|
Log-Analyse und Auswertung: Ransomware (bprotector) entfernen, aber wie?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
12.08.2013, 08:49 | #1 |
| Ransomware (bprotector) entfernen, aber wie? Ich habe Windows 8, benutze Kaspersky Antivirus, der sagt mein Laptop ist sauber, doch "Emsisoft" und "Exterminate it" sagt, dass da ein Ransomware ist. Ich Habe schon nachgelesen, und Ransomware ist ja ganz gefährlich. Ich kann z.B. jetzt mein Bibliothek (Bilder, Videos, Dokumente) nicht mehr öffnen. Was kann ich jetzt machen? |
12.08.2013, 08:58 | #2 |
/// the machine /// TB-Ausbilder | Ransomware (bprotector) entfernen, aber wie? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
12.08.2013, 09:26 | #3 |
| Ransomware (bprotector) entfernen, aber wie? Und wie kann ich da die FRST.txt und Addition.txt posten, da steht die sind viel zu lang dazu :/
__________________ |
12.08.2013, 09:33 | #4 |
| Ransomware (bprotector) entfernen, aber wie? ok,ich glaube ich habe es geschafft |
12.08.2013, 10:00 | #5 |
| Ransomware (bprotector) entfernen, aber wie? Und jetzt? |
12.08.2013, 10:12 | #6 |
/// the machine /// TB-Ausbilder | Ransomware (bprotector) entfernen, aber wie? Teile die Logs in Stücke und poste sie in Codetags. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ --> Ransomware (bprotector) entfernen, aber wie? |
12.08.2013, 10:31 | #7 |
| Ransomware (bprotector) entfernen, aber wie? [CODE] Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-08-2013 02 Ran by (administrator) on 12-08-2013 11:15:18 Running from C:\Users\jessi_000\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2W4Z2ZE Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Infowatch) C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteUser.exe (CurioLab S.M.B.A.) C:\Program Files (x86)\Exterminate It!\ExterminateIt.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\klwtblfs.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Farbar) C:\Users\jessi_000\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2W4Z2ZE\FRST64 (1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3053808 2013-08-04] (Synaptics Incorporated) HKCU\...\Run: [Power2GoExpress8] - C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe [1711680 2013-01-27] (CyberLink Corp.) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [581024 2012-09-07] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [HP CoolSense] - C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1343904 2012-11-05] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\runner_avp.exe [25608 2012-12-20] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] () HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {5F0F98CA-486A-4FAE-A0C4-E6CE7C7277D1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM-x32 - {5F0F98CA-486A-4FAE-A0C4-E6CE7C7277D1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKCU - {5F0F98CA-486A-4FAE-A0C4-E6CE7C7277D1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll (Kaspersky Lab) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM-x32 - Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll (Kaspersky Lab) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 213.154.124.1 193.231.252.1 Chrome: ======= CHR HomePage: hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=8A7CF4B7E2B20A05&affID=121962&tsp=4952 CHR RestoreOnStartup: "hxxp://google.de/" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{googleriginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{go ogle:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={goo gle:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave for Director) - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.) CHR Extension: (Google Docs) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Kaspersky URL Advisor) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_0 CHR Extension: (Safe Money) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.2.558_0 CHR Extension: (Virtual Keyboard) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.2.558_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0 CHR Extension: (Chloe) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pillplnpmfjckedkedpaoembffbpklnf\2_0 CHR Extension: (Gmail) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR Extension: (Anti-Banner) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.2.558_0 CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\urladvisor.crx CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\online_banking_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\content_blocker_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\virtkbd.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\ab.crx CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [356968 2012-12-20] (Kaspersky Lab ZAO) R2 CSObjectsSrv; C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [819040 2012-12-21] (Infowatch) R2 HPConnectedRemote; C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35744 2012-10-12] (Hewlett-Packard) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1900728 2013-06-10] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R3 cleanhlp; C:\EEK\Run\cleanhlp64.sys [57032 2013-07-23] (Emsisoft GmbH) R3 cleanhlp; C:\EEK\Run\cleanhlp64.sys [57032 2013-07-23] (Emsisoft GmbH) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R0 CSCrySec; C:\Windows\System32\DRIVERS\CSCrySec.sys [98064 2012-12-10] (Infowatch) R1 CSVirtualDiskDrv; C:\Windows\system32\DRIVERS\CSVirtualDiskDrv.sys [67344 2012-12-10] (Infowatch) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458584 2012-06-19] (Kaspersky Lab ZAO) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [619616 2013-07-20] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [28504 2012-08-02] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29016 2012-09-03] (Kaspersky Lab) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29528 2012-09-03] (Kaspersky Lab) R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-07-20] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-07-20] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-25] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2013-08-04] (Synaptics Incorporated) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-11 23:35 - 2013-08-11 23:35 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\IObit 2013-08-11 21:10 - 2013-08-11 21:10 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Malwarebytes 2013-08-11 21:07 - 2013-08-11 21:07 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-11 21:07 - 2013-08-11 21:07 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-11 21:07 - 2013-08-11 21:07 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-11 21:07 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-11 17:54 - 2013-08-11 17:54 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Curiolab 2013-08-11 17:32 - 2013-08-11 23:12 - 00000000 ____D C:\Program Files (x86)\Exterminate It! 2013-08-11 17:32 - 2013-08-11 17:32 - 00001081 _____ C:\Users\jessi_000\Desktop\Exterminate It!.lnk 2013-08-11 17:14 - 2013-08-11 17:14 - 00000000 ____D C:\Encryption 2013-08-11 15:57 - 2013-08-11 15:58 - 00000000 ____D C:\Users\jessi_000\Desktop\programme 2013-08-04 22:26 - 2013-08-04 22:26 - 00000902 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-04 20:58 - 2013-08-04 21:01 - 00000000 ____D C:\Windows\LastGood.Tmp 2013-08-04 20:57 - 2013-08-04 20:58 - 00006762 _____ C:\Windows\DPINST.LOG 2013-08-04 20:57 - 2013-08-04 20:58 - 00001332 _____ C:\Windows\Synaptics.log 2013-08-04 20:57 - 2013-08-04 20:56 - 01060080 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll 2013-08-04 20:57 - 2013-08-04 20:56 - 00544496 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCom.dll 2013-08-04 20:57 - 2013-08-04 20:56 - 00495856 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys 2013-08-04 20:57 - 2013-08-04 20:56 - 00264432 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2013-08-04 20:57 - 2013-08-04 20:56 - 00192240 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo18.dll 2013-08-04 20:57 - 2013-08-04 20:56 - 00151280 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynTPCom.dll 2013-08-04 20:57 - 2013-08-04 20:56 - 00033008 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\Smb_driver_Intel.sys 2013-08-04 20:28 - 2013-08-04 20:28 - 00003154 _____ C:\Windows\System32\Tasks\MirageAgent 2013-08-04 20:27 - 2013-08-04 20:27 - 00000000 ___HD C:\Users\Public\Documents\YouCam 2013-08-04 19:47 - 2013-08-04 19:47 - 00003166 _____ C:\Windows\System32\Tasks\CLVDLauncher 2013-08-04 19:47 - 2013-08-04 19:47 - 00003166 _____ C:\Windows\System32\Tasks\CLMLSvc_P2G8 2013-08-04 19:47 - 2012-06-25 11:24 - 00092536 _____ (CyberLink) C:\Windows\system32\Drivers\CLVirtualDrive.sys 2013-08-03 21:31 - 2013-08-03 21:31 - 10644535 _____ C:\Users\jessi_000\Downloads\WhatsApp.apk 2013-08-03 21:17 - 2013-08-03 21:17 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Windows Live 2013-08-03 21:16 - 2013-08-03 21:16 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\DivX 2013-07-31 15:38 - 2013-07-31 15:39 - 00000000 ____D C:\Windows\system32\MRT 2013-07-31 13:50 - 2013-07-31 13:51 - 00449736 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-30 23:10 - 2013-07-30 23:10 - 00000000 ____D C:\output 2013-07-30 23:08 - 2013-08-01 22:31 - 00020480 ____H C:\Users\jessi_000\Desktop\photothumb.db 2013-07-30 20:35 - 2013-07-30 20:35 - 00000566 _____ C:\Users\Public\Desktop\Pixlr-o-matic.lnk 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Pixlromatic 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\ProgramData\Adobe 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-30 20:23 - 2013-07-30 20:25 - 145394418 _____ C:\Users\JESSI_~1\AppData\Local\ACCCx189.zip.aamdownload 2013-07-30 20:23 - 2013-07-30 20:25 - 00001811 _____ C:\Users\JESSI_~1\AppData\Local\ACCCx189.zip.aamdownload.aamd 2013-07-30 20:22 - 2013-07-30 20:22 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Adobe 2013-07-30 20:20 - 2013-07-30 20:21 - 03867000 _____ (Adobe Systems Incorporated) C:\Users\jessi_000\Downloads\CreativeCloudSet-Up.exe 2013-07-30 20:05 - 2013-07-30 20:07 - 00000000 ____D C:\Users\jessi_000\Desktop\Musik 2013-07-30 18:40 - 2013-08-04 20:58 - 00003782 _____ C:\Windows\setupact.log 2013-07-30 18:40 - 2013-07-30 18:40 - 00000000 _____ C:\Windows\setuperr.log 2013-07-29 17:29 - 2013-07-29 17:29 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\WebApp 2013-07-29 17:25 - 2013-07-29 17:25 - 00000000 ____D C:\Users\jessi_000\Documents\CyberLink 2013-07-27 01:10 - 2012-10-12 09:13 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\dskquota.dll 2013-07-27 01:10 - 2012-10-12 08:39 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dskquota.dll 2013-07-27 01:09 - 2012-10-24 07:54 - 00396008 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll 2013-07-27 01:09 - 2012-10-17 07:32 - 01172992 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll 2013-07-27 01:09 - 2012-10-17 07:32 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll 2013-07-27 01:09 - 2012-10-17 07:32 - 00673280 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll 2013-07-27 01:09 - 2012-10-17 06:57 - 00929792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll 2013-07-27 01:09 - 2012-10-17 06:57 - 00568832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll 2013-07-27 01:09 - 2012-10-17 06:57 - 00513024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll 2013-07-27 01:09 - 2012-10-11 10:47 - 00793200 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2013-07-27 01:09 - 2012-10-11 10:25 - 00056552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdstor.sys 2013-07-27 01:09 - 2012-10-11 10:23 - 00441576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2013-07-27 01:09 - 2012-10-11 10:18 - 00172264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-07-27 01:09 - 2012-10-11 10:13 - 00058088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys 2013-07-27 01:09 - 2012-10-11 10:13 - 00033512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\battc.sys 2013-07-27 01:09 - 2012-10-11 10:08 - 00562392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-07-27 01:09 - 2012-10-11 08:46 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll 2013-07-27 01:09 - 2012-10-11 08:46 - 00517120 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2013-07-27 01:09 - 2012-10-11 08:46 - 00154112 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.Compression.dll 2013-07-27 01:09 - 2012-10-11 08:45 - 01045504 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll 2013-07-27 01:09 - 2012-10-11 08:45 - 00590848 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2013-07-27 01:09 - 2012-10-11 08:45 - 00579584 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll 2013-07-27 01:09 - 2012-10-11 08:45 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\SpaceControl.dll 2013-07-27 01:09 - 2012-10-11 08:44 - 01265152 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-07-27 01:09 - 2012-10-11 08:44 - 00904192 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2013-07-27 01:09 - 2012-10-11 08:44 - 00264704 _____ (Microsoft Corporation) C:\Windows\system32\ListSvc.dll 2013-07-27 01:09 - 2012-10-11 08:43 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2013-07-27 01:09 - 2012-10-11 08:42 - 00612416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2013-07-27 01:09 - 2012-10-11 08:16 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-07-27 01:09 - 2012-10-11 08:07 - 01226752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll 2013-07-27 01:09 - 2012-10-11 08:07 - 00962560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll 2013-07-27 01:09 - 2012-10-11 08:07 - 00460800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2013-07-27 01:09 - 2012-10-11 08:07 - 00414720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll 2013-07-27 01:09 - 2012-10-11 08:07 - 00116224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.Compression.dll 2013-07-27 01:09 - 2012-10-11 08:06 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll 2013-07-27 01:09 - 2012-10-11 08:06 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2013-07-27 01:09 - 2012-10-11 03:45 - 00478424 _____ C:\Windows\SysWOW64\locale.nls 2013-07-27 01:09 - 2012-10-11 03:44 - 00478424 _____ C:\Windows\system32\locale.nls 2013-07-27 01:08 - 2012-12-04 07:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll 2013-07-27 01:08 - 2012-11-20 08:24 - 01164800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Display.dll 2013-07-27 01:08 - 2012-11-20 08:17 - 01184256 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll 2013-07-27 01:08 - 2012-11-20 08:02 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDKURD.DLL 2013-07-27 01:08 - 2012-11-20 07:59 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDKURD.DLL 2013-07-27 01:08 - 2012-11-08 07:25 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2013-07-27 01:08 - 2012-11-08 07:25 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll 2013-07-27 01:08 - 2012-11-08 07:25 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-07-27 01:08 - 2012-11-08 07:22 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2013-07-27 01:08 - 2012-11-08 07:22 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll 2013-07-27 01:08 - 2012-11-08 07:22 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-07-27 01:08 - 2012-10-11 10:02 - 01636672 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll 2013-07-27 01:08 - 2012-10-11 08:46 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\BdeUISrv.exe 2013-07-27 01:08 - 2012-10-11 08:46 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll 2013-07-27 01:08 - 2012-10-11 08:45 - 00370176 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-07-27 01:08 - 2012-10-11 08:45 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\PCPKsp.dll 2013-07-27 01:08 - 2012-10-11 08:44 - 00355328 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-07-27 01:08 - 2012-10-11 08:44 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\input.dll 2013-07-27 01:08 - 2012-10-11 08:44 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 01280000 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00757760 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\AppxSip.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2013-07-27 01:08 - 2012-10-11 08:23 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-pdc.dll 2013-07-27 01:08 - 2012-10-11 08:23 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\kbdhebl3.dll 2013-07-27 01:08 - 2012-10-11 08:19 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys 2013-07-27 01:08 - 2012-10-11 08:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-07-27 01:08 - 2012-10-11 08:15 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys 2013-07-27 01:08 - 2012-10-11 08:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PCPKsp.dll 2013-07-27 01:08 - 2012-10-11 08:07 - 00019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll 2013-07-27 01:08 - 2012-10-11 08:06 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll 2013-07-27 01:08 - 2012-10-11 08:06 - 00289280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-07-27 01:08 - 2012-10-11 08:06 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll 2013-07-27 01:08 - 2012-10-11 08:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc.dll 2013-07-27 01:08 - 2012-10-11 08:06 - 00051712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2013-07-27 01:08 - 2012-10-11 08:05 - 00099840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxSip.dll 2013-07-27 01:08 - 2012-10-11 07:42 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdhebl3.dll 2013-07-27 01:07 - 2012-11-06 10:52 - 00277736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2013-07-27 01:07 - 2012-11-06 10:33 - 01566432 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2013-07-27 01:07 - 2012-11-06 07:48 - 01150160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00883712 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2013-07-27 01:07 - 2012-11-06 07:20 - 00516608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00386560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00375296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe 2013-07-27 01:07 - 2012-11-06 07:20 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfdprov.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 08552448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00470016 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00466944 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00126464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\wfdprov.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapPeerProxy.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapAuthProxy.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 11459584 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 01037312 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 00976384 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 00189440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bthprops.cpl 2013-07-27 01:07 - 2012-11-06 07:18 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll 2013-07-27 01:07 - 2012-11-06 07:17 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl 2013-07-27 01:07 - 2012-11-06 07:17 - 00110080 _____ (Microsoft Corporation) C:\Windows\system32\dafWCN.dll 2013-07-27 01:07 - 2012-11-06 07:00 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\iscsilog.dll 2013-07-27 01:07 - 2012-11-06 06:58 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll 2013-07-27 01:07 - 2012-11-06 06:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll 2013-07-27 01:07 - 2012-11-06 06:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys 2013-07-27 01:07 - 2012-11-06 06:55 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys 2013-07-27 01:07 - 2012-11-06 06:55 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys 2013-07-27 01:07 - 2012-11-06 06:55 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys 2013-07-27 01:07 - 2012-11-06 06:55 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fxppm.sys 2013-07-27 01:07 - 2012-11-06 06:53 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-07-27 01:07 - 2012-11-06 06:51 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-07-27 01:05 - 2012-11-27 09:39 - 01122768 _____ (Microsoft Corporation) C:\Windows\system32\Taskmgr.exe 2013-07-27 01:05 - 2012-11-27 07:49 - 01027152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Taskmgr.exe 2013-07-27 01:05 - 2012-11-27 07:20 - 01217536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\storagewmi.dll 2013-07-27 01:05 - 2012-11-27 07:20 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-07-27 01:05 - 2012-11-27 07:20 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-07-27 01:05 - 2012-11-27 07:20 - 00798208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll 2013-07-27 01:05 - 2012-11-27 07:20 - 00702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-07-27 01:05 - 2012-11-27 07:20 - 00560128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserLanguagesCpl.dll 2013-07-27 01:05 - 2012-11-27 07:20 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll 2013-07-27 01:05 - 2012-11-27 07:20 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vds_ps.dll 2013-07-27 01:05 - 2012-11-27 07:19 - 03245568 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-07-27 01:05 - 2012-11-27 07:19 - 01536512 _____ (Microsoft Corporation) C:\Windows\system32\storagewmi.dll 2013-07-27 01:05 - 2012-11-27 07:19 - 00955904 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll 2013-07-27 01:05 - 2012-11-27 07:19 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\UserLanguagesCpl.dll 2013-07-27 01:05 - 2012-11-27 07:19 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-07-27 01:05 - 2012-11-27 07:19 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll 2013-07-27 01:05 - 2012-11-27 07:18 - 01071104 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-07-27 01:05 - 2012-11-27 07:18 - 00888832 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-07-27 01:05 - 2012-11-27 07:18 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-07-27 01:05 - 2012-11-27 07:17 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL 2013-07-27 01:05 - 2012-10-12 11:08 - 00027880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2013-07-27 01:05 - 2012-10-12 09:14 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\rfxvmt.dll 2013-07-27 01:05 - 2012-10-12 08:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2013-07-27 00:14 - 2013-06-01 14:54 - 00194816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2013-07-27 00:14 - 2013-06-01 14:54 - 00125184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2013-07-27 00:14 - 2013-06-01 14:33 - 02233600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-27 00:14 - 2013-06-01 14:29 - 00337152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2013-07-27 00:14 - 2013-06-01 14:29 - 00213248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS 2013-07-27 00:14 - 2013-06-01 14:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-07-27 00:14 - 2013-06-01 14:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2013-07-27 00:14 - 2013-06-01 13:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2013-07-27 00:14 - 2013-06-01 12:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-07-27 00:14 - 2013-06-01 12:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2013-07-27 00:14 - 2013-06-01 12:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2013-07-27 00:14 - 2013-06-01 12:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll 2013-07-27 00:14 - 2013-06-01 12:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2013-07-27 00:14 - 2013-06-01 12:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2013-07-27 00:14 - 2013-06-01 12:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe 2013-07-27 00:14 - 2013-06-01 12:22 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-07-27 00:14 - 2013-06-01 12:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll 2013-07-27 00:14 - 2013-05-20 03:08 - 00386642 _____ C:\Windows\system32\ApnDatabase.xml 2013-07-27 00:14 - 2013-04-09 05:34 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-07-27 00:14 - 2013-04-09 05:34 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys 2013-07-27 00:13 - 2013-06-17 01:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-07-27 00:13 - 2013-06-01 14:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-07-27 00:13 - 2013-06-01 12:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-27 00:13 - 2013-06-01 12:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe 2013-07-27 00:13 - 2013-06-01 12:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2013-07-27 00:13 - 2013-06-01 12:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2013-07-27 00:13 - 2013-06-01 12:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2013-07-27 00:13 - 2013-06-01 12:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2013-07-27 00:13 - 2013-06-01 12:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll 2013-07-27 00:13 - 2013-06-01 12:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2013-07-27 00:13 - 2013-06-01 12:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2013-07-27 00:13 - 2013-06-01 12:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll 2013-07-27 00:13 - 2013-06-01 06:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys 2013-07-27 00:13 - 2013-05-25 01:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-07-27 00:13 - 2013-05-25 01:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-07-27 00:13 - 2013-05-25 01:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-07-27 00:13 - 2013-05-25 01:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-07-25 23:54 - 2013-06-28 01:04 - 00693112 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-07-25 23:54 - 2013-06-28 01:04 - 00078200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-07-25 23:53 - 2013-08-11 22:05 - 00102576 _____ C:\Windows\PFRO.log 2013-07-25 15:36 - 2013-07-25 15:36 - 00000000 ____D C:\sources 2013-07-25 14:45 - 2013-08-11 20:37 - 01606003 _____ C:\Windows\WindowsUpdate.log 2013-07-25 14:32 - 2013-07-25 14:32 - 00001274 _____ C:\Users\jessi_000\Desktop\shutdown.lnk 2013-07-25 13:54 - 2013-07-25 13:54 - 00000546 _____ C:\Users\jessi_000\Desktop\Emsisoft Emergency Kit.lnk 2013-07-25 13:54 - 2013-07-25 13:54 - 00000000 ____D C:\EEK 2013-07-25 13:51 - 2013-07-25 13:51 - 00082976 _____ C:\Users\jessi_000\Documents\cc_20130725_125126.reg 2013-07-25 13:49 - 2013-07-25 13:49 - 00002780 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-07-25 13:48 - 2013-07-25 13:48 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-07-25 13:48 - 2013-07-25 13:48 - 00000000 ____D C:\Program Files\CCleaner 2013-07-25 13:44 - 2013-07-25 13:44 - 04396440 _____ (Piriform Ltd) C:\Users\jessi_000\Desktop\ccsetup403.exe 2013-07-25 13:40 - 2013-07-25 13:43 - 181531216 _____ C:\Users\jessi_000\Downloads\EmsisoftEmergencyKit40012.exe 2013-07-25 12:35 - 2013-06-24 01:57 - 78277128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-07-25 00:25 - 2013-07-25 00:25 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\DDMSettings 2013-07-25 00:23 - 2013-07-25 00:24 - 00000000 ____D C:\Program Files\DivX 2013-07-25 00:21 - 2013-07-25 00:24 - 00000000 ____D C:\ProgramData\DivX 2013-07-25 00:21 - 2013-07-25 00:24 - 00000000 ____D C:\Program Files (x86)\DivX 2013-07-25 00:21 - 2013-07-25 00:21 - 00957248 _____ (DivX, LLC) C:\Users\jessi_000\Downloads\DivXWebPlayerInstaller.exe 2013-07-25 00:21 - 2013-07-25 00:21 - 00000000 _____ C:\END 2013-07-24 17:56 - 2013-05-16 01:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll 2013-07-24 17:56 - 2012-11-10 07:23 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2013-07-24 17:56 - 2012-11-10 07:23 - 00132608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2013-07-24 17:56 - 2012-11-10 07:22 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\RDWebAI.dll 2013-07-24 17:56 - 2012-11-10 07:22 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\VmHostAI.dll 2013-07-24 17:56 - 2012-11-10 07:20 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\appserverai.dll 2013-07-24 17:29 - 2013-03-22 06:49 - 02382336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll 2013-07-24 17:29 - 2013-03-22 01:47 - 02851840 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll 2013-07-24 17:29 - 2013-03-02 11:23 - 00375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll 2013-07-24 17:29 - 2013-03-02 05:44 - 01011200 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll 2013-07-24 17:29 - 2012-12-15 07:55 - 00443392 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll 2013-07-24 17:29 - 2012-11-03 08:26 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\sysreset.exe 2013-07-24 17:29 - 2012-11-03 08:25 - 00945152 _____ (Microsoft Corporation) C:\Windows\system32\resetengmig.dll 2013-07-24 17:29 - 2012-10-24 06:25 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\ReAgentc.exe 2013-07-24 17:29 - 2012-10-24 06:25 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2013-07-24 17:29 - 2012-10-24 06:24 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2013-07-24 17:29 - 2012-10-24 06:24 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2013-07-24 17:29 - 2012-10-24 06:05 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2013-07-24 17:29 - 2012-10-24 05:48 - 00024064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgentc.exe 2013-07-24 17:28 - 2013-04-03 02:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-07-24 17:28 - 2013-04-03 02:12 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-07-24 15:00 - 2013-01-10 02:26 - 01611776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe 2013-07-24 15:00 - 2013-01-10 02:26 - 00890880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2013-07-24 15:00 - 2013-01-10 02:23 - 02094592 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe 2013-07-24 15:00 - 2013-01-10 02:23 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll 2013-07-24 15:00 - 2013-01-10 02:22 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2013-07-24 14:59 - 2013-01-10 04:53 - 00028904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpiowin32.sys 2013-07-24 14:59 - 2013-01-10 04:29 - 00785504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-07-24 14:59 - 2013-01-10 04:29 - 00091880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2013-07-24 14:59 - 2013-01-10 02:26 - 01752064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll 2013-07-24 14:59 - 2013-01-10 02:26 - 00436736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL 2013-07-24 14:59 - 2013-01-10 02:26 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll 2013-07-24 14:59 - 2013-01-10 02:26 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wiaacmgr.exe 2013-07-24 14:59 - 2013-01-10 02:23 - 01886208 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll 2013-07-24 14:59 - 2013-01-10 02:23 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll 2013-07-24 14:59 - 2013-01-10 02:23 - 00256000 _____ (Microsoft Corporation) C:\Windows\system32\WSDMon.dll 2013-07-24 14:59 - 2013-01-10 02:23 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\wiaacmgr.exe 2013-07-24 14:59 - 2013-01-10 02:22 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2013-07-24 14:59 - 2013-01-10 02:22 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL 2013-07-24 14:59 - 2013-01-10 02:22 - 00438272 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll 2013-07-24 14:59 - 2013-01-10 02:22 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2013-07-24 14:59 - 2013-01-09 06:59 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys 2013-07-24 14:59 - 2012-11-02 08:19 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ncbservice.dll 2013-07-24 14:59 - 2012-11-02 08:18 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\httpprxm.dll 2013-07-24 14:59 - 2012-11-02 08:18 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\adhsvc.dll 2013-07-24 14:59 - 2012-11-02 08:18 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\adhapi.dll 2013-07-24 14:59 - 2012-11-02 08:18 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\httpprxp.dll 2013-07-24 14:59 - 2012-11-02 08:18 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\keepaliveprovider.dll 2013-07-24 14:59 - 2012-10-10 10:04 - 00094208 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2013-07-24 14:59 - 2012-10-10 09:31 - 00072192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll 2013-07-24 14:57 - 2012-11-26 07:21 - 00071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll 2013-07-24 14:57 - 2012-11-26 07:20 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll 2013-07-24 14:56 - 2013-04-16 05:34 - 01455368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-07-24 14:54 - 2012-08-31 03:52 - 00017888 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll 2013-07-24 14:53 - 2012-08-31 03:53 - 00017888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100_clr0400.dll 2013-07-24 14:42 - 2013-03-02 11:23 - 01338880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-07-24 14:42 - 2013-03-02 05:45 - 01627648 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-07-24 14:42 - 2013-03-02 05:45 - 01161728 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2013-07-24 14:42 - 2013-03-02 05:44 - 05978624 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-07-24 14:41 - 2013-03-02 13:57 - 00332520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2013-07-24 14:41 - 2013-03-02 13:39 - 00327912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2013-07-24 14:41 - 2013-03-02 11:23 - 00893952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll 2013-07-24 14:41 - 2013-03-02 11:23 - 00601088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll 2013-07-24 14:41 - 2013-03-02 11:22 - 05091840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-07-24 14:41 - 2013-03-02 11:22 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcfgx.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 01149952 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 01101824 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00951808 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\usbmon.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\TimeBrokerServer.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll 2013-07-24 14:41 - 2013-03-02 05:44 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll 2013-07-24 14:41 - 2013-03-02 05:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll 2013-07-24 14:41 - 2013-03-02 05:44 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll 2013-07-24 14:40 - 2013-03-02 13:57 - 00077544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storahci.sys 2013-07-24 14:40 - 2013-03-02 13:45 - 00148712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys 2013-07-24 14:40 - 2013-03-02 13:39 - 00495336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys 2013-07-24 14:40 - 2013-03-02 11:23 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2013-07-24 14:40 - 2013-03-02 11:23 - 00356352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll 2013-07-24 14:40 - 2013-03-02 11:23 - 00100864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncInfo.dll 2013-07-24 14:40 - 2013-03-02 11:21 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvstore.dll 2013-07-24 14:40 - 2013-03-02 11:21 - 00145408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\powercfg.cpl 2013-07-24 14:40 - 2013-03-02 11:21 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevDispItemProvider.dll 2013-07-24 14:40 - 2013-03-02 05:45 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\WSDPrintProxy.DLL 2013-07-24 14:40 - 2013-03-02 05:44 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\discan.dll 2013-07-24 14:40 - 2013-03-02 05:44 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncInfo.dll 2013-07-24 14:40 - 2013-03-02 05:44 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\NdisImPlatform.dll 2013-07-24 14:40 - 2013-03-02 05:44 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\DevDispItemProvider.dll 2013-07-24 14:40 - 2013-03-02 05:43 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\powercfg.cpl 2013-07-24 14:40 - 2013-03-02 05:15 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mouhid.sys 2013-07-24 14:40 - 2013-03-01 07:56 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\monitor.sys 2013-07-24 14:33 - 2013-05-31 02:14 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-24 14:33 - 2013-03-02 12:59 - 00411880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2013-07-24 14:30 - 2013-04-24 02:13 - 01013248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-07-24 14:30 - 2013-04-24 02:12 - 01569792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-07-24 14:30 - 2013-04-24 02:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-07-24 14:30 - 2013-04-24 01:56 - 01255936 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-07-24 14:30 - 2013-04-24 01:55 - 01889280 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-07-24 14:30 - 2013-04-24 01:55 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-07-24 14:30 - 2013-04-24 01:55 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-07-24 14:24 - 2013-06-01 12:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-24 14:24 - 2013-06-01 12:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-24 14:20 - 2013-02-02 14:19 - 00496872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-07-24 14:20 - 2013-02-02 14:19 - 00061672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\crashdmp.sys 2013-07-24 14:20 - 2013-02-02 13:54 - 01933544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-07-24 14:20 - 2013-02-02 11:40 - 00410624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlroamextension.dll 2013-07-24 14:20 - 2013-02-02 11:40 - 00370688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWanAPI.dll 2013-07-24 14:20 - 2013-02-02 11:40 - 00197632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll 2013-07-24 14:20 - 2013-02-02 11:40 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tasklist.exe 2013-07-24 14:20 - 2013-02-02 11:40 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskkill.exe 2013-07-24 14:20 - 2013-02-02 11:39 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mbsmsapi.dll 2013-07-24 14:20 - 2013-02-02 11:39 - 00055296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2013-07-24 14:20 - 2013-02-02 11:38 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\duser.dll 2013-07-24 14:20 - 2013-02-02 11:24 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\taskkill.exe 2013-07-24 14:20 - 2013-02-02 11:24 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\tasklist.exe 2013-07-24 14:20 - 2013-02-02 11:23 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll 2013-07-24 14:20 - 2013-02-02 11:23 - 00543232 _____ (Microsoft Corporation) C:\Windows\system32\wlroamextension.dll 2013-07-24 14:20 - 2013-02-02 11:23 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\WWanAPI.dll 2013-07-24 14:20 - 2013-02-02 11:23 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Connectivity.dll 2013-07-24 14:20 - 2013-02-02 11:23 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll 2013-07-24 14:20 - 2013-02-02 11:21 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2013-07-24 14:20 - 2013-02-02 11:21 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\mbsmsapi.dll 2013-07-24 14:20 - 2013-02-02 11:20 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\duser.dll 2013-07-24 14:20 - 2013-02-02 11:20 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\hotspotauth.dll 2013-07-24 14:20 - 2013-02-02 10:25 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys 2013-07-24 14:20 - 2012-11-27 06:57 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BtaMPM.sys 2013-07-24 14:20 - 2012-11-27 06:55 - 00029952 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthhfHid.sys 2013-07-24 14:20 - 2012-11-20 07:56 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-07-24 14:19 - 2013-02-06 01:29 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2013-07-24 14:19 - 2013-02-06 01:28 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2013-07-24 14:19 - 2013-02-02 08:41 - 01437184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2013-07-24 14:19 - 2013-02-02 08:31 - 01690624 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2013-07-24 14:18 - 2013-04-12 01:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-24 14:18 - 2013-04-12 01:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-24 14:17 - 2013-05-04 09:59 - 13644288 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2013-07-24 14:17 - 2013-05-04 09:59 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-07-24 14:17 - 2013-05-04 09:59 - 01483776 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe 2013-07-24 14:17 - 2013-05-04 09:59 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-07-24 14:17 - 2013-05-04 09:58 - 10116096 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2013-07-24 14:17 - 2013-05-04 09:58 - 01332736 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll 2013-07-24 14:17 - 2013-05-04 09:58 - 00470528 _____ (Microsoft Corporation) C:\Windows\system32\netprofmsvc.dll 2013-07-24 14:17 - 2013-05-04 09:58 - 00328192 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2013-07-24 14:17 - 2013-05-04 09:57 - 02305024 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-07-24 14:17 - 2013-05-04 09:57 - 01131520 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2013-07-24 14:17 - 2013-05-04 09:57 - 00389120 _____ (Microsoft Corporation) C:\Windows\system32\BCP47Langs.dll 2013-07-24 14:17 - 2013-05-04 07:57 - 10788864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2013-07-24 14:17 - 2013-05-04 07:57 - 08857088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2013-07-24 14:17 - 2013-05-04 07:57 - 00247296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll 2013-07-24 14:17 - 2013-05-04 07:47 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2013-07-24 14:16 - 2013-05-04 10:58 - 00120736 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe 2013-07-24 14:16 - 2013-05-04 10:34 - 00446720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS 2013-07-24 14:16 - 2013-05-04 10:34 - 00284416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys 2013-07-24 14:16 - 2013-05-04 10:30 - 00058312 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-07-24 14:16 - 2013-05-04 09:59 - 01619968 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-07-24 14:16 - 2013-05-04 09:59 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe 2013-07-24 14:16 - 2013-05-04 09:59 - 00251904 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2013-07-24 14:16 - 2013-05-04 09:59 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-07-24 14:16 - 2013-05-04 09:59 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-07-24 14:16 - 2013-05-04 09:59 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-07-24 14:16 - 2013-05-04 09:58 - 00330240 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll 2013-07-24 14:16 - 2013-05-04 09:58 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2013-07-24 14:16 - 2013-05-04 09:58 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll 2013-07-24 14:16 - 2013-05-04 09:58 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\netprofm.dll 2013-07-24 14:16 - 2013-05-04 09:58 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00708096 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00501760 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\biwinrt.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\muifontsetup.dll 2013-07-24 14:16 - 2013-05-04 09:56 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl 2013-07-24 14:16 - 2013-05-04 07:58 - 00758784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Magnify.exe 2013-07-24 14:16 - 2013-05-04 07:58 - 00621056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2013-07-24 14:16 - 2013-05-04 07:58 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2013-07-24 14:16 - 2013-05-04 07:58 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2013-07-24 14:16 - 2013-05-04 07:58 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2013-07-24 14:16 - 2013-05-04 07:57 - 00303616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll 2013-07-24 14:16 - 2013-05-04 07:57 - 00151040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netplwiz.dll 2013-07-24 14:16 - 2013-05-04 07:57 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netprofm.dll 2013-07-24 14:16 - 2013-05-04 07:57 - 00018432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\npmproxy.dll 2013-07-24 14:16 - 2013-05-04 07:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\muifontsetup.dll 2013-07-24 14:16 - 2013-05-04 07:56 - 02035712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-07-24 14:16 - 2013-05-04 07:56 - 00449536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairing.dll 2013-07-24 14:16 - 2013-05-04 07:56 - 00411136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll 2013-07-24 14:16 - 2013-05-04 07:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BCP47Langs.dll 2013-07-24 14:16 - 2013-05-04 07:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\biwinrt.dll 2013-07-24 14:16 - 2013-05-04 07:55 - 00389632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl 2013-07-24 14:16 - 2013-05-04 07:51 - 00014848 _____ (Microsoft) C:\Windows\system32\rars.rs 2013-07-24 14:16 - 2013-05-04 07:10 - 00014848 _____ (Microsoft) C:\Windows\SysWOW64\rars.rs 2013-07-24 14:16 - 2013-03-02 05:45 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2013-07-24 14:16 - 2013-03-02 05:45 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\taskhostex.exe 2013-07-24 14:16 - 2013-03-02 05:45 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-07-24 14:16 - 2013-02-02 11:39 - 00015872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlmproxy.dll 2013-07-24 14:16 - 2013-02-02 11:39 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlmsprep.dll 2013-07-24 14:16 - 2012-11-06 07:20 - 00018432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2013-07-24 14:16 - 2012-11-06 07:20 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll 2013-07-24 14:16 - 2012-11-06 07:00 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wushareduxresources.dll 2013-07-24 14:16 - 2012-11-02 08:20 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-07-24 14:15 - 2013-05-31 02:24 - 01257472 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-07-24 14:15 - 2013-05-31 02:08 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-07-24 14:15 - 2013-05-24 02:01 - 01300992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-07-24 14:15 - 2013-05-24 01:27 - 01022464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-07-24 14:15 - 2013-05-15 05:25 - 00888320 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe 2013-07-24 14:15 - 2013-05-15 05:25 - 00542208 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll 2013-07-24 14:15 - 2013-05-15 05:24 - 00793088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe 2013-07-24 14:15 - 2013-05-15 05:24 - 00482816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll 2013-07-24 14:13 - 2013-02-12 03:17 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-07-24 14:12 - 2013-03-06 10:10 - 00112872 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2013-07-24 14:12 - 2013-03-06 09:31 - 19758592 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-07-24 14:12 - 2013-03-06 09:31 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-07-24 14:12 - 2013-03-06 09:29 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2013-07-24 14:12 - 2013-03-06 08:03 - 17561600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-07-24 14:12 - 2013-03-06 08:03 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-07-24 14:04 - 2013-06-12 02:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-24 14:04 - 2013-06-12 02:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-24 14:04 - 2013-06-12 02:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-24 14:04 - 2013-06-12 02:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-24 14:04 - 2013-06-12 02:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-24 14:04 - 2013-06-12 02:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-24 14:04 - 2013-06-12 02:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-24 14:04 - 2013-06-12 02:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-24 14:04 - 2013-06-12 02:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-24 14:03 - 2013-06-12 02:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-24 14:03 - 2013-06-12 02:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-24 14:03 - 2013-06-12 02:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-24 14:03 - 2013-06-12 02:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-24 14:03 - 2013-06-12 02:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-24 14:03 - 2013-06-12 02:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-24 14:03 - 2013-04-29 01:28 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-07-24 14:03 - 2013-02-21 13:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-24 14:03 - 2013-02-21 13:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-24 14:03 - 2013-02-19 12:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2013-07-24 14:02 - 2013-06-12 02:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-24 14:02 - 2013-06-12 02:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-24 14:02 - 2013-05-16 01:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-07-24 14:02 - 2013-05-16 01:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2013-07-24 14:02 - 2013-05-14 16:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-24 14:02 - 2013-05-14 12:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-24 14:02 - 2013-02-21 13:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-24 14:02 - 2013-02-21 13:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-24 14:02 - 2013-02-21 13:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-24 14:02 - 2013-02-21 13:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-24 14:02 - 2012-11-08 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-24 14:02 - 2012-11-08 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-24 14:01 - 2013-05-04 09:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-24 14:01 - 2013-05-04 07:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-24 14:01 - 2013-04-27 08:20 - 00733184 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-07-24 14:00 - 2013-03-15 03:17 - 00861184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2013-07-24 14:00 - 2012-11-03 08:26 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\dpnsvr.exe 2013-07-24 14:00 - 2012-11-03 08:26 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnsvr.exe 2013-07-24 14:00 - 2012-11-03 08:24 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dpnathlp.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnathlp.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\dpnhupnp.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\dpnhpast.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnhupnp.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnhpast.dll 2013-07-24 14:00 - 2012-11-03 08:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dpnlobby.dll 2013-07-24 14:00 - 2012-11-03 08:04 - 00003584 _____ (Microsoft Corporation) C:\Windows\system32\dpnaddr.dll 2013-07-24 14:00 - 2012-11-03 08:00 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnlobby.dll 2013-07-24 14:00 - 2012-11-03 08:00 - 00002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnaddr.dll 2013-07-24 13:51 - 2012-12-16 11:08 - 00362496 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-07-24 13:51 - 2012-12-16 10:57 - 00300032 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-07-24 13:50 - 2012-12-16 11:28 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-07-24 13:50 - 2012-12-16 11:20 - 00035328 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-07-24 13:50 - 2012-11-08 07:24 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-07-24 13:50 - 2012-11-08 07:24 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-07-24 13:50 - 2012-11-08 07:20 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-07-24 13:50 - 2012-11-08 07:20 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-07-24 13:50 - 2012-11-08 07:02 - 00003072 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-07-24 13:50 - 2012-11-08 07:01 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-07-24 02:50 - 2013-04-09 08:33 - 00489576 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2013-07-24 02:50 - 2013-04-09 08:33 - 00446792 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2013-07-24 02:50 - 2013-04-09 08:33 - 00253544 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2013-07-24 02:50 - 2013-04-09 08:20 - 00306952 _____ (Microsoft Corporation) C:\Windows\system32\kd_02_10ec.dll 2013-07-24 02:50 - 2013-04-09 08:20 - 00086280 _____ (Microsoft Corporation) C:\Windows\system32\kdnet.dll 2013-07-24 02:50 - 2013-04-09 08:18 - 00077960 _____ (Microsoft Corporation) C:\Windows\system32\kdvm.dll 2013-07-24 02:50 - 2013-04-09 08:17 - 01829408 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-07-24 02:50 - 2013-04-09 07:52 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2013-07-24 02:50 - 2013-04-09 07:52 - 00804352 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe 2013-07-24 02:50 - 2013-04-09 07:52 - 00373760 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2013-07-24 02:50 - 2013-04-09 07:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2013-07-24 02:50 - 2013-04-09 07:52 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe 2013-07-24 02:50 - 2013-04-09 07:51 - 14267904 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-07-24 02:50 - 2013-04-09 07:51 - 03552768 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2013-07-24 02:50 - 2013-04-09 07:51 - 00595456 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll 2013-07-24 02:50 - 2013-04-09 07:51 - 00456704 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll 2013-07-24 02:50 - 2013-04-09 07:51 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll 2013-07-24 02:50 - 2013-04-09 07:51 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-07-24 02:50 - 2013-04-09 07:51 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 02107904 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 01285632 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00745984 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00435200 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\GenuineCenter.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 01444864 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00817152 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\fhengine.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\iuilp.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\dmvdsitf.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\fmifs.dll 2013-07-24 02:50 - 2013-04-09 07:48 - 00169472 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll 2013-07-24 02:50 - 2013-04-09 05:34 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys 2013-07-24 02:50 - 2013-04-09 05:33 - 00623104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2013-07-24 02:50 - 2013-04-09 05:33 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys 2013-07-24 02:50 - 2013-04-09 05:32 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2013-07-24 02:50 - 2013-04-09 05:31 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2013-07-24 02:50 - 2013-04-09 05:31 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys 2013-07-24 02:50 - 2013-04-09 02:44 - 00123880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll 2013-07-24 02:50 - 2013-04-09 02:39 - 01408896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-07-24 02:50 - 2013-04-09 02:37 - 00426024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2013-07-24 02:50 - 2013-04-09 02:37 - 00324368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2013-07-24 02:50 - 2013-04-09 00:52 - 11878912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-07-24 02:50 - 2013-04-09 00:52 - 00670208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2013-07-24 02:50 - 2013-04-09 00:52 - 00302592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2013-07-24 02:50 - 2013-04-09 00:52 - 00171008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2013-07-24 02:50 - 2013-04-09 00:52 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe 2013-07-24 02:50 - 2013-04-09 00:51 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 01593344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 01113600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00659456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00411136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00403968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00214528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00155648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2013-07-24 02:50 - 2013-04-05 02:30 - 00503080 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2013-07-24 02:50 - 2013-03-16 01:05 - 00298456 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll 2013-07-24 02:50 - 2013-03-16 01:05 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll 2013-07-24 02:50 - 2013-03-02 13:39 - 00069864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys 2013-07-24 02:50 - 2013-03-02 05:43 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2013-07-24 02:50 - 2013-02-07 04:33 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2013-07-24 02:50 - 2013-02-02 11:40 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsRasterService.dll 2013-07-24 02:50 - 2013-02-02 11:23 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll 2013-07-24 02:50 - 2013-01-10 04:40 - 00303848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-07-24 02:50 - 2012-11-20 07:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidi2c.sys 2013-07-24 02:50 - 2012-11-06 10:33 - 00522640 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2013-07-24 02:50 - 2012-11-06 08:00 - 00463768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2013-07-24 02:50 - 2012-11-06 07:18 - 00267264 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2013-07-24 02:50 - 2012-10-11 08:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2013-07-24 02:50 - 2012-10-11 08:44 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2013-07-24 02:50 - 2012-10-11 08:06 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2013-07-24 02:50 - 2012-10-11 08:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2013-07-24 02:49 - 2012-12-13 07:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-07-24 02:49 - 2012-12-13 06:59 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-07-24 02:48 - 2013-01-29 04:57 - 00035232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2013-07-24 02:48 - 2013-01-29 02:08 - 00230904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2013-07-24 02:48 - 2012-11-01 07:41 - 01802240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2013-07-24 02:48 - 2012-11-01 07:41 - 01438720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2013-07-24 02:48 - 2012-11-01 07:40 - 02361344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2013-07-24 02:48 - 2012-11-01 07:40 - 01836032 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2013-07-24 02:48 - 2012-11-01 07:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2013-07-24 02:48 - 2012-11-01 07:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2013-07-24 02:48 - 2012-11-01 07:20 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2013-07-24 02:48 - 2012-11-01 07:20 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2013-07-24 02:34 - 2013-07-24 02:34 - 00001162 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk |
12.08.2013, 10:40 | #8 |
| Ransomware (bprotector) entfernen, aber wie? 2013-07-24 02:32 - 2013-07-24 02:33 - 05487912 _____ (TeamViewer GmbH) C:\Users\jessi_000\Downloads\TeamViewer_Setup_de_8.0.19617.exe 2013-07-24 01:00 - 2013-07-24 02:16 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\TeamViewer 2013-07-24 00:44 - 2013-07-24 00:44 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-07-23 22:43 - 2013-07-23 22:43 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-23 22:05 - 2013-08-11 22:03 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Iminent 2013-07-23 22:05 - 2013-08-11 22:03 - 00000000 ____D C:\ProgramData\Iminent 2013-07-23 22:05 - 2013-07-23 22:05 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-23 22:05 - 2013-07-23 22:05 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-23 22:04 - 2013-08-11 22:03 - 00000000 ____D C:\ProgramData\BrowserDefender 2013-07-23 22:04 - 2013-07-23 22:04 - 00000000 ____D C:\ProgramData\Babylon 2013-07-23 22:04 - 2013-07-23 22:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-23 00:54 - 2013-07-25 15:35 - 00000000 ___RD C:\Windows\BrowserChoice 2013-07-22 23:01 - 2013-08-12 09:49 - 00403456 ___SH C:\Users\jessi_000\Downloads\Thumbs.db 2013-07-21 16:03 - 2013-08-04 22:27 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log 2013-07-21 16:03 - 2013-08-04 17:10 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2013-07-21 15:17 - 2013-07-21 15:17 - 00000000 ____D C:\Users\Public\CyberLink 2013-07-21 01:13 - 2013-08-11 19:48 - 00003934 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F1CED133-BBD8-4711-A46A-9337410EB9F1} 2013-07-21 01:11 - 2013-07-21 01:11 - 00001890 _____ C:\Users\jessi_000\Downloads\EverydayArt.theme 2013-07-21 01:10 - 2013-07-21 01:10 - 10652531 _____ C:\Users\jessi_000\Downloads\MomentsCaptured_RishAgarwal.themepack 2013-07-21 01:09 - 2013-07-21 01:10 - 13704881 _____ C:\Users\jessi_000\Downloads\CoastalGermanyFrankHojenski.themepack 2013-07-21 01:07 - 2013-07-21 01:07 - 13054133 _____ C:\Users\jessi_000\Downloads\Moonlight.themepack 2013-07-21 01:07 - 2013-07-21 01:07 - 03271810 _____ C:\Users\jessi_000\Downloads\Spain.themepack 2013-07-21 00:52 - 2013-07-21 00:52 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2013-07-21 00:40 - 2013-08-05 20:32 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\PhotoScape 2013-07-21 00:40 - 2013-07-21 00:40 - 00001031 _____ C:\Users\jessi_000\Desktop\PhotoScape.lnk 2013-07-21 00:39 - 2013-07-21 00:40 - 00000000 ____D C:\Program Files (x86)\PhotoScape 2013-07-20 23:00 - 2013-08-09 17:33 - 00744960 ___SH C:\Users\jessi_000\Desktop\Thumbs.db 2013-07-20 22:48 - 2013-07-20 22:48 - 00000000 ___RD C:\Users\jessi_000\SkyDrive 2013-07-20 22:34 - 2013-07-20 22:34 - 01351264 _____ C:\Windows\NIRMALA.tt2 2013-07-20 22:34 - 2013-07-20 22:34 - 01303396 _____ C:\Windows\NIRMALAB.tt2 2013-07-20 22:32 - 2013-07-20 22:33 - 00000000 ____D C:\Program Files\Microsoft Office 15 2013-07-20 22:32 - 2013-07-20 22:32 - 00574656 _____ (Microsoft Corporation) C:\Users\jessi_000\Downloads\Setup.X86.de-DE_O365HomePremRetail_56ca86e8-6e39-4f60-abb7-5d90325e1dad_TX_DB_.exe 2013-07-20 22:26 - 2013-07-20 22:27 - 15929873 _____ C:\Users\jessi_000\Downloads\Rückblick_9b2012-13.pptx 2013-07-20 22:17 - 2013-07-20 22:17 - 00001255 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky PURE 3.0.lnk 2013-07-20 22:16 - 2013-07-20 22:16 - 00001078 _____ C:\Users\Public\Desktop\Kaspersky PURE 3.0.lnk 2013-07-20 22:16 - 2012-07-11 18:09 - 00064856 _____ (Kaspersky Lab) C:\Windows\system32\klfphc.dll 2013-07-20 22:15 - 2013-08-11 23:50 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-07-20 22:15 - 2013-07-20 22:50 - 00619616 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2013-07-20 22:15 - 2013-07-20 22:50 - 00090208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2013-07-20 22:15 - 2013-07-20 22:15 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2013-07-20 22:15 - 2012-12-10 16:14 - 00098064 _____ (Infowatch) C:\Windows\system32\Drivers\CSCrySec.sys 2013-07-20 22:15 - 2012-12-10 16:14 - 00067344 _____ (Infowatch) C:\Windows\system32\Drivers\CSVirtualDiskDrv.sys 2013-07-20 21:50 - 2013-08-04 21:56 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\hpqlog 2013-07-20 21:49 - 2013-08-12 10:54 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-20 21:49 - 2013-08-11 22:06 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-20 21:49 - 2013-07-31 18:56 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-20 21:49 - 2013-07-20 21:50 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Google 2013-07-20 21:49 - 2013-07-20 21:49 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-20 21:49 - 2013-07-20 21:49 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-20 21:49 - 2013-07-20 21:49 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-20 21:48 - 2013-07-20 21:49 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Deployment 2013-07-20 21:48 - 2013-07-20 21:48 - 00000000 ____D C:\Users\jessi_000\AppData\Local\Apps\2.0 2013-07-20 14:54 - 2013-08-11 15:51 - 00000000 ____D C:\Users\jessi_000\Documents\Youcam 2013-07-20 14:54 - 2013-08-04 22:25 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\CyberLink 2013-07-20 14:54 - 2013-08-04 17:06 - 00001227 _____ C:\Users\jessi_000\Desktop\CyberLink YouCam(Webcam).lnk 2013-07-20 14:54 - 2013-07-20 14:54 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\CyberLink 2013-07-20 14:36 - 2013-08-12 00:14 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2077869928-1068183206-618238599-1001 2013-07-20 14:32 - 2013-07-20 14:32 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Macromedia 2013-07-20 14:31 - 2013-07-25 23:59 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-07-20 14:31 - 2013-07-25 23:59 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-07-20 14:31 - 2013-07-20 23:46 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Hewlett-Packard 2013-07-20 14:31 - 2013-07-20 14:31 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-07-20 14:31 - 2013-07-20 14:31 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Synaptics 2013-07-20 14:30 - 2013-07-30 20:34 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Adobe 2013-07-20 14:30 - 2013-07-20 14:30 - 00001438 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-07-20 14:29 - 2013-07-20 14:29 - 00000141 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2013-07-20 14:29 - 2013-07-20 14:29 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Power2Go8 2013-07-20 14:28 - 2013-07-21 00:31 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Hewlett-Packard 2013-07-20 14:28 - 2013-07-20 22:33 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\VirtualStore 2013-07-20 14:27 - 2013-08-11 17:30 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Packages 2013-07-20 14:27 - 2013-08-04 22:24 - 00000000 ____D C:\Users\jessi_000 2013-07-20 14:27 - 2013-07-20 22:48 - 00002286 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2013-07-20 14:27 - 2013-07-20 14:27 - 00000020 ___SH C:\Users\jessi_000\ntuser.ini 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Vorlagen 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Startmenü 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Netzwerkumgebung 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Lokale Einstellungen 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Eigene Dateien 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Druckumgebung 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Documents\Eigene Musik 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Documents\Eigene Bilder 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Anwendungsdaten 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\JESSI_~1\AppData\Local\Verlauf 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\JESSI_~1\AppData\Local\Anwendungsdaten 2013-07-20 14:27 - 2012-10-27 19:32 - 00000000 ___HD C:\Users\jessi_000\Documents\hp.system.package.metadata 2013-07-20 14:27 - 2012-07-26 11:13 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2013-07-20 14:27 - 2012-07-26 11:13 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-07-20 14:27 - 2012-07-26 11:13 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2013-07-20 14:27 - 2012-07-26 11:13 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Programme 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Dokumente und Einstellungen ==================== One Month Modified Files and Folders ======= 2013-08-12 11:14 - 2013-08-12 11:14 - 00000000 ____D C:\FRST 2013-08-12 11:02 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\sru 2013-08-12 10:54 - 2013-07-20 21:49 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-12 09:49 - 2013-07-22 23:01 - 00403456 ___SH C:\Users\jessi_000\Downloads\Thumbs.db 2013-08-12 00:14 - 2013-07-20 14:36 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2077869928-1068183206-618238599-1001 2013-08-11 23:50 - 2013-07-20 22:15 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-08-11 23:35 - 2013-08-11 23:35 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\IObit 2013-08-11 23:12 - 2013-08-11 17:32 - 00000000 ____D C:\Program Files (x86)\Exterminate It! 2013-08-11 22:13 - 2012-10-28 04:48 - 00831158 _____ C:\Windows\system32\perfh007.dat 2013-08-11 22:13 - 2012-10-28 04:48 - 00188760 _____ C:\Windows\system32\perfc007.dat 2013-08-11 22:13 - 2012-07-26 10:28 - 01952854 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-11 22:06 - 2013-07-20 21:49 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-11 22:06 - 2012-07-26 10:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-11 22:05 - 2013-07-25 23:53 - 00102576 _____ C:\Windows\PFRO.log 2013-08-11 22:05 - 2012-07-26 08:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-08-11 22:03 - 2013-07-23 22:05 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Iminent 2013-08-11 22:03 - 2013-07-23 22:05 - 00000000 ____D C:\ProgramData\Iminent 2013-08-11 22:03 - 2013-07-23 22:04 - 00000000 ____D C:\ProgramData\BrowserDefender 2013-08-11 21:10 - 2013-08-11 21:10 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Malwarebytes 2013-08-11 21:07 - 2013-08-11 21:07 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-11 21:07 - 2013-08-11 21:07 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-11 21:07 - 2013-08-11 21:07 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-11 20:37 - 2013-07-25 14:45 - 01606003 _____ C:\Windows\WindowsUpdate.log 2013-08-11 20:15 - 2012-12-28 11:53 - 00000000 ____D C:\ProgramData\CyberLink 2013-08-11 19:48 - 2013-07-21 01:13 - 00003934 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F1CED133-BBD8-4711-A46A-9337410EB9F1} 2013-08-11 17:54 - 2013-08-11 17:54 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Curiolab 2013-08-11 17:37 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-08-11 17:32 - 2013-08-11 17:32 - 00001081 _____ C:\Users\jessi_000\Desktop\Exterminate It!.lnk 2013-08-11 17:30 - 2013-07-20 14:27 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Packages 2013-08-11 17:14 - 2013-08-11 17:14 - 00000000 ____D C:\Encryption 2013-08-11 16:52 - 2012-12-28 11:36 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-08-11 15:58 - 2013-08-11 15:57 - 00000000 ____D C:\Users\jessi_000\Desktop\programme 2013-08-11 15:51 - 2013-07-20 14:54 - 00000000 ____D C:\Users\jessi_000\Documents\Youcam 2013-08-10 19:16 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\NDF 2013-08-09 17:33 - 2013-07-20 23:00 - 00744960 ___SH C:\Users\jessi_000\Desktop\Thumbs.db 2013-08-05 20:32 - 2013-07-21 00:40 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\PhotoScape 2013-08-04 22:27 - 2013-07-21 16:03 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log 2013-08-04 22:26 - 2013-08-04 22:26 - 00000902 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-04 22:25 - 2013-07-20 14:54 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\CyberLink 2013-08-04 22:24 - 2013-07-20 14:27 - 00000000 ____D C:\Users\jessi_000 2013-08-04 22:21 - 2012-08-04 03:02 - 00000000 ____D C:\SWSetup 2013-08-04 21:56 - 2013-07-20 21:50 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\hpqlog 2013-08-04 21:52 - 2012-12-28 11:51 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2013-08-04 21:52 - 2012-12-28 11:51 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2013-08-04 21:52 - 2012-12-28 11:51 - 00029480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll 2013-08-04 21:52 - 2012-10-27 19:35 - 00000000 ____D C:\Program Files (x86)\CyberLink 2013-08-04 21:01 - 2013-08-04 20:58 - 00000000 ____D C:\Windows\LastGood.Tmp 2013-08-04 21:01 - 2012-10-27 19:32 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard 2013-08-04 21:01 - 2012-09-19 05:56 - 00000000 ____D C:\Program Files\Hewlett-Packard 2013-08-04 20:58 - 2013-08-04 20:57 - 00006762 _____ C:\Windows\DPINST.LOG 2013-08-04 20:58 - 2013-08-04 20:57 - 00001332 _____ C:\Windows\Synaptics.log 2013-08-04 20:58 - 2013-07-30 18:40 - 00003782 _____ C:\Windows\setupact.log 2013-08-04 20:56 - 2013-08-04 20:57 - 01060080 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll 2013-08-04 20:56 - 2013-08-04 20:57 - 00544496 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCom.dll 2013-08-04 20:56 - 2013-08-04 20:57 - 00495856 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys 2013-08-04 20:56 - 2013-08-04 20:57 - 00264432 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2013-08-04 20:56 - 2013-08-04 20:57 - 00192240 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo18.dll 2013-08-04 20:56 - 2013-08-04 20:57 - 00151280 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynTPCom.dll 2013-08-04 20:56 - 2013-08-04 20:57 - 00033008 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\Smb_driver_Intel.sys 2013-08-04 20:28 - 2013-08-04 20:28 - 00003154 _____ C:\Windows\System32\Tasks\MirageAgent 2013-08-04 20:27 - 2013-08-04 20:27 - 00000000 ___HD C:\Users\Public\Documents\YouCam 2013-08-04 19:47 - 2013-08-04 19:47 - 00003166 _____ C:\Windows\System32\Tasks\CLVDLauncher 2013-08-04 19:47 - 2013-08-04 19:47 - 00003166 _____ C:\Windows\System32\Tasks\CLMLSvc_P2G8 2013-08-04 17:10 - 2013-07-21 16:03 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2013-08-04 17:06 - 2013-07-20 14:54 - 00001227 _____ C:\Users\jessi_000\Desktop\CyberLink YouCam(Webcam).lnk 2013-08-03 21:31 - 2013-08-03 21:31 - 10644535 _____ C:\Users\jessi_000\Downloads\WhatsApp.apk 2013-08-03 21:17 - 2013-08-03 21:17 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Windows Live 2013-08-03 21:16 - 2013-08-03 21:16 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\DivX 2013-08-02 16:08 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\rescache 2013-08-01 22:31 - 2013-07-30 23:08 - 00020480 ____H C:\Users\jessi_000\Desktop\photothumb.db 2013-07-31 18:56 - 2013-07-20 21:49 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-31 15:39 - 2013-07-31 15:38 - 00000000 ____D C:\Windows\system32\MRT 2013-07-31 13:51 - 2013-07-31 13:50 - 00449736 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-30 23:10 - 2013-07-30 23:10 - 00000000 ____D C:\output 2013-07-30 20:35 - 2013-07-30 20:35 - 00000566 _____ C:\Users\Public\Desktop\Pixlr-o-matic.lnk 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Pixlromatic 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\ProgramData\Adobe 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-30 20:34 - 2013-07-20 14:30 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Adobe 2013-07-30 20:25 - 2013-07-30 20:23 - 145394418 _____ C:\Users\JESSI_~1\AppData\Local\ACCCx189.zip.aamdownload 2013-07-30 20:25 - 2013-07-30 20:23 - 00001811 _____ C:\Users\JESSI_~1\AppData\Local\ACCCx189.zip.aamdownload.aamd 2013-07-30 20:22 - 2013-07-30 20:22 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Adobe 2013-07-30 20:21 - 2013-07-30 20:20 - 03867000 _____ (Adobe Systems Incorporated) C:\Users\jessi_000\Downloads\CreativeCloudSet-Up.exe 2013-07-30 20:07 - 2013-07-30 20:05 - 00000000 ____D C:\Users\jessi_000\Desktop\Musik 2013-07-30 18:40 - 2013-07-30 18:40 - 00000000 _____ C:\Windows\setuperr.log 2013-07-30 18:34 - 2012-07-26 11:12 - 00000000 ___RD C:\Windows\ToastData 2013-07-29 17:29 - 2013-07-29 17:29 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\WebApp 2013-07-29 17:25 - 2013-07-29 17:25 - 00000000 ____D C:\Users\jessi_000\Documents\CyberLink 2013-07-25 23:59 - 2013-07-20 14:31 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-07-25 23:59 - 2013-07-20 14:31 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-07-25 23:56 - 2012-07-26 08:37 - 00000000 ____D C:\Windows\servicing 2013-07-25 15:40 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-07-25 15:39 - 2012-10-28 04:52 - 00000000 ____D C:\Windows\en-GB 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ___RD C:\Windows\ImmersiveControlPanel 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\WinStore 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\MUI 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\migwiz 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\inetsrv 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\en-GB 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\Com 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\migwiz 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\en-GB 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files\Common Files\System 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-25 15:39 - 2012-07-26 10:52 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\SysWOW64\winrm 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\SysWOW64\WCN 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\SysWOW64\sysprep 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\SysWOW64\slmgr 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\system32\winrm 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\system32\slmgr 2013-07-25 15:39 - 2012-07-26 08:38 - 00000000 ____D C:\Windows\SysWOW64\oobe 2013-07-25 15:39 - 2012-07-26 08:38 - 00000000 ____D C:\Windows\SysWOW64\Dism 2013-07-25 15:39 - 2012-07-26 08:38 - 00000000 ____D C:\Windows\system32\Sysprep 2013-07-25 15:39 - 2012-07-26 08:38 - 00000000 ____D C:\Windows\system32\oobe 2013-07-25 15:38 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\inetsrv 2013-07-25 15:37 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\MUI 2013-07-25 15:37 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\system32\WCN 2013-07-25 15:37 - 2012-07-26 08:38 - 00000000 ____D C:\Windows\system32\Dism 2013-07-25 15:36 - 2013-07-25 15:36 - 00000000 ____D C:\sources 2013-07-25 15:36 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\SystemResetPlatform 2013-07-25 15:36 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\Com 2013-07-25 15:36 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2013-07-25 15:35 - 2013-07-23 00:54 - 00000000 ___RD C:\Windows\BrowserChoice 2013-07-25 14:32 - 2013-07-25 14:32 - 00001274 _____ C:\Users\jessi_000\Desktop\shutdown.lnk 2013-07-25 13:54 - 2013-07-25 13:54 - 00000546 _____ C:\Users\jessi_000\Desktop\Emsisoft Emergency Kit.lnk 2013-07-25 13:54 - 2013-07-25 13:54 - 00000000 ____D C:\EEK 2013-07-25 13:51 - 2013-07-25 13:51 - 00082976 _____ C:\Users\jessi_000\Documents\cc_20130725_125126.reg 2013-07-25 13:50 - 2012-08-04 02:21 - 00000000 ____D C:\Windows\Panther 2013-07-25 13:49 - 2013-07-25 13:49 - 00002780 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-07-25 13:48 - 2013-07-25 13:48 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-07-25 13:48 - 2013-07-25 13:48 - 00000000 ____D C:\Program Files\CCleaner 2013-07-25 13:44 - 2013-07-25 13:44 - 04396440 _____ (Piriform Ltd) C:\Users\jessi_000\Desktop\ccsetup403.exe 2013-07-25 13:43 - 2013-07-25 13:40 - 181531216 _____ C:\Users\jessi_000\Downloads\EmsisoftEmergencyKit40012.exe 2013-07-25 00:25 - 2013-07-25 00:25 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\DDMSettings 2013-07-25 00:24 - 2013-07-25 00:23 - 00000000 ____D C:\Program Files\DivX 2013-07-25 00:24 - 2013-07-25 00:21 - 00000000 ____D C:\ProgramData\DivX 2013-07-25 00:24 - 2013-07-25 00:21 - 00000000 ____D C:\Program Files (x86)\DivX 2013-07-25 00:21 - 2013-07-25 00:21 - 00957248 _____ (DivX, LLC) C:\Users\jessi_000\Downloads\DivXWebPlayerInstaller.exe 2013-07-25 00:21 - 2013-07-25 00:21 - 00000000 _____ C:\END 2013-07-24 02:34 - 2013-07-24 02:34 - 00001162 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk 2013-07-24 02:33 - 2013-07-24 02:32 - 05487912 _____ (TeamViewer GmbH) C:\Users\jessi_000\Downloads\TeamViewer_Setup_de_8.0.19617.exe 2013-07-24 02:22 - 2012-07-26 11:12 - 00000000 __RHD C:\Users\Public\Libraries 2013-07-24 02:22 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\WinMetadata 2013-07-24 02:22 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\Bthprops 2013-07-24 02:22 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\Bthprops 2013-07-24 02:22 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\L2Schemas 2013-07-24 02:20 - 2012-10-28 04:47 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2013-07-24 02:16 - 2013-07-24 01:00 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\TeamViewer 2013-07-24 02:09 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\registration 2013-07-24 00:44 - 2013-07-24 00:44 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-07-23 22:43 - 2013-07-23 22:43 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-23 22:05 - 2013-07-23 22:05 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-23 22:05 - 2013-07-23 22:05 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-23 22:04 - 2013-07-23 22:04 - 00000000 ____D C:\ProgramData\Babylon 2013-07-23 22:04 - 2013-07-23 22:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-23 21:42 - 2012-08-04 01:29 - 00000000 ____D C:\ProgramData\PRICache 2013-07-21 20:02 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\restore 2013-07-21 15:17 - 2013-07-21 15:17 - 00000000 ____D C:\Users\Public\CyberLink 2013-07-21 01:11 - 2013-07-21 01:11 - 00001890 _____ C:\Users\jessi_000\Downloads\EverydayArt.theme 2013-07-21 01:10 - 2013-07-21 01:10 - 10652531 _____ C:\Users\jessi_000\Downloads\MomentsCaptured_RishAgarwal.themepack 2013-07-21 01:10 - 2013-07-21 01:09 - 13704881 _____ C:\Users\jessi_000\Downloads\CoastalGermanyFrankHojenski.themepack 2013-07-21 01:07 - 2013-07-21 01:07 - 13054133 _____ C:\Users\jessi_000\Downloads\Moonlight.themepack 2013-07-21 01:07 - 2013-07-21 01:07 - 03271810 _____ C:\Users\jessi_000\Downloads\Spain.themepack 2013-07-21 00:52 - 2013-07-21 00:52 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2013-07-21 00:40 - 2013-07-21 00:40 - 00001031 _____ C:\Users\jessi_000\Desktop\PhotoScape.lnk 2013-07-21 00:40 - 2013-07-21 00:39 - 00000000 ____D C:\Program Files (x86)\PhotoScape 2013-07-21 00:31 - 2013-07-20 14:28 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Hewlett-Packard 2013-07-20 23:46 - 2013-07-20 14:31 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Hewlett-Packard 2013-07-20 22:50 - 2013-07-20 22:15 - 00619616 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2013-07-20 22:50 - 2013-07-20 22:15 - 00090208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2013-07-20 22:50 - 2012-10-23 16:45 - 00050448 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klwfp.sys 2013-07-20 22:50 - 2012-08-13 17:49 - 00178448 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2013-07-20 22:48 - 2013-07-20 22:48 - 00000000 ___RD C:\Users\jessi_000\SkyDrive 2013-07-20 22:48 - 2013-07-20 14:27 - 00002286 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2013-07-20 22:48 - 2012-10-27 19:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-07-20 22:34 - 2013-07-20 22:34 - 01351264 _____ C:\Windows\NIRMALA.tt2 2013-07-20 22:34 - 2013-07-20 22:34 - 01303396 _____ C:\Windows\NIRMALAB.tt2 2013-07-20 22:33 - 2013-07-20 22:32 - 00000000 ____D C:\Program Files\Microsoft Office 15 2013-07-20 22:33 - 2013-07-20 14:28 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\VirtualStore 2013-07-20 22:32 - 2013-07-20 22:32 - 00574656 _____ (Microsoft Corporation) C:\Users\jessi_000\Downloads\Setup.X86.de-DE_O365HomePremRetail_56ca86e8-6e39-4f60-abb7-5d90325e1dad_TX_DB_.exe 2013-07-20 22:27 - 2013-07-20 22:26 - 15929873 _____ C:\Users\jessi_000\Downloads\Rückblick_9b2012-13.pptx 2013-07-20 22:17 - 2013-07-20 22:17 - 00001255 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky PURE 3.0.lnk 2013-07-20 22:16 - 2013-07-20 22:16 - 00001078 _____ C:\Users\Public\Desktop\Kaspersky PURE 3.0.lnk 2013-07-20 22:16 - 2012-07-26 08:26 - 00262144 ___SH C:\Windows\system32\config\ELAM 2013-07-20 22:15 - 2013-07-20 22:15 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2013-07-20 22:15 - 2012-07-26 11:12 - 00000000 ___HD C:\Windows\ELAMBKUP 2013-07-20 22:12 - 2012-12-28 12:00 - 00000000 ____D C:\ProgramData\Norton 2013-07-20 21:50 - 2013-07-20 21:49 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Google 2013-07-20 21:49 - 2013-07-20 21:49 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-20 21:49 - 2013-07-20 21:49 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-20 21:49 - 2013-07-20 21:49 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-20 21:49 - 2013-07-20 21:48 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Deployment 2013-07-20 21:48 - 2013-07-20 21:48 - 00000000 ____D C:\Users\jessi_000\AppData\Local\Apps\2.0 2013-07-20 14:54 - 2013-07-20 14:54 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\CyberLink 2013-07-20 14:34 - 2012-12-28 11:34 - 00002887 _____ C:\Windows\system32\RaCoInst.log 2013-07-20 14:32 - 2013-07-20 14:32 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Macromedia 2013-07-20 14:31 - 2013-07-20 14:31 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-07-20 14:31 - 2013-07-20 14:31 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Synaptics 2013-07-20 14:30 - 2013-07-20 14:30 - 00001438 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-07-20 14:30 - 2012-10-27 19:46 - 00000000 ___RD C:\Program Files\Online Services 2013-07-20 14:30 - 2012-10-27 19:45 - 00000000 ___RD C:\Program Files (x86)\Online Services 2013-07-20 14:30 - 2012-08-04 03:02 - 00000000 ___HD C:\SYSTEM.SAV 2013-07-20 14:29 - 2013-07-20 14:29 - 00000141 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2013-07-20 14:29 - 2013-07-20 14:29 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Power2Go8 2013-07-20 14:27 - 2013-07-20 14:27 - 00000020 ___SH C:\Users\jessi_000\ntuser.ini 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Vorlagen 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Startmenü 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Netzwerkumgebung 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Lokale Einstellungen 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Eigene Dateien 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Druckumgebung 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Documents\Eigene Musik 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Documents\Eigene Bilder 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Anwendungsdaten 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\JESSI_~1\AppData\Local\Verlauf 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\JESSI_~1\AppData\Local\Anwendungsdaten 2013-07-20 14:26 - 2012-10-27 19:46 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Programme 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Dokumente und Einstellungen 2013-07-20 13:19 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files\Windows NT 2013-07-20 13:19 - 2012-07-26 08:37 - 00000000 __RHD C:\Users\Default ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-11 16:50 ==================== End Of Log ============================ [/CODE] und, additional: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2013 02 Ran by at 2013-08-12 11:16:14 Running from C:\Users\jessi_000\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2W4Z2ZE Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe AIR (x32 Version: 3.8.0.870) Adobe Shockwave Player 11.6 (x32 Version: 11.6.6.636) Bonjour (Version: 3.0.0.10) Connected Music powered by Universal Music Group version 1.0 (x32 Version: 1.0) CyberLink LabelPrint (x32 Version: 2.5.3.6326) CyberLink Media Suite 10 (x32 Version: 10.0.3.2608) CyberLink PhotoDirector (x32 Version: 2.0.2.3317) CyberLink Power2Go 8 (x32 Version: 8.0.3.2527) CyberLink PowerDirector 10 (x32 Version: 10.0.2.2126) CyberLink PowerDVD (x32 Version: 10.0.6.4319) CyberLink YouCam (x32 Version: 3.5.6.6119) D3DX10 (x32 Version: 15.4.2368.0902) DivX-Setup (x32 Version: 2.6.1.44) eaner (Version: 4.03) Energy Star (x32 Version: 1.0.9) Exterminate It! (x32 Version: 1.76.05.25) Fotogalerie (x32 Version: 16.4.3503.0728) Google Chrome (x32 Version: 28.0.1500.95) Google Update Helper (x32 Version: 1.3.21.153) Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000) HP 3D DriveGuard (Version: 4.2.9.1) HP Connected Music (Meridian - installer) (x32 Version: v1.0) HP Connected Music (Meridian - player) (HKCU Version: 1.1 (build 57) hp) HP Connected Remote (x32 Version: 1.0.1218) HP CoolSense (x32 Version: 2.10.51) HP Customer Experience Enhancements (x32 Version: 6.0.1.7) HP Documentation (x32 Version: 1.2.0.0) HP Postscript Converter (Version: 3.1.3591) HP Quick Launch (x32 Version: 3.0.6) HP Recovery Manager (x32 Version: 8.00) HP Registration Service (Version: 1.1.6232.4245) HP Support Assistant (x32 Version: 7.0.39.15) HP Utility Center (x32 Version: 1.0.8) HP Wireless Button Driver (x32 Version: 1.0.6.1) IDT Audio (x32 Version: 1.0.6425.0) Intel(R) Control Center (x32 Version: 1.2.1.1008) Intel(R) Management Engine Components (x32 Version: 8.1.0.1252) Intel(R) Processor Graphics (x32 Version: 9.17.10.2857) Intel(R) Rapid Storage Technology (x32 Version: 11.5.9.1002) Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149) Intel® Trusted Connect Service Client (Version: 1.24.388.1) Kaspersky PURE 3.0 (x32 Version: 13.0.2.558) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 365 Home Premium - de-de (Version: 15.0.4517.1005) Microsoft SkyDrive (HKCU Version: 17.0.2003.1112) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Movie Maker (x32 Version: 16.4.3503.0728) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT110 (x32 Version: 16.4.1108.0727) MSVCRT110_amd64 (Version: 16.4.1108.0727) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4517.1005) Office 15 Click-to-Run Licensing Component (Version: 15.0.4517.1005) Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4517.1005) Photo Common (x32 Version: 16.4.3503.0728) Photo Gallery (x32 Version: 16.4.3503.0728) PhotoScape (x32) Pixlr-o-matic (x32 Version: 2.1) Ralink RT5390R 802.11bgn Wi-Fi Adapter (x32 Version: 5.0.5.0) Realtek Ethernet Controller Driver (x32 Version: 8.3.730.2012) Realtek PCIE Card Reader (x32 Version: 6.2.8400.29029) swMSM (x32 Version: 12.0.0.1) Synaptics Pointing Device Driver (Version: 16.5.3.3) TeamViewer 8 (x32 Version: 8.0.19617) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) Windows Live Communications Platform (x32 Version: 16.4.3503.0728) Windows Live Essentials (x32 Version: 16.4.3503.0728) Windows Live Installer (x32 Version: 16.4.3503.0728) Windows Live Photo Common (x32 Version: 16.4.3503.0728) Windows Live PIMT Platform (x32 Version: 16.4.3503.0728) Windows Live SOXE (x32 Version: 16.4.3503.0728) Windows Live SOXE Definitions (x32 Version: 16.4.3503.0728) Windows Live UX Platform (x32 Version: 16.4.3503.0728) Windows Live UX Platform Language Pack (x32 Version: 16.4.3503.0728) ==================== Restore Points ========================= 24-07-2013 23:25:33 Sprachpaketdeinstallation 29-07-2013 13:59:55 Windows Update 04-08-2013 16:12:50 HPSF Applying updates ==================== Hosts content: ========================== 2012-07-26 08:26 - 2012-07-26 08:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0ABD1C42-189D-4C64-B3A1-BF4238883FEB} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2077869928-1068183206-618238599-500 Task: {10D85952-E3F6-47A1-96CF-5E1C2D874EA6} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe [2012-07-26] (Microsoft Corporation) Task: {13A2AC02-B682-48CC-9155-2E2673580117} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical Task: {17644F17-DC4C-4AC8-9444-7AAA52EB5CDC} - System32\Tasks\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {1C42B7C2-F719-4567-9B4B-4D976CDAA6FA} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2012-10-28] (Microsoft Corporation) Task: {1DB7C2F1-876C-4F24-AD17-8428211113F9} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents Task: {214B24F4-FEB4-4C59-AF1F-70136065199C} - System32\Tasks\Microsoft\Windows\Shell\IndexerAutomaticMaintenance Task: {23700E5C-0E77-499D-908A-415D5C6252F4} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Group Policy Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {2C6B9EA8-7F5A-4ABA-BF96-8D352D02A743} - System32\Tasks\Microsoft\Windows\Device Setup\Metadata Refresh Task: {2E030FA7-3D7C-4E1D-8CFE-56ADB26FD402} - System32\Tasks\Microsoft\Windows\PI\Sqm-Tasks Task: {3054485A-F517-4E95-9977-4DD827B1E9B3} - System32\Tasks\Microsoft\Windows\WS\Badge Update Task: {307BFB0E-2B42-47F3-A93B-8358F5E91310} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start => C:\Windows\system32\sc.exe [2012-07-26] (Microsoft Corporation) Task: {378401BA-A703-444A-A79C-3C47AD2DC5B6} - System32\Tasks\Microsoft\Windows\TaskScheduler\Maintenance Configurator Task: {3AE164E7-30CD-40BC-9422-3EC7A5618965} - System32\Tasks\Microsoft\Windows\WS\WSTask Task: {3C490ABD-D849-41AF-9AC4-87DD759B0996} - System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem Task: {400CA0EA-F26D-4796-8CCD-A876DDF22305} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe No File Task: {4073C1B3-6E16-4AA8-B7F3-C6A6D35D5071} - System32\Tasks\Microsoft\Windows\TPM\Tpm-Maintenance Task: {44B3F1B8-5943-4072-8D8C-A9484676AC44} - System32\Tasks\Microsoft\Windows\Live\Roaming\SynchronizeWithStorage Task: {483A8F5C-5D26-44B5-B49E-AF6741D1BBEB} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\Windows\System32\MbaeParserTask.exe [2013-06-01] (Microsoft Corporation) Task: {4B952129-9AE9-41A3-BE2B-8AD2E06F66B6} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon Task: {572EDB5C-A1DD-4BEA-8E75-DC4CFDF60C0E} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {5755E746-D7ED-4C20-A472-66C11834CDE4} - System32\Tasks\Microsoft\Windows\TaskScheduler\Manual Maintenance Task: {58CC1D05-9849-40D2-B402-B0D4C6AB2169} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-09-05] (Hewlett-Packard Company) Task: {5C4EFB77-EFA6-45DF-A373-D795C0725BFF} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Reboot Required Task: {5DF14724-D1FC-4438-8349-C40A5370BE9C} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUSessionConnect Task: {627441F3-8526-4B62-BF9A-1A3EA414E71A} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask => C:\Windows\system32\SpaceAgent.exe [2012-07-26] (Microsoft Corporation) Task: {62B741FC-EF4A-4B45-858F-4B25E157D32C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {6E9DE125-5583-4031-B572-FEE48F25CFFF} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitor => C:\Windows\System32\wpcmon.exe [2012-10-28] (Microsoft Corporation) Task: {6FDDEA7C-6310-428D-AEB2-54FFC72811EF} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Task: {7290E557-6349-47F0-B358-071501CEAAE8} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUScheduledInstall Task: {74096F94-B654-4DB0-96F5-3C3408B92FE3} - System32\Tasks\Microsoft\Windows\PI\Secure-Boot-Update Task: {755DB566-CBA7-46A9-A374-108B9AFCBA0E} - System32\Tasks\User_Feed_Synchronization-{F1CED133-BBD8-4711-A46A-9337410EB9F1} => C:\Windows\system32\msfeedssync.exe [2012-07-26] (Microsoft Corporation) Task: {75A19D98-7B7B-41A1-A484-00C5AED5C581} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {7D9A9A1C-499C-40A6-8F8A-5BCC4CC9A87C} - System32\Tasks\Microsoft\Windows\TaskScheduler\Regular Maintenance Task: {83106924-7A79-43F5-8357-B2B56E70CD5E} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2013-07-20] (Microsoft Corporation) Task: {845CB020-68B5-4C6B-9876-7BEC7B3E27AC} - System32\Tasks\Microsoft\Windows\TaskScheduler\Idle Maintenance Task: {87354DAA-66DF-4B41-9346-15958D96E1D2} - System32\Tasks\Microsoft\Windows\FileHistory\File History (maintenance mode) Task: {921A1D4E-32FB-46D7-B6C0-6F467884074D} - System32\Tasks\Microsoft\Windows\WS\Sync Licenses Task: {9479EF8E-11D4-41B3-9783-CC65070D592D} - System32\Tasks\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime Task: {94DCF254-64FB-4C4E-8E12-5F4055C10C2A} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Task: {989A7C6D-BE82-4C3C-AF96-6116039E336B} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic Task: {9CB9D559-4735-4037-949E-D0CD4862D956} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {A800277E-E202-4492-AD38-3312641CBC04} - System32\Tasks\Microsoft\Windows\Live\Roaming\MaintenanceTask Task: {A90639E8-A416-4997-BD97-B363E7B3951D} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-06-10] (Microsoft Corporation) Task: {AB62FA47-2C99-44B1-A5D0-D4161423BE43} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefresh Task: {AC6259DE-AC59-459E-849E-6ADFFD1ADE63} - System32\Tasks\Microsoft\Windows\Shell\CreateObjectTask Task: {AEB0B5BD-B9E5-458A-898A-E559BD9EB51B} - System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask Task: {AF549BD8-337C-4BF7-8681-36A182E30507} - System32\Tasks\Microsoft\Windows\Chkdsk\ProactiveScan Task: {B5DFE94A-AD61-4767-AB6C-F018462532B8} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2012-07-24] (CyberLink Corp.) Task: {B643C34F-A874-46E2-96B7-5AD493A41146} - System32\Tasks\Microsoft\Windows\Servicing\StartComponentCleanup Task: {BC76AEF7-2CF0-4EB6-B65B-A8803E0B5E12} - System32\Tasks\Microsoft\Windows\AppID\SmartScreenSpecific Task: {C1ACCD1E-4385-4FB2-B5E4-7F2A57A626A2} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan Task: {C463FD1E-31C7-4C20-AB65-08E514CA152D} - System32\Tasks\Microsoft\Windows\IME\SQM data sender Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {CAACFFD2-D8FD-4A6F-9961-38915E2C8851} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-20] (Google Inc.) Task: {CD1054FF-8005-4904-8B9C-436EAB1E2021} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork Task: {CEF606A7-542B-4F6D-8307-E5202FF561C3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-20] (Google Inc.) Task: {D36BD75F-CC62-4917-8E35-BC4D1DD7A77B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {D64BB313-DD3C-431E-A836-460F9B6A7A19} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-07-29] (Hewlett-Packard) Task: {DBCF6E1B-CE0A-441E-B7A5-219C8BE50C65} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical Task: {DCF76DC8-58D9-44EE-A73C-5C905D93C423} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2077869928-1068183206-618238599-1001 Task: {DECE5921-598D-454B-9A04-B2DE95EFC1B3} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery Task: {E3602B1B-FF55-4A2A-9E31-D6368E4E4A58} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-08] (CyberLink) Task: {E4DFE66F-E089-4CC3-A70F-957223D565F4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask Task: {E8DAA09B-DF2A-4951-9134-6FA9587793F9} - System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers => C:\Windows\System32\drvinst.exe [2012-10-28] (Microsoft Corporation) Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {ED0C1F69-C3A2-41EA-B8C3-3F0D83A1F6C0} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/12/2013 10:20:08 AM) (Source: Customer Experience Improvement Program) (User: ) Description: 80070005 Error: (08/11/2013 09:19:20 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16537, Zeitstempel: 0x512347f7 Name des fehlerhaften Moduls: MSHTML.dll, Version: 10.0.9200.16635, Zeitstempel: 0x51b7b287 Ausnahmecode: 0xc0000005 Fehleroffset: 0x006faf2d ID des fehlerhaften Prozesses: 0x1264 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Vollständiger Name des fehlerhaften Pakets: IEXPLORE.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: IEXPLORE.EXE5 Error: (08/11/2013 05:21:24 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 203109 Error: (08/11/2013 05:21:24 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 203109 Error: (08/11/2013 05:21:24 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/11/2013 05:21:08 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 187484 Error: (08/11/2013 05:21:08 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 187484 Error: (08/11/2013 05:21:08 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/11/2013 05:20:52 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 171859 Error: (08/11/2013 05:20:52 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 171859 System errors: ============= Error: (08/11/2013 08:32:40 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst hpqwmiex erreicht. Error: (08/11/2013 05:23:02 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 11.08.2013 um 17:15:28 unerwartet heruntergefahren. Error: (08/09/2013 05:17:37 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 09.08.2013 um 16:15:12 unerwartet heruntergefahren. Error: (08/04/2013 08:31:29 PM) (Source: ACPI) (User: ) Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Error: (08/04/2013 08:31:24 PM) (Source: ACPI) (User: ) Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Error: (08/04/2013 08:31:19 PM) (Source: ACPI) (User: ) Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Error: (08/04/2013 08:31:13 PM) (Source: ACPI) (User: ) Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Error: (08/04/2013 07:47:22 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "CLVirtualDrive" wurde aufgrund folgenden Fehlers nicht gestartet: %%183 Error: (07/30/2013 06:39:11 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (07/30/2013 06:32:04 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst Windows Modules Installer konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Microsoft Office Sessions: ========================= Error: (08/12/2013 10:20:08 AM) (Source: Customer Experience Improvement Program)(User: ) Description: 80070005 Error: (08/11/2013 09:19:20 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE10.0.9200.16537512347f7MSHTML.dll10.0.9200.1663551b7b287c0000005006faf2d126401ce96bee77f066cC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SYSTEM32\MSHTML.dll89db4cf8-02b2-11e3-be95-7446a077446e Error: (08/11/2013 05:21:24 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 203109 Error: (08/11/2013 05:21:24 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 203109 Error: (08/11/2013 05:21:24 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/11/2013 05:21:08 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 187484 Error: (08/11/2013 05:21:08 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 187484 Error: (08/11/2013 05:21:08 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/11/2013 05:20:52 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 171859 Error: (08/11/2013 05:20:52 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 171859 ==================== Memory info =========================== Percentage of memory in use: 62% Total physical RAM: 3986.27 MB Available physical RAM: 1493.14 MB Total Pagefile: 4690.27 MB Available Pagefile: 1929.82 MB Total Virtual: 8192 MB Available Virtual: 8191.76 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:448.22 GB) (Free:396.19 GB) NTFS (Disk=0 Partition=4) ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:16.77 GB) (Free:2.16 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: DCCDF995) Partition: GPT Partition Type ==================== End Of Log ============================ |
12.08.2013, 11:26 | #9 |
/// the machine /// TB-Ausbilder | Ransomware (bprotector) entfernen, aber wie? jup Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.08.2013, 13:43 | #10 |
| Ransomware (bprotector) entfernen, aber wie? ok, das ist schon fertig: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.11.04 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16635 jessi_000 :: JESSY [Administrator] Schutz: Aktiviert 12.08.2013 13:54:10 mbam-log-2013-08-12 (13-54-10).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 410290 Laufzeit: 56 Minute(n), 29 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.306 - Datei am 12/08/2013 um 14:56:23 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 8 (64 bits) # Benutzer : jessi_000 - JESSY # Bootmodus : Normal # Ausgeführt unter : C:\Users\jessi_000\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2W4Z2ZE\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\END Datei Gelöscht : C:\Users\jessi_000\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\BrowserDefender Ordner Gelöscht : C:\ProgramData\Iminent Ordner Gelöscht : C:\Users\jessi_000\AppData\LocalLow\boost_interprocess Ordner Gelöscht : C:\Users\jessi_000\AppData\Roaming\Iminent ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Conduit ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16537 [OK] Die Registrierungsdatenbank ist sauber. -\\ Google Chrome v28.0.1500.95 Datei : C:\Users\jessi_000\AppData\Local\Google\Chrome\User Data\Default\Preferences Gelöscht [l.2462] : homepage = "hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=8A7CF4B7E2B20A05&affID=121962&tsp=495[...] ************************* AdwCleaner[S1].txt - [1307 octets] - [12/08/2013 14:56:23] ########## EOF - C:\AdwCleaner[S1].txt - [1367 octets] ########## Ich kann aber Junkware Removal nicht aufmachen, da steht : "Der Computer wurde durch Windows geschützt Von Windows Smart wurde der Start einer unbekannten App verhindert. Die Ausführung dieser App stellt unter Umständen ein Risiko für den PC da." Was soll ich jetzt machen? Soll ich den trotzdem aufmachen? Ich habe es aufgemacht, da ist es : Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.4.4 (08.12.2013:1) OS: Windows 8 x64 Ran by jessi_000 on 12.08.2013 at 15:23:57,35 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5F0F98CA-486A-4FAE-A0C4-E6CE7C7277D1} Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{5F0F98CA-486A-4FAE-A0C4-E6CE7C7277D1} Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\microsoft\Internet Explorer\SearchScopes\{5F0F98CA-486A-4FAE-A0C4-E6CE7C7277D1} ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12.08.2013 at 15:35:30,05 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ [CODE] Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-08-2013 02 Ran by jessi_000 (administrator) on 12-08-2013 15:39:54 Running from C:\Users\jessi_000\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IZ5SSMBE Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Infowatch) C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteUser.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\klwtblfs.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3053808 2013-08-04] (Synaptics Incorporated) HKCU\...\Run: [Power2GoExpress8] - C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe [1711680 2013-01-27] (CyberLink Corp.) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [581024 2012-09-07] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [HP CoolSense] - C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1343904 2012-11-05] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\runner_avp.exe [25608 2012-12-20] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] () HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {5F0F98CA-486A-4FAE-A0C4-E6CE7C7277D1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM-x32 - {5F0F98CA-486A-4FAE-A0C4-E6CE7C7277D1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll (Kaspersky Lab) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM-x32 - Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll (Kaspersky Lab) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 213.154.124.1 193.231.252.1 Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR RestoreOnStartup: "hxxp://google.de/" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{googleriginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{go ogle:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={goo gle:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave for Director) - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.) CHR Extension: (Google Docs) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Kaspersky URL Advisor) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_0 CHR Extension: (Safe Money) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.2.558_0 CHR Extension: (Virtual Keyboard) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.2.558_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0 CHR Extension: (Chloe) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pillplnpmfjckedkedpaoembffbpklnf\2_0 CHR Extension: (Gmail) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR Extension: (Anti-Banner) - C:\Users\JESSI_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.2.558_0 CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\urladvisor.crx CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\online_banking_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\content_blocker_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\virtkbd.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\ab.crx CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [356968 2012-12-20] (Kaspersky Lab ZAO) R2 CSObjectsSrv; C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [819040 2012-12-21] (Infowatch) R2 HPConnectedRemote; C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35744 2012-10-12] (Hewlett-Packard) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1900728 2013-06-10] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S3 cleanhlp; C:\EEK\Run\cleanhlp64.sys [57032 2013-07-23] (Emsisoft GmbH) S3 cleanhlp; C:\EEK\Run\cleanhlp64.sys [57032 2013-07-23] (Emsisoft GmbH) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R0 CSCrySec; C:\Windows\System32\DRIVERS\CSCrySec.sys [98064 2012-12-10] (Infowatch) R1 CSVirtualDiskDrv; C:\Windows\system32\DRIVERS\CSVirtualDiskDrv.sys [67344 2012-12-10] (Infowatch) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458584 2012-06-19] (Kaspersky Lab ZAO) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [619616 2013-07-20] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [28504 2012-08-02] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29016 2012-09-03] (Kaspersky Lab) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29528 2012-09-03] (Kaspersky Lab) R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-07-20] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-07-20] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-25] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2013-08-04] (Synaptics Incorporated) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-12 15:23 - 2013-08-12 15:23 - 00000000 ____D C:\Windows\ERUNT 2013-08-12 14:56 - 2013-08-12 14:56 - 00001436 _____ C:\AdwCleaner[S1].txt 2013-08-12 11:31 - 2013-08-12 11:31 - 00026900 _____ C:\Users\jessi_000\Desktop\Addition.zip 2013-08-12 11:23 - 2013-08-12 11:23 - 00123662 _____ C:\Users\jessi_000\Desktop\f.txt 2013-08-12 11:21 - 2013-08-12 11:21 - 00023345 _____ C:\Users\jessi_000\Desktop\Addition.txt 2013-08-12 11:14 - 2013-08-12 11:14 - 00000000 ____D C:\FRST 2013-08-11 23:35 - 2013-08-11 23:35 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\IObit 2013-08-11 21:10 - 2013-08-11 21:10 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Malwarebytes 2013-08-11 21:07 - 2013-08-11 21:07 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-11 21:07 - 2013-08-11 21:07 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-11 21:07 - 2013-08-11 21:07 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-11 21:07 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-11 17:54 - 2013-08-11 17:54 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Curiolab 2013-08-11 17:32 - 2013-08-11 23:12 - 00000000 ____D C:\Program Files (x86)\Exterminate It! 2013-08-11 17:32 - 2013-08-11 17:32 - 00001081 _____ C:\Users\jessi_000\Desktop\Exterminate It!.lnk 2013-08-11 17:14 - 2013-08-11 17:14 - 00000000 ____D C:\Encryption 2013-08-11 15:57 - 2013-08-11 15:58 - 00000000 ____D C:\Users\jessi_000\Desktop\programme 2013-08-04 22:26 - 2013-08-04 22:26 - 00000902 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-04 20:58 - 2013-08-04 21:01 - 00000000 ____D C:\Windows\LastGood.Tmp 2013-08-04 20:57 - 2013-08-04 20:58 - 00006762 _____ C:\Windows\DPINST.LOG 2013-08-04 20:57 - 2013-08-04 20:58 - 00001332 _____ C:\Windows\Synaptics.log 2013-08-04 20:57 - 2013-08-04 20:56 - 01060080 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll 2013-08-04 20:57 - 2013-08-04 20:56 - 00544496 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCom.dll 2013-08-04 20:57 - 2013-08-04 20:56 - 00495856 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys 2013-08-04 20:57 - 2013-08-04 20:56 - 00264432 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2013-08-04 20:57 - 2013-08-04 20:56 - 00192240 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo18.dll 2013-08-04 20:57 - 2013-08-04 20:56 - 00151280 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynTPCom.dll 2013-08-04 20:57 - 2013-08-04 20:56 - 00033008 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\Smb_driver_Intel.sys 2013-08-04 20:28 - 2013-08-04 20:28 - 00003154 _____ C:\Windows\System32\Tasks\MirageAgent 2013-08-04 20:27 - 2013-08-04 20:27 - 00000000 ___HD C:\Users\Public\Documents\YouCam 2013-08-04 19:47 - 2013-08-04 19:47 - 00003166 _____ C:\Windows\System32\Tasks\CLVDLauncher 2013-08-04 19:47 - 2013-08-04 19:47 - 00003166 _____ C:\Windows\System32\Tasks\CLMLSvc_P2G8 2013-08-04 19:47 - 2012-06-25 11:24 - 00092536 _____ (CyberLink) C:\Windows\system32\Drivers\CLVirtualDrive.sys 2013-08-03 21:31 - 2013-08-03 21:31 - 10644535 _____ C:\Users\jessi_000\Downloads\WhatsApp.apk 2013-08-03 21:17 - 2013-08-03 21:17 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Windows Live 2013-08-03 21:16 - 2013-08-03 21:16 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\DivX 2013-07-31 15:38 - 2013-07-31 15:39 - 00000000 ____D C:\Windows\system32\MRT 2013-07-31 13:50 - 2013-07-31 13:51 - 00449736 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-30 23:10 - 2013-07-30 23:10 - 00000000 ____D C:\output 2013-07-30 23:08 - 2013-08-01 22:31 - 00020480 ____H C:\Users\jessi_000\Desktop\photothumb.db 2013-07-30 20:35 - 2013-07-30 20:35 - 00000566 _____ C:\Users\Public\Desktop\Pixlr-o-matic.lnk 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Pixlromatic 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\ProgramData\Adobe 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-30 20:23 - 2013-07-30 20:25 - 145394418 _____ C:\Users\JESSI_~1\AppData\Local\ACCCx189.zip.aamdownload 2013-07-30 20:23 - 2013-07-30 20:25 - 00001811 _____ C:\Users\JESSI_~1\AppData\Local\ACCCx189.zip.aamdownload.aamd 2013-07-30 20:22 - 2013-07-30 20:22 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Adobe 2013-07-30 20:20 - 2013-07-30 20:21 - 03867000 _____ (Adobe Systems Incorporated) C:\Users\jessi_000\Downloads\CreativeCloudSet-Up.exe 2013-07-30 20:05 - 2013-07-30 20:07 - 00000000 ____D C:\Users\jessi_000\Desktop\Musik 2013-07-30 18:40 - 2013-08-04 20:58 - 00003782 _____ C:\Windows\setupact.log 2013-07-30 18:40 - 2013-07-30 18:40 - 00000000 _____ C:\Windows\setuperr.log 2013-07-29 17:29 - 2013-07-29 17:29 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\WebApp 2013-07-29 17:25 - 2013-07-29 17:25 - 00000000 ____D C:\Users\jessi_000\Documents\CyberLink 2013-07-27 01:10 - 2012-10-12 09:13 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\dskquota.dll 2013-07-27 01:10 - 2012-10-12 08:39 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dskquota.dll 2013-07-27 01:09 - 2012-10-24 07:54 - 00396008 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll 2013-07-27 01:09 - 2012-10-17 07:32 - 01172992 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll 2013-07-27 01:09 - 2012-10-17 07:32 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll 2013-07-27 01:09 - 2012-10-17 07:32 - 00673280 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll 2013-07-27 01:09 - 2012-10-17 06:57 - 00929792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll 2013-07-27 01:09 - 2012-10-17 06:57 - 00568832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll 2013-07-27 01:09 - 2012-10-17 06:57 - 00513024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll 2013-07-27 01:09 - 2012-10-11 10:47 - 00793200 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2013-07-27 01:09 - 2012-10-11 10:25 - 00056552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdstor.sys 2013-07-27 01:09 - 2012-10-11 10:23 - 00441576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2013-07-27 01:09 - 2012-10-11 10:18 - 00172264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-07-27 01:09 - 2012-10-11 10:13 - 00058088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys 2013-07-27 01:09 - 2012-10-11 10:13 - 00033512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\battc.sys 2013-07-27 01:09 - 2012-10-11 10:08 - 00562392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-07-27 01:09 - 2012-10-11 08:46 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll 2013-07-27 01:09 - 2012-10-11 08:46 - 00517120 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2013-07-27 01:09 - 2012-10-11 08:46 - 00154112 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.Compression.dll 2013-07-27 01:09 - 2012-10-11 08:45 - 01045504 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll 2013-07-27 01:09 - 2012-10-11 08:45 - 00590848 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2013-07-27 01:09 - 2012-10-11 08:45 - 00579584 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll 2013-07-27 01:09 - 2012-10-11 08:45 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\SpaceControl.dll 2013-07-27 01:09 - 2012-10-11 08:44 - 01265152 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-07-27 01:09 - 2012-10-11 08:44 - 00904192 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2013-07-27 01:09 - 2012-10-11 08:44 - 00264704 _____ (Microsoft Corporation) C:\Windows\system32\ListSvc.dll 2013-07-27 01:09 - 2012-10-11 08:43 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2013-07-27 01:09 - 2012-10-11 08:42 - 00612416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2013-07-27 01:09 - 2012-10-11 08:16 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-07-27 01:09 - 2012-10-11 08:07 - 01226752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll 2013-07-27 01:09 - 2012-10-11 08:07 - 00962560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll 2013-07-27 01:09 - 2012-10-11 08:07 - 00460800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2013-07-27 01:09 - 2012-10-11 08:07 - 00414720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll 2013-07-27 01:09 - 2012-10-11 08:07 - 00116224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.Compression.dll 2013-07-27 01:09 - 2012-10-11 08:06 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll 2013-07-27 01:09 - 2012-10-11 08:06 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2013-07-27 01:09 - 2012-10-11 03:45 - 00478424 _____ C:\Windows\SysWOW64\locale.nls 2013-07-27 01:09 - 2012-10-11 03:44 - 00478424 _____ C:\Windows\system32\locale.nls 2013-07-27 01:08 - 2012-12-04 07:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll 2013-07-27 01:08 - 2012-11-20 08:24 - 01164800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Display.dll 2013-07-27 01:08 - 2012-11-20 08:17 - 01184256 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll 2013-07-27 01:08 - 2012-11-20 08:02 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDKURD.DLL 2013-07-27 01:08 - 2012-11-20 07:59 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDKURD.DLL 2013-07-27 01:08 - 2012-11-08 07:25 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2013-07-27 01:08 - 2012-11-08 07:25 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll 2013-07-27 01:08 - 2012-11-08 07:25 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-07-27 01:08 - 2012-11-08 07:22 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2013-07-27 01:08 - 2012-11-08 07:22 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll 2013-07-27 01:08 - 2012-11-08 07:22 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-07-27 01:08 - 2012-10-11 10:02 - 01636672 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll 2013-07-27 01:08 - 2012-10-11 08:46 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\BdeUISrv.exe 2013-07-27 01:08 - 2012-10-11 08:46 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll 2013-07-27 01:08 - 2012-10-11 08:45 - 00370176 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-07-27 01:08 - 2012-10-11 08:45 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\PCPKsp.dll 2013-07-27 01:08 - 2012-10-11 08:44 - 00355328 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-07-27 01:08 - 2012-10-11 08:44 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\input.dll 2013-07-27 01:08 - 2012-10-11 08:44 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 01280000 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00757760 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\AppxSip.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc.dll 2013-07-27 01:08 - 2012-10-11 08:43 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2013-07-27 01:08 - 2012-10-11 08:23 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-pdc.dll 2013-07-27 01:08 - 2012-10-11 08:23 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\kbdhebl3.dll 2013-07-27 01:08 - 2012-10-11 08:19 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys 2013-07-27 01:08 - 2012-10-11 08:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-07-27 01:08 - 2012-10-11 08:15 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys 2013-07-27 01:08 - 2012-10-11 08:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PCPKsp.dll 2013-07-27 01:08 - 2012-10-11 08:07 - 00019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll 2013-07-27 01:08 - 2012-10-11 08:06 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll 2013-07-27 01:08 - 2012-10-11 08:06 - 00289280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-07-27 01:08 - 2012-10-11 08:06 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll 2013-07-27 01:08 - 2012-10-11 08:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc.dll 2013-07-27 01:08 - 2012-10-11 08:06 - 00051712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2013-07-27 01:08 - 2012-10-11 08:05 - 00099840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxSip.dll 2013-07-27 01:08 - 2012-10-11 07:42 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdhebl3.dll 2013-07-27 01:07 - 2012-11-06 10:52 - 00277736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2013-07-27 01:07 - 2012-11-06 10:33 - 01566432 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2013-07-27 01:07 - 2012-11-06 07:48 - 01150160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00883712 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2013-07-27 01:07 - 2012-11-06 07:20 - 00516608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00386560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00375296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe 2013-07-27 01:07 - 2012-11-06 07:20 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll 2013-07-27 01:07 - 2012-11-06 07:20 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfdprov.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 08552448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00470016 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00466944 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00126464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\wfdprov.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapPeerProxy.dll 2013-07-27 01:07 - 2012-11-06 07:19 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapAuthProxy.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 11459584 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 01037312 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 00976384 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 00189440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bthprops.cpl 2013-07-27 01:07 - 2012-11-06 07:18 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll 2013-07-27 01:07 - 2012-11-06 07:18 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll 2013-07-27 01:07 - 2012-11-06 07:17 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl 2013-07-27 01:07 - 2012-11-06 07:17 - 00110080 _____ (Microsoft Corporation) C:\Windows\system32\dafWCN.dll 2013-07-27 01:07 - 2012-11-06 07:00 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\iscsilog.dll 2013-07-27 01:07 - 2012-11-06 06:58 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll 2013-07-27 01:07 - 2012-11-06 06:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll 2013-07-27 01:07 - 2012-11-06 06:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys 2013-07-27 01:07 - 2012-11-06 06:55 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys 2013-07-27 01:07 - 2012-11-06 06:55 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys 2013-07-27 01:07 - 2012-11-06 06:55 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys 2013-07-27 01:07 - 2012-11-06 06:55 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fxppm.sys 2013-07-27 01:07 - 2012-11-06 06:53 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-07-27 01:07 - 2012-11-06 06:51 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-07-27 01:05 - 2012-11-27 09:39 - 01122768 _____ (Microsoft Corporation) C:\Windows\system32\Taskmgr.exe 2013-07-27 01:05 - 2012-11-27 07:49 - 01027152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Taskmgr.exe 2013-07-27 01:05 - 2012-11-27 07:20 - 01217536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\storagewmi.dll 2013-07-27 01:05 - 2012-11-27 07:20 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-07-27 01:05 - 2012-11-27 07:20 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-07-27 01:05 - 2012-11-27 07:20 - 00798208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll 2013-07-27 01:05 - 2012-11-27 07:20 - 00702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-07-27 01:05 - 2012-11-27 07:20 - 00560128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserLanguagesCpl.dll 2013-07-27 01:05 - 2012-11-27 07:20 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll 2013-07-27 01:05 - 2012-11-27 07:20 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vds_ps.dll 2013-07-27 01:05 - 2012-11-27 07:19 - 03245568 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-07-27 01:05 - 2012-11-27 07:19 - 01536512 _____ (Microsoft Corporation) C:\Windows\system32\storagewmi.dll 2013-07-27 01:05 - 2012-11-27 07:19 - 00955904 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll 2013-07-27 01:05 - 2012-11-27 07:19 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\UserLanguagesCpl.dll 2013-07-27 01:05 - 2012-11-27 07:19 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-07-27 01:05 - 2012-11-27 07:19 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll 2013-07-27 01:05 - 2012-11-27 07:18 - 01071104 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-07-27 01:05 - 2012-11-27 07:18 - 00888832 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-07-27 01:05 - 2012-11-27 07:18 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-07-27 01:05 - 2012-11-27 07:17 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL 2013-07-27 01:05 - 2012-10-12 11:08 - 00027880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2013-07-27 01:05 - 2012-10-12 09:14 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\rfxvmt.dll 2013-07-27 01:05 - 2012-10-12 08:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2013-07-27 00:14 - 2013-06-01 14:54 - 00194816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2013-07-27 00:14 - 2013-06-01 14:54 - 00125184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2013-07-27 00:14 - 2013-06-01 14:33 - 02233600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-27 00:14 - 2013-06-01 14:29 - 00337152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2013-07-27 00:14 - 2013-06-01 14:29 - 00213248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS 2013-07-27 00:14 - 2013-06-01 14:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-07-27 00:14 - 2013-06-01 14:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2013-07-27 00:14 - 2013-06-01 13:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2013-07-27 00:14 - 2013-06-01 12:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-07-27 00:14 - 2013-06-01 12:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2013-07-27 00:14 - 2013-06-01 12:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2013-07-27 00:14 - 2013-06-01 12:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll 2013-07-27 00:14 - 2013-06-01 12:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2013-07-27 00:14 - 2013-06-01 12:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2013-07-27 00:14 - 2013-06-01 12:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe 2013-07-27 00:14 - 2013-06-01 12:22 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-07-27 00:14 - 2013-06-01 12:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll 2013-07-27 00:14 - 2013-05-20 03:08 - 00386642 _____ C:\Windows\system32\ApnDatabase.xml 2013-07-27 00:14 - 2013-04-09 05:34 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-07-27 00:14 - 2013-04-09 05:34 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys 2013-07-27 00:13 - 2013-06-17 01:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-07-27 00:13 - 2013-06-01 14:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-07-27 00:13 - 2013-06-01 12:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-27 00:13 - 2013-06-01 12:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe 2013-07-27 00:13 - 2013-06-01 12:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2013-07-27 00:13 - 2013-06-01 12:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2013-07-27 00:13 - 2013-06-01 12:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2013-07-27 00:13 - 2013-06-01 12:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2013-07-27 00:13 - 2013-06-01 12:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll 2013-07-27 00:13 - 2013-06-01 12:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2013-07-27 00:13 - 2013-06-01 12:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2013-07-27 00:13 - 2013-06-01 12:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll 2013-07-27 00:13 - 2013-06-01 06:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys 2013-07-27 00:13 - 2013-05-25 01:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-07-27 00:13 - 2013-05-25 01:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-07-27 00:13 - 2013-05-25 01:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-07-27 00:13 - 2013-05-25 01:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-07-25 23:54 - 2013-06-28 01:04 - 00693112 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-07-25 23:54 - 2013-06-28 01:04 - 00078200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-07-25 23:53 - 2013-08-11 22:05 - 00102576 _____ C:\Windows\PFRO.log 2013-07-25 15:36 - 2013-07-25 15:36 - 00000000 ____D C:\sources 2013-07-25 14:45 - 2013-08-12 15:23 - 01695905 _____ C:\Windows\WindowsUpdate.log 2013-07-25 14:32 - 2013-07-25 14:32 - 00001274 _____ C:\Users\jessi_000\Desktop\shutdown.lnk 2013-07-25 13:54 - 2013-07-25 13:54 - 00000546 _____ C:\Users\jessi_000\Desktop\Emsisoft Emergency Kit.lnk 2013-07-25 13:54 - 2013-07-25 13:54 - 00000000 ____D C:\EEK 2013-07-25 13:51 - 2013-07-25 13:51 - 00082976 _____ C:\Users\jessi_000\Documents\cc_20130725_125126.reg 2013-07-25 13:49 - 2013-07-25 13:49 - 00002780 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-07-25 13:48 - 2013-07-25 13:48 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-07-25 13:48 - 2013-07-25 13:48 - 00000000 ____D C:\Program Files\CCleaner 2013-07-25 13:44 - 2013-07-25 13:44 - 04396440 _____ (Piriform Ltd) C:\Users\jessi_000\Desktop\ccsetup403.exe 2013-07-25 13:40 - 2013-07-25 13:43 - 181531216 _____ C:\Users\jessi_000\Downloads\EmsisoftEmergencyKit40012.exe 2013-07-25 12:35 - 2013-06-24 01:57 - 78277128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-07-25 00:25 - 2013-07-25 00:25 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\DDMSettings 2013-07-25 00:23 - 2013-07-25 00:24 - 00000000 ____D C:\Program Files\DivX 2013-07-25 00:21 - 2013-07-25 00:24 - 00000000 ____D C:\ProgramData\DivX 2013-07-25 00:21 - 2013-07-25 00:24 - 00000000 ____D C:\Program Files (x86)\DivX 2013-07-25 00:21 - 2013-07-25 00:21 - 00957248 _____ (DivX, LLC) C:\Users\jessi_000\Downloads\DivXWebPlayerInstaller.exe 2013-07-24 17:56 - 2013-05-16 01:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll 2013-07-24 17:56 - 2012-11-10 07:23 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2013-07-24 17:56 - 2012-11-10 07:23 - 00132608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2013-07-24 17:56 - 2012-11-10 07:22 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\RDWebAI.dll 2013-07-24 17:56 - 2012-11-10 07:22 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\VmHostAI.dll 2013-07-24 17:56 - 2012-11-10 07:20 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\appserverai.dll 2013-07-24 17:29 - 2013-03-22 06:49 - 02382336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll 2013-07-24 17:29 - 2013-03-22 01:47 - 02851840 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll 2013-07-24 17:29 - 2013-03-02 11:23 - 00375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll 2013-07-24 17:29 - 2013-03-02 05:44 - 01011200 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll 2013-07-24 17:29 - 2012-12-15 07:55 - 00443392 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll 2013-07-24 17:29 - 2012-11-03 08:26 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\sysreset.exe 2013-07-24 17:29 - 2012-11-03 08:25 - 00945152 _____ (Microsoft Corporation) C:\Windows\system32\resetengmig.dll 2013-07-24 17:29 - 2012-10-24 06:25 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\ReAgentc.exe 2013-07-24 17:29 - 2012-10-24 06:25 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2013-07-24 17:29 - 2012-10-24 06:24 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2013-07-24 17:29 - 2012-10-24 06:24 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2013-07-24 17:29 - 2012-10-24 06:05 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2013-07-24 17:29 - 2012-10-24 05:48 - 00024064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgentc.exe 2013-07-24 17:28 - 2013-04-03 02:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-07-24 17:28 - 2013-04-03 02:12 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-07-24 15:00 - 2013-01-10 02:26 - 01611776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe 2013-07-24 15:00 - 2013-01-10 02:26 - 00890880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2013-07-24 15:00 - 2013-01-10 02:23 - 02094592 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe 2013-07-24 15:00 - 2013-01-10 02:23 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll 2013-07-24 15:00 - 2013-01-10 02:22 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2013-07-24 14:59 - 2013-01-10 04:53 - 00028904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpiowin32.sys 2013-07-24 14:59 - 2013-01-10 04:29 - 00785504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-07-24 14:59 - 2013-01-10 04:29 - 00091880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2013-07-24 14:59 - 2013-01-10 02:26 - 01752064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll 2013-07-24 14:59 - 2013-01-10 02:26 - 00436736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL 2013-07-24 14:59 - 2013-01-10 02:26 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll 2013-07-24 14:59 - 2013-01-10 02:26 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wiaacmgr.exe 2013-07-24 14:59 - 2013-01-10 02:23 - 01886208 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll 2013-07-24 14:59 - 2013-01-10 02:23 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll 2013-07-24 14:59 - 2013-01-10 02:23 - 00256000 _____ (Microsoft Corporation) C:\Windows\system32\WSDMon.dll 2013-07-24 14:59 - 2013-01-10 02:23 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\wiaacmgr.exe 2013-07-24 14:59 - 2013-01-10 02:22 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2013-07-24 14:59 - 2013-01-10 02:22 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL 2013-07-24 14:59 - 2013-01-10 02:22 - 00438272 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll 2013-07-24 14:59 - 2013-01-10 02:22 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2013-07-24 14:59 - 2013-01-09 06:59 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys 2013-07-24 14:59 - 2012-11-02 08:19 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ncbservice.dll 2013-07-24 14:59 - 2012-11-02 08:18 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\httpprxm.dll 2013-07-24 14:59 - 2012-11-02 08:18 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\adhsvc.dll 2013-07-24 14:59 - 2012-11-02 08:18 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\adhapi.dll 2013-07-24 14:59 - 2012-11-02 08:18 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\httpprxp.dll 2013-07-24 14:59 - 2012-11-02 08:18 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\keepaliveprovider.dll 2013-07-24 14:59 - 2012-10-10 10:04 - 00094208 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2013-07-24 14:59 - 2012-10-10 09:31 - 00072192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll 2013-07-24 14:57 - 2012-11-26 07:21 - 00071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll 2013-07-24 14:57 - 2012-11-26 07:20 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll 2013-07-24 14:56 - 2013-04-16 05:34 - 01455368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-07-24 14:54 - 2012-08-31 03:52 - 00017888 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll 2013-07-24 14:53 - 2012-08-31 03:53 - 00017888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100_clr0400.dll 2013-07-24 14:42 - 2013-03-02 11:23 - 01338880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-07-24 14:42 - 2013-03-02 05:45 - 01627648 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-07-24 14:42 - 2013-03-02 05:45 - 01161728 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2013-07-24 14:42 - 2013-03-02 05:44 - 05978624 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-07-24 14:41 - 2013-03-02 13:57 - 00332520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2013-07-24 14:41 - 2013-03-02 13:39 - 00327912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2013-07-24 14:41 - 2013-03-02 11:23 - 00893952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll 2013-07-24 14:41 - 2013-03-02 11:23 - 00601088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll 2013-07-24 14:41 - 2013-03-02 11:22 - 05091840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-07-24 14:41 - 2013-03-02 11:22 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcfgx.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 01149952 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 01101824 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00951808 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\usbmon.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\TimeBrokerServer.dll 2013-07-24 14:41 - 2013-03-02 05:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll 2013-07-24 14:41 - 2013-03-02 05:44 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll 2013-07-24 14:41 - 2013-03-02 05:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll 2013-07-24 14:41 - 2013-03-02 05:44 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll 2013-07-24 14:40 - 2013-03-02 13:57 - 00077544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storahci.sys 2013-07-24 14:40 - 2013-03-02 13:45 - 00148712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys 2013-07-24 14:40 - 2013-03-02 13:39 - 00495336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys 2013-07-24 14:40 - 2013-03-02 11:23 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2013-07-24 14:40 - 2013-03-02 11:23 - 00356352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll 2013-07-24 14:40 - 2013-03-02 11:23 - 00100864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncInfo.dll 2013-07-24 14:40 - 2013-03-02 11:21 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvstore.dll 2013-07-24 14:40 - 2013-03-02 11:21 - 00145408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\powercfg.cpl 2013-07-24 14:40 - 2013-03-02 11:21 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevDispItemProvider.dll 2013-07-24 14:40 - 2013-03-02 05:45 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\WSDPrintProxy.DLL 2013-07-24 14:40 - 2013-03-02 05:44 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\discan.dll 2013-07-24 14:40 - 2013-03-02 05:44 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncInfo.dll 2013-07-24 14:40 - 2013-03-02 05:44 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\NdisImPlatform.dll 2013-07-24 14:40 - 2013-03-02 05:44 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\DevDispItemProvider.dll 2013-07-24 14:40 - 2013-03-02 05:43 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\powercfg.cpl 2013-07-24 14:40 - 2013-03-02 05:15 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mouhid.sys 2013-07-24 14:40 - 2013-03-01 07:56 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\monitor.sys 2013-07-24 14:33 - 2013-05-31 02:14 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-24 14:33 - 2013-03-02 12:59 - 00411880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2013-07-24 14:30 - 2013-04-24 02:13 - 01013248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-07-24 14:30 - 2013-04-24 02:12 - 01569792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-07-24 14:30 - 2013-04-24 02:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-07-24 14:30 - 2013-04-24 01:56 - 01255936 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-07-24 14:30 - 2013-04-24 01:55 - 01889280 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-07-24 14:30 - 2013-04-24 01:55 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-07-24 14:30 - 2013-04-24 01:55 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-07-24 14:24 - 2013-06-01 12:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-24 14:24 - 2013-06-01 12:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-24 14:20 - 2013-02-02 14:19 - 00496872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-07-24 14:20 - 2013-02-02 14:19 - 00061672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\crashdmp.sys 2013-07-24 14:20 - 2013-02-02 13:54 - 01933544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-07-24 14:20 - 2013-02-02 11:40 - 00410624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlroamextension.dll 2013-07-24 14:20 - 2013-02-02 11:40 - 00370688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWanAPI.dll 2013-07-24 14:20 - 2013-02-02 11:40 - 00197632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll 2013-07-24 14:20 - 2013-02-02 11:40 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tasklist.exe 2013-07-24 14:20 - 2013-02-02 11:40 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskkill.exe 2013-07-24 14:20 - 2013-02-02 11:39 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mbsmsapi.dll 2013-07-24 14:20 - 2013-02-02 11:39 - 00055296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2013-07-24 14:20 - 2013-02-02 11:38 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\duser.dll 2013-07-24 14:20 - 2013-02-02 11:24 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\taskkill.exe 2013-07-24 14:20 - 2013-02-02 11:24 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\tasklist.exe 2013-07-24 14:20 - 2013-02-02 11:23 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll 2013-07-24 14:20 - 2013-02-02 11:23 - 00543232 _____ (Microsoft Corporation) C:\Windows\system32\wlroamextension.dll 2013-07-24 14:20 - 2013-02-02 11:23 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\WWanAPI.dll 2013-07-24 14:20 - 2013-02-02 11:23 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Connectivity.dll 2013-07-24 14:20 - 2013-02-02 11:23 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll 2013-07-24 14:20 - 2013-02-02 11:21 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2013-07-24 14:20 - 2013-02-02 11:21 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\mbsmsapi.dll 2013-07-24 14:20 - 2013-02-02 11:20 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\duser.dll 2013-07-24 14:20 - 2013-02-02 11:20 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\hotspotauth.dll 2013-07-24 14:20 - 2013-02-02 10:25 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys 2013-07-24 14:20 - 2012-11-27 06:57 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BtaMPM.sys 2013-07-24 14:20 - 2012-11-27 06:55 - 00029952 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthhfHid.sys 2013-07-24 14:20 - 2012-11-20 07:56 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-07-24 14:19 - 2013-02-06 01:29 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2013-07-24 14:19 - 2013-02-06 01:28 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2013-07-24 14:19 - 2013-02-02 08:41 - 01437184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2013-07-24 14:19 - 2013-02-02 08:31 - 01690624 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2013-07-24 14:18 - 2013-04-12 01:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-24 14:18 - 2013-04-12 01:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-24 14:17 - 2013-05-04 09:59 - 13644288 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2013-07-24 14:17 - 2013-05-04 09:59 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-07-24 14:17 - 2013-05-04 09:59 - 01483776 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe 2013-07-24 14:17 - 2013-05-04 09:59 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-07-24 14:17 - 2013-05-04 09:58 - 10116096 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2013-07-24 14:17 - 2013-05-04 09:58 - 01332736 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll 2013-07-24 14:17 - 2013-05-04 09:58 - 00470528 _____ (Microsoft Corporation) C:\Windows\system32\netprofmsvc.dll 2013-07-24 14:17 - 2013-05-04 09:58 - 00328192 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2013-07-24 14:17 - 2013-05-04 09:57 - 02305024 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-07-24 14:17 - 2013-05-04 09:57 - 01131520 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2013-07-24 14:17 - 2013-05-04 09:57 - 00389120 _____ (Microsoft Corporation) C:\Windows\system32\BCP47Langs.dll 2013-07-24 14:17 - 2013-05-04 07:57 - 10788864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2013-07-24 14:17 - 2013-05-04 07:57 - 08857088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2013-07-24 14:17 - 2013-05-04 07:57 - 00247296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll 2013-07-24 14:17 - 2013-05-04 07:47 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2013-07-24 14:16 - 2013-05-04 10:58 - 00120736 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe 2013-07-24 14:16 - 2013-05-04 10:34 - 00446720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS 2013-07-24 14:16 - 2013-05-04 10:34 - 00284416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys 2013-07-24 14:16 - 2013-05-04 10:30 - 00058312 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-07-24 14:16 - 2013-05-04 09:59 - 01619968 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-07-24 14:16 - 2013-05-04 09:59 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe 2013-07-24 14:16 - 2013-05-04 09:59 - 00251904 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2013-07-24 14:16 - 2013-05-04 09:59 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-07-24 14:16 - 2013-05-04 09:59 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-07-24 14:16 - 2013-05-04 09:59 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-07-24 14:16 - 2013-05-04 09:58 - 00330240 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll 2013-07-24 14:16 - 2013-05-04 09:58 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2013-07-24 14:16 - 2013-05-04 09:58 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll 2013-07-24 14:16 - 2013-05-04 09:58 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\netprofm.dll 2013-07-24 14:16 - 2013-05-04 09:58 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00708096 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00501760 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\biwinrt.dll 2013-07-24 14:16 - 2013-05-04 09:57 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\muifontsetup.dll 2013-07-24 14:16 - 2013-05-04 09:56 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl 2013-07-24 14:16 - 2013-05-04 07:58 - 00758784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Magnify.exe 2013-07-24 14:16 - 2013-05-04 07:58 - 00621056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2013-07-24 14:16 - 2013-05-04 07:58 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2013-07-24 14:16 - 2013-05-04 07:58 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2013-07-24 14:16 - 2013-05-04 07:58 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2013-07-24 14:16 - 2013-05-04 07:57 - 00303616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll 2013-07-24 14:16 - 2013-05-04 07:57 - 00151040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netplwiz.dll 2013-07-24 14:16 - 2013-05-04 07:57 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netprofm.dll 2013-07-24 14:16 - 2013-05-04 07:57 - 00018432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\npmproxy.dll 2013-07-24 14:16 - 2013-05-04 07:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\muifontsetup.dll 2013-07-24 14:16 - 2013-05-04 07:56 - 02035712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-07-24 14:16 - 2013-05-04 07:56 - 00449536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairing.dll 2013-07-24 14:16 - 2013-05-04 07:56 - 00411136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll 2013-07-24 14:16 - 2013-05-04 07:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BCP47Langs.dll 2013-07-24 14:16 - 2013-05-04 07:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\biwinrt.dll 2013-07-24 14:16 - 2013-05-04 07:55 - 00389632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl 2013-07-24 14:16 - 2013-05-04 07:51 - 00014848 _____ (Microsoft) C:\Windows\system32\rars.rs 2013-07-24 14:16 - 2013-05-04 07:10 - 00014848 _____ (Microsoft) C:\Windows\SysWOW64\rars.rs |
12.08.2013, 13:56 | #11 |
| Ransomware (bprotector) entfernen, aber wie? 2013-07-24 14:16 - 2013-03-02 05:45 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2013-07-24 14:16 - 2013-03-02 05:45 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\taskhostex.exe 2013-07-24 14:16 - 2013-03-02 05:45 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-07-24 14:16 - 2013-02-02 11:39 - 00015872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlmproxy.dll 2013-07-24 14:16 - 2013-02-02 11:39 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlmsprep.dll 2013-07-24 14:16 - 2012-11-06 07:20 - 00018432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2013-07-24 14:16 - 2012-11-06 07:20 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll 2013-07-24 14:16 - 2012-11-06 07:00 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wushareduxresources.dll 2013-07-24 14:16 - 2012-11-02 08:20 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-07-24 14:15 - 2013-05-31 02:24 - 01257472 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-07-24 14:15 - 2013-05-31 02:08 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-07-24 14:15 - 2013-05-24 02:01 - 01300992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-07-24 14:15 - 2013-05-24 01:27 - 01022464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-07-24 14:15 - 2013-05-15 05:25 - 00888320 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe 2013-07-24 14:15 - 2013-05-15 05:25 - 00542208 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll 2013-07-24 14:15 - 2013-05-15 05:24 - 00793088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe 2013-07-24 14:15 - 2013-05-15 05:24 - 00482816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll 2013-07-24 14:13 - 2013-02-12 03:17 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-07-24 14:12 - 2013-03-06 10:10 - 00112872 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2013-07-24 14:12 - 2013-03-06 09:31 - 19758592 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-07-24 14:12 - 2013-03-06 09:31 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-07-24 14:12 - 2013-03-06 09:29 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2013-07-24 14:12 - 2013-03-06 08:03 - 17561600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-07-24 14:12 - 2013-03-06 08:03 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-07-24 14:04 - 2013-06-12 02:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-24 14:04 - 2013-06-12 02:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-24 14:04 - 2013-06-12 02:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-24 14:04 - 2013-06-12 02:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-24 14:04 - 2013-06-12 02:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-24 14:04 - 2013-06-12 02:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-24 14:04 - 2013-06-12 02:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-24 14:04 - 2013-06-12 02:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-24 14:04 - 2013-06-12 02:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-24 14:03 - 2013-06-12 02:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-24 14:03 - 2013-06-12 02:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-24 14:03 - 2013-06-12 02:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-24 14:03 - 2013-06-12 02:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-24 14:03 - 2013-06-12 02:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-24 14:03 - 2013-06-12 02:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-24 14:03 - 2013-04-29 01:28 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-07-24 14:03 - 2013-02-21 13:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-24 14:03 - 2013-02-21 13:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-24 14:03 - 2013-02-19 12:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2013-07-24 14:02 - 2013-06-12 02:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-24 14:02 - 2013-06-12 02:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-24 14:02 - 2013-05-16 01:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-07-24 14:02 - 2013-05-16 01:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2013-07-24 14:02 - 2013-05-14 16:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-24 14:02 - 2013-05-14 12:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-24 14:02 - 2013-02-21 13:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-24 14:02 - 2013-02-21 13:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-24 14:02 - 2013-02-21 13:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-24 14:02 - 2013-02-21 13:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-24 14:02 - 2012-11-08 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-24 14:02 - 2012-11-08 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-24 14:01 - 2013-05-04 09:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-24 14:01 - 2013-05-04 07:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-24 14:01 - 2013-04-27 08:20 - 00733184 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-07-24 14:00 - 2013-03-15 03:17 - 00861184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2013-07-24 14:00 - 2012-11-03 08:26 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\dpnsvr.exe 2013-07-24 14:00 - 2012-11-03 08:26 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnsvr.exe 2013-07-24 14:00 - 2012-11-03 08:24 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dpnathlp.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnathlp.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\dpnhupnp.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\dpnhpast.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnhupnp.dll 2013-07-24 14:00 - 2012-11-03 08:24 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnhpast.dll 2013-07-24 14:00 - 2012-11-03 08:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dpnlobby.dll 2013-07-24 14:00 - 2012-11-03 08:04 - 00003584 _____ (Microsoft Corporation) C:\Windows\system32\dpnaddr.dll 2013-07-24 14:00 - 2012-11-03 08:00 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnlobby.dll 2013-07-24 14:00 - 2012-11-03 08:00 - 00002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnaddr.dll 2013-07-24 13:51 - 2012-12-16 11:08 - 00362496 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-07-24 13:51 - 2012-12-16 10:57 - 00300032 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-07-24 13:50 - 2012-12-16 11:28 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-07-24 13:50 - 2012-12-16 11:20 - 00035328 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-07-24 13:50 - 2012-11-08 07:24 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-07-24 13:50 - 2012-11-08 07:24 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-07-24 13:50 - 2012-11-08 07:20 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-07-24 13:50 - 2012-11-08 07:20 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-07-24 13:50 - 2012-11-08 07:02 - 00003072 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-07-24 13:50 - 2012-11-08 07:01 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-07-24 02:50 - 2013-04-09 08:33 - 00489576 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2013-07-24 02:50 - 2013-04-09 08:33 - 00446792 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2013-07-24 02:50 - 2013-04-09 08:33 - 00253544 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2013-07-24 02:50 - 2013-04-09 08:20 - 00306952 _____ (Microsoft Corporation) C:\Windows\system32\kd_02_10ec.dll 2013-07-24 02:50 - 2013-04-09 08:20 - 00086280 _____ (Microsoft Corporation) C:\Windows\system32\kdnet.dll 2013-07-24 02:50 - 2013-04-09 08:18 - 00077960 _____ (Microsoft Corporation) C:\Windows\system32\kdvm.dll 2013-07-24 02:50 - 2013-04-09 08:17 - 01829408 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-07-24 02:50 - 2013-04-09 07:52 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2013-07-24 02:50 - 2013-04-09 07:52 - 00804352 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe 2013-07-24 02:50 - 2013-04-09 07:52 - 00373760 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2013-07-24 02:50 - 2013-04-09 07:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2013-07-24 02:50 - 2013-04-09 07:52 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe 2013-07-24 02:50 - 2013-04-09 07:51 - 14267904 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-07-24 02:50 - 2013-04-09 07:51 - 03552768 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2013-07-24 02:50 - 2013-04-09 07:51 - 00595456 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll 2013-07-24 02:50 - 2013-04-09 07:51 - 00456704 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll 2013-07-24 02:50 - 2013-04-09 07:51 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll 2013-07-24 02:50 - 2013-04-09 07:51 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-07-24 02:50 - 2013-04-09 07:51 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 02107904 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 01285632 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00745984 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00435200 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\GenuineCenter.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2013-07-24 02:50 - 2013-04-09 07:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 01444864 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00817152 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\fhengine.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\iuilp.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\dmvdsitf.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll 2013-07-24 02:50 - 2013-04-09 07:49 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\fmifs.dll 2013-07-24 02:50 - 2013-04-09 07:48 - 00169472 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll 2013-07-24 02:50 - 2013-04-09 05:34 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys 2013-07-24 02:50 - 2013-04-09 05:33 - 00623104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2013-07-24 02:50 - 2013-04-09 05:33 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys 2013-07-24 02:50 - 2013-04-09 05:32 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2013-07-24 02:50 - 2013-04-09 05:31 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2013-07-24 02:50 - 2013-04-09 05:31 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys 2013-07-24 02:50 - 2013-04-09 02:44 - 00123880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll 2013-07-24 02:50 - 2013-04-09 02:39 - 01408896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-07-24 02:50 - 2013-04-09 02:37 - 00426024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2013-07-24 02:50 - 2013-04-09 02:37 - 00324368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2013-07-24 02:50 - 2013-04-09 00:52 - 11878912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-07-24 02:50 - 2013-04-09 00:52 - 00670208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2013-07-24 02:50 - 2013-04-09 00:52 - 00302592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2013-07-24 02:50 - 2013-04-09 00:52 - 00171008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2013-07-24 02:50 - 2013-04-09 00:52 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe 2013-07-24 02:50 - 2013-04-09 00:51 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 01593344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 01113600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00659456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00411136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00403968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00214528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00155648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2013-07-24 02:50 - 2013-04-09 00:51 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2013-07-24 02:50 - 2013-04-05 02:30 - 00503080 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2013-07-24 02:50 - 2013-03-16 01:05 - 00298456 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll 2013-07-24 02:50 - 2013-03-16 01:05 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll 2013-07-24 02:50 - 2013-03-02 13:39 - 00069864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys 2013-07-24 02:50 - 2013-03-02 05:43 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2013-07-24 02:50 - 2013-02-07 04:33 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2013-07-24 02:50 - 2013-02-02 11:40 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsRasterService.dll 2013-07-24 02:50 - 2013-02-02 11:23 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll 2013-07-24 02:50 - 2013-01-10 04:40 - 00303848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-07-24 02:50 - 2012-11-20 07:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidi2c.sys 2013-07-24 02:50 - 2012-11-06 10:33 - 00522640 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2013-07-24 02:50 - 2012-11-06 08:00 - 00463768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2013-07-24 02:50 - 2012-11-06 07:18 - 00267264 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2013-07-24 02:50 - 2012-10-11 08:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2013-07-24 02:50 - 2012-10-11 08:44 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2013-07-24 02:50 - 2012-10-11 08:06 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2013-07-24 02:50 - 2012-10-11 08:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2013-07-24 02:49 - 2012-12-13 07:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-07-24 02:49 - 2012-12-13 06:59 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-07-24 02:48 - 2013-01-29 04:57 - 00035232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2013-07-24 02:48 - 2013-01-29 02:08 - 00230904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2013-07-24 02:48 - 2012-11-01 07:41 - 01802240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2013-07-24 02:48 - 2012-11-01 07:41 - 01438720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2013-07-24 02:48 - 2012-11-01 07:40 - 02361344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2013-07-24 02:48 - 2012-11-01 07:40 - 01836032 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2013-07-24 02:48 - 2012-11-01 07:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2013-07-24 02:48 - 2012-11-01 07:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2013-07-24 02:48 - 2012-11-01 07:20 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2013-07-24 02:48 - 2012-11-01 07:20 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2013-07-24 02:34 - 2013-07-24 02:34 - 00001162 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk 2013-07-24 02:32 - 2013-07-24 02:33 - 05487912 _____ (TeamViewer GmbH) C:\Users\jessi_000\Downloads\TeamViewer_Setup_de_8.0.19617.exe 2013-07-24 01:00 - 2013-07-24 02:16 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\TeamViewer 2013-07-24 00:44 - 2013-07-24 00:44 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-07-23 22:43 - 2013-07-23 22:43 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-23 22:05 - 2013-07-23 22:05 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-23 22:05 - 2013-07-23 22:05 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-23 22:04 - 2013-07-23 22:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-23 00:54 - 2013-07-25 15:35 - 00000000 ___RD C:\Windows\BrowserChoice 2013-07-22 23:01 - 2013-08-12 09:49 - 00403456 ___SH C:\Users\jessi_000\Downloads\Thumbs.db 2013-07-21 16:03 - 2013-08-04 22:27 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log 2013-07-21 16:03 - 2013-08-04 17:10 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2013-07-21 15:17 - 2013-07-21 15:17 - 00000000 ____D C:\Users\Public\CyberLink 2013-07-21 01:13 - 2013-08-11 19:48 - 00003934 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F1CED133-BBD8-4711-A46A-9337410EB9F1} 2013-07-21 01:11 - 2013-07-21 01:11 - 00001890 _____ C:\Users\jessi_000\Downloads\EverydayArt.theme 2013-07-21 01:10 - 2013-07-21 01:10 - 10652531 _____ C:\Users\jessi_000\Downloads\MomentsCaptured_RishAgarwal.themepack 2013-07-21 01:09 - 2013-07-21 01:10 - 13704881 _____ C:\Users\jessi_000\Downloads\CoastalGermanyFrankHojenski.themepack 2013-07-21 01:07 - 2013-07-21 01:07 - 13054133 _____ C:\Users\jessi_000\Downloads\Moonlight.themepack 2013-07-21 01:07 - 2013-07-21 01:07 - 03271810 _____ C:\Users\jessi_000\Downloads\Spain.themepack 2013-07-21 00:52 - 2013-07-21 00:52 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2013-07-21 00:40 - 2013-08-05 20:32 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\PhotoScape 2013-07-21 00:40 - 2013-07-21 00:40 - 00001031 _____ C:\Users\jessi_000\Desktop\PhotoScape.lnk 2013-07-21 00:39 - 2013-07-21 00:40 - 00000000 ____D C:\Program Files (x86)\PhotoScape 2013-07-20 23:00 - 2013-08-09 17:33 - 00744960 ___SH C:\Users\jessi_000\Desktop\Thumbs.db 2013-07-20 22:48 - 2013-07-20 22:48 - 00000000 ___RD C:\Users\jessi_000\SkyDrive 2013-07-20 22:34 - 2013-07-20 22:34 - 01351264 _____ C:\Windows\NIRMALA.tt2 2013-07-20 22:34 - 2013-07-20 22:34 - 01303396 _____ C:\Windows\NIRMALAB.tt2 2013-07-20 22:32 - 2013-07-20 22:33 - 00000000 ____D C:\Program Files\Microsoft Office 15 2013-07-20 22:32 - 2013-07-20 22:32 - 00574656 _____ (Microsoft Corporation) C:\Users\jessi_000\Downloads\Setup.X86.de-DE_O365HomePremRetail_56ca86e8-6e39-4f60-abb7-5d90325e1dad_TX_DB_.exe 2013-07-20 22:26 - 2013-07-20 22:27 - 15929873 _____ C:\Users\jessi_000\Downloads\Rückblick_9b2012-13.pptx 2013-07-20 22:17 - 2013-07-20 22:17 - 00001255 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky PURE 3.0.lnk 2013-07-20 22:16 - 2013-07-20 22:16 - 00001078 _____ C:\Users\Public\Desktop\Kaspersky PURE 3.0.lnk 2013-07-20 22:16 - 2012-07-11 18:09 - 00064856 _____ (Kaspersky Lab) C:\Windows\system32\klfphc.dll 2013-07-20 22:15 - 2013-08-12 15:00 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-07-20 22:15 - 2013-07-20 22:50 - 00619616 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2013-07-20 22:15 - 2013-07-20 22:50 - 00090208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2013-07-20 22:15 - 2013-07-20 22:15 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2013-07-20 22:15 - 2012-12-10 16:14 - 00098064 _____ (Infowatch) C:\Windows\system32\Drivers\CSCrySec.sys 2013-07-20 22:15 - 2012-12-10 16:14 - 00067344 _____ (Infowatch) C:\Windows\system32\Drivers\CSVirtualDiskDrv.sys 2013-07-20 21:50 - 2013-08-04 21:56 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\hpqlog 2013-07-20 21:49 - 2013-08-12 14:59 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-20 21:49 - 2013-08-12 14:54 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-20 21:49 - 2013-07-31 18:56 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-20 21:49 - 2013-07-20 21:50 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Google 2013-07-20 21:49 - 2013-07-20 21:49 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-20 21:49 - 2013-07-20 21:49 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-20 21:49 - 2013-07-20 21:49 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-20 21:48 - 2013-07-20 21:49 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Deployment 2013-07-20 21:48 - 2013-07-20 21:48 - 00000000 ____D C:\Users\jessi_000\AppData\Local\Apps\2.0 2013-07-20 14:54 - 2013-08-11 15:51 - 00000000 ____D C:\Users\jessi_000\Documents\Youcam 2013-07-20 14:54 - 2013-08-04 22:25 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\CyberLink 2013-07-20 14:54 - 2013-08-04 17:06 - 00001227 _____ C:\Users\jessi_000\Desktop\CyberLink YouCam(Webcam).lnk 2013-07-20 14:54 - 2013-07-20 14:54 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\CyberLink 2013-07-20 14:36 - 2013-08-12 15:30 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2077869928-1068183206-618238599-1001 2013-07-20 14:32 - 2013-07-20 14:32 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Macromedia 2013-07-20 14:31 - 2013-07-25 23:59 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-07-20 14:31 - 2013-07-25 23:59 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-07-20 14:31 - 2013-07-20 23:46 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Hewlett-Packard 2013-07-20 14:31 - 2013-07-20 14:31 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-07-20 14:31 - 2013-07-20 14:31 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Synaptics 2013-07-20 14:30 - 2013-07-30 20:34 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Adobe 2013-07-20 14:30 - 2013-07-20 14:30 - 00001438 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-07-20 14:29 - 2013-07-20 14:29 - 00000141 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2013-07-20 14:29 - 2013-07-20 14:29 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Power2Go8 2013-07-20 14:28 - 2013-07-21 00:31 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Hewlett-Packard 2013-07-20 14:28 - 2013-07-20 22:33 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\VirtualStore 2013-07-20 14:27 - 2013-08-11 17:30 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Packages 2013-07-20 14:27 - 2013-08-04 22:24 - 00000000 ____D C:\Users\jessi_000 2013-07-20 14:27 - 2013-07-20 22:48 - 00002286 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2013-07-20 14:27 - 2013-07-20 14:27 - 00000020 ___SH C:\Users\jessi_000\ntuser.ini 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Vorlagen 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Startmenü 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Netzwerkumgebung 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Lokale Einstellungen 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Eigene Dateien 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Druckumgebung 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Documents\Eigene Musik 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Documents\Eigene Bilder 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Anwendungsdaten 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\JESSI_~1\AppData\Local\Verlauf 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\JESSI_~1\AppData\Local\Anwendungsdaten 2013-07-20 14:27 - 2012-10-27 19:32 - 00000000 ___HD C:\Users\jessi_000\Documents\hp.system.package.metadata 2013-07-20 14:27 - 2012-07-26 11:13 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2013-07-20 14:27 - 2012-07-26 11:13 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-07-20 14:27 - 2012-07-26 11:13 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2013-07-20 14:27 - 2012-07-26 11:13 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Programme 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Dokumente und Einstellungen ==================== One Month Modified Files and Folders ======= 2013-08-12 15:35 - 2013-08-12 15:35 - 00001059 _____ C:\Users\jessi_000\Desktop\JRT.txt 2013-08-12 15:30 - 2013-07-20 14:36 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2077869928-1068183206-618238599-1001 2013-08-12 15:23 - 2013-08-12 15:23 - 00000000 ____D C:\Windows\ERUNT 2013-08-12 15:23 - 2013-07-25 14:45 - 01695905 _____ C:\Windows\WindowsUpdate.log 2013-08-12 15:05 - 2012-10-28 04:48 - 00831158 _____ C:\Windows\system32\perfh007.dat 2013-08-12 15:05 - 2012-10-28 04:48 - 00188760 _____ C:\Windows\system32\perfc007.dat 2013-08-12 15:05 - 2012-07-26 10:28 - 01952854 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-12 15:00 - 2013-07-20 22:15 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-08-12 15:00 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\sru 2013-08-12 14:59 - 2013-07-20 21:49 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-12 14:58 - 2012-07-26 10:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-12 14:58 - 2012-07-26 08:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-08-12 14:56 - 2013-08-12 14:56 - 00001436 _____ C:\AdwCleaner[S1].txt 2013-08-12 14:54 - 2013-07-20 21:49 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-12 12:36 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-08-12 11:31 - 2013-08-12 11:31 - 00026900 _____ C:\Users\jessi_000\Desktop\Addition.zip 2013-08-12 11:23 - 2013-08-12 11:23 - 00123662 _____ C:\Users\jessi_000\Desktop\f.txt 2013-08-12 11:21 - 2013-08-12 11:21 - 00023345 _____ C:\Users\jessi_000\Desktop\Addition.txt 2013-08-12 11:14 - 2013-08-12 11:14 - 00000000 ____D C:\FRST 2013-08-12 09:49 - 2013-07-22 23:01 - 00403456 ___SH C:\Users\jessi_000\Downloads\Thumbs.db 2013-08-11 23:35 - 2013-08-11 23:35 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\IObit 2013-08-11 23:12 - 2013-08-11 17:32 - 00000000 ____D C:\Program Files (x86)\Exterminate It! 2013-08-11 22:05 - 2013-07-25 23:53 - 00102576 _____ C:\Windows\PFRO.log 2013-08-11 21:10 - 2013-08-11 21:10 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Malwarebytes 2013-08-11 21:07 - 2013-08-11 21:07 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-11 21:07 - 2013-08-11 21:07 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-11 21:07 - 2013-08-11 21:07 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-11 20:15 - 2012-12-28 11:53 - 00000000 ____D C:\ProgramData\CyberLink 2013-08-11 19:48 - 2013-07-21 01:13 - 00003934 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F1CED133-BBD8-4711-A46A-9337410EB9F1} 2013-08-11 17:54 - 2013-08-11 17:54 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Curiolab 2013-08-11 17:32 - 2013-08-11 17:32 - 00001081 _____ C:\Users\jessi_000\Desktop\Exterminate It!.lnk 2013-08-11 17:30 - 2013-07-20 14:27 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Packages 2013-08-11 17:14 - 2013-08-11 17:14 - 00000000 ____D C:\Encryption 2013-08-11 16:52 - 2012-12-28 11:36 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-08-11 15:58 - 2013-08-11 15:57 - 00000000 ____D C:\Users\jessi_000\Desktop\programme 2013-08-11 15:51 - 2013-07-20 14:54 - 00000000 ____D C:\Users\jessi_000\Documents\Youcam 2013-08-10 19:16 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\NDF 2013-08-09 17:33 - 2013-07-20 23:00 - 00744960 ___SH C:\Users\jessi_000\Desktop\Thumbs.db 2013-08-05 20:32 - 2013-07-21 00:40 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\PhotoScape 2013-08-04 22:27 - 2013-07-21 16:03 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log 2013-08-04 22:26 - 2013-08-04 22:26 - 00000902 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-04 22:25 - 2013-07-20 14:54 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\CyberLink 2013-08-04 22:24 - 2013-07-20 14:27 - 00000000 ____D C:\Users\jessi_000 2013-08-04 22:21 - 2012-08-04 03:02 - 00000000 ____D C:\SWSetup 2013-08-04 21:56 - 2013-07-20 21:50 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\hpqlog 2013-08-04 21:52 - 2012-12-28 11:51 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2013-08-04 21:52 - 2012-12-28 11:51 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2013-08-04 21:52 - 2012-12-28 11:51 - 00029480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll 2013-08-04 21:52 - 2012-10-27 19:35 - 00000000 ____D C:\Program Files (x86)\CyberLink 2013-08-04 21:01 - 2013-08-04 20:58 - 00000000 ____D C:\Windows\LastGood.Tmp 2013-08-04 21:01 - 2012-10-27 19:32 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard 2013-08-04 21:01 - 2012-09-19 05:56 - 00000000 ____D C:\Program Files\Hewlett-Packard 2013-08-04 20:58 - 2013-08-04 20:57 - 00006762 _____ C:\Windows\DPINST.LOG 2013-08-04 20:58 - 2013-08-04 20:57 - 00001332 _____ C:\Windows\Synaptics.log 2013-08-04 20:58 - 2013-07-30 18:40 - 00003782 _____ C:\Windows\setupact.log 2013-08-04 20:56 - 2013-08-04 20:57 - 01060080 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll 2013-08-04 20:56 - 2013-08-04 20:57 - 00544496 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCom.dll 2013-08-04 20:56 - 2013-08-04 20:57 - 00495856 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys 2013-08-04 20:56 - 2013-08-04 20:57 - 00264432 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2013-08-04 20:56 - 2013-08-04 20:57 - 00192240 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo18.dll 2013-08-04 20:56 - 2013-08-04 20:57 - 00151280 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynTPCom.dll 2013-08-04 20:56 - 2013-08-04 20:57 - 00033008 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\Smb_driver_Intel.sys 2013-08-04 20:28 - 2013-08-04 20:28 - 00003154 _____ C:\Windows\System32\Tasks\MirageAgent 2013-08-04 20:27 - 2013-08-04 20:27 - 00000000 ___HD C:\Users\Public\Documents\YouCam 2013-08-04 19:47 - 2013-08-04 19:47 - 00003166 _____ C:\Windows\System32\Tasks\CLVDLauncher 2013-08-04 19:47 - 2013-08-04 19:47 - 00003166 _____ C:\Windows\System32\Tasks\CLMLSvc_P2G8 2013-08-04 17:10 - 2013-07-21 16:03 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2013-08-04 17:06 - 2013-07-20 14:54 - 00001227 _____ C:\Users\jessi_000\Desktop\CyberLink YouCam(Webcam).lnk 2013-08-03 21:31 - 2013-08-03 21:31 - 10644535 _____ C:\Users\jessi_000\Downloads\WhatsApp.apk 2013-08-03 21:17 - 2013-08-03 21:17 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Windows Live 2013-08-03 21:16 - 2013-08-03 21:16 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\DivX 2013-08-02 16:08 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\rescache 2013-08-01 22:31 - 2013-07-30 23:08 - 00020480 ____H C:\Users\jessi_000\Desktop\photothumb.db 2013-07-31 18:56 - 2013-07-20 21:49 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-31 15:39 - 2013-07-31 15:38 - 00000000 ____D C:\Windows\system32\MRT 2013-07-31 13:51 - 2013-07-31 13:50 - 00449736 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-30 23:10 - 2013-07-30 23:10 - 00000000 ____D C:\output 2013-07-30 20:35 - 2013-07-30 20:35 - 00000566 _____ C:\Users\Public\Desktop\Pixlr-o-matic.lnk 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Pixlromatic 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\ProgramData\Adobe 2013-07-30 20:35 - 2013-07-30 20:35 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-30 20:34 - 2013-07-20 14:30 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Adobe 2013-07-30 20:25 - 2013-07-30 20:23 - 145394418 _____ C:\Users\JESSI_~1\AppData\Local\ACCCx189.zip.aamdownload 2013-07-30 20:25 - 2013-07-30 20:23 - 00001811 _____ C:\Users\JESSI_~1\AppData\Local\ACCCx189.zip.aamdownload.aamd 2013-07-30 20:22 - 2013-07-30 20:22 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Adobe 2013-07-30 20:21 - 2013-07-30 20:20 - 03867000 _____ (Adobe Systems Incorporated) C:\Users\jessi_000\Downloads\CreativeCloudSet-Up.exe 2013-07-30 20:07 - 2013-07-30 20:05 - 00000000 ____D C:\Users\jessi_000\Desktop\Musik 2013-07-30 18:40 - 2013-07-30 18:40 - 00000000 _____ C:\Windows\setuperr.log 2013-07-30 18:34 - 2012-07-26 11:12 - 00000000 ___RD C:\Windows\ToastData 2013-07-29 17:29 - 2013-07-29 17:29 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\WebApp 2013-07-29 17:25 - 2013-07-29 17:25 - 00000000 ____D C:\Users\jessi_000\Documents\CyberLink 2013-07-25 23:59 - 2013-07-20 14:31 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-07-25 23:59 - 2013-07-20 14:31 - 00000000 ___RD C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-07-25 23:56 - 2012-07-26 08:37 - 00000000 ____D C:\Windows\servicing 2013-07-25 15:40 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-07-25 15:39 - 2012-10-28 04:52 - 00000000 ____D C:\Windows\en-GB 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ___RD C:\Windows\ImmersiveControlPanel 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\WinStore 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\MUI 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\migwiz 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\inetsrv 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\en-GB 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\Com 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\migwiz 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\en-GB 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files\Common Files\System 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2013-07-25 15:39 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-25 15:39 - 2012-07-26 10:52 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\SysWOW64\winrm 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\SysWOW64\WCN 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\SysWOW64\sysprep 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\SysWOW64\slmgr 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\system32\winrm 2013-07-25 15:39 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\system32\slmgr 2013-07-25 15:39 - 2012-07-26 08:38 - 00000000 ____D C:\Windows\SysWOW64\oobe 2013-07-25 15:39 - 2012-07-26 08:38 - 00000000 ____D C:\Windows\SysWOW64\Dism 2013-07-25 15:39 - 2012-07-26 08:38 - 00000000 ____D C:\Windows\system32\Sysprep 2013-07-25 15:39 - 2012-07-26 08:38 - 00000000 ____D C:\Windows\system32\oobe 2013-07-25 15:38 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\inetsrv 2013-07-25 15:37 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\MUI 2013-07-25 15:37 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\system32\WCN 2013-07-25 15:37 - 2012-07-26 08:38 - 00000000 ____D C:\Windows\system32\Dism 2013-07-25 15:36 - 2013-07-25 15:36 - 00000000 ____D C:\sources 2013-07-25 15:36 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\SystemResetPlatform 2013-07-25 15:36 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\Com 2013-07-25 15:36 - 2012-07-26 10:51 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2013-07-25 15:35 - 2013-07-23 00:54 - 00000000 ___RD C:\Windows\BrowserChoice 2013-07-25 14:32 - 2013-07-25 14:32 - 00001274 _____ C:\Users\jessi_000\Desktop\shutdown.lnk 2013-07-25 13:54 - 2013-07-25 13:54 - 00000546 _____ C:\Users\jessi_000\Desktop\Emsisoft Emergency Kit.lnk 2013-07-25 13:54 - 2013-07-25 13:54 - 00000000 ____D C:\EEK 2013-07-25 13:51 - 2013-07-25 13:51 - 00082976 _____ C:\Users\jessi_000\Documents\cc_20130725_125126.reg 2013-07-25 13:50 - 2012-08-04 02:21 - 00000000 ____D C:\Windows\Panther 2013-07-25 13:49 - 2013-07-25 13:49 - 00002780 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-07-25 13:48 - 2013-07-25 13:48 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-07-25 13:48 - 2013-07-25 13:48 - 00000000 ____D C:\Program Files\CCleaner 2013-07-25 13:44 - 2013-07-25 13:44 - 04396440 _____ (Piriform Ltd) C:\Users\jessi_000\Desktop\ccsetup403.exe 2013-07-25 13:43 - 2013-07-25 13:40 - 181531216 _____ C:\Users\jessi_000\Downloads\EmsisoftEmergencyKit40012.exe 2013-07-25 00:25 - 2013-07-25 00:25 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\DDMSettings 2013-07-25 00:24 - 2013-07-25 00:23 - 00000000 ____D C:\Program Files\DivX 2013-07-25 00:24 - 2013-07-25 00:21 - 00000000 ____D C:\ProgramData\DivX 2013-07-25 00:24 - 2013-07-25 00:21 - 00000000 ____D C:\Program Files (x86)\DivX 2013-07-25 00:21 - 2013-07-25 00:21 - 00957248 _____ (DivX, LLC) C:\Users\jessi_000\Downloads\DivXWebPlayerInstaller.exe 2013-07-24 02:34 - 2013-07-24 02:34 - 00001162 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk 2013-07-24 02:33 - 2013-07-24 02:32 - 05487912 _____ (TeamViewer GmbH) C:\Users\jessi_000\Downloads\TeamViewer_Setup_de_8.0.19617.exe 2013-07-24 02:22 - 2012-07-26 11:12 - 00000000 __RHD C:\Users\Public\Libraries 2013-07-24 02:22 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\WinMetadata 2013-07-24 02:22 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\SysWOW64\Bthprops 2013-07-24 02:22 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\Bthprops 2013-07-24 02:22 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\L2Schemas 2013-07-24 02:20 - 2012-10-28 04:47 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2013-07-24 02:16 - 2013-07-24 01:00 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\TeamViewer 2013-07-24 02:09 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\registration 2013-07-24 00:44 - 2013-07-24 00:44 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-07-23 22:43 - 2013-07-23 22:43 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-23 22:05 - 2013-07-23 22:05 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-23 22:05 - 2013-07-23 22:05 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-23 22:04 - 2013-07-23 22:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-23 21:42 - 2012-08-04 01:29 - 00000000 ____D C:\ProgramData\PRICache 2013-07-21 20:02 - 2012-07-26 11:12 - 00000000 ____D C:\Windows\system32\restore 2013-07-21 15:17 - 2013-07-21 15:17 - 00000000 ____D C:\Users\Public\CyberLink 2013-07-21 01:11 - 2013-07-21 01:11 - 00001890 _____ C:\Users\jessi_000\Downloads\EverydayArt.theme 2013-07-21 01:10 - 2013-07-21 01:10 - 10652531 _____ C:\Users\jessi_000\Downloads\MomentsCaptured_RishAgarwal.themepack 2013-07-21 01:10 - 2013-07-21 01:09 - 13704881 _____ C:\Users\jessi_000\Downloads\CoastalGermanyFrankHojenski.themepack 2013-07-21 01:07 - 2013-07-21 01:07 - 13054133 _____ C:\Users\jessi_000\Downloads\Moonlight.themepack 2013-07-21 01:07 - 2013-07-21 01:07 - 03271810 _____ C:\Users\jessi_000\Downloads\Spain.themepack 2013-07-21 00:52 - 2013-07-21 00:52 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2013-07-21 00:40 - 2013-07-21 00:40 - 00001031 _____ C:\Users\jessi_000\Desktop\PhotoScape.lnk 2013-07-21 00:40 - 2013-07-21 00:39 - 00000000 ____D C:\Program Files (x86)\PhotoScape 2013-07-21 00:31 - 2013-07-20 14:28 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Hewlett-Packard 2013-07-20 23:46 - 2013-07-20 14:31 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Hewlett-Packard 2013-07-20 22:50 - 2013-07-20 22:15 - 00619616 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2013-07-20 22:50 - 2013-07-20 22:15 - 00090208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2013-07-20 22:50 - 2012-10-23 16:45 - 00050448 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klwfp.sys 2013-07-20 22:50 - 2012-08-13 17:49 - 00178448 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2013-07-20 22:48 - 2013-07-20 22:48 - 00000000 ___RD C:\Users\jessi_000\SkyDrive 2013-07-20 22:48 - 2013-07-20 14:27 - 00002286 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2013-07-20 22:48 - 2012-10-27 19:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-07-20 22:34 - 2013-07-20 22:34 - 01351264 _____ C:\Windows\NIRMALA.tt2 2013-07-20 22:34 - 2013-07-20 22:34 - 01303396 _____ C:\Windows\NIRMALAB.tt2 2013-07-20 22:33 - 2013-07-20 22:32 - 00000000 ____D C:\Program Files\Microsoft Office 15 2013-07-20 22:33 - 2013-07-20 14:28 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\VirtualStore 2013-07-20 22:32 - 2013-07-20 22:32 - 00574656 _____ (Microsoft Corporation) C:\Users\jessi_000\Downloads\Setup.X86.de-DE_O365HomePremRetail_56ca86e8-6e39-4f60-abb7-5d90325e1dad_TX_DB_.exe 2013-07-20 22:27 - 2013-07-20 22:26 - 15929873 _____ C:\Users\jessi_000\Downloads\Rückblick_9b2012-13.pptx 2013-07-20 22:17 - 2013-07-20 22:17 - 00001255 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky PURE 3.0.lnk 2013-07-20 22:16 - 2013-07-20 22:16 - 00001078 _____ C:\Users\Public\Desktop\Kaspersky PURE 3.0.lnk 2013-07-20 22:16 - 2012-07-26 08:26 - 00262144 ___SH C:\Windows\system32\config\ELAM 2013-07-20 22:15 - 2013-07-20 22:15 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2013-07-20 22:15 - 2012-07-26 11:12 - 00000000 ___HD C:\Windows\ELAMBKUP 2013-07-20 22:12 - 2012-12-28 12:00 - 00000000 ____D C:\ProgramData\Norton 2013-07-20 21:50 - 2013-07-20 21:49 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Google 2013-07-20 21:49 - 2013-07-20 21:49 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-20 21:49 - 2013-07-20 21:49 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-20 21:49 - 2013-07-20 21:49 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-20 21:49 - 2013-07-20 21:48 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Deployment 2013-07-20 21:48 - 2013-07-20 21:48 - 00000000 ____D C:\Users\jessi_000\AppData\Local\Apps\2.0 2013-07-20 14:54 - 2013-07-20 14:54 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\CyberLink 2013-07-20 14:34 - 2012-12-28 11:34 - 00002887 _____ C:\Windows\system32\RaCoInst.log 2013-07-20 14:32 - 2013-07-20 14:32 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Macromedia 2013-07-20 14:31 - 2013-07-20 14:31 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-07-20 14:31 - 2013-07-20 14:31 - 00000000 ____D C:\Users\jessi_000\AppData\Roaming\Synaptics 2013-07-20 14:30 - 2013-07-20 14:30 - 00001438 _____ C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-07-20 14:30 - 2012-10-27 19:46 - 00000000 ___RD C:\Program Files\Online Services 2013-07-20 14:30 - 2012-10-27 19:45 - 00000000 ___RD C:\Program Files (x86)\Online Services 2013-07-20 14:30 - 2012-08-04 03:02 - 00000000 ___HD C:\SYSTEM.SAV 2013-07-20 14:29 - 2013-07-20 14:29 - 00000141 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2013-07-20 14:29 - 2013-07-20 14:29 - 00000000 ____D C:\Users\JESSI_~1\AppData\Local\Power2Go8 2013-07-20 14:27 - 2013-07-20 14:27 - 00000020 ___SH C:\Users\jessi_000\ntuser.ini 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Vorlagen 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Startmenü 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Netzwerkumgebung 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Lokale Einstellungen 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Eigene Dateien 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Druckumgebung 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Documents\Eigene Musik 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Documents\Eigene Bilder 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\jessi_000\Anwendungsdaten 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\JESSI_~1\AppData\Local\Verlauf 2013-07-20 14:27 - 2013-07-20 14:27 - 00000000 _SHDL C:\Users\JESSI_~1\AppData\Local\Anwendungsdaten 2013-07-20 14:26 - 2012-10-27 19:46 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Programme 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-07-20 13:19 - 2013-07-20 13:19 - 00000000 _SHDL C:\Dokumente und Einstellungen 2013-07-20 13:19 - 2012-07-26 11:12 - 00000000 ____D C:\Program Files\Windows NT 2013-07-20 13:19 - 2012-07-26 08:37 - 00000000 __RHD C:\Users\Default ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-11 16:50 ==================== End Of Log ============================ [/CODE] Hab ich schon den Trojaner entfernt? Oder muss ich noch etwas machen? ^^ Und, eine Frage noch, ich kann immer noch nicht in meiner Bibliothek Bilder, Videos, Dokumente und Musik aufmachen, ich denke das hat noch der Trojaner gesperrt/gelöscht. Wie kann ich das wieder gut machen? :S |
12.08.2013, 17:24 | #12 | |
/// the machine /// TB-Ausbilder | Ransomware (bprotector) entfernen, aber wie?Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.08.2013, 09:04 | #13 |
| Ransomware (bprotector) entfernen, aber wie? Wenn ich das aufmachen will, dann kommt: "Musik.library-ms kann nicht länger ausgeführt werden Diese Bibliothek kann sicher vom Computer gelöscht werden. Darin enthaltene Ordner sind nicht davon betroffen." |
13.08.2013, 12:14 | #14 |
/// the machine /// TB-Ausbilder | Ransomware (bprotector) entfernen, aber wie? Screenshot davon bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.08.2013, 13:43 | #15 |
| Ransomware (bprotector) entfernen, aber wie? Ich habe das schon gelöst, das Problem war das: hxxp://www.finosoft.de/news/2011/02/problembehebung-document-library-ms-kann-nicht-langer-ausgefuhrt-werden/ |
Themen zu Ransomware (bprotector) entfernen, aber wie? |
antivirus, bilder, bprotector, dokumente, emsisoft, entferne, entfernen, exterminate, hilfe, kaspersky, laptop, nicht mehr, ransomware, sauber, trojan, videos, virus, windows, windows 8, windows8 |