Code:
OTL Extras logfile created on: 03.04.2012 14:45:44 - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\R-o-B-i-N\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
8,00 Gb Total Physical Memory | 6,39 Gb Available Physical Memory | 79,93% Memory free
16,04 Gb Paging File | 14,52 Gb Available in Paging File | 90,53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450,68 Gb Total Space | 210,36 Gb Free Space | 46,68% Space Free | Partition Type: NTFS
Drive D: | 15,00 Gb Total Space | 5,63 Gb Free Space | 37,51% Space Free | Partition Type: NTFS
Drive E: | 602,17 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: R-O-B-I-N | User Name: R-o-B-i-N | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
InternetShortcut [print] -- rundll32.exe C:\Windows\system32\mshtml.dll,PrintHTML "%1" ()
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{51B95829-A371-420F-86F1-05A29EA7C7AF}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{5FBF6C32-F949-4DA5-92A9-95E3C06911A0}" = protocol=6 | dir=in | app=c:\gamez\starcraft ii\starcraft ii.exe |
"{D0255774-F882-411A-990D-95C332C80E76}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{F5A37020-EE9B-402D-B7A6-8C313799ADAF}" = protocol=17 | dir=in | app=c:\gamez\starcraft ii\starcraft ii.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{AC76BA86-7AD7-1031-7B44-A90000000001}" = Adobe Reader 9 - Deutsch
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Freemake Video Downloader_is1" = Freemake Video Downloader
"InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.1.1000
"VLC media player" = VLC media player 1.1.9
"WinPcapInst" = WinPcap 4.1.2
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Mozilla Firefox 11.0 (x86 de)" = Mozilla Firefox 11.0 (x86 de)
"MyFreeCodec" = MyFreeCodec
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 03.04.2012 08:15:43 | Computer Name = R-o-B-i-N | Source = Windows Search Service | ID = 3013
Description =
Error - 03.04.2012 08:15:43 | Computer Name = R-o-B-i-N | Source = Windows Search Service | ID = 3013
Description =
Error - 03.04.2012 08:15:43 | Computer Name = R-o-B-i-N | Source = Windows Search Service | ID = 3013
Description =
Error - 03.04.2012 08:15:43 | Computer Name = R-o-B-i-N | Source = Windows Search Service | ID = 3013
Description =
Error - 03.04.2012 08:15:43 | Computer Name = R-o-B-i-N | Source = Windows Search Service | ID = 3013
Description =
Error - 03.04.2012 08:15:43 | Computer Name = R-o-B-i-N | Source = Windows Search Service | ID = 3013
Description =
Error - 03.04.2012 08:15:44 | Computer Name = R-o-B-i-N | Source = Windows Search Service | ID = 3013
Description =
Error - 03.04.2012 08:15:44 | Computer Name = R-o-B-i-N | Source = Windows Search Service | ID = 3013
Description =
Error - 03.04.2012 08:15:44 | Computer Name = R-o-B-i-N | Source = Windows Search Service | ID = 3013
Description =
Error - 03.04.2012 08:28:09 | Computer Name = R-o-B-i-N | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 02.04.2012 04:41:01 | Computer Name = R-o-B-i-N | Source = HTTP | ID = 15016
Description =
Error - 03.04.2012 05:33:07 | Computer Name = R-o-B-i-N | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 03.04.2012 05:33:37 | Computer Name = R-o-B-i-N | Source = HTTP | ID = 15016
Description =
Error - 03.04.2012 08:00:43 | Computer Name = R-o-B-i-N | Source = HTTP | ID = 15016
Description =
Error - 03.04.2012 08:02:32 | Computer Name = R-o-B-i-N | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 03.04.2012 08:09:14 | Computer Name = R-o-B-i-N | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 03.04.2012 um 14:08:11 unerwartet heruntergefahren.
Error - 03.04.2012 08:10:08 | Computer Name = R-o-B-i-N | Source = HTTP | ID = 15016
Description =
Error - 03.04.2012 08:10:38 | Computer Name = R-o-B-i-N | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 03.04.2012 08:26:54 | Computer Name = R-o-B-i-N | Source = HTTP | ID = 15016
Description =
Error - 03.04.2012 08:27:28 | Computer Name = R-o-B-i-N | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
< End of report >
Code:
OTL logfile created on: 03.04.2012 14:45:44 - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\R-o-B-i-N\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
8,00 Gb Total Physical Memory | 6,39 Gb Available Physical Memory | 79,93% Memory free
16,04 Gb Paging File | 14,52 Gb Available in Paging File | 90,53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450,68 Gb Total Space | 210,36 Gb Free Space | 46,68% Space Free | Partition Type: NTFS
Drive D: | 15,00 Gb Total Space | 5,63 Gb Free Space | 37,51% Space Free | Partition Type: NTFS
Drive E: | 602,17 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: R-O-B-I-N | User Name: R-o-B-i-N | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\R-o-B-i-N\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Windows\SysWOW64\conime.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Users\R-o-B-i-N\AppData\Local\Temp\6573b3c6-4299-4ce1-bc75-7f3a9cd9d739\CliSecureRT.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\76d7e84f5dca7908b45edba58bd12f48\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\8985ef7c12df01b25c53bd80f7103819\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\19f85a4f6faaeb87a9055ccf23a9f8b7\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\2250ddb1626087da27fb00f46a679ff5\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\ca8307311e87b234b2faa5ee08332722\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f3e016a2e799cfe233b13d88e90c0e0b\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\3154b66d01dcd674b256e03d5f359fac\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\53591520988a6ee49924e1efc911df30\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\0d4cdd1b911d6e28b4fd5c43ab39f7ea\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\b61b31d1f518e9663fc204e7de21215a\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\7cc17b90932adaad5651ceb526cade44\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\5a8bf6ab1a6ba60e7355fa4cc61fd0c5\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\74353039393f68f4c068cc37f759e5be\mscorlib.ni.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (Ati External Event Utility) -- C:\Windows\SysNative\Ati2evxx.exe ()
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys ()
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys ()
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys ()
DRV:64bit: - (ssadmdm) -- C:\Windows\SysNative\DRIVERS\ssadmdm.sys ()
DRV:64bit: - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) -- C:\Windows\SysNative\DRIVERS\ssadbus.sys ()
DRV:64bit: - (ssadmdfl) SAMSUNG Android USB Modem (Filter) -- C:\Windows\SysNative\DRIVERS\ssadmdfl.sys ()
DRV:64bit: - (npf) -- C:\Windows\SysNative\drivers\npf.sys ()
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys ()
DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys ()
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys ()
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache =
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmdownloader@gmail.com: C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ [2012.03.21 00:15:46 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.03.18 00:56:18 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.09.07 21:16:00 | 000,000,000 | ---D | M]
[2011.12.28 03:44:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\R-o-B-i-N\AppData\Roaming\mozilla\Extensions
[2012.03.04 11:26:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\R-o-B-i-N\AppData\Roaming\mozilla\Firefox\Profiles\xatobif2.default\extensions
[2012.03.04 11:26:54 | 000,000,000 | ---D | M] (WOT) -- C:\Users\R-o-B-i-N\AppData\Roaming\mozilla\Firefox\Profiles\xatobif2.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2012.03.21 00:15:46 | 000,000,000 | ---D | M] (Freemake Video Downloader Plugin) -- C:\PROGRAM FILES (X86)\FREEMAKE\FREEMAKE VIDEO DOWNLOADER\BROWSERPLUGIN\FIREFOX
() (No name found) -- C:\USERS\R-O-B-I-N\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XATOBIF2.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
O1 HOSTS File: ([2006.09.18 23:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - Startup: C:\Users\R-o-B-i-N\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.225.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A342D7E3-D811-4C0A-9042-719E02FD36AC}: DhcpNameServer = 10.225.0.1
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\R-o-B-i-N\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\R-o-B-i-N\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - Unable to obtain root file information for disk D:\
O32 - AutoRun File - [2003.01.17 22:32:20 | 000,000,000 | ---D | M] - E:\Autorun -- [ CDFS ]
O32 - AutoRun File - [2003.01.13 22:01:56 | 001,101,824 | R--- | M] () - E:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2003.01.13 09:28:00 | 000,002,012 | R--- | M] () - E:\autorun.csf -- [ CDFS ]
O32 - AutoRun File - [2003.01.13 09:28:00 | 000,000,027 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012.04.03 14:07:39 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.04.03 14:05:22 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\R-o-B-i-N\Desktop\OTL.exe
[2012.04.02 20:05:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2012.04.02 20:05:54 | 000,000,000 | ---D | C] -- C:\Users\R-o-B-i-N\Documents\StarCraft II
[2012.04.02 20:02:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Blizzard Entertainment
[2012.04.02 10:34:54 | 002,068,528 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\R-o-B-i-N\Desktop\TDSSKiller.exe
[2012.04.02 02:16:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\IO
[2012.03.22 22:13:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MAGIX
[2012.03.17 21:09:39 | 000,000,000 | ---D | C] -- C:\Users\R-o-B-i-N\Desktop\backups
[2012.03.16 22:33:38 | 000,000,000 | ---D | C] -- C:\Users\R-o-B-i-N\AppData\Roaming\Temp
[2012.03.16 22:24:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec
[2012.03.16 22:23:57 | 000,000,000 | ---D | C] -- C:\Users\R-o-B-i-N\Documents\SelfMV
[2012.03.16 16:35:53 | 000,000,000 | ---D | C] -- C:\Users\R-o-B-i-N\AppData\Local\Samsung
[2012.03.16 16:35:48 | 000,000,000 | ---D | C] -- C:\Users\R-o-B-i-N\AppData\Roaming\Samsung
[2012.03.16 16:35:46 | 000,000,000 | ---D | C] -- C:\Users\R-o-B-i-N\Documents\samsung
[2012.03.16 16:31:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2012.03.16 16:31:24 | 004,659,712 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\SysWow64\Redemption.dll
[2012.03.16 16:30:35 | 000,821,824 | ---- | C] (Devguru Co., Ltd.) -- C:\Windows\SysWow64\dgderapi.dll
[2012.03.16 16:30:35 | 000,319,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DIFxAPI.dll
[2012.03.16 16:30:35 | 000,020,032 | ---- | C] (Devguru Co., Ltd) -- C:\Windows\SysWow64\drivers\dgderdrv.sys
[2012.03.16 16:30:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MarkAny
[2012.03.16 16:29:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
[2012.03.16 16:29:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung
[2012.03.16 16:26:59 | 000,000,000 | ---D | C] -- C:\Users\R-o-B-i-N\AppData\Local\Downloaded Installations
[2012.03.13 14:48:11 | 000,000,000 | ---D | C] -- C:\Users\R-o-B-i-N\AppData\Roaming\Bufuy
========== Files - Modified Within 30 Days ==========
[2012.04.03 14:31:24 | 001,445,310 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.04.03 14:31:24 | 000,628,504 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.04.03 14:31:24 | 000,595,798 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.04.03 14:31:24 | 000,126,248 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.04.03 14:31:24 | 000,103,872 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.04.03 14:26:28 | 000,003,712 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.04.03 14:26:28 | 000,003,712 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.04.03 14:26:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.04.03 14:05:24 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\R-o-B-i-N\Desktop\OTL.exe
[2012.04.03 11:32:16 | 000,256,008 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.04.03 03:28:42 | 000,044,032 | ---- | M] () -- C:\Users\R-o-B-i-N\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.04.02 20:03:43 | 000,000,628 | ---- | M] () -- C:\Users\R-o-B-i-N\Desktop\StarCraft.lnk
[2012.04.02 20:02:32 | 000,000,658 | ---- | M] () -- C:\Users\R-o-B-i-N\Desktop\StarCraft II.lnk
[2012.04.02 11:51:55 | 000,674,439 | ---- | M] () -- C:\Users\R-o-B-i-N\AppData\Local\census.cache
[2012.04.02 11:51:52 | 000,000,000 | ---- | M] () -- C:\Users\R-o-B-i-N\AppData\Local\ars.cache
[2012.04.02 10:34:54 | 002,068,528 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\R-o-B-i-N\Desktop\TDSSKiller.exe
[2012.03.31 18:52:26 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2012.03.31 18:52:26 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2012.03.29 10:07:42 | 000,001,634 | ---- | M] () -- C:\Users\Public\Desktop\Command & Conquer(TM) Generals.lnk
[2012.03.24 17:52:25 | 000,000,040 | ---- | M] () -- C:\Users\R-o-B-i-N\AppData\Roaming\cdr.ini
[2012.03.22 22:11:28 | 000,001,257 | ---- | M] () -- C:\Users\R-o-B-i-N\Desktop\MovieEdit.lnk
[2012.03.21 00:15:47 | 000,001,169 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Downloader.lnk
[2012.03.16 16:35:42 | 000,001,790 | ---- | M] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
[2012.03.16 15:08:34 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2012.03.12 18:02:01 | 000,013,085 | ---- | M] () -- C:\Users\R-o-B-i-N\Documents\epro Anmeldung.odt
[2012.03.12 09:19:29 | 000,000,772 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
========== Files Created - No Company Name ==========
[2012.04.02 20:03:43 | 000,000,628 | ---- | C] () -- C:\Users\R-o-B-i-N\Desktop\StarCraft.lnk
[2012.04.02 20:02:32 | 000,000,658 | ---- | C] () -- C:\Users\R-o-B-i-N\Desktop\StarCraft II.lnk
[2012.04.02 09:21:03 | 000,674,439 | ---- | C] () -- C:\Users\R-o-B-i-N\AppData\Local\census.cache
[2012.04.02 09:21:03 | 000,000,000 | ---- | C] () -- C:\Users\R-o-B-i-N\AppData\Local\ars.cache
[2012.03.22 22:11:28 | 000,001,257 | ---- | C] () -- C:\Users\R-o-B-i-N\Desktop\MovieEdit.lnk
[2012.03.16 16:35:42 | 000,001,790 | ---- | C] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
[2012.03.16 16:33:50 | 000,177,640 | ---- | C] () -- C:\Windows\SysNative\drivers\ssadmdm.sys
[2012.03.16 16:33:50 | 000,157,672 | ---- | C] () -- C:\Windows\SysNative\drivers\ssadbus.sys
[2012.03.16 16:33:50 | 000,016,872 | ---- | C] () -- C:\Windows\SysNative\drivers\ssadmdfl.sys
[2012.03.16 16:33:50 | 000,013,800 | ---- | C] () -- C:\Windows\SysNative\drivers\ssadwhnt.sys
[2012.03.16 16:33:50 | 000,013,800 | ---- | C] () -- C:\Windows\SysNative\drivers\ssadwh.sys
[2012.03.16 16:33:50 | 000,013,288 | ---- | C] () -- C:\Windows\SysNative\drivers\ssadcmnt.sys
[2012.03.16 16:33:50 | 000,013,288 | ---- | C] () -- C:\Windows\SysNative\drivers\ssadcm.sys
[2012.03.16 15:08:34 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2012.03.13 12:10:24 | 000,224,256 | ---- | C] () -- C:\Windows\SysNative\iphlpsvc.dll
[2012.03.13 12:10:24 | 000,029,696 | ---- | C] () -- C:\Windows\SysNative\drivers\tunnel.sys
[2012.03.12 18:01:26 | 000,013,085 | ---- | C] () -- C:\Users\R-o-B-i-N\Documents\epro Anmeldung.odt
[2012.02.15 21:38:35 | 000,000,620 | ---- | C] () -- C:\Windows\eReg.dat
[2012.01.31 19:15:44 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012.01.31 19:15:42 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012.01.31 19:15:42 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012.01.31 19:15:42 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012.01.31 19:15:42 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012.01.19 20:03:45 | 000,000,040 | ---- | C] () -- C:\Users\R-o-B-i-N\AppData\Roaming\cdr.ini
[2012.01.10 19:59:13 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2012.01.10 19:59:13 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2012.01.10 09:00:09 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll
[2012.01.09 05:25:11 | 000,106,605 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2012.01.09 05:25:11 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2011.12.28 03:50:02 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.12.28 03:21:33 | 000,172,032 | ---- | C] () -- C:\Windows\WsBtn.dll
[2011.12.28 00:02:12 | 000,000,680 | ---- | C] () -- C:\Users\R-o-B-i-N\AppData\Local\d3d9caps.dat
[2011.12.27 23:53:18 | 000,044,032 | ---- | C] () -- C:\Users\R-o-B-i-N\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.12.27 23:44:50 | 000,000,732 | ---- | C] () -- C:\Users\R-o-B-i-N\AppData\Local\d3d9caps64.dat
[2011.02.11 23:23:34 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
< End of report >