(der Rest von FRST)
Code:
Alles auswählen Aufklappen ATTFilter
==================== One Month Modified Files and Folders =======
2013-09-19 17:42 - 2010-11-21 05:47 - 00019472 _____ C:\Windows\PFRO.log
2013-09-19 17:42 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-19 17:42 - 2009-07-14 06:51 - 00026831 _____ C:\Windows\setupact.log
2013-09-19 17:41 - 2013-09-17 21:06 - 00000000 ____D C:\AdwCleaner
2013-09-19 17:41 - 2013-09-16 18:49 - 01621614 _____ C:\Windows\WindowsUpdate.log
2013-09-19 17:06 - 2013-09-19 17:06 - 00002395 _____ C:\Users\Andi\Desktop\gmer.log
2013-09-19 16:58 - 2009-07-14 06:45 - 00025872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-19 16:58 - 2009-07-14 06:45 - 00025872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-19 16:55 - 2013-09-19 16:55 - 00000470 _____ C:\Users\Andi\Desktop\defogger_disable.log
2013-09-19 16:55 - 2013-09-19 16:55 - 00000000 _____ C:\Users\Andi\defogger_reenable
2013-09-19 16:55 - 2013-09-17 04:44 - 00697082 _____ C:\Windows\system32\perfh007.dat
2013-09-19 16:55 - 2013-09-17 04:44 - 00148346 _____ C:\Windows\system32\perfc007.dat
2013-09-19 16:55 - 2013-09-16 18:54 - 00000000 ____D C:\Users\Andi
2013-09-19 16:55 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-19 00:49 - 2013-09-17 19:07 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Guitar Pro 6
2013-09-19 00:44 - 2013-09-19 00:51 - 00377856 _____ C:\Users\Andi\Desktop\gmer_2.1.19163.exe
2013-09-19 00:44 - 2013-09-19 00:51 - 00050477 _____ C:\Users\Andi\Desktop\Defogger.exe
2013-09-19 00:37 - 2013-09-19 00:37 - 00000000 ____D C:\FRST
2013-09-19 00:30 - 2013-09-19 00:51 - 01950594 _____ (Farbar) C:\Users\Andi\Desktop\FRST64.exe
2013-09-19 00:17 - 2013-09-16 21:01 - 00000000 ____D C:\Users\Andi\AppData\Roaming\vlc
2013-09-18 18:24 - 2013-09-18 18:24 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Malwarebytes
2013-09-18 18:23 - 2013-09-18 18:23 - 00001117 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-09-18 18:23 - 2013-09-18 18:23 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-18 18:23 - 2013-09-18 18:23 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-18 17:41 - 2013-09-16 19:45 - 00000000 ____D C:\Users\Andi\AppData\Local\Mozilla
2013-09-17 23:47 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-17 22:27 - 2013-09-16 23:09 - 00000000 ____D C:\Program Files\Unlocker
2013-09-17 21:05 - 2013-09-19 00:51 - 01039554 _____ C:\Users\Andi\Desktop\adwcleaner004.exe
2013-09-17 19:37 - 2013-09-17 19:37 - 00000000 ____D C:\Users\Andi\Documents\MeineBackups
2013-09-17 19:37 - 2013-09-17 19:37 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Acronis
2013-09-17 19:36 - 2013-09-17 19:36 - 00000000 ____D C:\ProgramData\Acronis
2013-09-17 19:36 - 2009-07-14 06:45 - 00309264 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-17 19:35 - 2013-09-16 19:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-17 19:27 - 2013-09-17 19:27 - 00000940 _____ C:\Users\Andi\Desktop\Guitar Pro 5.lnk
2013-09-17 19:27 - 2013-09-17 19:27 - 00000000 ____D C:\Program Files (x86)\Guitar Pro 5
2013-09-17 19:17 - 2013-09-16 19:08 - 00067232 _____ C:\Users\Andi\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-17 19:14 - 2013-09-15 16:01 - 00000000 ____D C:\Users\Andi\Desktop\ATMOM
2013-09-17 19:12 - 2013-09-17 19:07 - 00000000 ____D C:\ProgramData\Guitar Pro 6
2013-09-17 18:50 - 2013-09-17 18:50 - 01581088 _____ (Acronis) C:\Windows\system32\Drivers\tdrpm174.sys
2013-09-17 18:50 - 2013-09-17 18:50 - 00880160 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys
2013-09-17 18:50 - 2013-09-17 18:50 - 00237600 _____ (Acronis) C:\Windows\system32\Drivers\snman380.sys
2013-09-17 18:50 - 2013-09-17 18:50 - 00083488 _____ (Acronis) C:\Windows\system32\Drivers\tifsfilt.sys
2013-09-17 18:50 - 2013-09-17 18:50 - 00001103 _____ C:\Users\Public\Desktop\Acronis True Image Home 2009.lnk
2013-09-17 18:50 - 2013-09-17 18:50 - 00000000 ____D C:\Program Files (x86)\Acronis
2013-09-17 18:48 - 2013-09-17 18:48 - 00000638 _____ C:\Users\Andi\Desktop\Müll.lnk
2013-09-17 18:25 - 2013-09-17 18:25 - 00001155 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-17 18:25 - 2013-09-17 18:25 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Mozilla
2013-09-17 18:25 - 2013-09-17 18:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-17 18:05 - 2013-09-17 18:04 - 00001870 ____H C:\Windows\EPMBatch.ept
2013-09-17 17:48 - 2013-09-17 17:48 - 00000000 ____D C:\Program Files (x86)\EaseUS
2013-09-17 17:35 - 2013-09-17 17:35 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Thunderbird
2013-09-17 17:35 - 2013-09-17 17:35 - 00000000 ____D C:\Users\Andi\AppData\Local\Thunderbird
2013-09-17 17:27 - 2013-09-17 17:37 - 00000378 _____ C:\Users\Andi\Documents\indexfile.txt
2013-09-17 17:17 - 2013-09-17 17:17 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2013-09-17 17:17 - 2013-09-17 17:17 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01009.Wdf
2013-09-17 17:17 - 2013-09-17 17:17 - 00000000 ____D C:\Program Files\Synaptics
2013-09-17 17:17 - 2013-09-16 19:20 - 00016456 _____ C:\Windows\DPINST.LOG
2013-09-17 17:16 - 2013-09-17 17:16 - 00003068 _____ C:\Windows\System32\Tasks\{3C368D3A-BA94-47BE-9941-9C07389850A9}
2013-09-17 17:16 - 2013-09-17 17:16 - 00001390 _____ C:\Windows\Synaptics.log
2013-09-17 04:45 - 2013-09-17 04:45 - 00000000 ____D C:\Hotfix
2013-09-17 04:45 - 2009-07-14 07:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG
2013-09-17 04:45 - 2009-07-14 07:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2013-09-17 04:45 - 2009-07-14 06:45 - 00000000 ____D C:\Windows\Setup
2013-09-17 04:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Recovery
2013-09-17 04:43 - 2013-09-17 04:44 - 00295922 _____ C:\Windows\system32\perfi007.dat
2013-09-17 04:43 - 2013-09-17 04:44 - 00038104 _____ C:\Windows\system32\perfd007.dat
2013-09-17 04:43 - 2013-09-17 04:43 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer
2013-09-17 04:43 - 2013-09-17 04:43 - 00000000 ____D C:\Windows\SysWOW64\de
2013-09-17 04:43 - 2013-09-17 04:43 - 00000000 ____D C:\Windows\SysWOW64\0407
2013-09-17 04:43 - 2013-09-17 04:43 - 00000000 ____D C:\Windows\system32\de
2013-09-17 04:43 - 2013-09-17 04:43 - 00000000 ____D C:\Windows\system32\0407
2013-09-17 04:43 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2013-09-17 04:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing
2013-09-17 00:42 - 2010-11-21 09:17 - 00000000 ____D C:\Program Files\Windows Journal
2013-09-17 00:42 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\winrm
2013-09-17 00:42 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\WCN
2013-09-17 00:42 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\sysprep
2013-09-17 00:42 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\slmgr
2013-09-17 00:42 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2013-09-17 00:42 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\winrm
2013-09-17 00:42 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\slmgr
2013-09-17 00:42 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\DigitalLocker
2013-09-17 00:42 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2013-09-17 00:42 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-09-17 00:42 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-09-17 00:42 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker
2013-09-17 00:42 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2013-09-17 00:42 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-09-17 00:42 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Setup
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\oobe
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\MUI
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\com
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Setup
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\oobe
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\migwiz
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\IME
2013-09-17 00:42 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\System
2013-09-17 00:41 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\WCN
2013-09-17 00:41 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2013-09-17 00:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\MUI
2013-09-17 00:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Dism
2013-09-17 00:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\com
2013-09-16 23:09 - 2013-09-16 23:09 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
2013-09-16 23:07 - 2013-09-16 21:18 - 00000000 ____D C:\Program Files (x86)\Unlocker
2013-09-16 23:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-09-16 22:59 - 2013-09-16 22:54 - 00000000 ____D C:\Users\Andi\AppData\Roaming\DVDVideoSoft
2013-09-16 22:59 - 2013-09-16 22:54 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-09-16 22:57 - 2013-09-16 19:26 - 01591234 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-09-16 22:44 - 2013-09-16 19:02 - 00000000 ____D C:\Program Files (x86)\Intel
2013-09-16 22:27 - 2013-09-16 18:54 - 00001417 _____ C:\Users\Andi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-09-16 22:27 - 2013-09-16 18:54 - 00000000 ___RD C:\Users\Andi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-16 22:27 - 2013-09-16 18:54 - 00000000 ___RD C:\Users\Andi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-16 22:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-09-16 22:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-09-16 22:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-09-16 22:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-09-16 22:12 - 2013-09-16 22:12 - 00000000 ____D C:\Program Files\7-Zip
2013-09-16 22:09 - 2013-09-16 22:09 - 00001590 _____ C:\Users\Andi\Desktop\Shutdown Manager.lnk
2013-09-16 22:08 - 2013-09-16 22:08 - 00000000 ____D C:\Program Files (x86)\Shutdown Manager
2013-09-16 21:57 - 2013-09-16 21:56 - 00000000 ____D C:\Windows\system32\MRT
2013-09-16 21:53 - 2013-09-16 21:46 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-09-16 21:44 - 2013-09-16 21:34 - 00013667 _____ C:\Windows\IE10_main.log
2013-09-16 21:40 - 2013-09-16 21:40 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-16 21:40 - 2013-09-16 21:40 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-16 21:40 - 2013-09-16 21:40 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-16 21:40 - 2013-09-16 21:40 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-09-16 21:40 - 2013-09-16 21:40 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-09-16 21:40 - 2013-09-16 21:40 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-09-16 21:40 - 2013-09-16 21:40 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-09-16 21:40 - 2013-09-16 21:40 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-09-16 21:40 - 2013-09-16 21:40 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-09-16 21:40 - 2013-09-16 21:40 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-09-16 21:40 - 2013-09-16 21:40 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-09-16 21:40 - 2013-09-16 21:40 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-09-16 21:40 - 2013-09-16 21:40 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-09-16 21:36 - 2013-09-16 21:36 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-09-16 21:36 - 2013-09-16 21:36 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-09-16 21:34 - 2013-09-16 21:34 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-09-16 21:34 - 2013-09-16 21:34 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-09-16 21:27 - 2013-09-16 21:27 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Macromedia
2013-09-16 21:27 - 2013-09-16 21:27 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Adobe
2013-09-16 21:27 - 2013-09-16 21:27 - 00000000 ____D C:\Users\Andi\AppData\Local\Macromedia
2013-09-16 21:26 - 2013-09-16 21:26 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-16 21:26 - 2013-09-16 21:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-16 21:26 - 2013-09-16 21:26 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-09-16 21:26 - 2013-09-16 21:26 - 00000000 ____D C:\Windows\system32\Macromed
2013-09-16 21:26 - 2013-09-16 21:26 - 00000000 ____D C:\Users\Andi\AppData\Local\Adobe
2013-09-16 21:26 - 2013-09-16 21:22 - 00003875 _____ C:\Windows\IE9_main.log
2013-09-16 21:16 - 2013-09-16 21:16 - 00000000 ____D C:\Users\Andi\AppData\Roaming\OpenOffice
2013-09-16 21:14 - 2013-09-16 21:14 - 00000696 _____ C:\Users\Andi\Desktop\jDownloads.lnk
2013-09-16 21:14 - 2013-09-16 21:14 - 00000627 _____ C:\Users\Andi\Desktop\hsp.lnk
2013-09-16 20:59 - 2013-09-16 20:59 - 00000000 ____D C:\ProgramData\CyberLink
2013-09-16 20:58 - 2013-09-16 19:33 - 00002247 _____ C:\Users\Andi\Desktop\OneKey Recovery.lnk
2013-09-16 20:35 - 2013-09-16 20:35 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-09-16 20:35 - 2013-09-16 20:35 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-16 20:22 - 2013-09-16 20:22 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2013-09-16 19:58 - 2013-09-16 19:58 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Avira
2013-09-16 19:57 - 2013-09-16 19:57 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-09-16 19:51 - 2013-09-16 19:51 - 00002094 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2013-09-16 19:51 - 2013-09-16 19:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-09-16 19:50 - 2013-09-16 19:50 - 00001074 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-09-16 19:50 - 2013-09-16 19:50 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2013-09-16 19:49 - 2013-09-16 19:48 - 00000000 ____D C:\ProgramData\Avira
2013-09-16 19:48 - 2013-09-16 19:48 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-09-16 19:48 - 2013-09-16 19:48 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-09-16 19:48 - 2013-09-16 19:48 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-09-16 19:48 - 2013-09-16 19:48 - 00000000 ____D C:\Program Files (x86)\Avira
2013-09-16 19:45 - 2013-09-16 19:45 - 00000000 ____D C:\ProgramData\Mozilla
2013-09-16 19:35 - 2013-09-16 19:35 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_iusb3hcs_01009.Wdf
2013-09-16 19:35 - 2013-09-16 19:06 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-09-16 19:34 - 2013-09-16 19:34 - 00039008 _____ (Lenovo.) C:\Windows\system32\Drivers\LhdX64.sys
2013-09-16 19:34 - 2013-09-16 19:34 - 00019872 _____ (Lenovo (Beijing) Limited) C:\Windows\system32\LenovoSDKEmSubSystem.dll
2013-09-16 19:34 - 2013-09-16 19:34 - 00000000 ____D C:\ProgramData\Downloaded Installations
2013-09-16 19:34 - 2013-09-16 19:34 - 00000000 ____D C:\Program Files\DIFX
2013-09-16 19:34 - 2013-09-16 19:34 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-09-16 19:34 - 2013-09-16 19:33 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2013-09-16 19:34 - 2013-09-16 19:22 - 00000000 ____D C:\Program Files\Lenovo
2013-09-16 19:34 - 2011-12-15 14:09 - 00030816 _____ (Lenovo Corporation) C:\Windows\system32\Drivers\AcpiVpc.sys
2013-09-16 19:33 - 2013-09-16 19:33 - 00002108 _____ C:\Users\Default\Desktop\OneKey Recovery.lnk
2013-09-16 19:33 - 2013-09-16 19:33 - 00002108 _____ C:\Users\Default User\Desktop\OneKey Recovery.lnk
2013-09-16 19:33 - 2013-09-16 19:33 - 00000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2013-09-16 19:33 - 2013-09-16 19:33 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2013-09-16 19:33 - 2013-09-16 19:33 - 00000000 ____D C:\ProgramData\OneKey Recovery
2013-09-16 19:30 - 2013-09-16 19:30 - 00000000 ____D C:\Windows\SysWOW64\sda
2013-09-16 19:29 - 2013-09-16 19:29 - 00000000 ____D C:\Program Files (x86)\Realtek
2013-09-16 19:27 - 2013-09-16 19:27 - 00000000 ____D C:\Windows\Options
2013-09-16 19:27 - 2013-09-16 19:27 - 00000000 ____D C:\Program Files (x86)\USB Camera2
2013-09-16 19:27 - 2013-09-16 19:27 - 00000000 ____D C:\Program Files (x86)\BisonCam
2013-09-16 19:27 - 2009-07-14 05:20 - 00000000 __RSD C:\Windows\Media
2013-09-16 19:27 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2013-09-16 19:27 - 2009-07-14 04:34 - 00000427 _____ C:\Windows\win.ini
2013-09-16 19:24 - 2013-09-16 19:24 - 00000000 ____D C:\Users\Andi\Documents\Bluetooth-Exchange-Ordner
2013-09-16 19:24 - 2013-09-16 19:24 - 00000000 ____D C:\Users\Andi\AppData\Local\Broadcom
2013-09-16 19:21 - 2013-09-16 19:21 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_AMPPAL_01009.Wdf
2013-09-16 19:21 - 2013-09-16 19:09 - 00000000 ____D C:\Program Files\Intel
2013-09-16 19:20 - 2013-09-16 19:20 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Intel
2013-09-16 19:20 - 2013-09-16 19:20 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-09-16 19:20 - 2013-09-16 19:13 - 00000000 ____D C:\Program Files\Common Files\Intel
2013-09-16 19:20 - 2013-09-16 19:10 - 00000000 ____D C:\ProgramData\Intel
2013-09-16 19:20 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-09-16 19:18 - 2013-09-16 19:18 - 00000000 ____D C:\Windows\SysWOW64\Atheros_L1e
2013-09-16 19:17 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\restore
2013-09-16 19:16 - 2013-09-16 19:16 - 00000000 ____D C:\Program Files\CONEXANT
2013-09-16 19:16 - 2013-09-16 19:16 - 00000000 ____D C:\Program Files (x86)\Dolby Advanced Audio v2
2013-09-16 19:14 - 2013-09-16 19:14 - 00015418 _____ C:\Windows\system32\results.xml
2013-09-16 19:12 - 2013-09-16 19:01 - 00000000 ____D C:\Intel
2013-09-16 19:09 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-09-16 19:08 - 2013-09-16 19:08 - 00000000 ____D C:\Users\Andi\AppData\Roaming\Intel Corporation
2013-09-16 19:06 - 2013-09-16 19:06 - 00000000 ____D C:\Users\Andi\AppData\Roaming\InstallShield
2013-09-16 18:54 - 2013-09-17 04:45 - 00000000 ____D C:\Windows\Panther
2013-09-16 18:54 - 2013-09-16 18:54 - 00000020 ___SH C:\Users\Andi\ntuser.ini
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\Vorlagen
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\Startmenü
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\Vorlagen
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\Startmenü
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\Netzwerkumgebung
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\Lokale Einstellungen
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\Eigene Dateien
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\Druckumgebung
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\Documents\Eigene Musik
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\Documents\Eigene Bilder
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\AppData\Local\Verlauf
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\AppData\Local\Anwendungsdaten
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Users\Andi\Anwendungsdaten
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Programme
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\ProgramData\Vorlagen
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\ProgramData\Startmenü
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\ProgramData\Favoriten
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\ProgramData\Dokumente
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 _SHDL C:\Dokumente und Einstellungen
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 __SHD C:\Recovery
2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 ____D C:\Users\Andi\AppData\Local\VirtualStore
2013-09-16 18:54 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT
2013-09-16 18:49 - 2013-09-16 18:49 - 00001355 _____ C:\Windows\TSSysprep.log
2013-09-16 18:49 - 2009-07-14 06:46 - 00002790 _____ C:\Windows\DtcInstall.log
2013-09-16 18:47 - 2010-11-21 09:17 - 00000000 ____D C:\Windows\CSC
2013-09-01 17:08 - 2013-09-16 21:56 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Andi\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\Andi\AppData\Local\Temp\fp_pl_pfs_installer-2.exe
C:\Users\Andi\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Andi\AppData\Local\Temp\Quarantine.exe
C:\Users\Andi\AppData\Local\Temp\_is35FD.exe
C:\Users\Andi\AppData\Local\Temp\_isC81E.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-17 00:00
==================== End Of Log ============================