20/2013 01:00:42 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy40,0xc0000000,0x00000003,...)". hr = 0x80070005.
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (07/20/2013 01:00:37 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy38,0xc0000000,0x00000003,...)". hr = 0x80070005.
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (07/20/2013 01:00:37 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy38,0xc0000000,0x00000003,...)". hr = 0x80070005.
Error: (07/20/2013 01:00:32 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy38,0xc0000000,0x00000003,...)". hr = 0x80070005.
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (07/20/2013 01:00:27 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy36,0xc0000000,0x00000003,...)". hr = 0x80070005.
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (07/20/2013 01:00:27 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy36,0xc0000000,0x00000003,...)". hr = 0x80070005.
Error: (07/20/2013 01:00:20 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy36,0xc0000000,0x00000003,...)". hr = 0x80070005.
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
System errors:
=============
Error: (07/20/2013 06:06:13 PM) (Source: Service Control Manager) (User: )
Description: ComputerbrowserLanmanWorkstation
Error: (07/20/2013 05:56:58 PM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058
Error: (07/20/2013 05:56:58 PM) (Source: Service Control Manager) (User: )
Description: ComputerbrowserLanmanWorkstation
Error: (07/20/2013 07:55:04 AM) (Source: DCOM) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
Error: (07/20/2013 07:43:36 AM) (Source: Service Control Manager) (User: )
Description: ComputerbrowserLanmanWorkstation
Error: (07/20/2013 07:42:41 AM) (Source: Service Control Manager) (User: )
Description: 30000WSearch
Error: (07/20/2013 07:42:41 AM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058
Error: (07/20/2013 07:42:41 AM) (Source: Service Control Manager) (User: )
Description: ComputerbrowserLanmanWorkstation
Error: (07/20/2013 01:54:20 AM) (Source: DCOM) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
Error: (07/20/2013 01:09:51 AM) (Source: Service Control Manager) (User: )
Description: ComputerbrowserLanmanWorkstation
Microsoft Office Sessions:
=========================
Error: (07/20/2013 01:01:00 AM) (Source: VSS)(User: )
Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy40,0xc0000000,0x00000003,...)0x80070005
Error: (07/20/2013 01:00:52 AM) (Source: VSS)(User: )
Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy40,0xc0000000,0x00000003,...)0x80070005
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (07/20/2013 01:00:51 AM) (Source: VSS)(User: )
Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy40,0xc0000000,0x00000003,...)0x80070005
Error: (07/20/2013 01:00:42 AM) (Source: VSS)(User: )
Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy40,0xc0000000,0x00000003,...)0x80070005
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (07/20/2013 01:00:37 AM) (Source: VSS)(User: )
Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy38,0xc0000000,0x00000003,...)0x80070005
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (07/20/2013 01:00:37 AM) (Source: VSS)(User: )
Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy38,0xc0000000,0x00000003,...)0x80070005
Error: (07/20/2013 01:00:32 AM) (Source: VSS)(User: )
Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy38,0xc0000000,0x00000003,...)0x80070005
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (07/20/2013 01:00:27 AM) (Source: VSS)(User: )
Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy36,0xc0000000,0x00000003,...)0x80070005
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
Error: (07/20/2013 01:00:27 AM) (Source: VSS)(User: )
Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy36,0xc0000000,0x00000003,...)0x80070005
Error: (07/20/2013 01:00:20 AM) (Source: VSS)(User: )
Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy36,0xc0000000,0x00000003,...)0x80070005
Vorgang:
EndPrepareSnapshots wird verarbeitet
Kontext:
Ausführungskontext: System Provider
CodeIntegrity Errors:
===================================
Date: 2013-04-20 14:54:32.247
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-04-20 14:54:31.967
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\NETGATE\FortKnox Personal Firewall\protect.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-04-20 14:54:31.691
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-04-20 14:54:31.409
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\NETGATE\FortKnox Personal Firewall\protect.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-09-20 14:23:11.571
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-09-20 14:23:11.339
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\NETGATE\FortKnox Personal Firewall\protect.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-09-20 14:23:11.079
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-09-20 14:23:10.846
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\NETGATE\FortKnox Personal Firewall\protect.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2011-12-31 21:38:27.413
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2011-12-31 21:38:27.236
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\NETGATE\FortKnox Personal Firewall\protect.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 64%
Total physical RAM: 1789.45 MB
Available physical RAM: 628.22 MB
Total Pagefile: 3824.45 MB
Available Pagefile: 2406.74 MB
Total Virtual: 2047.88 MB
Available Virtual: 1888.15 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:69.05 GB) (Free:15.37 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:70 GB) (Free:20.63 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149 GB) (Disk ID: CCE881D1)
Partition 1: (Not Active) - (Size=10 GB) - (Type=27)
Partition 2: (Active) - (Size=69 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=70 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |