|
Log-Analyse und Auswertung: ESET Bootsektor Prüfung nicht durführbarWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
22.09.2013, 13:35 | #1 |
| ESET Bootsektor Prüfung nicht durführbar Liebe Helfer, seit einigen Tagen kann ich die ESET ON-Demand Prüfung nicht mehr durchführen, da sich die Prüfung beim Abschnitt Bootsektor scheinbar aufhängt. Das heißt, es ist kein Fortschritt auch nach über einer Stunde Prüfzeit erkennbar. Zudem kann die Prüfung auch nicht abgebrochen werden. Auch das Herunterfahren von Windows ist dann nicht mehr möglich. Wenn die On-Demand Prüfung ausgeführt wird, schlägt sich das zudem sehr negativ auf die Performance nieder. Ich benutze Windows 7 Home Premium. Vielen Dank für Eure Hilfe im Vorraus. Hier die Logfiles: FRST Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-09-2013 Ran by Kai (administrator) on KAI-PC on 22-09-2013 12:40:43 Running from C:\Users\Kai\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (AVM Berlin) C:\Program Files\FRITZ!DSL\IGDCTRL.EXE (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (O2Micro International) C:\Windows\system32\DRIVERS\o2flash.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Spotify Ltd) C:\Users\Kai\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (AVM Berlin) C:\Program Files\FRITZ!DSL\FwebProt.exe () C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe () C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Dropbox, Inc.) C:\Users\Kai\AppData\Roaming\Dropbox\bin\Dropbox.exe () C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (AVM Berlin) C:\Program Files\FRITZ!DSL\StCenter.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe () C:\Users\Kai\Desktop\Defogger.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1812776 2009-06-26] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [524800 2010-12-02] (IDT, Inc.) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated) HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2839840 2010-04-07] (ESET) HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1475952 2013-01-10] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe [578560 2012-12-18] (Samsung Electronics) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.) HKCU\...\Run: [Spotify Web Helper] - C:\Users\Kai\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-07] (Spotify Ltd) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-14] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [PDVDDXSrv] - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe [140520 2009-06-25] (CyberLink Corp.) HKLM-x32\...\Run: [UCam_Menu] - C:\Program Files (x86)\Dell\Dell TouchCam\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [195072 2010-01-29] (ArcSoft Inc.) HKLM-x32\...\Run: [Desktop Disc Tool] - c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [498160 2009-10-15] () HKLM-x32\...\Run: [HTC Sync Loader] - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [634880 2011-12-20] () HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-03-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310128 2013-01-10] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-04-15] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] () Startup: C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Kai\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {A124FC7A-4BDE-4453-A3C4-A3B0882262BD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {1E166907-098A-4B6B-A5E0-F7AC987A4012} URL = SearchScopes: HKCU - {8C930743-6431-4A84-A7FD-63366F781AA2} URL = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Web Check - {E155F23C-9931-47c6-A619-20E6FCA86D75} - C:\Program Files (x86)\Web Check\WebCheck.dll No File Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU - No Name - {472734EA-242A-422B-ADF8-83D1E48CC825} - No File DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{204B577C-80AB-4B5A-8CAB-D9EF5D48A92F}: [NameServer]8.8.8.8 Tcpip\..\Interfaces\{BAC4F26B-5246-4AD2-B435-89017704A0F6}: [NameServer]8.8.8.8,8.8.4.4 FireFox: ======== FF ProfilePath: C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\s9e67oj7.default FF DefaultSearchEngine: Google FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass64.dll (LastPass) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll No File FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\s9e67oj7.default\searchplugins\duckduckgo.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: LastPass - C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\s9e67oj7.default\Extensions\support@lastpass.com FF Extension: WOT - C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\s9e67oj7.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: No Name - C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\s9e67oj7.default\Extensions\706e0191cf7aed088f2608af3565372fd0a93b395dc77a00c5b2e5ac00df6696_lp.key FF Extension: jid1-ZAdIEUB7XOzOJw - C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\s9e67oj7.default\Extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi FF Extension: No Name - C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\s9e67oj7.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\s9e67oj7.default\Extensions\{EE223D7A-F30F-11DD-8F0A-D2AD55D89593}.xpi FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Hotspot Shield Extension - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afext@anchorfree.com FF HKLM-x32\...\Firefox\Extensions: [{B7082FAA-CB62-4872-9106-E42DD88EDE45}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF HKLM-x32\...\Firefox\Extensions: [{52b0f3db-f988-4788-b9dc-861d016f4487}] - C:\Program Files (x86)\Web Check\WebCheck.xpi FF Extension: No Name - C:\Program Files (x86)\Web Check\WebCheck.xpi FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Vaaudix) - C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnklejglagpaefibjecglekajipngnbi\1.3 CHR Extension: (Web Check) - C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\dacechnliklhcacondhhkkfobapdopee\0.1_0 CHR Extension: (McAfee SiteAdvisor) - C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.31.131.2_0 CHR Extension: (Skype Click to Call) - C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Kai\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.0.900_0 CHR HKLM-x32\...\Chrome\Extension: [bddpogknpjlgfpbboediomaiiaecfajn] - C:\Program Files (x86)\HomeTab\chrome\HomeTab.crx CHR HKLM-x32\...\Chrome\Extension: [dacechnliklhcacondhhkkfobapdopee] - C:\Program Files (x86)\Web Check\WebCheck.crx CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2010-01-29] (ArcSoft Inc.) S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [42336 2010-04-07] (ESET) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [810120 2010-04-07] (ESET) S2 gupdate1caa52916959165; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [133104 2010-02-04] (Google Inc.) R2 IGDCTRL; C:\Program Files\FRITZ!DSL\IGDCTRL.EXE [88888 2009-07-28] (AVM Berlin) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [227232 2010-01-15] (McAfee, Inc.) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [88576 2011-09-15] () R2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE [33280 2009-07-17] () S2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [x] S2 McAfee SiteAdvisor Service; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [x] ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2010-02-13] () R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [163888 2010-04-07] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [139704 2010-04-07] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [169592 2010-04-07] (ESET) R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33608 2010-04-07] (ESET) R2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50600 2010-04-07] (ESET) R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [46792 2013-08-13] (AnchorFree Inc.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2010-02-13] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [41032 2009-06-18] (McAfee, Inc.) S3 mferkdk; C:\Windows\System32\drivers\mferkdk.sys [40904 2009-11-04] (McAfee, Inc.) S3 mfesmfk; C:\Windows\System32\drivers\mfesmfk.sys [49480 2009-11-04] (McAfee, Inc.) S3 NMRKUSBA; C:\Windows\System32\drivers\nmrkusba.sys [50240 2010-04-22] (Numark) S3 NMRKUSBU; C:\Windows\System32\Drivers\nmrkusbu.sys [398912 2010-04-22] (Ploytec GmbH) S3 nmwcdx64; C:\Windows\System32\drivers\nmwcdx64.sys [173056 2007-06-28] (Nokia) R3 O2SDGRDR; C:\Windows\System32\DRIVERS\o2sdgx64.sys [50976 2010-01-11] (O2Micro ) S3 RRNetCap; C:\Windows\System32\DRIVERS\rrnetcap.sys [37480 2012-05-16] (RapidSolution Software AG) R3 RRNetCapMP; C:\Windows\System32\DRIVERS\rrnetcap.sys [37480 2012-05-16] (RapidSolution Software AG) S3 s125bus; C:\Windows\System32\DRIVERS\s125bus.sys [108296 2007-04-24] (MCCI Corporation) S3 s125mdfl; C:\Windows\System32\DRIVERS\s125mdfl.sys [19720 2007-04-24] (MCCI Corporation) S3 s125mdm; C:\Windows\System32\DRIVERS\s125mdm.sys [144648 2007-04-24] (MCCI Corporation) S3 s125mgmt; C:\Windows\System32\DRIVERS\s125mgmt.sys [126216 2007-04-24] (MCCI Corporation) S3 s125obex; C:\Windows\System32\DRIVERS\s125obex.sys [123656 2007-04-24] (MCCI Corporation) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.) R3 TotRec8; C:\Windows\system32\drivers\TotRec8.sys [122448 2010-10-14] (High Criteria inc.) R3 TotRec8; C:\Windows\system32\drivers\TotRec8.sys [122448 2010-10-14] (High Criteria inc.) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] () S3 ALSysIO; \??\C:\Users\Kai\AppData\Local\Temp\ALSysIO64.sys [x] U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 PCDSRVC{D3412D80-CF3B4A27-06020200}_0; \??\c:\program files\my dell\pcdsrvc_x64.pkms [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-22 12:40 - 2013-09-22 12:40 - 00000000 ____D C:\FRST 2013-09-22 12:39 - 2013-09-22 12:39 - 01956670 _____ (Farbar) C:\Users\Kai\Desktop\FRST64.exe 2013-09-22 12:37 - 2013-09-22 12:39 - 00000468 _____ C:\Users\Kai\Desktop\defogger_disable.log 2013-09-22 12:37 - 2013-09-22 12:37 - 00000000 _____ C:\Users\Kai\defogger_reenable 2013-09-22 12:35 - 2013-09-22 12:35 - 00050477 _____ C:\Users\Kai\Desktop\Defogger.exe 2013-09-22 12:13 - 2013-09-22 12:13 - 00000000 ____D C:\ProgramData\ESET 2013-09-22 11:34 - 2013-09-22 11:34 - 00037394 _____ C:\ComboFix.txt 2013-09-22 11:05 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-22 11:05 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-22 11:05 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-22 11:05 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-22 11:05 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-22 11:05 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-22 11:05 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-22 11:05 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-22 11:03 - 2013-09-22 11:34 - 00000000 ____D C:\Qoobox 2013-09-22 11:02 - 2013-09-22 11:31 - 00000000 ____D C:\Windows\erdnt 2013-09-21 19:43 - 2013-09-21 19:44 - 05128554 ____R (Swearware) C:\Users\Kai\Desktop\ComboFix.exe 2013-09-21 19:31 - 2010-04-13 00:00 - 47201792 _____ C:\Users\Kai\Desktop\ess_nt64_deu.msi 2013-09-21 19:17 - 2013-09-21 19:20 - 00026448 _____ C:\Windows\diagwrn.xml 2013-09-21 19:17 - 2013-09-21 19:20 - 00001908 _____ C:\Windows\diagerr.xml 2013-09-21 18:23 - 2013-09-21 18:23 - 00533656 _____ C:\Windows\Minidump\092113-52853-01.dmp 2013-09-21 14:18 - 2013-09-21 14:18 - 00656136 _____ C:\Windows\Minidump\092113-23883-01.dmp 2013-09-21 13:17 - 2013-09-21 13:17 - 00001786 _____ C:\Users\Kai\Desktop\JRT.txt 2013-09-21 13:09 - 2013-09-21 13:09 - 00000000 ____D C:\Windows\ERUNT 2013-09-21 12:58 - 2013-09-21 13:01 - 00000000 ____D C:\AdwCleaner 2013-09-21 12:58 - 2013-09-21 12:58 - 01029675 _____ (Thisisu) C:\Users\Kai\Desktop\JRT.exe 2013-09-21 12:56 - 2013-09-21 12:56 - 01039554 _____ C:\Users\Kai\Desktop\adwcleaner(2).exe 2013-09-21 12:40 - 2013-09-21 12:40 - 02347384 _____ (ESET) C:\Users\Kai\Downloads\esetsmartinstaller_deu.exe 2013-09-21 08:53 - 2013-09-21 08:53 - 00657488 _____ C:\Windows\Minidump\092113-26488-01.dmp 2013-09-20 23:22 - 2013-09-20 23:22 - 01039554 _____ C:\Users\Kai\Downloads\adwcleaner(1).exe 2013-09-20 23:21 - 2013-09-20 23:22 - 01039554 _____ C:\Users\Kai\Downloads\adwcleaner.exe 2013-09-20 01:43 - 2013-09-20 01:43 - 00657272 _____ C:\Windows\Minidump\092013-85738-01.dmp 2013-09-19 23:50 - 2013-09-19 23:50 - 00270008 _____ C:\Windows\Minidump\091913-25147-01.dmp 2013-09-18 00:20 - 2013-09-18 00:20 - 00004143 _____ C:\Users\Kai\Downloads\cancelation(2) 2013-09-16 20:21 - 2013-09-16 20:21 - 00275176 _____ C:\Windows\Minidump\091613-21808-01.dmp 2013-09-15 22:29 - 2013-09-20 04:37 - 00000000 ____D C:\Program Files (x86)\HIDE.IO 2013-09-15 22:29 - 2013-09-15 22:29 - 00001115 _____ C:\Users\Public\Desktop\HIDE.IO.lnk 2013-09-15 22:28 - 2013-09-15 22:29 - 01394656 _____ C:\Users\Kai\Downloads\HIDE.IO-install.exe 2013-09-15 20:07 - 2013-09-15 20:07 - 00001050 _____ C:\Users\Public\Desktop\Hotspot Shield.lnk 2013-09-15 20:07 - 2013-08-13 01:07 - 00046792 _____ (AnchorFree Inc.) C:\Windows\system32\Drivers\hssdrv6.sys 2013-09-15 19:58 - 2013-09-20 04:32 - 00000000 ____D C:\Program Files (x86)\OpenVPN 2013-09-15 19:57 - 2013-09-15 19:57 - 00322642 _____ (dnsleaktest.com ) C:\Users\Kai\Downloads\dnsfixsetup.exe 2013-09-15 16:11 - 2013-09-15 16:11 - 00004143 _____ C:\Users\Kai\Downloads\cancelation(1) 2013-09-14 12:54 - 2013-09-20 04:37 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-09-14 12:54 - 2013-09-20 04:37 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-09-14 12:54 - 2013-09-14 12:54 - 00001198 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk 2013-09-14 12:53 - 2013-09-14 12:53 - 15641088 _____ (LastPass) C:\Users\Kai\Downloads\lastpass_x64.exe 2013-09-11 03:17 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-11 03:17 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-11 03:17 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-11 03:17 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-11 03:17 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-11 03:17 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-11 03:17 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-11 03:17 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-11 03:17 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-11 03:17 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-11 03:17 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-11 03:17 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-11 03:17 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-11 03:17 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-11 03:17 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-11 03:17 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-11 03:17 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-11 03:17 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-11 03:17 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-11 03:17 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-11 03:17 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-11 03:17 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-11 03:17 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-11 03:17 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-11 03:17 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-11 03:17 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-11 03:17 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-11 03:17 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-11 03:17 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-11 03:16 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-11 03:16 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-11 00:52 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 00:52 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-11 00:52 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-11 00:52 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-11 00:52 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-11 00:52 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-11 00:52 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-11 00:52 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 00:52 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-11 00:52 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 00:52 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-11 00:52 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-11 00:52 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-11 00:52 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-11 00:52 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-11 00:52 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 00:52 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-11 00:52 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-11 00:52 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-11 00:52 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-11 00:52 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-11 00:52 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 00:52 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-11 00:52 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 00:52 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 00:52 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-11 00:52 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-05 16:10 - 2013-09-05 16:10 - 00662640 _____ C:\Windows\Minidump\090513-22666-01.dmp 2013-09-05 09:44 - 2013-09-20 04:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-05 09:44 - 2013-09-05 09:44 - 00001153 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-03 20:19 - 2013-09-03 20:19 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-01 15:47 - 2013-09-01 15:47 - 00002219 _____ C:\Users\Public\Desktop\Steuer-Spar-Erklärung 2012.lnk 2013-09-01 11:06 - 2013-09-01 11:22 - 183232848 _____ C:\Users\Kai\Downloads\SSEStandard_17.13.exe 2013-09-01 11:06 - 2013-09-01 11:21 - 199698768 _____ C:\Users\Kai\Downloads\SSE_16.17.exe 2013-09-01 11:06 - 2013-09-01 11:20 - 162097488 _____ C:\Users\Kai\Downloads\SSEStandard_18.09.exe 2013-09-01 11:05 - 2013-09-01 11:17 - 110774608 _____ C:\Users\Kai\Downloads\SSE_15.17.exe 2013-08-28 22:58 - 2013-08-28 22:58 - 00008014 _____ C:\Users\Kai\Documents\lotto.xlsx 2013-08-28 18:58 - 2013-08-28 18:58 - 00000000 ____D C:\Windows\SysWOW64\SDA 2013-08-28 18:58 - 2013-08-28 18:58 - 00000000 ____D C:\Program Files\IDT 2013-08-28 18:58 - 2013-08-28 18:58 - 00000000 ____D C:\Program Files (x86)\O2Micro 2013-08-28 10:10 - 2010-02-27 07:32 - 00158976 _____ (Intel Corporation) C:\Windows\system32\Drivers\Impcd.sys 2013-08-28 08:47 - 2013-09-20 04:33 - 00000000 ____D C:\Users\Kai\Documents\Freemium Driver Utilities 2013-08-28 08:47 - 2013-08-28 08:48 - 00000000 ____D C:\ProgramData\FreeDriverScout 2013-08-28 08:40 - 2013-08-28 08:40 - 00000000 ____D C:\SoloApp 2013-08-28 08:39 - 2013-09-21 13:01 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater 2013-08-28 08:39 - 2013-08-28 08:39 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch 2013-08-28 08:39 - 2013-08-13 08:38 - 00032328 _____ C:\Windows\Launcher.exe 2013-08-28 08:37 - 2013-08-28 08:37 - 00002543 _____ C:\Users\Public\Desktop\Free Driver Scout.lnk 2013-08-28 08:37 - 2013-08-28 08:37 - 00000000 ____D C:\Program Files\Covus Freemium 2013-08-28 08:36 - 2013-09-22 11:22 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-08-28 08:36 - 2013-08-28 08:37 - 00000000 ____D C:\ProgramData\Package Cache 2013-08-28 08:35 - 2013-08-28 08:35 - 00444400 _____ C:\Users\Kai\Downloads\DLG_free-driver-scout_chip_de-DE.exe 2013-08-28 08:35 - 2013-08-28 08:35 - 00000206 _____ C:\Users\Kai\Desktop\Amazon.url 2013-08-28 00:02 - 2013-08-28 00:02 - 05099520 _____ ((c) Phoenix Technologies Ltd. ) C:\Users\Kai\Downloads\1747A14_W32-64(2).exe 2013-08-28 00:01 - 2013-08-28 00:01 - 02485664 _____ C:\Users\Kai\Downloads\R236961(1).exe 2013-08-28 00:00 - 2013-08-28 00:00 - 02029416 _____ C:\Users\Kai\Downloads\SAMSUNG_MULTI-DEVICE_A00_R276513(1).exe 2013-08-27 23:59 - 2013-08-27 23:59 - 07426608 _____ C:\Users\Kai\Downloads\R235680(1).exe 2013-08-27 23:57 - 2013-08-28 18:57 - 00000000 ____D C:\Program Files (x86)\Intel 2013-08-27 23:57 - 2013-08-27 23:57 - 00000000 ____D C:\Intel 2013-08-27 23:57 - 2013-07-16 08:32 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll 2013-08-27 23:50 - 2013-08-27 23:50 - 00003230 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-27 23:50 - 2013-08-27 23:50 - 00000000 ____D C:\Program Files\Intel 2013-08-27 23:38 - 2013-08-27 23:38 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-08-27 23:35 - 2013-08-27 23:40 - 00000000 ____D C:\Program Files\ATI Technologies 2013-08-27 23:35 - 2013-08-27 23:35 - 00000000 ____D C:\Program Files\ATI 2013-08-27 23:34 - 2010-04-12 14:28 - 06405120 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\atipmdag.sys 2013-08-27 23:34 - 2010-04-12 14:28 - 06405120 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-08-27 23:34 - 2010-04-12 14:17 - 00446464 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-08-27 23:34 - 2010-04-12 14:17 - 00143360 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-08-27 23:34 - 2010-04-12 14:17 - 00033624 _____ C:\Windows\system32\atiapfxx.blb 2013-08-27 23:34 - 2010-04-12 14:16 - 00497152 _____ (ATI Technologies Inc. ) C:\Windows\system32\aticfx64.dll 2013-08-27 23:34 - 2010-04-12 14:15 - 18845696 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-08-27 23:34 - 2010-04-12 14:14 - 00450560 _____ (AMD) C:\Windows\system32\atieclxx.exe 2013-08-27 23:34 - 2010-04-12 14:14 - 00446464 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIDEMGX.dll 2013-08-27 23:34 - 2010-04-12 14:14 - 00202752 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2013-08-27 23:34 - 2010-04-12 14:12 - 00420864 _____ (ATI Technologies, Inc.) C:\Windows\system32\atipdl64.dll 2013-08-27 23:34 - 2010-04-12 14:12 - 00356352 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\atipdlxx.dll 2013-08-27 23:34 - 2010-04-12 14:12 - 00274432 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\Oemdspif.dll 2013-08-27 23:34 - 2010-04-12 14:12 - 00120320 _____ (AMD) C:\Windows\system32\atitmm64.dll 2013-08-27 23:34 - 2010-04-12 14:11 - 00059392 _____ (ATI Technologies, Inc.) C:\Windows\system32\atiedu64.dll 2013-08-27 23:34 - 2010-04-12 14:11 - 00043520 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll 2013-08-27 23:34 - 2010-04-12 14:11 - 00012288 _____ (AMD) C:\Windows\system32\atimuixx.dll 2013-08-27 23:34 - 2010-04-12 14:08 - 03131392 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-08-27 23:34 - 2010-04-12 13:56 - 14261248 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-08-27 23:34 - 2010-04-12 13:45 - 04801536 _____ (ATI Technologies Inc. ) C:\Windows\system32\atiumd64.dll 2013-08-27 23:34 - 2010-04-12 13:38 - 02716160 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2013-08-27 23:34 - 2010-04-12 13:36 - 00511072 _____ C:\Windows\system32\atiumd6a.cap 2013-08-27 23:34 - 2010-04-12 13:35 - 00055296 _____ (AMD) C:\Windows\system32\coinst.dll 2013-08-27 23:34 - 2010-04-12 13:31 - 00511072 _____ C:\Windows\SysWOW64\atiumdva.cap 2013-08-27 23:34 - 2010-04-12 13:31 - 00053248 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-08-27 23:34 - 2010-04-12 13:31 - 00053248 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-08-27 23:34 - 2010-04-12 13:31 - 00043008 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-08-27 23:34 - 2010-04-12 13:31 - 00039936 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-08-27 23:34 - 2010-04-12 13:30 - 04781568 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-08-27 23:34 - 2010-04-12 13:29 - 03657728 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-08-27 23:34 - 2010-04-12 13:19 - 00330752 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2013-08-27 23:34 - 2010-04-12 13:19 - 00237568 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-08-27 23:34 - 2010-04-12 13:19 - 00053248 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2013-08-27 23:34 - 2010-04-12 13:19 - 00053248 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2013-08-27 23:34 - 2010-04-12 13:19 - 00052224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-08-27 23:34 - 2010-04-12 13:19 - 00052224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-08-27 23:34 - 2010-04-12 13:19 - 00014848 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-08-27 23:34 - 2010-04-12 13:18 - 00188928 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-08-27 23:34 - 2010-04-12 13:18 - 00036352 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2013-08-27 23:34 - 2010-04-12 13:18 - 00016896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-08-27 23:34 - 2010-04-12 13:18 - 00015360 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-08-27 23:34 - 2010-04-12 13:18 - 00012800 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-08-27 23:34 - 2010-04-12 13:18 - 00012800 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2013-08-27 23:34 - 2010-04-12 13:17 - 00053248 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2013-08-27 23:34 - 2010-04-12 13:17 - 00028160 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2013-08-27 23:34 - 2010-04-12 13:17 - 00027648 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-08-27 23:34 - 2010-04-12 13:17 - 00020480 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-08-27 23:34 - 2010-04-08 04:12 - 00124944 _____ (ATI Technologies, Inc.) C:\Windows\system32\Drivers\AtiHdmi.sys 2013-08-27 23:34 - 2010-03-24 11:25 - 00002093 _____ C:\Windows\SysWOW64\atipblag.dat 2013-08-27 23:34 - 2010-03-24 11:25 - 00002093 _____ C:\Windows\system32\atipblag.dat 2013-08-27 23:34 - 2010-03-02 15:57 - 00020692 _____ C:\Windows\atiogl.xml 2013-08-27 23:34 - 2010-02-25 14:55 - 00201875 _____ C:\Windows\system32\atiicdxx.dat 2013-08-27 23:34 - 2009-05-11 17:35 - 00118784 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atibtmon.exe 2013-08-27 23:29 - 2013-08-27 23:30 - 15313016 _____ C:\Users\Kai\Downloads\R237507.exe 2013-08-27 23:29 - 2013-08-27 23:30 - 14496272 _____ C:\Users\Kai\Downloads\R259111.exe 2013-08-27 23:29 - 2013-08-27 23:29 - 02485664 _____ C:\Users\Kai\Downloads\R236961.exe 2013-08-27 23:29 - 2013-08-27 23:29 - 01954306 _____ (Sony Optiarc Inc.) C:\Users\Kai\Downloads\BC5600S_V10AB.exe 2013-08-27 23:29 - 2013-08-27 23:29 - 01791800 _____ C:\Users\Kai\Downloads\R225697.exe 2013-08-27 23:29 - 2013-08-27 23:29 - 01322160 _____ C:\Users\Kai\Downloads\PANASONIC_UJ235A-12-7MM-SATA_A01_R227099.exe 2013-08-27 23:28 - 2013-08-27 23:29 - 02499446 _____ C:\Users\Kai\Downloads\GA11N-A101.zip 2013-08-27 23:28 - 2013-08-27 23:29 - 01564161 _____ C:\Users\Kai\Downloads\AD-7640S HD18.zip 2013-08-27 23:28 - 2013-08-27 23:28 - 05260208 _____ C:\Users\Kai\Downloads\R244464(1).exe 2013-08-27 23:28 - 2013-08-27 23:28 - 04669872 _____ C:\Users\Kai\Downloads\R250352.exe 2013-08-27 23:28 - 2013-08-27 23:28 - 04669544 _____ C:\Users\Kai\Downloads\R250679.exe 2013-08-27 23:28 - 2013-08-27 23:28 - 02753386 _____ C:\Users\Kai\Downloads\CA10N-WIN7-A108-normal.zip 2013-08-27 23:28 - 2013-08-27 23:28 - 02672272 _____ C:\Users\Kai\Downloads\R306353.exe 2013-08-27 23:27 - 2013-08-27 23:29 - 18264696 _____ C:\Users\Kai\Downloads\R260675.exe 2013-08-27 23:27 - 2013-08-27 23:28 - 13644544 _____ C:\Users\Kai\Downloads\R239756.exe 2013-08-27 23:27 - 2013-08-27 23:28 - 07426608 _____ C:\Users\Kai\Downloads\R235680.exe 2013-08-27 23:27 - 2013-08-27 23:28 - 05260208 _____ C:\Users\Kai\Downloads\R244464.exe 2013-08-27 23:27 - 2013-08-27 23:28 - 02029416 _____ C:\Users\Kai\Downloads\SAMSUNG_MULTI-DEVICE_A00_R276513.exe 2013-08-27 23:26 - 2013-08-27 23:33 - 250171160 _____ C:\Users\Kai\Downloads\R271318.exe 2013-08-27 23:16 - 2013-09-21 13:00 - 00000000 ____D C:\ProgramData\Uniblue 2013-08-27 23:15 - 2013-08-27 23:16 - 05653360 _____ (Uniblue Systems Ltd ) C:\Users\Kai\Downloads\driverscanner.exe 2013-08-27 23:00 - 2013-08-27 23:00 - 00347424 _____ (Microsoft Corporation) C:\Users\Kai\Downloads\MicrosoftFixit.Codec.FISC.33301067952429906.1.1.Run.exe 2013-08-27 01:28 - 2013-08-27 01:28 - 05099520 _____ ((c) Phoenix Technologies Ltd. ) C:\Users\Kai\Downloads\1747A14_W32-64(1).exe 2013-08-25 11:43 - 2013-09-21 18:30 - 00000000 ____D C:\Users\Kai\AppData\Local\Deployment 2013-08-25 11:43 - 2013-08-25 11:52 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell 2013-08-25 11:43 - 2013-08-25 11:43 - 00010699 _____ C:\Users\Kai\Downloads\dellsystemdetect.bootstrapper.application 2013-08-25 11:43 - 2013-08-25 11:43 - 00000000 ____D C:\Users\Kai\AppData\Local\Apps\2.0 2013-08-25 11:40 - 2013-08-25 11:40 - 04282512 _____ C:\Users\Kai\Downloads\CW1384A0.exe ==================== One Month Modified Files and Folders ======= 2013-09-22 12:40 - 2013-09-22 12:40 - 00000000 ____D C:\FRST 2013-09-22 12:39 - 2013-09-22 12:39 - 01956670 _____ (Farbar) C:\Users\Kai\Desktop\FRST64.exe 2013-09-22 12:39 - 2013-09-22 12:37 - 00000468 _____ C:\Users\Kai\Desktop\defogger_disable.log 2013-09-22 12:37 - 2013-09-22 12:37 - 00000000 _____ C:\Users\Kai\defogger_reenable 2013-09-22 12:37 - 2010-02-03 13:06 - 00000000 ____D C:\Users\Kai 2013-09-22 12:35 - 2013-09-22 12:35 - 00050477 _____ C:\Users\Kai\Desktop\Defogger.exe 2013-09-22 12:31 - 2009-07-14 06:45 - 00014240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-22 12:31 - 2009-07-14 06:45 - 00014240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-22 12:26 - 2013-07-14 16:15 - 00000000 ___RD C:\Users\Kai\Dropbox 2013-09-22 12:26 - 2013-07-14 16:11 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Dropbox 2013-09-22 12:26 - 2010-05-11 21:41 - 05088348 _____ C:\Users\Kai\DesktopStCenter.txt 2013-09-22 12:25 - 2012-02-29 03:42 - 00000000 ____D C:\Users\Kai\AppData\Local\Htc 2013-09-22 12:23 - 2011-03-24 22:31 - 00013379 _____ C:\Windows\setupact.log 2013-09-22 12:23 - 2010-02-04 01:47 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-22 12:23 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-22 12:22 - 2009-07-14 07:10 - 01754923 _____ C:\Windows\WindowsUpdate.log 2013-09-22 12:14 - 2010-02-04 00:36 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Skype 2013-09-22 12:13 - 2013-09-22 12:13 - 00000000 ____D C:\ProgramData\ESET 2013-09-22 12:09 - 2012-08-06 08:53 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-22 12:07 - 2010-02-04 01:47 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-22 11:36 - 2011-03-24 23:05 - 00056178 _____ C:\Windows\PFRO.log 2013-09-22 11:34 - 2013-09-22 11:34 - 00037394 _____ C:\ComboFix.txt 2013-09-22 11:34 - 2013-09-22 11:03 - 00000000 ____D C:\Qoobox 2013-09-22 11:31 - 2013-09-22 11:02 - 00000000 ____D C:\Windows\erdnt 2013-09-22 11:30 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-09-22 11:22 - 2013-08-28 08:36 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-09-22 01:44 - 2010-02-28 16:34 - 00003914 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{B60F1CF8-C01B-4A12-A9C5-8A456C1D502C} 2013-09-21 19:44 - 2013-09-21 19:43 - 05128554 ____R (Swearware) C:\Users\Kai\Desktop\ComboFix.exe 2013-09-21 19:20 - 2013-09-21 19:17 - 00026448 _____ C:\Windows\diagwrn.xml 2013-09-21 19:20 - 2013-09-21 19:17 - 00001908 _____ C:\Windows\diagerr.xml 2013-09-21 19:17 - 2011-03-24 22:31 - 00000000 _____ C:\Windows\setuperr.log 2013-09-21 18:35 - 2011-07-20 07:22 - 00000000 ____D C:\personal improvement 2013-09-21 18:30 - 2013-08-25 11:43 - 00000000 ____D C:\Users\Kai\AppData\Local\Deployment 2013-09-21 18:23 - 2013-09-21 18:23 - 00533656 _____ C:\Windows\Minidump\092113-52853-01.dmp 2013-09-21 18:23 - 2010-04-10 23:40 - 00000000 ____D C:\Windows\Minidump 2013-09-21 18:22 - 2011-04-28 08:12 - 646794281 _____ C:\Windows\MEMORY.DMP 2013-09-21 17:18 - 2009-07-14 19:58 - 00714832 _____ C:\Windows\system32\perfh007.dat 2013-09-21 17:18 - 2009-07-14 19:58 - 00153980 _____ C:\Windows\system32\perfc007.dat 2013-09-21 17:18 - 2009-07-14 07:13 - 01650444 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-21 14:18 - 2013-09-21 14:18 - 00656136 _____ C:\Windows\Minidump\092113-23883-01.dmp 2013-09-21 13:24 - 2013-03-16 23:48 - 00000000 ____D C:\Users\Kai\AppData\Local\Pokki 2013-09-21 13:17 - 2013-09-21 13:17 - 00001786 _____ C:\Users\Kai\Desktop\JRT.txt 2013-09-21 13:09 - 2013-09-21 13:09 - 00000000 ____D C:\Windows\ERUNT 2013-09-21 13:01 - 2013-09-21 12:58 - 00000000 ____D C:\AdwCleaner 2013-09-21 13:01 - 2013-08-28 08:39 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater 2013-09-21 13:00 - 2013-08-27 23:16 - 00000000 ____D C:\ProgramData\Uniblue 2013-09-21 12:58 - 2013-09-21 12:58 - 01029675 _____ (Thisisu) C:\Users\Kai\Desktop\JRT.exe 2013-09-21 12:56 - 2013-09-21 12:56 - 01039554 _____ C:\Users\Kai\Desktop\adwcleaner(2).exe 2013-09-21 12:40 - 2013-09-21 12:40 - 02347384 _____ (ESET) C:\Users\Kai\Downloads\esetsmartinstaller_deu.exe 2013-09-21 08:53 - 2013-09-21 08:53 - 00657488 _____ C:\Windows\Minidump\092113-26488-01.dmp 2013-09-20 23:22 - 2013-09-20 23:22 - 01039554 _____ C:\Users\Kai\Downloads\adwcleaner(1).exe 2013-09-20 23:22 - 2013-09-20 23:21 - 01039554 _____ C:\Users\Kai\Downloads\adwcleaner.exe 2013-09-20 16:01 - 2013-05-22 11:09 - 00003440 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask 2013-09-20 04:38 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-09-20 04:38 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-20 04:37 - 2013-09-15 22:29 - 00000000 ____D C:\Program Files (x86)\HIDE.IO 2013-09-20 04:37 - 2013-09-14 12:54 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-09-20 04:37 - 2013-09-14 12:54 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-09-20 04:37 - 2013-09-05 09:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-20 04:37 - 2013-08-18 19:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-20 04:37 - 2013-05-22 11:07 - 00000000 ____D C:\Program Files\My Dell 2013-09-20 04:37 - 2011-11-26 20:33 - 00000000 ____D C:\Windows\system32\Macromed 2013-09-20 04:37 - 2011-08-27 15:45 - 00000000 __RSD C:\Users\Kai\Documents\My Stationery 2013-09-20 04:37 - 2011-08-16 13:21 - 00000000 ____D C:\Users\Kai\Documents\DVDVideoSoft 2013-09-20 04:37 - 2010-03-07 16:49 - 00000000 ____D C:\Users\Kai\AppData\Roaming\vlc 2013-09-20 04:37 - 2010-02-04 01:14 - 00000000 ____D C:\Users\Kai\Documents\Traktor3 2013-09-20 04:37 - 2010-02-03 13:10 - 00000000 ____D C:\Users\Kai\AppData\Roaming\ArcSoft 2013-09-20 04:37 - 2010-02-03 13:09 - 00000000 ___RD C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-20 04:37 - 2010-02-03 13:09 - 00000000 ___RD C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-20 04:37 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-09-20 04:37 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat 2013-09-20 04:37 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-09-20 04:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2013-09-20 04:33 - 2013-08-28 08:47 - 00000000 ____D C:\Users\Kai\Documents\Freemium Driver Utilities 2013-09-20 04:33 - 2012-06-23 11:49 - 00000000 ____D C:\Users\Kai\AppData\Roaming\PCDr 2013-09-20 04:33 - 2010-04-14 01:00 - 00000000 ____D C:\Users\Kai\Documents\Wondershare PPT2Flash Standard 2013-09-20 04:33 - 2010-04-14 00:08 - 00000000 ____D C:\Users\Kai\Documents\Ratskeller 2013-09-20 04:33 - 2010-04-14 00:05 - 00000000 ____D C:\Users\Kai\Documents\authorGEN Projects 2013-09-20 04:33 - 2010-02-04 00:33 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Mozilla 2013-09-20 04:32 - 2013-09-15 19:58 - 00000000 ____D C:\Program Files (x86)\OpenVPN 2013-09-20 04:32 - 2010-01-29 11:54 - 00000000 ____D C:\ProgramData\PCDr 2013-09-20 01:43 - 2013-09-20 01:43 - 00657272 _____ C:\Windows\Minidump\092013-85738-01.dmp 2013-09-20 00:09 - 2012-08-06 08:53 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-20 00:09 - 2012-05-10 00:50 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-20 00:09 - 2011-06-11 13:04 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-19 23:50 - 2013-09-19 23:50 - 00270008 _____ C:\Windows\Minidump\091913-25147-01.dmp 2013-09-18 20:55 - 2010-08-20 19:59 - 00000000 ____D C:\Users\Kai\AppData\Local\FRITZ! 2013-09-18 00:20 - 2013-09-18 00:20 - 00004143 _____ C:\Users\Kai\Downloads\cancelation(2) 2013-09-16 20:21 - 2013-09-16 20:21 - 00275176 _____ C:\Windows\Minidump\091613-21808-01.dmp 2013-09-15 23:59 - 2013-02-22 23:57 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Spotify 2013-09-15 22:29 - 2013-09-15 22:29 - 00001115 _____ C:\Users\Public\Desktop\HIDE.IO.lnk 2013-09-15 22:29 - 2013-09-15 22:28 - 01394656 _____ C:\Users\Kai\Downloads\HIDE.IO-install.exe 2013-09-15 20:07 - 2013-09-15 20:07 - 00001050 _____ C:\Users\Public\Desktop\Hotspot Shield.lnk 2013-09-15 19:57 - 2013-09-15 19:57 - 00322642 _____ (dnsleaktest.com ) C:\Users\Kai\Downloads\dnsfixsetup.exe 2013-09-15 19:26 - 2013-01-20 12:36 - 00000375 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-09-15 16:25 - 2013-08-10 20:04 - 00000000 ____D C:\Users\Kai\Desktop\backup 2013-09-15 16:11 - 2013-09-15 16:11 - 00004143 _____ C:\Users\Kai\Downloads\cancelation(1) 2013-09-14 12:54 - 2013-09-14 12:54 - 00001198 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk 2013-09-14 12:53 - 2013-09-14 12:53 - 15641088 _____ (LastPass) C:\Users\Kai\Downloads\lastpass_x64.exe 2013-09-12 20:52 - 2013-02-22 23:58 - 00000000 ____D C:\Users\Kai\AppData\Local\Spotify 2013-09-11 20:01 - 2009-07-14 06:45 - 05263512 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-11 03:16 - 2013-08-15 00:00 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 03:14 - 2010-06-14 21:11 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 03:14 - 2010-01-29 11:55 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-08 16:46 - 2010-02-08 11:08 - 00000000 ____D C:\Users\Kai\Documents\OneNote-Notizbücher 2013-09-05 16:10 - 2013-09-05 16:10 - 00662640 _____ C:\Windows\Minidump\090513-22666-01.dmp 2013-09-05 09:44 - 2013-09-05 09:44 - 00001153 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-03 20:19 - 2013-09-03 20:19 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-01 16:45 - 2010-05-13 19:47 - 00000000 ____D C:\Users\Kai\Documents\Steuerfälle 2013-09-01 15:47 - 2013-09-01 15:47 - 00002219 _____ C:\Users\Public\Desktop\Steuer-Spar-Erklärung 2012.lnk 2013-09-01 15:42 - 2011-05-07 12:52 - 00001779 _____ C:\Users\Kai\Documents\OuProxy.log 2013-09-01 11:22 - 2013-09-01 11:06 - 183232848 _____ C:\Users\Kai\Downloads\SSEStandard_17.13.exe 2013-09-01 11:21 - 2013-09-01 11:06 - 199698768 _____ C:\Users\Kai\Downloads\SSE_16.17.exe 2013-09-01 11:20 - 2013-09-01 11:06 - 162097488 _____ C:\Users\Kai\Downloads\SSEStandard_18.09.exe 2013-09-01 11:17 - 2013-09-01 11:05 - 110774608 _____ C:\Users\Kai\Downloads\SSE_15.17.exe 2013-08-28 22:58 - 2013-08-28 22:58 - 00008014 _____ C:\Users\Kai\Documents\lotto.xlsx 2013-08-28 19:04 - 2012-02-29 03:39 - 00092274 _____ C:\Windows\DPINST.LOG 2013-08-28 18:58 - 2013-08-28 18:58 - 00000000 ____D C:\Windows\SysWOW64\SDA 2013-08-28 18:58 - 2013-08-28 18:58 - 00000000 ____D C:\Program Files\IDT 2013-08-28 18:58 - 2013-08-28 18:58 - 00000000 ____D C:\Program Files (x86)\O2Micro 2013-08-28 18:58 - 2010-01-29 11:48 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-08-28 18:57 - 2013-08-27 23:57 - 00000000 ____D C:\Program Files (x86)\Intel 2013-08-28 08:48 - 2013-08-28 08:47 - 00000000 ____D C:\ProgramData\FreeDriverScout 2013-08-28 08:40 - 2013-08-28 08:40 - 00000000 ____D C:\SoloApp 2013-08-28 08:39 - 2013-08-28 08:39 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch 2013-08-28 08:37 - 2013-08-28 08:37 - 00002543 _____ C:\Users\Public\Desktop\Free Driver Scout.lnk 2013-08-28 08:37 - 2013-08-28 08:37 - 00000000 ____D C:\Program Files\Covus Freemium 2013-08-28 08:37 - 2013-08-28 08:36 - 00000000 ____D C:\ProgramData\Package Cache 2013-08-28 08:35 - 2013-08-28 08:35 - 00444400 _____ C:\Users\Kai\Downloads\DLG_free-driver-scout_chip_de-DE.exe 2013-08-28 08:35 - 2013-08-28 08:35 - 00000206 _____ C:\Users\Kai\Desktop\Amazon.url 2013-08-28 00:25 - 2010-02-04 01:15 - 00000000 ____D C:\Users\Kai\AppData\Local\Adobe 2013-08-28 00:02 - 2013-08-28 00:02 - 05099520 _____ ((c) Phoenix Technologies Ltd. ) C:\Users\Kai\Downloads\1747A14_W32-64(2).exe 2013-08-28 00:01 - 2013-08-28 00:01 - 02485664 _____ C:\Users\Kai\Downloads\R236961(1).exe 2013-08-28 00:00 - 2013-08-28 00:00 - 02029416 _____ C:\Users\Kai\Downloads\SAMSUNG_MULTI-DEVICE_A00_R276513(1).exe 2013-08-27 23:59 - 2013-08-27 23:59 - 07426608 _____ C:\Users\Kai\Downloads\R235680(1).exe 2013-08-27 23:57 - 2013-08-27 23:57 - 00000000 ____D C:\Intel 2013-08-27 23:50 - 2013-08-27 23:50 - 00003230 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-27 23:50 - 2013-08-27 23:50 - 00000000 ____D C:\Program Files\Intel 2013-08-27 23:40 - 2013-08-27 23:35 - 00000000 ____D C:\Program Files\ATI Technologies 2013-08-27 23:38 - 2013-08-27 23:38 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-08-27 23:35 - 2013-08-27 23:35 - 00000000 ____D C:\Program Files\ATI 2013-08-27 23:33 - 2013-08-27 23:26 - 250171160 _____ C:\Users\Kai\Downloads\R271318.exe 2013-08-27 23:33 - 2010-01-29 12:57 - 00000000 ____D C:\dell 2013-08-27 23:30 - 2013-08-27 23:29 - 15313016 _____ C:\Users\Kai\Downloads\R237507.exe 2013-08-27 23:30 - 2013-08-27 23:29 - 14496272 _____ C:\Users\Kai\Downloads\R259111.exe 2013-08-27 23:29 - 2013-08-27 23:29 - 02485664 _____ C:\Users\Kai\Downloads\R236961.exe 2013-08-27 23:29 - 2013-08-27 23:29 - 01954306 _____ (Sony Optiarc Inc.) C:\Users\Kai\Downloads\BC5600S_V10AB.exe 2013-08-27 23:29 - 2013-08-27 23:29 - 01791800 _____ C:\Users\Kai\Downloads\R225697.exe 2013-08-27 23:29 - 2013-08-27 23:29 - 01322160 _____ C:\Users\Kai\Downloads\PANASONIC_UJ235A-12-7MM-SATA_A01_R227099.exe 2013-08-27 23:29 - 2013-08-27 23:28 - 02499446 _____ C:\Users\Kai\Downloads\GA11N-A101.zip 2013-08-27 23:29 - 2013-08-27 23:28 - 01564161 _____ C:\Users\Kai\Downloads\AD-7640S HD18.zip 2013-08-27 23:29 - 2013-08-27 23:27 - 18264696 _____ C:\Users\Kai\Downloads\R260675.exe 2013-08-27 23:28 - 2013-08-27 23:28 - 05260208 _____ C:\Users\Kai\Downloads\R244464(1).exe 2013-08-27 23:28 - 2013-08-27 23:28 - 04669872 _____ C:\Users\Kai\Downloads\R250352.exe 2013-08-27 23:28 - 2013-08-27 23:28 - 04669544 _____ C:\Users\Kai\Downloads\R250679.exe 2013-08-27 23:28 - 2013-08-27 23:28 - 02753386 _____ C:\Users\Kai\Downloads\CA10N-WIN7-A108-normal.zip 2013-08-27 23:28 - 2013-08-27 23:28 - 02672272 _____ C:\Users\Kai\Downloads\R306353.exe 2013-08-27 23:28 - 2013-08-27 23:27 - 13644544 _____ C:\Users\Kai\Downloads\R239756.exe 2013-08-27 23:28 - 2013-08-27 23:27 - 07426608 _____ C:\Users\Kai\Downloads\R235680.exe 2013-08-27 23:28 - 2013-08-27 23:27 - 05260208 _____ C:\Users\Kai\Downloads\R244464.exe 2013-08-27 23:28 - 2013-08-27 23:27 - 02029416 _____ C:\Users\Kai\Downloads\SAMSUNG_MULTI-DEVICE_A00_R276513.exe 2013-08-27 23:16 - 2013-08-27 23:15 - 05653360 _____ (Uniblue Systems Ltd ) C:\Users\Kai\Downloads\driverscanner.exe 2013-08-27 23:00 - 2013-08-27 23:00 - 00347424 _____ (Microsoft Corporation) C:\Users\Kai\Downloads\MicrosoftFixit.Codec.FISC.33301067952429906.1.1.Run.exe 2013-08-27 21:48 - 2012-11-01 22:10 - 01628338 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-08-27 01:28 - 2013-08-27 01:28 - 05099520 _____ ((c) Phoenix Technologies Ltd. ) C:\Users\Kai\Downloads\1747A14_W32-64(1).exe 2013-08-25 11:52 - 2013-08-25 11:43 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell 2013-08-25 11:43 - 2013-08-25 11:43 - 00010699 _____ C:\Users\Kai\Downloads\dellsystemdetect.bootstrapper.application 2013-08-25 11:43 - 2013-08-25 11:43 - 00000000 ____D C:\Users\Kai\AppData\Local\Apps\2.0 2013-08-25 11:40 - 2013-08-25 11:40 - 04282512 _____ C:\Users\Kai\Downloads\CW1384A0.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-21 04:31 ==================== End Of Log ============================ GMER Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-09-22 13:20:20 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK5055GSX rev.FG000D 465,76GB Running: gmer_2.1.19163.exe; Driver: C:\Users\Kai\AppData\Local\Temp\pwldqpow.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 544 fffff800033ff000 93 bytes [89, 6C, 24, 70, E9, 4B, FF, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 638 fffff800033ff05e 57 bytes [05, 05, 20, 1B, 00, 49, 8D, ...] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75] .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75] .text ... * 2 .text C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe[1788] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000077198769 4 bytes [C2, 04, 00, 00] .text C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe[1788] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75] .text C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe[1788] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75] .text ... * 2 .text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75] .text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75] .text ... * 2 .text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75] .text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75] .text ... * 2 .text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[2436] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75] .text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[2436] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75] .text ... * 2 .text C:\Program Files (x86)\Skype\Phone\Skype.exe[3492] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75] .text C:\Program Files (x86)\Skype\Phone\Skype.exe[3492] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75] .text ... * 2 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[4312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75] .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[4312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75] .text ... * 2 .text C:\Users\Kai\AppData\Roaming\Dropbox\bin\Dropbox.exe[4740] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75] .text C:\Users\Kai\AppData\Roaming\Dropbox\bin\Dropbox.exe[4740] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75] .text ... * 2 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{42A358F4-2F74-46C3-AF71-899CC44D95EE}@InterfaceName isatap.{D75C6288-980F-431A-9B8A-9B5D896B55B1} Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{42A358F4-2F74-46C3-AF71-899CC44D95EE}@ReusableType 0 ---- EOF - GMER 2.1 ---- |
22.09.2013, 15:05 | #2 |
/// the machine /// TB-Ausbilder | ESET Bootsektor Prüfung nicht durführbar Hi,
__________________Additional.txt von FRST fehlt noch.
__________________ |
25.09.2013, 21:04 | #3 |
| ESET Bootsektor Prüfung nicht durführbar Hi Schrauber, danke für deine schnelle Antwort. Inzwischen musste ich Windows 7 neu aufspielen weil einfach gar nichts mehr richtig funktionierte. Mich würde aber dennoch interessieren ob mein System jetzt "clean" ist. Also folgend die entsprechenden Scripte:
__________________Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 00:48 on 25/09/2013 (Kai) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-09-2013 Ran by Kai (administrator) on KAI-PC on 25-09-2013 00:49:08 Running from C:\Users\Kai\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2839840 2010-04-07] (ESET) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x14A43D9D87B8CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\o8d2zkwp.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass64.dll (LastPass) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: LastPass - C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\o8d2zkwp.default\Extensions\support@lastpass.com FF Extension: WOT - C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\o8d2zkwp.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: No Name - C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\o8d2zkwp.default\Extensions\706e0191cf7aed088f2608af3565372fd0a93b395dc77a00c5b2e5ac00df6696_lp.key FF Extension: No Name - C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\o8d2zkwp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird ==================== Services (Whitelisted) ================= S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [42336 2010-04-07] (ESET) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [810120 2010-04-07] (ESET) ==================== Drivers (Whitelisted) ==================== R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [163888 2010-04-07] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [139704 2010-04-07] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [169592 2010-04-07] (ESET) R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33608 2010-04-07] (ESET) R2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50600 2010-04-07] (ESET) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2013-07-01] () S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2013-07-01] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [12384 2013-07-01] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [12384 2013-07-01] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-25 00:48 - 2013-09-25 00:48 - 00000468 _____ C:\Users\Kai\Desktop\defogger_disable.log 2013-09-25 00:48 - 2013-09-25 00:48 - 00000000 ____D C:\FRST 2013-09-25 00:48 - 2013-09-25 00:48 - 00000000 _____ C:\Users\Kai\defogger_reenable 2013-09-25 00:47 - 2013-09-25 00:47 - 00377856 _____ C:\Users\Kai\Desktop\gmer_2.1.19163.exe 2013-09-25 00:46 - 2013-09-25 00:46 - 01955802 _____ (Farbar) C:\Users\Kai\Desktop\FRST64.exe 2013-09-25 00:46 - 2013-09-25 00:46 - 00050477 _____ C:\Users\Kai\Desktop\Defogger.exe 2013-09-24 07:36 - 2009-07-14 03:38 - 00383562 __RSH C:\bootmgr 2013-09-23 22:59 - 2009-09-10 08:28 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2013-09-23 22:59 - 2009-09-10 07:52 - 00257024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2013-09-23 22:48 - 2013-09-23 22:48 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Macromedia 2013-09-23 22:48 - 2013-09-23 22:48 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Adobe 2013-09-23 22:48 - 2013-09-23 22:48 - 00000000 ____D C:\Users\Kai\AppData\Local\Macromedia 2013-09-23 22:46 - 2013-09-25 00:30 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-23 22:46 - 2013-09-23 22:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-23 22:46 - 2013-09-23 22:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-23 22:46 - 2013-09-23 22:46 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-23 22:46 - 2013-09-23 22:46 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2013-09-23 22:46 - 2013-09-23 22:46 - 00000000 ____D C:\Windows\system32\Macromed 2013-09-23 22:42 - 2009-11-25 12:47 - 01942856 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2013-09-23 22:42 - 2009-11-25 12:47 - 01130824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2013-09-23 22:42 - 2009-11-25 12:47 - 00444752 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2013-09-23 22:42 - 2009-11-25 12:47 - 00320352 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2013-09-23 22:42 - 2009-11-25 12:47 - 00297808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll 2013-09-23 22:42 - 2009-11-25 12:47 - 00295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe 2013-09-23 22:42 - 2009-11-25 12:47 - 00109912 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2013-09-23 22:42 - 2009-11-25 12:47 - 00099176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll 2013-09-23 22:42 - 2009-11-25 12:47 - 00049472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll 2013-09-23 22:42 - 2009-11-25 12:47 - 00048960 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2013-09-23 22:41 - 2010-02-23 10:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 17833472 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 12335104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-09-23 22:39 - 2013-09-23 22:39 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-09-23 22:39 - 2013-09-23 22:39 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-23 22:39 - 2013-09-23 22:39 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-23 22:39 - 2013-09-23 22:39 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-09-23 22:39 - 2013-09-23 22:39 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-09-23 22:39 - 2013-09-23 22:39 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01104896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-09-23 22:39 - 2013-09-23 22:39 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-09-23 22:39 - 2013-09-23 22:39 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-09-23 22:39 - 2013-09-23 22:39 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-09-23 22:39 - 2013-09-23 22:39 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-09-23 22:38 - 2013-09-23 22:38 - 04068864 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 03181568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-09-23 22:38 - 2013-09-23 22:38 - 01863680 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 01619456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-09-23 22:38 - 2013-09-23 22:38 - 01495040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00982912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-09-23 22:38 - 2013-09-23 22:38 - 00662528 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00470016 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00283648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00265088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-09-23 22:38 - 2013-09-23 22:38 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00196608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsRasterService.dll 2013-09-23 22:36 - 2013-09-23 22:41 - 00004423 _____ C:\Windows\IE9_main.log 2013-09-23 22:30 - 2012-12-16 18:52 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-09-23 22:30 - 2012-12-16 16:40 - 00367616 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-09-23 22:30 - 2012-12-16 16:25 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-09-23 22:30 - 2012-12-16 16:25 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-09-23 22:30 - 2009-10-19 16:46 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-09-23 22:30 - 2009-10-19 16:10 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-09-23 22:26 - 2012-03-01 08:54 - 00022896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2013-09-23 22:26 - 2012-03-01 08:40 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-09-23 22:26 - 2012-03-01 08:35 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2013-09-23 22:26 - 2012-03-01 07:45 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-09-23 22:26 - 2012-03-01 07:40 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll 2013-09-23 22:22 - 2012-11-09 07:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-09-23 22:22 - 2012-11-09 06:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-09-23 22:20 - 2013-03-19 08:19 - 05497688 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-23 22:20 - 2013-03-19 07:54 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-23 22:20 - 2013-03-19 07:06 - 03958120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-23 22:20 - 2013-03-19 07:06 - 03902312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-23 22:20 - 2013-03-19 06:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-23 22:20 - 2013-03-19 05:19 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-23 22:20 - 2013-02-12 17:42 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-09-23 22:20 - 2013-02-12 17:37 - 03138048 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-09-23 22:20 - 2013-02-12 17:31 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-09-23 22:20 - 2013-02-12 17:13 - 02691072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-09-23 22:20 - 2013-02-12 17:07 - 00131072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-09-23 22:20 - 2013-02-12 15:59 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-09-23 22:20 - 2013-01-04 07:41 - 01893224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-09-23 22:20 - 2013-01-04 07:40 - 00287576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2013-09-23 22:20 - 2013-01-04 07:37 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-23 22:20 - 2013-01-04 07:37 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-23 22:20 - 2013-01-04 07:37 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-23 22:20 - 2013-01-04 07:36 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-23 22:20 - 2013-01-04 07:33 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-23 22:20 - 2013-01-04 07:30 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-23 22:20 - 2013-01-04 07:30 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-23 22:20 - 2013-01-04 07:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:51 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-23 22:20 - 2013-01-04 06:51 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-23 22:20 - 2013-01-04 06:51 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 05:19 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-23 22:20 - 2013-01-04 04:48 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-23 22:20 - 2013-01-04 04:48 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-23 22:20 - 2013-01-04 04:48 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-23 22:20 - 2013-01-04 04:48 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-23 22:20 - 2013-01-04 04:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 04:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 04:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-23 22:20 - 2013-01-04 04:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-23 22:20 - 2012-11-09 07:34 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-09-23 22:20 - 2012-11-09 06:49 - 00492032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-09-23 22:20 - 2012-03-03 08:29 - 01837568 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-09-23 22:20 - 2012-03-03 08:29 - 01541120 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-09-23 22:20 - 2012-03-03 08:29 - 00902656 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-09-23 22:20 - 2012-03-03 08:29 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-09-23 22:20 - 2012-03-03 08:29 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-09-23 22:20 - 2012-03-03 07:40 - 01170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-09-23 22:20 - 2012-03-03 07:40 - 01074176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-09-23 22:20 - 2012-03-03 07:40 - 00739840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-09-23 22:20 - 2012-03-03 07:40 - 00218624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-09-23 22:20 - 2012-03-03 07:40 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-09-23 22:20 - 2011-11-17 09:12 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2013-09-23 22:20 - 2011-11-17 07:39 - 00314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2013-09-23 22:20 - 2009-09-03 09:36 - 01975296 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll 2013-09-23 22:20 - 2009-09-03 09:04 - 01320960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll 2013-09-23 22:19 - 2013-04-12 16:36 - 01653096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-09-23 22:19 - 2012-11-02 07:30 - 02001408 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2013-09-23 22:19 - 2012-11-02 07:30 - 01880064 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2013-09-23 22:19 - 2012-11-02 06:50 - 01388544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2013-09-23 22:19 - 2012-11-02 06:50 - 01236992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2013-09-23 22:19 - 2012-06-09 07:30 - 14165504 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-23 22:19 - 2012-06-09 06:46 - 12868608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-23 22:19 - 2012-06-02 07:38 - 00152432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-09-23 22:19 - 2012-06-02 07:38 - 00095088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-09-23 22:19 - 2012-06-02 07:37 - 00459216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-09-23 22:19 - 2012-06-02 07:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-09-23 22:19 - 2012-06-02 06:48 - 00225280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-09-23 22:19 - 2012-06-02 06:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-09-23 22:19 - 2012-06-02 06:42 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-09-23 22:19 - 2011-11-17 09:11 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-09-23 22:19 - 2011-11-17 09:11 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-09-23 22:19 - 2011-11-17 09:11 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-09-23 22:19 - 2011-11-17 09:08 - 01446912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-09-23 22:19 - 2011-11-17 09:05 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-09-23 22:19 - 2011-08-27 07:40 - 00861184 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2013-09-23 22:19 - 2011-08-27 07:40 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll 2013-09-23 22:19 - 2011-08-27 06:43 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2013-09-23 22:19 - 2011-08-27 06:43 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll 2013-09-23 22:19 - 2011-08-17 07:32 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2013-09-23 22:19 - 2011-08-17 07:27 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax 2013-09-23 22:19 - 2011-08-17 07:27 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax 2013-09-23 22:19 - 2011-08-17 07:27 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax 2013-09-23 22:19 - 2011-08-17 07:27 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax 2013-09-23 22:19 - 2011-08-17 06:26 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll 2013-09-23 22:19 - 2011-08-17 06:22 - 00204288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSNP.ax 2013-09-23 22:19 - 2011-08-17 06:22 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax 2013-09-23 22:19 - 2011-08-17 06:22 - 00072704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mpeg2Data.ax 2013-09-23 22:19 - 2011-08-17 06:22 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSDvbNP.ax 2013-09-23 22:19 - 2011-06-15 11:58 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll 2013-09-23 22:19 - 2011-06-15 11:58 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll 2013-09-23 22:19 - 2011-06-15 11:58 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll 2013-09-23 22:19 - 2011-06-15 11:58 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll 2013-09-23 22:19 - 2011-06-15 11:04 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll 2013-09-23 22:19 - 2011-06-15 11:04 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll 2013-09-23 22:19 - 2011-06-15 11:04 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll 2013-09-23 22:19 - 2011-06-15 11:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll 2013-09-23 22:19 - 2011-06-15 11:04 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll 2013-09-23 22:19 - 2011-04-29 05:13 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2013-09-23 22:19 - 2011-04-29 05:12 - 00399872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2013-09-23 22:19 - 2011-04-29 05:12 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2013-09-23 22:19 - 2011-04-09 08:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2013-09-23 22:19 - 2011-04-09 07:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2013-09-23 22:19 - 2011-02-05 14:41 - 00640896 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-09-23 22:19 - 2011-02-05 14:41 - 00556928 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-09-23 22:19 - 2011-02-05 14:41 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2013-09-23 22:19 - 2011-02-05 14:41 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2013-09-23 22:19 - 2011-02-05 14:41 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2013-09-23 22:19 - 2011-02-05 14:39 - 00603976 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-09-23 22:19 - 2011-02-05 14:39 - 00518160 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-09-23 22:19 - 2010-12-23 08:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll 2013-09-23 22:19 - 2010-12-23 08:07 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll 2013-09-23 22:19 - 2010-12-23 08:02 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax 2013-09-23 22:19 - 2010-12-23 07:28 - 00850432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll 2013-09-23 22:19 - 2010-12-23 07:28 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2013-09-23 22:19 - 2010-12-23 07:24 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax 2013-09-23 22:19 - 2010-11-02 07:18 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll 2013-09-23 22:19 - 2010-11-02 07:17 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll 2013-09-23 22:19 - 2010-11-02 07:17 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll 2013-09-23 22:19 - 2010-11-02 07:16 - 01114624 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll 2013-09-23 22:19 - 2010-11-02 07:10 - 00464384 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe 2013-09-23 22:19 - 2010-11-02 07:10 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe 2013-09-23 22:19 - 2010-11-02 06:40 - 00496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll 2013-09-23 22:19 - 2010-11-02 06:40 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll 2013-09-23 22:19 - 2010-11-02 06:34 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe 2013-09-23 22:19 - 2010-11-02 06:34 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe 2013-09-23 22:19 - 2010-10-16 07:17 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll 2013-09-23 22:19 - 2010-10-16 06:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbc32.dll 2013-09-23 22:19 - 2010-09-01 07:21 - 14627840 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-09-23 22:19 - 2010-09-01 07:12 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-09-23 22:19 - 2010-09-01 06:29 - 11406848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-09-23 22:19 - 2010-09-01 06:23 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-09-23 22:19 - 2010-08-31 06:32 - 00954752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40.dll 2013-09-23 22:19 - 2010-08-31 06:32 - 00954288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40u.dll 2013-09-23 22:19 - 2010-08-21 08:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-09-23 22:19 - 2010-08-21 07:33 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-09-23 22:18 - 2013-03-01 05:32 - 03150848 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-23 22:18 - 2013-02-12 16:02 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-09-23 22:18 - 2012-11-20 07:55 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-09-23 22:18 - 2012-11-20 07:10 - 00219136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-09-23 22:18 - 2012-11-02 07:27 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2013-09-23 22:18 - 2012-11-02 06:48 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll 2013-09-23 22:18 - 2012-09-26 00:39 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2013-09-23 22:18 - 2012-09-25 23:55 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll 2013-09-23 22:18 - 2012-09-06 19:38 - 00295792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2013-09-23 22:18 - 2012-08-24 20:05 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-09-23 22:18 - 2012-08-24 19:10 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-09-23 22:18 - 2012-08-11 02:53 - 00714752 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2013-09-23 22:18 - 2012-08-11 01:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2013-09-23 22:18 - 2012-07-05 00:04 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2013-09-23 22:18 - 2012-07-05 00:01 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll 2013-09-23 22:18 - 2012-07-05 00:01 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll 2013-09-23 22:18 - 2012-07-04 23:26 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2013-09-23 22:18 - 2012-07-04 23:23 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2013-09-23 22:18 - 2012-05-14 07:20 - 00956416 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2013-09-23 22:18 - 2012-04-28 05:50 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2013-09-23 22:18 - 2012-04-26 07:34 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2013-09-23 22:18 - 2012-04-26 07:34 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2013-09-23 22:18 - 2012-04-26 07:28 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe 2013-09-23 22:18 - 2012-03-17 09:55 - 00075632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2013-09-23 22:18 - 2011-12-28 05:59 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-09-23 22:18 - 2011-12-16 10:42 - 00634368 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2013-09-23 22:18 - 2011-12-16 09:59 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll 2013-09-23 22:18 - 2011-11-17 09:14 - 01739160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-23 22:18 - 2011-11-17 07:41 - 01292592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-23 22:18 - 2011-10-26 07:22 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2013-09-23 22:18 - 2011-10-26 07:22 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-09-23 22:18 - 2011-10-26 06:28 - 01328640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2013-09-23 22:18 - 2011-10-26 06:28 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-09-23 22:18 - 2011-10-15 08:25 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2013-09-23 22:18 - 2011-10-15 07:48 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2013-09-23 22:18 - 2011-07-09 04:44 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2013-09-23 22:18 - 2011-05-24 13:21 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll 2013-09-23 22:18 - 2011-05-24 12:34 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll 2013-09-23 22:18 - 2011-05-24 12:34 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll 2013-09-23 22:18 - 2011-05-24 12:34 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll 2013-09-23 22:18 - 2011-05-24 12:32 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe 2013-09-23 22:18 - 2011-05-04 04:51 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2013-09-23 22:18 - 2011-05-04 04:51 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2013-09-23 22:18 - 2011-05-03 07:21 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2013-09-23 22:18 - 2011-05-03 06:50 - 00740864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2013-09-23 22:18 - 2011-04-27 04:57 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys 2013-09-23 22:18 - 2011-03-11 08:19 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2013-09-23 22:18 - 2011-03-11 08:19 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2013-09-23 22:18 - 2011-03-11 07:40 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2013-09-23 22:18 - 2011-03-11 07:40 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2013-09-23 22:18 - 2011-03-03 08:17 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2013-09-23 22:18 - 2011-03-03 08:17 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2013-09-23 22:18 - 2011-03-03 08:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe 2013-09-23 22:18 - 2011-03-03 07:29 - 00269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2013-09-23 22:18 - 2011-03-03 07:27 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe 2013-09-23 22:18 - 2011-02-12 08:14 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe 2013-09-23 22:18 - 2010-12-18 08:08 - 01097216 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-09-23 22:18 - 2010-12-18 07:26 - 01034240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-09-23 22:18 - 2010-08-27 08:14 - 00236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll 2013-09-23 22:18 - 2010-08-27 07:46 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll 2013-09-23 22:18 - 2010-08-26 07:27 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll 2013-09-23 22:18 - 2010-08-26 06:39 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll 2013-09-23 22:18 - 2010-08-21 08:38 - 01024512 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2013-09-23 22:18 - 2010-08-21 08:29 - 00558592 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2013-09-23 22:18 - 2010-08-21 07:36 - 00738816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll 2013-09-23 22:18 - 2010-07-29 08:30 - 00082944 _____ (Radius Inc.) C:\Windows\SysWOW64\iccvid.dll 2013-09-23 22:18 - 2010-06-29 07:39 - 02085376 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2013-09-23 22:18 - 2010-06-29 07:02 - 01413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2013-09-23 22:18 - 2010-06-19 08:53 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\rtutils.dll 2013-09-23 22:18 - 2010-06-19 08:23 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtutils.dll 2013-09-23 22:18 - 2010-03-05 09:52 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll 2013-09-23 22:18 - 2010-03-05 09:42 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll 2013-09-23 22:18 - 2009-12-19 11:50 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\tsbyuv.dll 2013-09-23 22:18 - 2009-12-19 11:47 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\msvidc32.dll 2013-09-23 22:18 - 2009-12-19 11:47 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msyuv.dll 2013-09-23 22:18 - 2009-12-19 11:47 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\msrle32.dll 2013-09-23 22:18 - 2009-12-19 11:46 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\iyuv_32.dll 2013-09-23 22:18 - 2009-12-19 11:02 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\avifil32.dll 2013-09-23 22:18 - 2009-12-19 11:02 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mciavi32.dll 2013-09-23 22:18 - 2009-12-19 11:02 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iyuv_32.dll 2013-09-23 22:18 - 2009-12-19 11:02 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvidc32.dll 2013-09-23 22:18 - 2009-12-19 11:02 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msyuv.dll 2013-09-23 22:18 - 2009-12-19 11:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrle32.dll 2013-09-23 22:18 - 2009-12-19 11:02 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsbyuv.dll 2013-09-23 22:18 - 2009-10-31 08:34 - 02870272 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-09-23 22:18 - 2009-10-31 07:45 - 02614272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2013-09-23 22:18 - 2009-10-28 08:24 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2013-09-23 22:18 - 2009-08-29 09:50 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\msasn1.dll 2013-09-23 22:18 - 2009-08-29 08:57 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msasn1.dll 2013-09-23 22:17 - 2011-02-23 07:15 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys 2013-09-23 22:17 - 2010-10-16 07:23 - 00112000 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2013-09-23 22:17 - 2010-05-05 09:37 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll 2013-09-23 22:17 - 2010-05-05 08:46 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll 2013-09-23 22:16 - 2012-06-02 07:25 - 01462784 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-09-23 22:16 - 2012-06-02 07:25 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-09-23 22:16 - 2012-06-02 07:25 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-09-23 22:16 - 2012-06-02 06:45 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-09-23 22:16 - 2012-06-02 06:45 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-09-23 22:16 - 2012-06-02 06:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-09-23 22:10 - 2013-09-23 22:10 - 00001198 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk 2013-09-23 22:10 - 2013-09-23 22:10 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-09-23 22:10 - 2013-09-23 22:10 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-09-23 22:09 - 2013-09-23 22:09 - 15641088 _____ (LastPass) C:\Users\Kai\Downloads\lastpass_x64.exe 2013-09-23 22:07 - 2013-09-23 22:07 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Thunderbird 2013-09-23 22:07 - 2013-09-23 22:07 - 00000000 ____D C:\Users\Kai\AppData\Local\Thunderbird 2013-09-23 22:04 - 2011-11-19 17:07 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2013-09-23 22:04 - 2011-11-19 16:06 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2013-09-23 20:36 - 2013-09-23 20:36 - 00000000 ____D C:\Program Files (x86)\MiniTool Partition Wizard Home Edition 8.0 2013-09-23 20:36 - 2013-07-01 10:25 - 03151040 _____ C:\Windows\system32\pwNative.exe 2013-09-23 20:36 - 2013-07-01 10:25 - 00019032 ____N C:\Windows\system32\pwdrvio.sys 2013-09-23 20:36 - 2013-07-01 10:25 - 00012384 ____N C:\Windows\system32\pwdspio.sys 2013-09-23 20:35 - 2013-09-23 20:35 - 20198792 _____ (MiniTool Solution Ltd. ) C:\Users\Kai\Downloads\pwhe8.exe 2013-09-23 20:32 - 2013-09-23 20:32 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-23 20:32 - 2013-09-23 20:32 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Mozilla 2013-09-23 20:32 - 2013-09-23 20:32 - 00000000 ____D C:\Users\Kai\AppData\Local\Mozilla 2013-09-23 20:32 - 2013-09-23 20:32 - 00000000 ____D C:\ProgramData\Mozilla 2013-09-23 20:32 - 2013-09-23 20:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-23 20:31 - 2013-09-23 20:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-23 20:24 - 2013-09-23 20:24 - 00281896 _____ (Mozilla) C:\Users\Kai\Downloads\Firefox Setup Stub 24.0.exe 2013-09-23 20:21 - 2013-08-07 04:22 - 00278800 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-09-23 20:13 - 2013-09-23 20:13 - 00000000 ____D C:\Users\Kai\AppData\Roaming\ESET 2013-09-23 20:13 - 2013-09-23 20:13 - 00000000 ____D C:\Users\Kai\AppData\Local\ESET 2013-09-23 20:12 - 2013-09-23 20:12 - 00000000 ____D C:\ProgramData\ESET 2013-09-23 20:12 - 2013-09-23 20:12 - 00000000 ____D C:\Program Files\ESET 2013-09-23 20:10 - 2012-02-15 08:27 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2013-09-23 20:10 - 2012-02-15 07:44 - 00826368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2013-09-23 20:10 - 2012-02-15 06:46 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2013-09-23 20:10 - 2010-01-09 09:19 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll 2013-09-23 20:10 - 2010-01-09 08:52 - 00132608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cabview.dll 2013-09-23 20:09 - 2013-09-23 20:09 - 00003292 _____ C:\Windows\System32\Tasks\{C464CAD9-BB4E-44A5-9D2A-4D8391DB0AF7} 2013-09-23 20:05 - 2013-09-23 23:52 - 00001443 _____ C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-23 20:05 - 2013-09-23 23:52 - 00001409 _____ C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-09-23 20:05 - 2013-09-23 23:52 - 00000000 ___RD C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-23 20:05 - 2013-09-23 23:52 - 00000000 ___RD C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-23 20:05 - 2012-06-03 00:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-09-23 20:05 - 2012-06-03 00:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-09-23 20:05 - 2012-06-03 00:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-09-23 20:05 - 2012-06-03 00:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-09-23 20:04 - 2013-09-23 20:04 - 00000000 ____D C:\Users\Kai\AppData\Local\VirtualStore 2013-09-23 20:04 - 2012-06-03 00:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-09-23 20:04 - 2012-06-03 00:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-09-23 20:04 - 2012-06-03 00:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-09-23 20:04 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-09-23 20:04 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-09-23 20:03 - 2013-09-25 00:48 - 00000000 ____D C:\Users\Kai 2013-09-23 20:03 - 2013-09-23 20:03 - 00000020 ___SH C:\Users\Kai\ntuser.ini 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Vorlagen 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Startmenü 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Netzwerkumgebung 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Lokale Einstellungen 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Eigene Dateien 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Druckumgebung 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Documents\Eigene Musik 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Documents\Eigene Bilder 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\AppData\Local\Verlauf 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\AppData\Local\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-09-23 20:03 - 2009-07-14 06:54 - 00000000 ___RD C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-09-23 20:03 - 2009-07-14 06:49 - 00000000 ___RD C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-09-23 19:14 - 2013-09-23 20:03 - 00000000 ____D C:\Windows\Panther 2013-09-23 19:14 - 2009-08-15 12:13 - 00000013 ____R C:\Windows\csup.txt 2013-09-23 19:14 - 2009-08-12 09:09 - 00000024 ___RH C:\Windows\DELL_version 2013-09-23 19:13 - 2013-09-25 00:33 - 00643866 _____ C:\Windows\system32\perfh007.dat 2013-09-23 19:13 - 2013-09-25 00:33 - 00126394 _____ C:\Windows\system32\perfc007.dat 2013-09-23 19:13 - 2013-09-23 19:13 - 00295922 _____ C:\Windows\system32\perfi007.dat 2013-09-23 19:13 - 2013-09-23 19:13 - 00038104 _____ C:\Windows\system32\perfd007.dat 2013-09-23 19:13 - 2013-09-23 19:13 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2013-09-23 19:13 - 2013-09-23 19:13 - 00000000 ____D C:\Windows\SysWOW64\de 2013-09-23 19:13 - 2013-09-23 19:13 - 00000000 ____D C:\Windows\SysWOW64\0407 2013-09-23 19:13 - 2013-09-23 19:13 - 00000000 ____D C:\Windows\system32\de 2013-09-23 19:13 - 2013-09-23 19:13 - 00000000 ____D C:\Windows\system32\0407 2013-09-23 18:58 - 2013-09-23 18:58 - 00000000 ____D C:\Windows.old 2013-09-23 09:19 - 2013-09-23 09:19 - 00001313 _____ C:\Windows\TSSysprep.log 2013-09-23 09:19 - 2013-09-23 09:19 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-09-23 09:18 - 2013-09-25 00:34 - 01463407 _____ C:\Windows\WindowsUpdate.log 2013-09-23 08:27 - 2013-09-23 20:03 - 00000000 __SHD C:\Recovery 2013-09-23 08:27 - 2013-09-23 08:27 - 00000000 _SHDL C:\Programme 2013-09-23 08:27 - 2013-09-23 08:27 - 00000000 _SHDL C:\Dokumente und Einstellungen ==================== One Month Modified Files and Folders ======= 2013-09-25 00:48 - 2013-09-25 00:48 - 00000468 _____ C:\Users\Kai\Desktop\defogger_disable.log 2013-09-25 00:48 - 2013-09-25 00:48 - 00000000 ____D C:\FRST 2013-09-25 00:48 - 2013-09-25 00:48 - 00000000 _____ C:\Users\Kai\defogger_reenable 2013-09-25 00:48 - 2013-09-23 20:03 - 00000000 ____D C:\Users\Kai 2013-09-25 00:47 - 2013-09-25 00:47 - 00377856 _____ C:\Users\Kai\Desktop\gmer_2.1.19163.exe 2013-09-25 00:46 - 2013-09-25 00:46 - 01955802 _____ (Farbar) C:\Users\Kai\Desktop\FRST64.exe 2013-09-25 00:46 - 2013-09-25 00:46 - 00050477 _____ C:\Users\Kai\Desktop\Defogger.exe 2013-09-25 00:35 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-25 00:35 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-25 00:34 - 2013-09-23 09:18 - 01463407 _____ C:\Windows\WindowsUpdate.log 2013-09-25 00:33 - 2013-09-23 19:13 - 00643866 _____ C:\Windows\system32\perfh007.dat 2013-09-25 00:33 - 2013-09-23 19:13 - 00126394 _____ C:\Windows\system32\perfc007.dat 2013-09-25 00:33 - 2009-07-14 07:13 - 01472002 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-25 00:30 - 2013-09-23 22:46 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-25 00:27 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-25 00:27 - 2009-07-14 06:51 - 00016193 _____ C:\Windows\setupact.log 2013-09-23 23:52 - 2013-09-23 20:05 - 00001443 _____ C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-23 23:52 - 2013-09-23 20:05 - 00001409 _____ C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-09-23 23:52 - 2013-09-23 20:05 - 00000000 ___RD C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-23 23:52 - 2013-09-23 20:05 - 00000000 ___RD C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-23 23:50 - 2009-07-14 06:45 - 00274464 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-23 23:48 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\System 2013-09-23 23:47 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-09-23 23:46 - 2009-07-14 09:45 - 00000000 ____D C:\Program Files\Windows Journal 2013-09-23 22:48 - 2013-09-23 22:48 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Macromedia 2013-09-23 22:48 - 2013-09-23 22:48 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Adobe 2013-09-23 22:48 - 2013-09-23 22:48 - 00000000 ____D C:\Users\Kai\AppData\Local\Macromedia 2013-09-23 22:46 - 2013-09-23 22:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-23 22:46 - 2013-09-23 22:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-23 22:46 - 2013-09-23 22:46 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-23 22:46 - 2013-09-23 22:46 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2013-09-23 22:46 - 2013-09-23 22:46 - 00000000 ____D C:\Windows\system32\Macromed 2013-09-23 22:41 - 2013-09-23 22:36 - 00004423 _____ C:\Windows\IE9_main.log 2013-09-23 22:39 - 2013-09-23 22:39 - 17833472 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 12335104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-09-23 22:39 - 2013-09-23 22:39 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-09-23 22:39 - 2013-09-23 22:39 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-23 22:39 - 2013-09-23 22:39 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-23 22:39 - 2013-09-23 22:39 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-09-23 22:39 - 2013-09-23 22:39 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-09-23 22:39 - 2013-09-23 22:39 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01104896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-09-23 22:39 - 2013-09-23 22:39 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-09-23 22:39 - 2013-09-23 22:39 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-09-23 22:39 - 2013-09-23 22:39 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-09-23 22:39 - 2013-09-23 22:39 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-09-23 22:39 - 2013-09-23 22:39 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-09-23 22:38 - 2013-09-23 22:38 - 04068864 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 03181568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-09-23 22:38 - 2013-09-23 22:38 - 01863680 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 01619456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-09-23 22:38 - 2013-09-23 22:38 - 01495040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00982912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-09-23 22:38 - 2013-09-23 22:38 - 00662528 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00470016 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00283648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00265088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-09-23 22:38 - 2013-09-23 22:38 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00196608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-09-23 22:38 - 2013-09-23 22:38 - 00135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsRasterService.dll 2013-09-23 22:10 - 2013-09-23 22:10 - 00001198 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk 2013-09-23 22:10 - 2013-09-23 22:10 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-09-23 22:10 - 2013-09-23 22:10 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-09-23 22:09 - 2013-09-23 22:09 - 15641088 _____ (LastPass) C:\Users\Kai\Downloads\lastpass_x64.exe 2013-09-23 22:07 - 2013-09-23 22:07 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Thunderbird 2013-09-23 22:07 - 2013-09-23 22:07 - 00000000 ____D C:\Users\Kai\AppData\Local\Thunderbird 2013-09-23 20:36 - 2013-09-23 20:36 - 00000000 ____D C:\Program Files (x86)\MiniTool Partition Wizard Home Edition 8.0 2013-09-23 20:35 - 2013-09-23 20:35 - 20198792 _____ (MiniTool Solution Ltd. ) C:\Users\Kai\Downloads\pwhe8.exe 2013-09-23 20:32 - 2013-09-23 20:32 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-23 20:32 - 2013-09-23 20:32 - 00000000 ____D C:\Users\Kai\AppData\Roaming\Mozilla 2013-09-23 20:32 - 2013-09-23 20:32 - 00000000 ____D C:\Users\Kai\AppData\Local\Mozilla 2013-09-23 20:32 - 2013-09-23 20:32 - 00000000 ____D C:\ProgramData\Mozilla 2013-09-23 20:32 - 2013-09-23 20:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-23 20:32 - 2013-09-23 20:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-23 20:24 - 2013-09-23 20:24 - 00281896 _____ (Mozilla) C:\Users\Kai\Downloads\Firefox Setup Stub 24.0.exe 2013-09-23 20:13 - 2013-09-23 20:13 - 00000000 ____D C:\Users\Kai\AppData\Roaming\ESET 2013-09-23 20:13 - 2013-09-23 20:13 - 00000000 ____D C:\Users\Kai\AppData\Local\ESET 2013-09-23 20:12 - 2013-09-23 20:12 - 00000000 ____D C:\ProgramData\ESET 2013-09-23 20:12 - 2013-09-23 20:12 - 00000000 ____D C:\Program Files\ESET 2013-09-23 20:09 - 2013-09-23 20:09 - 00003292 _____ C:\Windows\System32\Tasks\{C464CAD9-BB4E-44A5-9D2A-4D8391DB0AF7} 2013-09-23 20:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-23 20:04 - 2013-09-23 20:04 - 00000000 ____D C:\Users\Kai\AppData\Local\VirtualStore 2013-09-23 20:03 - 2013-09-23 20:03 - 00000020 ___SH C:\Users\Kai\ntuser.ini 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Vorlagen 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Startmenü 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Netzwerkumgebung 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Lokale Einstellungen 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Eigene Dateien 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Druckumgebung 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Documents\Eigene Musik 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Documents\Eigene Bilder 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\AppData\Local\Verlauf 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\AppData\Local\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Kai\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-09-23 20:03 - 2013-09-23 20:03 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-09-23 20:03 - 2013-09-23 19:14 - 00000000 ____D C:\Windows\Panther 2013-09-23 20:03 - 2013-09-23 08:27 - 00000000 __SHD C:\Recovery 2013-09-23 20:03 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\restore 2013-09-23 20:03 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-09-23 20:03 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-09-23 20:03 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT 2013-09-23 19:14 - 2009-07-14 07:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2013-09-23 19:14 - 2009-07-14 07:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2013-09-23 19:14 - 2009-07-14 06:45 - 00000000 ____D C:\Windows\Setup 2013-09-23 19:14 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\oobe 2013-09-23 19:13 - 2013-09-23 19:13 - 00295922 _____ C:\Windows\system32\perfi007.dat 2013-09-23 19:13 - 2013-09-23 19:13 - 00038104 _____ C:\Windows\system32\perfd007.dat 2013-09-23 19:13 - 2013-09-23 19:13 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2013-09-23 19:13 - 2013-09-23 19:13 - 00000000 ____D C:\Windows\SysWOW64\de 2013-09-23 19:13 - 2013-09-23 19:13 - 00000000 ____D C:\Windows\SysWOW64\0407 2013-09-23 19:13 - 2013-09-23 19:13 - 00000000 ____D C:\Windows\system32\de 2013-09-23 19:13 - 2013-09-23 19:13 - 00000000 ____D C:\Windows\system32\0407 2013-09-23 19:13 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\SysWOW64\winrm 2013-09-23 19:13 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\SysWOW64\WCN 2013-09-23 19:13 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\SysWOW64\sysprep 2013-09-23 19:13 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\SysWOW64\slmgr 2013-09-23 19:13 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2013-09-23 19:13 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\system32\winrm 2013-09-23 19:13 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\system32\WCN 2013-09-23 19:13 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\system32\slmgr 2013-09-23 19:13 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2013-09-23 19:13 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\DigitalLocker 2013-09-23 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2013-09-23 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2013-09-23 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2013-09-23 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-09-23 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker 2013-09-23 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar 2013-09-23 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2013-09-23 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Setup 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\oobe 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\MUI 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Dism 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\com 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Setup 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\MUI 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\migwiz 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Dism 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\com 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing 2013-09-23 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\IME 2013-09-23 18:58 - 2013-09-23 18:58 - 00000000 ____D C:\Windows.old 2013-09-23 09:19 - 2013-09-23 09:19 - 00001313 _____ C:\Windows\TSSysprep.log 2013-09-23 09:19 - 2013-09-23 09:19 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-09-23 09:19 - 2009-07-14 06:46 - 00001774 _____ C:\Windows\DtcInstall.log 2013-09-23 09:19 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep 2013-09-23 08:27 - 2013-09-23 08:27 - 00000000 _SHDL C:\Programme 2013-09-23 08:27 - 2013-09-23 08:27 - 00000000 _SHDL C:\Dokumente und Einstellungen ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-23 09:15 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-09-2013 Ran by Kai at 2013-09-25 00:51:14 Running from C:\Users\Kai\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: ESET Smart Security 4.2 (Enabled - Up to date) {CB0F8167-5331-BA19-698E-64816B6801A5} AS: ESET Smart Security 4.2 (Enabled - Up to date) {706E6083-750B-B597-533E-5FF310EF4B18} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Personal Firewall (Enabled) {F3340042-195E-BB41-42D1-CDB495BB46DE} ==================== Installed Programs ====================== Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168) ESET Smart Security (Version: 4.2.40.10) LastPass (Nur deinstallieren) (x32) MiniTool Partition Wizard Home Edition 8.0 (x32) Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0) Mozilla Maintenance Service (x32 Version: 24.0) ==================== Restore Points ========================= 23-09-2013 18:03:29 Windows Update 23-09-2013 18:10:11 Windows Update 23-09-2013 18:12:05 ESET Smart Security wird installiert 23-09-2013 20:23:58 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0049C0EE-D15D-476E-A86C-E276C05D83B1} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: {9A760336-8FB9-457B-B414-61BDD7118EAD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-23] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2009-07-14 02:35 - 2009-07-14 03:41 - 01434112 _____ (Microsoft Corporation) C:\Windows\System32\Speech\Common\sapi.dll 2013-09-23 22:18 - 2011-11-17 07:41 - 01292592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-23 22:20 - 2013-01-04 06:51 - 01114112 _____ (Microsoft Corporation) C:\Windows\syswow64\kernel32.dll 2013-09-23 22:20 - 2013-01-04 06:51 - 00274944 _____ (Microsoft Corporation) C:\Windows\syswow64\KERNELBASE.dll 2009-07-14 01:24 - 2009-07-14 03:11 - 00833024 _____ (Microsoft Corporation) C:\Windows\syswow64\USER32.dll 2009-07-14 01:25 - 2009-07-14 03:11 - 00310784 _____ (Microsoft Corporation) C:\Windows\syswow64\GDI32.dll 2009-07-14 01:25 - 2009-07-14 03:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\syswow64\LPK.dll 2009-07-14 01:25 - 2009-07-14 03:16 - 00627200 _____ (Microsoft Corporation) C:\Windows\syswow64\USP10.dll 2013-09-23 22:18 - 2011-12-16 09:59 - 00690688 _____ (Microsoft Corporation) C:\Windows\syswow64\msvcrt.dll 2009-07-14 02:20 - 2009-07-14 03:14 - 00640000 _____ (Microsoft Corporation) C:\Windows\syswow64\ADVAPI32.dll 2009-07-14 01:11 - 2009-07-14 03:16 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll 2009-07-14 01:12 - 2009-07-14 03:11 - 00662528 _____ (Microsoft Corporation) C:\Windows\syswow64\RPCRT4.dll 2013-09-23 22:19 - 2012-06-02 06:42 - 00096768 _____ (Microsoft Corporation) C:\Windows\syswow64\SspiCli.dll 2009-07-14 01:12 - 2009-07-14 03:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\syswow64\CRYPTBASE.dll 2009-07-14 01:28 - 2009-07-14 03:15 - 00828928 _____ (Microsoft Corporation) C:\Windows\syswow64\MSCTF.dll 2009-07-14 01:12 - 2009-07-14 03:16 - 00206336 _____ (Microsoft Corporation) C:\Windows\syswow64\WS2_32.dll 2009-07-14 01:12 - 2009-07-14 03:16 - 00008704 _____ (Microsoft Corporation) C:\Windows\syswow64\NSI.dll 2013-09-23 20:31 - 2013-09-11 04:26 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2009-07-14 01:15 - 2009-07-14 03:16 - 00006144 _____ (Microsoft Corporation) C:\Windows\syswow64\PSAPI.DLL 2013-09-23 22:18 - 2010-06-29 07:02 - 01413632 _____ (Microsoft Corporation) C:\Windows\syswow64\ole32.dll 2013-09-23 22:19 - 2012-06-09 06:46 - 12868608 _____ (Microsoft Corporation) C:\Windows\syswow64\SHELL32.dll 2009-07-14 01:39 - 2009-07-14 03:16 - 00350208 _____ (Microsoft Corporation) C:\Windows\syswow64\SHLWAPI.dll 2009-07-14 01:16 - 2009-07-14 03:16 - 01668608 _____ (Microsoft Corporation) C:\Windows\syswow64\SETUPAPI.dll 2013-09-23 22:18 - 2011-05-24 12:34 - 00145920 _____ (Microsoft Corporation) C:\Windows\syswow64\CFGMGR32.dll 2013-09-23 22:19 - 2011-08-27 06:43 - 00571904 _____ (Microsoft Corporation) C:\Windows\syswow64\OLEAUT32.dll 2013-09-23 22:18 - 2011-05-24 12:34 - 00064512 _____ (Microsoft Corporation) C:\Windows\syswow64\DEVOBJ.dll 2009-07-14 01:44 - 2009-07-14 03:15 - 00522240 _____ (Microsoft Corporation) C:\Windows\syswow64\CLBCatQ.DLL 2009-07-14 01:38 - 2009-07-14 03:16 - 00268800 _____ (Microsoft Corporation) C:\Windows\syswow64\WLDAP32.dll 2013-09-23 22:18 - 2012-08-24 19:10 - 00172544 _____ (Microsoft Corporation) C:\Windows\syswow64\WINTRUST.dll 2013-09-23 22:16 - 2012-06-02 06:45 - 01157632 _____ (Microsoft Corporation) C:\Windows\syswow64\CRYPT32.dll 2013-09-23 22:18 - 2009-08-29 08:57 - 00034816 _____ (Microsoft Corporation) C:\Windows\syswow64\MSASN1.dll 2013-09-23 22:10 - 2013-09-23 22:10 - 01019904 _____ () C:\Users\Kai\AppData\Roaming\Mozilla\Firefox\Profiles\o8d2zkwp.default\extensions\support@lastpass.com\platform\WINNT_x86-msvc\components\lpxpcom.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01129472 _____ (Microsoft Corporation) C:\Windows\syswow64\WININET.dll 2009-07-14 01:15 - 2009-07-14 03:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\syswow64\Normaliz.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01796096 _____ (Microsoft Corporation) C:\Windows\syswow64\iertutil.dll 2013-09-23 22:39 - 2013-09-23 22:39 - 01104896 _____ (Microsoft Corporation) C:\Windows\syswow64\urlmon.dll 2009-07-14 01:39 - 2009-07-14 03:15 - 00486912 _____ (Microsoft Corporation) C:\Windows\syswow64\COMDLG32.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Massenspeichercontroller Description: Massenspeichercontroller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: DuoSense Description: DuoSense Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Error: (09/25/2013 00:35:36 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597 (Definition 1.159.552.0) Error: (09/25/2013 00:27:25 AM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/25/2013 00:27:25 AM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (09/24/2013 09:01:23 AM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/24/2013 06:37:19 AM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/24/2013 00:03:10 AM) (Source: ACPI) (User: ) Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Error: (09/23/2013 11:52:03 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%16405 Error: (09/23/2013 11:50:34 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/23/2013 11:50:34 PM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (09/23/2013 11:49:18 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde mit folgendem Fehler beendet: %%-2147467243 Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 54% Total physical RAM: 4084.51 MB Available physical RAM: 1878.37 MB Total Pagefile: 8167.16 MB Available Pagefile: 5987.71 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:50 GB) (Free:19.46 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Daten) (Fixed) (Total:215.72 GB) (Free:215.51 GB) NTFS Drive e: (WIN_7_HOMEPREMIUM) (CDROM) (Total:5.75 GB) (Free:0 GB) UDF Drive f: (Programme) (Fixed) (Total:200 GB) (Free:199.84 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 1C796BD1) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Not Active) - (Size=216 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=200 GB) - (Type=07 NTFS) Partition 4: (Active) - (Size=50 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-09-25 02:31:34 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK5055GSX rev.FG000D 465,76GB Running: gmer_2.1.19163.exe; Driver: C:\Users\Kai\AppData\Local\Temp\uwldqpow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe[1392] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000759687b1 4 bytes [C2, 04, 00, 00] .text C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe[1392] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000076f31465 2 bytes [F3, 76] .text C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe[1392] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000076f314bb 2 bytes [F3, 76] .text ... * 2 ---- EOF - GMER 2.1 ---- Code:
ATTFilter Log Version der Signaturdatenbank: 8835 (20130923) Datum: 23.09.2013 Uhrzeit: 23:54:12 Geprüfte Laufwerke, Ordner und Dateien: Arbeitsspeicher;C:\Bootsektor;C:\;D:\Bootsektor;D:\;F:\Bootsektor;F:\ C:\hiberfil.sys - Fehler beim Öffnen [4] C:\pagefile.sys - Fehler beim Öffnen [4] C:\Boot\BCD - Fehler beim Öffnen [4] C:\Boot\BCD.LOG - Fehler beim Öffnen [4] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log - Fehler beim Öffnen [4] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log - Fehler beim Öffnen [4] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb - Fehler beim Öffnen [4] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb - Fehler beim Öffnen [4] C:\ProgramData\Microsoft\Windows Defender\IMpService925A3ACA-C353-458A-AC8D-A7E5EB378092.lock - Fehler beim Öffnen [4] C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\MSS.log - Fehler beim Öffnen [4] C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\MSStmp.log - Fehler beim Öffnen [4] C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\tmp.edb - Fehler beim Öffnen [4] C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb - Fehler beim Öffnen [4] C:\Users\All Users\Microsoft\Windows Defender\IMpService925A3ACA-C353-458A-AC8D-A7E5EB378092.lock - Fehler beim Öffnen [4] C:\Users\Kai\NTUSER.DAT - Fehler beim Öffnen [4] C:\Users\Kai\ntuser.dat.LOG1 - Fehler beim Öffnen [4] C:\Users\Kai\ntuser.dat.LOG2 - Fehler beim Öffnen [4] C:\Users\Kai\AppData\Local\Microsoft\Windows\UsrClass.dat - Fehler beim Öffnen [4] C:\Users\Kai\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - Fehler beim Öffnen [4] C:\Users\Kai\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - Fehler beim Öffnen [4] C:\Users\Kai\AppData\Roaming\Thunderbird\Profiles\2vpvpuca.default\ImapMail\imap.googlemail.com\INBOX = MBOX - - OK (eingebettete Archive NICHT geprüft) C:\Windows\Microsoft.NET\ngenservice_pri1_lock.dat - Fehler beim Öffnen [4] C:\Windows\Microsoft.NET\Framework\v2.0.50727\ngenrootstorelock.dat - Fehler beim Öffnen [4] C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT - Fehler beim Öffnen [4] C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1 - Fehler beim Öffnen [4] C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2 - Fehler beim Öffnen [4] C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - Fehler beim Öffnen [4] C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - Fehler beim Öffnen [4] C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\898adf6215535b73711a505cd45550415049909f.HomeGroupClassifier\43d68249728222ceaedd53ab4842dc3a\grouping\db.mdb - Fehler beim Öffnen [4] C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\898adf6215535b73711a505cd45550415049909f.HomeGroupClassifier\43d68249728222ceaedd53ab4842dc3a\grouping\edb.log - Fehler beim Öffnen [4] C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\898adf6215535b73711a505cd45550415049909f.HomeGroupClassifier\43d68249728222ceaedd53ab4842dc3a\grouping\tmp.edb - Fehler beim Öffnen [4] C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT - Fehler beim Öffnen [4] C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1 - Fehler beim Öffnen [4] C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2 - Fehler beim Öffnen [4] C:\Windows\System32\catroot2\edb.log - Fehler beim Öffnen [4] C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - Fehler beim Öffnen [4] C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - Fehler beim Öffnen [4] C:\Windows.old\Documents and Settings\Kai\AppData\Local\Anwendungsdaten\Microsoft\Windows\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\AppData\Local\Anwendungsdaten\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\AppData\Local\Anwendungsdaten\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\AppData\Local\Anwendungsdaten\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\AppData\Local\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\AppData\Local\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\Lokale Einstellungen\Microsoft\Windows\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\Lokale Einstellungen\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\Lokale Einstellungen\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\Lokale Einstellungen\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Users\Kai\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Users\Kai\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Users\Kai\AppData\Local\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Users\Kai\AppData\Local\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Users\Kai\Lokale Einstellungen\Microsoft\Windows\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Users\Kai\Lokale Einstellungen\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Users\Kai\Lokale Einstellungen\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Users\Kai\Lokale Einstellungen\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans C:\Windows.old\Documents and Settings\Kai\AppData\Local\Anwendungsdaten\Microsoft\Windows\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Gesäubert durch Löschen - in Quarantäne kopiert [1] C:\Windows.old\Documents and Settings\Kai\AppData\Local\Anwendungsdaten\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Variante von Win32/InstallCore.CX evtl. unerwünschte Anwendung - Gesäubert durch Löschen - in Quarantäne kopiert [1] C:\Windows.old\Documents and Settings\Kai\AppData\Local\Anwendungsdaten\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Documents and Settings\Kai\AppData\Local\Anwendungsdaten\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Documents and Settings\Kai\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Documents and Settings\Kai\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Documents and Settings\Kai\AppData\Local\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Documents and Settings\Kai\AppData\Local\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Documents and Settings\Kai\Lokale Einstellungen\Microsoft\Windows\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Documents and Settings\Kai\Lokale Einstellungen\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Documents and Settings\Kai\Lokale Einstellungen\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Documents and Settings\Kai\Lokale Einstellungen\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Users\Kai\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Users\Kai\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Users\Kai\AppData\Local\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Users\Kai\AppData\Local\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Users\Kai\Lokale Einstellungen\Microsoft\Windows\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Users\Kai\Lokale Einstellungen\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Users\Kai\Lokale Einstellungen\Temporary Internet Files\Content.IE5\6WYFHML9\download[1].exe - Fehler beim Öffnen [4] C:\Windows.old\Users\Kai\Lokale Einstellungen\Temporary Internet Files\Low\Content.IE5\T0GSIAO4\Firefox_Setup[1].exe - Fehler beim Öffnen [4] Geprüfte Objekte: 270120 Erkannte Bedrohungen: 20 Anzahl gesäuberter Objekte: 2 Abgeschlossen: 09:18:52 Benötigte Zeit: 33880 Sek. (09:24:40) Hinweise: [1] Objekt wurde gelöscht. Es enthielt ausschließlich Viruscode. [4] Objekt kann nicht geöffnet werden. Möglicherweise in Benutzung durch eine andere Anwendung oder das Betriebssystem. |
26.09.2013, 09:04 | #4 |
/// the machine /// TB-Ausbilder | ESET Bootsektor Prüfung nicht durführbar Windows.old Ordner löschen. Ansonsten passt das
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu ESET Bootsektor Prüfung nicht durführbar |
bonjour, chromium, combofix, dsl, eset bootsektor perfofmance, explorer, farbar, farbar recovery scan tool, firefox, flash player, freemium, herunterfahren, home, hotspot, iexplore.exe, installation, minidump, mozilla, performance, plug-in, registry, scan, security, services.exe, siteadvisor, software, spotify web helper, svchost.exe, system, temp, windows, windows xp, winlogon.exe, wlan |