|
Alles rund um Windows: Windows 7 1) Systemwiederherstellungspunkte nach Neustart weg / 2) F8-Menü -> Abgesicherter Modus etc. funktioniert nicht mehrWindows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
13.11.2013, 20:28 | #1 |
| Problem: Windows 7 1) Systemwiederherstellungspunkte nach Neustart weg / 2) F8-Menü -> Abgesicherter Modus etc. funktioniert nicht mehr Hallo Leute, seit kurzem kann ich zwar Wiederherstellungspunkte unter Windows 7 erstellen (teilweise werden auch automatische erstellt), doch nach Neustart des Rechners sind diese verschwunden. Habe nach dieser Anleitung hxxp://www.drwindows.de/windows-anleitungen-und-faq/33991-windows-7-loescht-alle-wiederherstellungspunkte-beim-neustart.html versucht die Sache wieder in den Griff zu bekommen. Habe mit O&O Defrag defragmentiert anstatt mit dem Windows7-Defragmentierer. Defragmentiere sowieso recht häufig. Jedoch hat die Sache das Problem nicht gelöst. Von der Windows7-DVD starten und Reparatur-Optionen ausführen bringt nichts, da "keine Fehler" gemeldet werden. Hatte vor kurzem diese Treiber: Actual nForce Driverpack v9.0 for Vista/Win7 x64 installiert und (zufällig?) seitdem besteht das Problem. Hatte vorher 2 Jahre die gleichen als v8.9 installiert und nie Probleme gehabt. Außerdem habe ich festgestellt, dass durch drücken von F8 beim Booten nichts mehr passiert. Der Rechner startet weiterhin direkt ganz normal. Ich kann jedoch durch das Systemkonfigurationsprogramm einen Start im Abgesicherten Modus hervorrufen, möchte das aber wie früher mit der F8-Taste können! Danke schonmal für konstruktive Hilfe! Geändert von Sol UP (13.11.2013 um 21:26 Uhr) |
13.11.2013, 23:04 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7 1) Systemwiederherstellungspunkte nach Neustart weg / 2) F8-Menü -> Abgesicherter Modus etc. funktioniert nicht mehr Anleitung / Hilfe Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
14.11.2013, 01:03 | #3 |
| Windows 7 1) Systemwiederherstellungspunkte nach Neustart weg / 2) F8-Menü -> Abgesicherter Modus etc. funktioniert nicht mehr Details FRST Logfile:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2013 Ran by Uli (administrator) on BROTKASTEN on 14-11-2013 00:54:36 Running from C:\Users\Uli\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Ray Adams) C:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe () C:\Program Files\Prio\prio_svc.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Farbar) C:\Users\Uli\Desktop\FRST64(1).exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [AtiTrayTools] - C:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe [929792 2011-10-29] (Ray Adams) HKCU\...\Run: [CCleaner] - C:\Program Files\CCleaner\CCleaner64.exe [5487384 2013-10-22] (Piriform Ltd) MountPoints2: {0a659c35-d986-11e2-94d5-824f548bc2ff} - Z:\launcher.exe MountPoints2: {14bff628-0751-11e2-a498-11fc2c5d8e9d} - Z:\setup.exe MountPoints2: {1dd40e0e-446f-11e2-be5a-11fc2c5d8e9d} - Z:\Setup.exe MountPoints2: {1f9932a0-8e57-11e2-baf4-ef8ccfa426f9} - Z:\autorun.exe MountPoints2: {212888b4-1f9f-11e3-8b81-fb29c15f4ef4} - Z:\setup.exe MountPoints2: {212888cf-1f9f-11e3-8b81-fb29c15f4ef4} - Z:\setup.exe MountPoints2: {2c2d2bcc-8a60-11e2-9ee4-d923de242594} - Z:\Setup.exe MountPoints2: {2df4f4b1-aeb7-11e2-bf34-a98bbb2445ff} - Z:\autorun.exe MountPoints2: {2e86ab16-23bc-11e2-8d49-11fc2c5d8e9d} - Z:\SETUP.EXE MountPoints2: {2e86ab1c-23bc-11e2-8d49-11fc2c5d8e9d} - H:\SETUP.EXE MountPoints2: {2f4ade67-2b8f-11e3-aee5-99a80f47b6fa} - Z:\setup.exe /autorun MountPoints2: {30aa2a4f-d510-11e2-99fe-af0f522c2ff0} - E:\OriginInstaller.exe MountPoints2: {30aa2b4d-d510-11e2-99fe-af0f522c2ff0} - Z:\OriginInstaller.exe MountPoints2: {30aa2b67-d510-11e2-99fe-af0f522c2ff0} - Z:\setup.exe MountPoints2: {30aa2c96-d510-11e2-99fe-af0f522c2ff0} - Z:\setup.exe MountPoints2: {3bcc0f47-1481-11e3-93c2-f6d59dd144fb} - Z:\Setup.exe MountPoints2: {3e536b81-0969-11e2-836f-11fc2c5d8e9d} - Z:\SWTFU_Autorun.exe MountPoints2: {40173a93-7673-11e1-9e9a-11fc2c5d8e9d} - Z:\setup.exe MountPoints2: {40173ad7-7673-11e1-9e9a-11fc2c5d8e9d} - Z:\setup.exe MountPoints2: {413f56de-d144-11e2-ad06-9bbdccf83cfc} - Z:\setup.exe MountPoints2: {46df26b0-077b-11e2-b1c2-11fc2c5d8e9d} - Z:\setup.exe MountPoints2: {5aa897ac-e056-11e2-a690-c74f959d6efa} - Z:\Setup.exe MountPoints2: {5cf5ab49-b0ef-11e2-b1f0-c65c3cc3fbfb} - Z:\setup.exe MountPoints2: {6b737242-1807-11e3-8800-a412319246f4} - Z:\setup.exe MountPoints2: {6eeb9c22-6964-11e1-afa6-11fc2c5d8e9d} - Z:\setup.exe MountPoints2: {6eeb9c66-6964-11e1-afa6-11fc2c5d8e9d} - Z:\setup.exe MountPoints2: {712e89e0-8540-11e2-8c98-a289467295ff} - Z:\setup.exe MountPoints2: {712e89e1-8540-11e2-8c98-a289467295ff} - Z:\setup.exe MountPoints2: {744fbe00-dcd6-11e2-a23a-fcc90f7843f5} - Z:\setup.exe MountPoints2: {760acf4c-db82-11e2-96da-c0f19dcd50ff} - Z:\AutoRun.exe MountPoints2: {760acf6c-db82-11e2-96da-c0f19dcd50ff} - Z:\AutoRun.exe MountPoints2: {833d407f-32af-11e2-b5ce-11fc2c5d8e9d} - Z:\setup.exe MountPoints2: {840d7edc-6a02-11e1-b895-11fc2c5d8e9d} - Z:\setup.exe MountPoints2: {870d5a36-aeb0-11e2-b157-a3a0c5495bf2} - Z:\autorun.exe MountPoints2: {892110a7-3765-11e2-a24d-11fc2c5d8e9d} - Z:\autorun.exe MountPoints2: {892110b4-3765-11e2-a24d-11fc2c5d8e9d} - Z:\autorun.exe MountPoints2: {892110c4-3765-11e2-a24d-11fc2c5d8e9d} - E:\autorun.exe MountPoints2: {892110c5-3765-11e2-a24d-11fc2c5d8e9d} - E:\autorun.exe MountPoints2: {8c8f54a8-745b-11e1-a91a-11fc2c5d8e9d} - E:\Autorun.exe MountPoints2: {8c8f55e3-745b-11e1-a91a-11fc2c5d8e9d} - Z:\Autorun.exe MountPoints2: {94b2064a-9625-11e2-a2a7-a74a94bf0dfa} - Z:\setup.exe MountPoints2: {94b2065c-9625-11e2-a2a7-a74a94bf0dfa} - Z:\setup.exe MountPoints2: {957acc40-ce10-11e2-8bf8-b2dd6440d4f0} - Z:\setup.exe MountPoints2: {957acc4a-ce10-11e2-8bf8-b2dd6440d4f0} - Z:\setup.exe MountPoints2: {95e12c32-d98a-11e2-89c8-cfaabb39eaff} - Z:\launcher.exe MountPoints2: {961e975d-3eb0-11e3-9ca2-be62eaa576f1} - Z:\setup.exe MountPoints2: {9cc06000-88f8-11e2-9705-e0cbdc38a9fe} - Z:\Setup.exe MountPoints2: {9f5aa144-8ff5-11e2-a76c-c080f49689fd} - Z:\setup.exe MountPoints2: {a196d92d-27db-11e2-b146-11fc2c5d8e9d} - Z:\setup.exe MountPoints2: {a1b802d3-0f0d-11e2-87c4-11fc2c5d8e9d} - notepad readme.txt MountPoints2: {a29624fa-a1e0-11e2-a483-a6ba982ab3fb} - Z:\autorun.exe MountPoints2: {a9eb0164-4a4b-11e3-9dbe-91d395db74fe} - Z:\setup.exe MountPoints2: {af059bc0-e3f7-11e2-bd64-8b78206475f5} - Z:\Setup.exe MountPoints2: {af059bcb-e3f7-11e2-bd64-8b78206475f5} - Z:\Setup.exe MountPoints2: {af059bcd-e3f7-11e2-bd64-8b78206475f5} - Z:\Setup.exe MountPoints2: {b8a714dc-7a69-11e1-aeed-11fc2c5d8e9d} - Z:\setup.exe MountPoints2: {bba7dedd-d79a-11e2-9b17-daf01f2a2cfb} - Z:\setup.exe MountPoints2: {bbcaa0c6-11b6-11e2-987e-11fc2c5d8e9d} - Z:\setup.exe /autorun MountPoints2: {bd8e3a59-cf8a-11e2-9fe5-ed6c423814fb} - Z:\setup.exe MountPoints2: {c14271c8-a7b5-11e2-b069-e308ae5179fa} - Z:\autorun.exe MountPoints2: {c3f6b2db-e38c-11e2-8c96-e981dc7878f3} - Z:\setup.exe MountPoints2: {c979bb53-a2bf-11e2-8daf-bba254ec055a} - autorun.exe MountPoints2: {d3c7e292-4092-11e2-a93c-11fc2c5d8e9d} - Z:\Setup.exe MountPoints2: {d4762411-8e44-11e2-a1e2-da9b892fb7f9} - Z:\autorun.exe MountPoints2: {d4762430-8e44-11e2-a1e2-da9b892fb7f9} - Z:\autorun.exe MountPoints2: {d476243d-8e44-11e2-a1e2-da9b892fb7f9} - Z:\autorun.exe MountPoints2: {d9ed2ab0-76ac-11e2-9921-806e6f6e6963} - D:\setup.exe MountPoints2: {e0492b86-18b8-11e3-9053-8e44e64b7cf4} - Z:\start.exe MountPoints2: {e0c83fb7-4c24-11e3-8cb3-83d60fed428f} - E:\setup.exe MountPoints2: {e1aa3eb9-de7e-11e2-b15e-a8444e8c6bfe} - Z:\OriginInstaller.exe MountPoints2: {e3b7a8d0-8e79-11e2-8751-d7a50b0060ff} - Z:\setup.exe MountPoints2: {ea8d3407-767d-11e1-9965-000129f8a9fc} - Z:\setup.exe MountPoints2: {ebbab2a1-2d1d-11e2-93c7-000129f8a9fc} - Z:\AUTOSTARTER.EXE MountPoints2: {ebbab2a2-2d1d-11e2-93c7-000129f8a9fc} - Z:\AUTOSTARTER.EXE MountPoints2: {f282b36e-1eb5-11e3-b4e8-fef75579e1f8} - Z:\setup.exe MountPoints2: {f282b37f-1eb5-11e3-b4e8-fef75579e1f8} - Z:\setup.exe MountPoints2: {f282b393-1eb5-11e3-b4e8-fef75579e1f8} - Z:\setup.exe MountPoints2: {fbf85e3d-411e-11e2-9ed2-11fc2c5d8e9d} - Z:\autorun.exe HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\avastui.exe [3567800 2013-10-19] (AVAST Software) AppInit_DLLs: prio.dll [ ] () AppInit_DLLs-x32: prio32.dll [ ] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x429F5024082ECC01 URLSearchHook: HKCU - (No Name) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {7832C251-89E7-4339-AAFA-6636C77D358A} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {7832C251-89E7-4339-AAFA-6636C77D358A} URL = hxxp://www.google.de/search?q={searchTerms} BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll (Adblock Plus) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll (Adblock Plus) DPF: HKLM-x32 {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\..\Interfaces\{1FC3657C-53D8-4032-81FA-8E8100E63CB1}: [NameServer]192.168.1.1 Tcpip\..\Interfaces\{C47208B4-3C5D-4729-BE07-9E6902B174C9}: [NameServer]192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default FF user.js: detected! => C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\user.js FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll No File FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX64.dll No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL No File FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @sun.com/npsopluginmi;version=1.0 - C:\Program Files (x86)\LibreOffice\program () FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll No File FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: adobe.com/AdobeExManCCDetect32 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect32.dll (Adobe Systems) FF Plugin HKCU: adobe.com/AdobeExManCCDetect64 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect64.dll (Adobe Systems) FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\de-pt-beolingus.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\iminent.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\leo-deu-chi.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\leo-deu-fra.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\leo-deu-ita.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\leo-deu-spa.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\leo-por-deu.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\stupidedia-de-at.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\the-pirate-bay.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\youtube-videosuche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: FoxyProxy Basic - C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\Extensions\foxyproxy@eric.h.jung FF Extension: firefox - C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\Extensions\firefox@glindorus.net.xpi FF Extension: Adblock Plus - C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: dta - C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [ealchnonpofjocgofjpopjdoegbbkofj] - C:\Program Files (x86)\HappyLyrics\Chrome.crx ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-10-19] (AVAST Software) S4 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) S3 Droppix Service; C:\Program Files (x86)\Common Files\Droppix\DxService.exe [221184 2009-08-28] (Droppix) S3 npggsvc; C:\Windows\SysWow64\GameMon.des [4109472 2012-03-08] (INCA Internet Co., Ltd.) R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [1638696 2013-11-05] (O&O Software GmbH) R2 prio_svc; C:\Program Files\Prio\prio_svc.exe [12656 2012-11-08] () S3 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390672 2012-09-11] () S3 SharedAccess; %SystemRoot%\SysWOW64\ipnathlp.dll [x] ==================== Drivers (Whitelisted) ==================== R3 ALCXWDM; C:\Windows\System32\drivers\RTKVAC64.SYS [3491616 2009-06-19] (Realtek Semiconductor Corp.) S3 AmdTools64; C:\Windows\System32\DRIVERS\AmdTools64.sys [47160 2008-04-28] (AMD, Inc.) R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [139352 2013-03-04] (SlySoft, Inc.) R3 AnyDVD; C:\Windows\SysWow64\Drivers\AnyDVD.sys [139352 2013-03-04] (SlySoft, Inc.) R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-10-19] (AVAST Software) R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [84328 2013-10-19] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-19] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-19] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-10-19] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-11-09] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-10-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-10-19] () S3 atillk64; C:\Program Files (x86)\ATI Winflash\atillk64.sys [14608 2006-07-19] (ATI Technologies Inc.) S3 ATITool; C:\Windows\System32\DRIVERS\ATITool64.sys [30720 2006-11-10] () R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31136 2013-10-02] (REALiX(tm)) R3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [27648 2008-01-19] (Microsoft Corporation) S3 kinonivd; C:\Windows\System32\DRIVERS\kinonivd.sys [2782848 2013-02-26] (Windows (R) Win 7 DDK provider) S3 KINONI_Wave; C:\Windows\System32\drivers\kinonivad.sys [23040 2013-02-26] (Windows (R) Win 7 DDK provider) S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC) S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [12800 2009-02-03] (ZTE Incorporated) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-09-18] (Duplex Secure Ltd.) U3 asek5b7b; C:\Windows\System32\Drivers\asek5b7b.sys [0 ] (NVIDIA Corporation) S3 athr; system32\DRIVERS\athrx.sys [x] S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [x] S3 dgderdrv; System32\drivers\dgderdrv.sys [x] S3 DIRECTIO; \??\C:\Program Files\PerformanceTest\DirectIo64.sys [x] R4 DRIVER_B; \??\C:\Windows\system32\Drivers\DRIVER_BIN64 [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\Game Booster\Driver\WinRing0x64.sys [x] ==================== NetSvcs (Whitelisted) =================== NETSVCx32: Mcx2Svc -> No ServiceDLL Path. ==================== One Month Created Files and Folders ======== 2013-11-14 00:54 - 2013-11-14 00:55 - 00020450 _____ C:\Users\Uli\Desktop\FRST.txt 2013-11-14 00:53 - 2013-11-14 00:53 - 01957794 _____ (Farbar) C:\Users\Uli\Desktop\FRST64(1).exe 2013-11-14 00:52 - 2013-11-14 00:52 - 00000000 ____D C:\FRST 2013-11-14 00:51 - 2013-11-14 00:50 - 00821145 _____ C:\Users\Uli\Desktop\CBS.log 2013-11-14 00:42 - 2013-11-14 00:42 - 00001085 _____ C:\Windows\setupact.log 2013-11-14 00:42 - 2013-11-14 00:42 - 00000000 _____ C:\Windows\setuperr.log 2013-11-14 00:15 - 2011-10-05 10:11 - 02643456 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-11-14 00:08 - 2013-11-14 00:09 - 00000000 ____D C:\Program Files (x86)\IminentToolbar 2013-11-14 00:08 - 2013-11-14 00:08 - 00000000 ____D C:\Users\Uli\AppData\Local\Google 2013-11-13 23:29 - 2013-11-14 00:44 - 00073522 _____ C:\Windows\WindowsUpdate.log 2013-11-13 22:48 - 2013-11-13 22:48 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-11-13 21:17 - 2013-11-13 21:17 - 00438658 __RSH C:\LJVEY 2013-11-13 18:46 - 2013-11-13 18:47 - 00014781 _____ C:\Windows\system32\oodbs.lor 2013-11-13 06:41 - 2013-11-13 06:41 - 00000000 ____D C:\ProgramData\OO Software 2013-11-13 05:02 - 2013-10-22 13:13 - 00455328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120.dll 2013-11-13 04:59 - 2013-11-13 04:59 - 00970912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120.dll 2013-11-13 04:58 - 2013-04-11 16:12 - 00019392 _____ (Dll-Files.com) C:\Windows\system32\roboot64.exe 2013-11-12 00:34 - 2013-11-11 21:44 - 00001515 _____ C:\Users\Uli\Desktop\Windows Media Player.lnk 2013-11-11 21:56 - 2013-11-11 21:56 - 00000000 ____D C:\Users\Uli\AppData\Local\VirtualStore 2013-11-11 20:59 - 2013-11-11 20:59 - 00000000 ____D C:\Program Files\Adblock Plus for IE 2013-11-11 20:26 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-11 20:20 - 2013-11-11 20:20 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-11 20:20 - 2013-11-11 20:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-11 20:20 - 2013-11-11 20:20 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-11 20:20 - 2013-11-11 20:20 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-11 20:20 - 2013-11-11 20:20 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-11 20:20 - 2013-11-11 20:20 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-11 20:20 - 2013-11-11 20:20 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-11 20:20 - 2013-11-11 20:20 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-11 20:20 - 2013-11-11 20:20 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-11 20:20 - 2013-11-11 20:20 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-11 20:20 - 2013-11-11 20:20 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-10 23:09 - 2013-11-10 23:09 - 00000000 ____D C:\Users\Uli\AppData\Local\EMU 2013-11-10 23:08 - 2013-11-10 23:08 - 00002181 _____ C:\Users\Public\Desktop\ENSLAVED Odyssey to the West Premium Edition.lnk 2013-11-09 23:30 - 2013-11-09 23:30 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-11-09 23:25 - 2013-11-07 18:39 - 09764088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 08927704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 08412680 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 08287008 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 07751920 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 06630232 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 01318552 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 01100216 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00115512 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00098496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-11-09 23:25 - 2013-11-07 18:24 - 13200896 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-11-09 23:25 - 2013-11-07 18:11 - 00230912 _____ C:\Windows\system32\clinfo.exe 2013-11-09 23:25 - 2013-11-07 18:10 - 29363712 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2013-11-09 23:25 - 2013-11-07 18:10 - 01187342 _____ C:\Windows\system32\amdocl_as64.exe 2013-11-09 23:25 - 2013-11-07 18:10 - 01061902 _____ C:\Windows\system32\amdocl_ld64.exe 2013-11-09 23:25 - 2013-11-07 18:10 - 00995342 _____ C:\Windows\SysWOW64\amdocl_as32.exe 2013-11-09 23:25 - 2013-11-07 18:10 - 00798734 _____ C:\Windows\SysWOW64\amdocl_ld32.exe 2013-11-09 23:25 - 2013-11-07 18:10 - 00100352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2013-11-09 23:25 - 2013-11-07 18:10 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2013-11-09 23:25 - 2013-11-07 18:10 - 00083968 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2013-11-09 23:25 - 2013-11-07 18:10 - 00073728 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2013-11-09 23:25 - 2013-11-07 18:07 - 24846848 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2013-11-09 23:25 - 2013-11-07 18:05 - 00063488 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-11-09 23:25 - 2013-11-07 18:05 - 00057344 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2013-11-09 23:25 - 2013-11-07 18:02 - 00129536 _____ (AMD) C:\Windows\system32\coinst_13.25.18.dll 2013-11-09 23:25 - 2013-11-07 17:44 - 26350592 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-11-09 23:25 - 2013-11-07 17:41 - 00547152 _____ C:\Windows\SysWOW64\atiapfxx.blb 2013-11-09 23:25 - 2013-11-07 17:41 - 00547152 _____ C:\Windows\system32\atiapfxx.blb 2013-11-09 23:25 - 2013-11-07 17:40 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-11-09 23:25 - 2013-11-07 17:40 - 00368640 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-11-09 23:25 - 2013-11-07 17:40 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-11-09 23:25 - 2013-11-07 17:40 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-11-09 23:25 - 2013-11-07 17:40 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-11-09 23:25 - 2013-11-07 17:40 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-11-09 23:25 - 2013-11-07 17:37 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-11-09 23:25 - 2013-11-07 17:26 - 22156288 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-11-09 23:25 - 2013-11-07 17:21 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2013-11-09 23:25 - 2013-11-07 17:21 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2013-11-09 23:25 - 2013-11-07 17:20 - 00585216 _____ (AMD) C:\Windows\system32\atieclxx.exe 2013-11-09 23:25 - 2013-11-07 17:20 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2013-11-09 23:25 - 2013-11-07 17:18 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2013-11-09 23:25 - 2013-11-07 17:09 - 03399312 _____ C:\Windows\system32\atiumd6a.cap 2013-11-09 23:25 - 2013-11-07 17:06 - 00204952 _____ C:\Windows\SysWOW64\ativvsvl.dat 2013-11-09 23:25 - 2013-11-07 17:06 - 00204952 _____ C:\Windows\system32\ativvsvl.dat 2013-11-09 23:25 - 2013-11-07 17:06 - 00157144 _____ C:\Windows\SysWOW64\ativvsva.dat 2013-11-09 23:25 - 2013-11-07 17:06 - 00157144 _____ C:\Windows\system32\ativvsva.dat 2013-11-09 23:25 - 2013-11-07 16:58 - 03433360 _____ C:\Windows\SysWOW64\atiumdva.cap 2013-11-09 23:25 - 2013-11-07 16:50 - 01145344 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00825856 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00100352 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00096768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00074752 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2013-11-09 23:25 - 2013-11-07 16:49 - 00624128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-11-09 23:25 - 2013-11-07 16:46 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2013-11-09 23:25 - 2013-09-30 21:48 - 00047887 _____ C:\Windows\atiogl.xml 2013-11-09 23:25 - 2013-09-26 22:14 - 00083552 _____ C:\Windows\system32\ativce02.dat 2013-11-09 23:25 - 2013-09-24 10:21 - 00717907 _____ C:\Windows\system32\atiicdxx.dat 2013-11-09 23:25 - 2013-09-12 17:31 - 00233776 _____ C:\Windows\system32\ativvaxy_cik_nd.dat 2013-11-09 23:25 - 2013-09-12 17:30 - 00234036 _____ C:\Windows\system32\ativvaxy_cik.dat 2013-11-09 23:25 - 2013-04-10 16:34 - 00332800 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODE.exe 2013-11-09 23:25 - 2013-04-10 16:34 - 00118784 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atibtmon.exe 2013-11-09 23:25 - 2013-04-10 16:34 - 00051200 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODCLI.exe 2013-11-09 23:25 - 2011-09-12 23:06 - 00003917 _____ C:\Windows\SysWOW64\atipblag.dat 2013-11-09 23:25 - 2011-09-12 23:06 - 00003917 _____ C:\Windows\system32\atipblag.dat 2013-11-07 12:21 - 2013-11-07 12:21 - 00051200 _____ C:\Windows\system32\kdbsdk64.dll 2013-11-07 12:16 - 2013-11-07 12:16 - 00038912 _____ C:\Windows\SysWOW64\kdbsdk32.dll 2013-11-06 08:18 - 2013-11-11 22:13 - 00294912 ___SH C:\Users\Uli\Desktop\Thumbs.db 2013-11-05 14:57 - 2013-11-05 14:57 - 02843432 _____ (O&O Software GmbH) C:\Windows\system32\ooscrsav.scr 2013-11-05 14:57 - 2013-11-05 14:57 - 00543528 _____ (O&O Software GmbH) C:\Windows\system32\oodssrs.dll 2013-11-05 14:57 - 2013-11-05 14:57 - 00240936 _____ (O&O Software GmbH) C:\Windows\system32\oodbs.exe 2013-11-05 14:57 - 2013-11-05 14:57 - 00011048 _____ (O&O Software GmbH) C:\Windows\system32\oodbsrs.dll 2013-11-05 08:59 - 2013-11-05 08:59 - 00000000 ____D C:\Program Files\ATI Technologies 2013-11-02 15:54 - 2013-11-02 15:57 - 00000000 ____D C:\ProgramData\install_clap 2013-10-31 06:43 - 2013-10-31 06:43 - 00000000 ____D C:\ProgramData\Trymedia 2013-10-30 15:33 - 2013-11-08 16:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-28 01:20 - 2013-10-28 01:20 - 00000000 ____D C:\Users\Uli\AppData\Local\DDMSettings 2013-10-27 04:07 - 2013-11-13 17:45 - 00000000 ____D C:\ProgramData\Steam 2013-10-27 03:18 - 2013-10-27 03:18 - 00000000 ____D C:\AMD 2013-10-27 03:14 - 2013-09-24 15:53 - 00094208 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdW76.sys 2013-10-27 03:14 - 2013-09-24 15:51 - 00110080 _____ (TODO: <Company name>) C:\Windows\system32\DelayAPO.dll 2013-10-21 19:34 - 2013-10-21 19:34 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-21 19:34 - 2013-10-21 19:34 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-21 14:49 - 2013-10-21 14:48 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-21 14:48 - 2013-10-21 14:48 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-21 14:48 - 2013-10-21 14:48 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-21 14:48 - 2013-10-21 14:48 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-21 14:48 - 2013-10-21 14:48 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-21 14:46 - 2013-10-21 14:46 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-10-21 14:46 - 2013-10-21 14:46 - 00000000 ____D C:\Program Files\Java 2013-10-19 02:02 - 2013-10-19 02:02 - 00000000 ____D C:\Users\Uli\AppData\Roaming\AVAST Software ==================== One Month Modified Files and Folders ======= 2013-11-14 00:55 - 2013-11-14 00:54 - 00020450 _____ C:\Users\Uli\Desktop\FRST.txt 2013-11-14 00:53 - 2013-11-14 00:53 - 01957794 _____ (Farbar) C:\Users\Uli\Desktop\FRST64(1).exe 2013-11-14 00:52 - 2013-11-14 00:52 - 00000000 ____D C:\FRST 2013-11-14 00:50 - 2013-11-14 00:51 - 00821145 _____ C:\Users\Uli\Desktop\CBS.log 2013-11-14 00:50 - 2011-06-30 06:05 - 00002562 _____ C:\Windows\diagwrn.xml 2013-11-14 00:50 - 2011-06-30 06:05 - 00001908 _____ C:\Windows\diagerr.xml 2013-11-14 00:44 - 2013-11-13 23:29 - 00073522 _____ C:\Windows\WindowsUpdate.log 2013-11-14 00:42 - 2013-11-14 00:42 - 00001085 _____ C:\Windows\setupact.log 2013-11-14 00:42 - 2013-11-14 00:42 - 00000000 _____ C:\Windows\setuperr.log 2013-11-14 00:27 - 2013-01-16 03:19 - 00000000 ____D C:\Program Files\Revo Uninstaller Pro 2013-11-14 00:09 - 2013-11-14 00:08 - 00000000 ____D C:\Program Files (x86)\IminentToolbar 2013-11-14 00:08 - 2013-11-14 00:08 - 00000000 ____D C:\Users\Uli\AppData\Local\Google 2013-11-14 00:08 - 2013-05-22 00:57 - 00001530 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-11-13 23:58 - 2012-12-12 01:14 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-13 23:36 - 2009-07-14 05:45 - 00023632 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-13 23:36 - 2009-07-14 05:45 - 00023632 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-13 23:28 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-13 23:09 - 2012-07-06 12:59 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-13 22:48 - 2013-11-13 22:48 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-11-13 22:38 - 2011-06-19 00:12 - 00000000 ____D C:\Users\Uli\AppData\Roaming\uTorrent 2013-11-13 22:34 - 2012-10-09 03:20 - 00000000 ____D C:\Program Files (x86)\uTorrent 2013-11-13 21:34 - 2012-03-01 14:51 - 00000000 ____D C:\Users\Uli 2013-11-13 21:17 - 2013-11-13 21:17 - 00438658 __RSH C:\LJVEY 2013-11-13 20:44 - 2011-06-19 00:15 - 00000000 ____D C:\Nvidia 2013-11-13 19:30 - 2012-03-25 14:08 - 00000000 ____D C:\Windows\pss 2013-11-13 18:47 - 2013-11-13 18:46 - 00014781 _____ C:\Windows\system32\oodbs.lor 2013-11-13 17:46 - 2011-11-17 00:50 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-11-13 17:45 - 2013-10-27 04:07 - 00000000 ____D C:\ProgramData\Steam 2013-11-13 06:42 - 2013-02-24 01:44 - 00002527 _____ C:\Users\Public\Desktop\O&O Defrag.lnk 2013-11-13 06:41 - 2013-11-13 06:41 - 00000000 ____D C:\ProgramData\OO Software 2013-11-13 04:59 - 2013-11-13 04:59 - 00970912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120.dll 2013-11-13 04:56 - 2011-10-24 16:12 - 00000000 ____D C:\Program Files (x86)\Origin 2013-11-13 04:26 - 2012-10-01 03:46 - 00000000 ____D C:\Users\Uli\AppData\Local\Adobe 2013-11-12 23:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-12 05:00 - 2012-03-09 00:58 - 00000000 ____D C:\Windows\Minidump 2013-11-12 00:00 - 2011-06-27 22:08 - 00000000 ____D C:\Users\Uli\Documents\Music Lyrics & Tabs 2013-11-11 23:50 - 2011-09-03 23:50 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-11-11 22:13 - 2013-11-06 08:18 - 00294912 ___SH C:\Users\Uli\Desktop\Thumbs.db 2013-11-11 21:56 - 2013-11-11 21:56 - 00000000 ____D C:\Users\Uli\AppData\Local\VirtualStore 2013-11-11 21:44 - 2013-11-12 00:34 - 00001515 _____ C:\Users\Uli\Desktop\Windows Media Player.lnk 2013-11-11 20:59 - 2013-11-11 20:59 - 00000000 ____D C:\Program Files\Adblock Plus for IE 2013-11-11 20:32 - 2012-01-10 18:34 - 00000000 ____D C:\Windows\Panther 2013-11-11 20:31 - 2012-03-01 16:58 - 00001435 _____ C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-11 20:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-11 20:20 - 2013-11-11 20:20 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-11 20:20 - 2013-11-11 20:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-11 20:20 - 2013-11-11 20:20 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-11 20:20 - 2013-11-11 20:20 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-11 20:20 - 2013-11-11 20:20 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-11 20:20 - 2013-11-11 20:20 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-11 20:20 - 2013-11-11 20:20 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-11 20:20 - 2013-11-11 20:20 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-11 20:20 - 2013-11-11 20:20 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-11 20:20 - 2013-11-11 20:20 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-11 20:20 - 2013-11-11 20:20 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-11 20:20 - 2013-11-11 20:20 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-11 20:20 - 2013-11-11 20:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-10 23:09 - 2013-11-10 23:09 - 00000000 ____D C:\Users\Uli\AppData\Local\EMU 2013-11-10 23:09 - 2013-03-26 16:56 - 00000000 ____D C:\Users\Uli\Documents\My Games 2013-11-10 23:08 - 2013-11-10 23:08 - 00002181 _____ C:\Users\Public\Desktop\ENSLAVED Odyssey to the West Premium Edition.lnk 2013-11-10 22:47 - 2011-06-19 17:22 - 00000000 ____D C:\Games 2013-11-10 07:53 - 2011-06-20 03:23 - 00006369 _____ C:\Users\Uli\AppData\Roaming\prio.ini 2013-11-10 06:32 - 2013-06-14 19:43 - 00000000 ____D C:\Program Files (x86)\BRS 2013-11-10 06:24 - 2011-11-19 04:37 - 00001668 _____ C:\Users\Public\Desktop\Recuva.lnk 2013-11-10 06:24 - 2011-06-25 15:44 - 00000000 ____D C:\Program Files\Recuva 2013-11-10 06:24 - 2011-06-19 04:37 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Audacity 2013-11-10 05:10 - 2013-09-13 23:05 - 00000863 _____ C:\Users\Uli\Desktop\µTorrent.lnk 2013-11-10 05:10 - 2013-09-13 23:05 - 00000843 _____ C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2013-11-10 01:22 - 2012-10-15 23:54 - 00000000 ____D C:\Users\Uli\Documents\FIFA 13 2013-11-09 23:30 - 2013-11-09 23:30 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-11-09 23:30 - 2012-10-24 04:33 - 00000000 ____D C:\ProgramData\AMD 2013-11-09 23:22 - 2012-10-30 02:29 - 00000000 ____D C:\Users\Uli\Documents\AMD Treiber MOD 2013-11-09 21:43 - 2012-02-23 23:24 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2013-11-08 16:56 - 2013-10-30 15:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-08 05:56 - 2013-03-18 22:15 - 00000000 ____D C:\Users\Uli\Documents\Aktuelles 2013-11-07 18:39 - 2013-11-09 23:25 - 09764088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 08927704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 08412680 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 08287008 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 07751920 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 06630232 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 01318552 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 01100216 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00115512 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00098496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-11-07 18:24 - 2013-11-09 23:25 - 13200896 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-11-07 18:11 - 2013-11-09 23:25 - 00230912 _____ C:\Windows\system32\clinfo.exe 2013-11-07 18:10 - 2013-11-09 23:25 - 29363712 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2013-11-07 18:10 - 2013-11-09 23:25 - 01187342 _____ C:\Windows\system32\amdocl_as64.exe 2013-11-07 18:10 - 2013-11-09 23:25 - 01061902 _____ C:\Windows\system32\amdocl_ld64.exe 2013-11-07 18:10 - 2013-11-09 23:25 - 00995342 _____ C:\Windows\SysWOW64\amdocl_as32.exe 2013-11-07 18:10 - 2013-11-09 23:25 - 00798734 _____ C:\Windows\SysWOW64\amdocl_ld32.exe 2013-11-07 18:10 - 2013-11-09 23:25 - 00100352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2013-11-07 18:10 - 2013-11-09 23:25 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2013-11-07 18:10 - 2013-11-09 23:25 - 00083968 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2013-11-07 18:10 - 2013-11-09 23:25 - 00073728 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2013-11-07 18:07 - 2013-11-09 23:25 - 24846848 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2013-11-07 18:05 - 2013-11-09 23:25 - 00063488 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-11-07 18:05 - 2013-11-09 23:25 - 00057344 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2013-11-07 18:02 - 2013-11-09 23:25 - 00129536 _____ (AMD) C:\Windows\system32\coinst_13.25.18.dll 2013-11-07 17:44 - 2013-11-09 23:25 - 26350592 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-11-07 17:41 - 2013-11-09 23:25 - 00547152 _____ C:\Windows\SysWOW64\atiapfxx.blb 2013-11-07 17:41 - 2013-11-09 23:25 - 00547152 _____ C:\Windows\system32\atiapfxx.blb 2013-11-07 17:40 - 2013-11-09 23:25 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-11-07 17:40 - 2013-11-09 23:25 - 00368640 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-11-07 17:40 - 2013-11-09 23:25 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-11-07 17:40 - 2013-11-09 23:25 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-11-07 17:40 - 2013-11-09 23:25 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-11-07 17:40 - 2013-11-09 23:25 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-11-07 17:37 - 2013-11-09 23:25 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-11-07 17:26 - 2013-11-09 23:25 - 22156288 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-11-07 17:21 - 2013-11-09 23:25 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2013-11-07 17:21 - 2013-11-09 23:25 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2013-11-07 17:20 - 2013-11-09 23:25 - 00585216 _____ (AMD) C:\Windows\system32\atieclxx.exe 2013-11-07 17:20 - 2013-11-09 23:25 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2013-11-07 17:18 - 2013-11-09 23:25 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2013-11-07 17:09 - 2013-11-09 23:25 - 03399312 _____ C:\Windows\system32\atiumd6a.cap 2013-11-07 17:06 - 2013-11-09 23:25 - 00204952 _____ C:\Windows\SysWOW64\ativvsvl.dat 2013-11-07 17:06 - 2013-11-09 23:25 - 00204952 _____ C:\Windows\system32\ativvsvl.dat 2013-11-07 17:06 - 2013-11-09 23:25 - 00157144 _____ C:\Windows\SysWOW64\ativvsva.dat 2013-11-07 17:06 - 2013-11-09 23:25 - 00157144 _____ C:\Windows\system32\ativvsva.dat 2013-11-07 16:58 - 2013-11-09 23:25 - 03433360 _____ C:\Windows\SysWOW64\atiumdva.cap 2013-11-07 16:50 - 2013-11-09 23:25 - 01145344 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00825856 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00100352 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00096768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00074752 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2013-11-07 16:49 - 2013-11-09 23:25 - 00624128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-11-07 16:46 - 2013-11-09 23:25 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2013-11-07 12:21 - 2013-11-07 12:21 - 00051200 _____ C:\Windows\system32\kdbsdk64.dll 2013-11-07 12:16 - 2013-11-07 12:16 - 00038912 _____ C:\Windows\SysWOW64\kdbsdk32.dll 2013-11-07 01:16 - 2011-07-10 03:11 - 00000000 ____D C:\Program Files (x86)\Steam 2013-11-07 01:14 - 2011-07-10 03:15 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-11-05 14:57 - 2013-11-05 14:57 - 02843432 _____ (O&O Software GmbH) C:\Windows\system32\ooscrsav.scr 2013-11-05 14:57 - 2013-11-05 14:57 - 00543528 _____ (O&O Software GmbH) C:\Windows\system32\oodssrs.dll 2013-11-05 14:57 - 2013-11-05 14:57 - 00240936 _____ (O&O Software GmbH) C:\Windows\system32\oodbs.exe 2013-11-05 14:57 - 2013-11-05 14:57 - 00011048 _____ (O&O Software GmbH) C:\Windows\system32\oodbsrs.dll 2013-11-05 08:59 - 2013-11-05 08:59 - 00000000 ____D C:\Program Files\ATI Technologies 2013-11-02 17:38 - 2013-01-06 03:07 - 00000000 ____D C:\Users\Uli\AppData\Roaming\avidemux 2013-11-02 17:15 - 2013-04-29 21:02 - 00000000 ____D C:\Program Files (x86)\Virtual Dub 2013-11-02 17:11 - 2013-10-11 04:13 - 00000000 ____D C:\Users\Uli\AppData\Roaming\vlc 2013-11-02 16:51 - 2013-01-06 03:07 - 00000000 ____D C:\Program Files\Avidemux 2013-11-02 16:23 - 2011-06-19 00:22 - 00000876 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-11-02 16:14 - 2012-09-26 02:34 - 00000000 ____D C:\Users\Uli\AppData\Local\Windows Live 2013-11-02 15:57 - 2013-11-02 15:54 - 00000000 ____D C:\ProgramData\install_clap 2013-11-02 15:54 - 2012-01-17 03:11 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-11-02 15:31 - 2013-03-09 06:51 - 00000000 ____D C:\ProgramData\CyberLink 2013-11-01 04:48 - 2013-08-30 23:52 - 00679718 _____ C:\Windows\system32\perfh00A.dat 2013-11-01 04:48 - 2013-08-30 23:52 - 00129614 _____ C:\Windows\system32\perfc00A.dat 2013-10-31 19:09 - 2011-06-19 04:36 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-10-31 18:59 - 2011-06-19 01:23 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Skype 2013-10-31 18:46 - 2011-06-19 01:23 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-10-31 18:46 - 2011-06-19 01:23 - 00000000 ____D C:\ProgramData\Skype 2013-10-31 18:18 - 2012-04-29 03:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-31 06:43 - 2013-10-31 06:43 - 00000000 ____D C:\ProgramData\Trymedia 2013-10-31 06:27 - 2011-06-19 00:22 - 00000000 ____D C:\Program Files\CCleaner 2013-10-29 18:36 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-28 22:58 - 2011-07-11 05:32 - 00060416 _____ (Realtek Semiconductor Corp.) C:\Windows\ALCFDRTM.VER 2013-10-28 01:20 - 2013-10-28 01:20 - 00000000 ____D C:\Users\Uli\AppData\Local\DDMSettings 2013-10-28 01:16 - 2013-05-27 11:17 - 00000000 ____D C:\Program Files (x86)\DivX 2013-10-28 01:16 - 2011-06-19 01:10 - 00000000 ____D C:\Program Files\DivX 2013-10-28 01:16 - 2011-06-19 01:07 - 00000000 ____D C:\ProgramData\DivX 2013-10-27 03:18 - 2013-10-27 03:18 - 00000000 ____D C:\AMD 2013-10-25 16:38 - 2012-02-23 23:24 - 00002020 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-10-25 16:07 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2013-10-25 16:06 - 2011-06-18 23:48 - 00000000 ____D C:\Users\Uli\AppData\Local\Mozilla 2013-10-23 19:29 - 2011-06-28 16:31 - 00000000 ____D C:\Users\Uli\Documents\WG 2013-10-23 19:26 - 2011-08-22 14:36 - 00012862 _____ C:\Windows\EPISMG00.SWB 2013-10-22 13:13 - 2013-11-13 05:02 - 00455328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120.dll 2013-10-21 19:34 - 2013-10-21 19:34 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-21 19:34 - 2013-10-21 19:34 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-21 14:48 - 2013-10-21 14:49 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-21 14:48 - 2013-10-21 14:48 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-21 14:48 - 2013-10-21 14:48 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-21 14:48 - 2013-10-21 14:48 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-21 14:48 - 2013-10-21 14:48 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-21 14:46 - 2013-10-21 14:46 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-10-21 14:46 - 2013-10-21 14:46 - 00000000 ____D C:\Program Files\Java 2013-10-19 02:02 - 2013-10-19 02:02 - 00000000 ____D C:\Users\Uli\AppData\Roaming\AVAST Software 2013-10-19 01:42 - 2013-03-02 06:05 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-19 01:42 - 2013-03-02 06:05 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-19 01:42 - 2012-02-23 23:24 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-19 01:42 - 2012-02-23 23:24 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-19 01:42 - 2012-02-23 23:24 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-19 01:42 - 2012-02-23 23:24 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-19 01:42 - 2012-02-23 23:24 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-19 01:42 - 2012-02-23 23:23 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-19 01:42 - 2012-02-23 22:58 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-19 01:37 - 2011-06-19 00:50 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-19 01:18 - 2011-06-19 00:52 - 00000000 _____ C:\Windows\SysWOW64\config.nt Some content of TEMP: ==================== C:\Users\Uli\AppData\Local\Temp\_attdrv64.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-10 10:56 ==================== End Of Log ============================ --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-11-2013 Ran by Uli at 2013-11-14 00:55:48 Running from C:\Users\Uli\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== µTorrent (HKCU Version: 3.4.0.30304) abcAVI (x32) AC3Filter 2.5b (x32 Version: 2.5b) Adblock Plus for IE (32-bit and 64-bit) (Version: 1.1) Adblock Plus for IE (x32 Version: 1.1) Adobe Extension Manager CC (x32 Version: 7.1) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Photoshop CS6 (x32 Version: 13.0) AMD Accelerated Video Transcoding (Version: 13.20.100.31107) AMD APP CPU SDK Runtime (Version: 2.8.1016.5) AMD APP SDK Developer (Version: 2.8.1016.5) AMD APP SDK Runtime (Version: 10.0.1124.2) AMD APP SDK Samples (x32 Version: 2.8.1016.5) AMD AVIVO64 Codecs (Version: 12.5.100.20611) AMD Catalyst Install Manager (Version: 8.0.915.0) AMD Demo - Leo (x32 Version: 1.1) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.81107.1147) AMD Wireless Display v3.0 (Version: 1.0.0.12) AMD Wireless Display v3.0 (Version: 1.0.0.14) AnyDVD (x32 Version: 7.1.6.0) Application Profiles (x32 Version: 2.0.4674.34053) Application Profiles (x32 Version: 2.0.4719.35969) Application Profiles (x32 Version: 2.0.4888.34279) Audacity 2.0.5 (x32 Version: 2.0.5) avast! Free Antivirus (x32 Version: 9.0.2006) Avidemux 2.6 - 64bits (x32 Version: 2.6.6.8941) Avidemux 2.6 (x32 Version: 2.6.1.8321) Biet-O-Matic v2.14.8 (x32 Version: 2.14.8) BioShock 2 (x32 Version: 1.0.0005.131) BioShock Infinite (x32) BioShock Infinite Burial at Sea - Episode 1 (x32 Version: 1) BioShock Infinite Update v1.1.22.55730 1.0 (x32) Caesar IV (x32 Version: 1.2) CanoScan Toolbox Ver4.9 (x32) Catalyst Control Center InstallProxy (x32 Version: 2012.1022.2311.39807) Catalyst Control Center InstallProxy (x32 Version: 2013.1107.1129.20543) CCleaner (Version: 4.07) CDBurnerXP (x32 Version: 4.5.2.4291) CloneDVD2 (x32 Version: 2.9.3.0) CyberLink PowerDirector 11 (Version: 11.0.0.3230) CyberLink PowerDirector 11 (x32 Version: 11.0.0.3230) CyberLink PowerDirector 11 Content Pack Essential (x32 Version: 11) CyberLink PowerDirector 11 Content Pack Premium (x32 Version: 11) D3DX10 (x32 Version: 15.4.2368.0902) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition DHTML Editing Component (x32 Version: 6.02.0001) DivX-Setup (x32 Version: 2.6.1.84) Droppix Label Maker 2.x (x32 Version: 2.9.8) DVD Audio Extractor 6.3.0 (x32) eMule (x32) ENSLAVED: Odyssey to the West Premium Edition (x32) EPSON-Drucker-Software Eusing Free Registry Cleaner (x32) FFmpeg v0.6.2 for Audacity (x32) FIFA 13 (x32 Version: 1.7.0.0) Flashtool (x32 Version: 0.9.0.0) Fotogalerie (x32 Version: 16.4.3505.0912) Google Earth Plug-in (x32 Version: 6.2.2.6613) HD Tune 2.55 (x32) HydraVision (x32 Version: 4.2.248.0) Icaros 2.1.5 (Version: 2.1.5.0) IP Camera DS Filter (x32 Version: 5.5.0.0) Java 7 Update 45 (64-bit) (Version: 7.0.450) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) JDownloader 0.9 (x32 Version: 0.9) LADSPA_plugins-win-0.4.15 (x32) LAME v3.99.3 (for Windows) (x32) LibreOffice 4.0.5.2 (x32 Version: 4.0.5.2) LightScribe System Software (x32 Version: 1.18.26.7) Lyrics Plugin for Windows Media Player (x32 Version: 0.4) Marvell Miniport Driver (x32 Version: 11.45.4.3) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938) Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0) Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0) Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Xbox 360 Accessories 1.2 (Version: 1.20.146.0) Microsoft XNA Framework Redistributable 3.1 (x32 Version: 3.1.10527.0) Microsoft XNA Framework Redistributable 4.0 Refresh (x32 Version: 4.0.30901.0) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053) Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000) Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000) Morphyre (x32) Movie Maker (x32 Version: 16.4.3505.0912) Mozilla Firefox 25.0 (x86 de) (x32 Version: 25.0) Mozilla Maintenance Service (x32 Version: 25.0) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT110 (x32 Version: 16.4.1108.0727) MSVCRT110_amd64 (Version: 16.4.1109.0912) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) MSXML 4.0 SP2 Parser und SDK (x32 Version: 4.20.9818.0) MuseScore 1.3 (x32 Version: 1.3.0) neroxml (x32 Version: 1.0.0) Newblue Art Effects for PowerDirector (Version: 2.0) NirSoft RegScanner (x32) NVIDIA Drivers (Version: 1.10.62.40) NVIDIA PhysX (x32 Version: 9.12.1031) O&O Defrag Professional (Version: 17.0.468) OpenAL (x32) Origin (x32 Version: 8.5.0.4550) PDF Settings CS6 (x32 Version: 11.0) PDF-Viewer (Version: 2.5.212.0) PDF-XChange Lite 2012 (Version: 5.0.266.0) PDF-XChange Pro 4.0 (Version: 4.201.201.0) Photo Gallery (x32 Version: 16.4.3505.0912) PowerDirector (Version: 11.0) Prio (Version: 2.0.0.2960) Rapture3D 2.5.6 Game (x32) Ray Adams ATI Tray Tools (x32) Readiris Pro 14 (x32 Version: 14.00.2573) Realtek AC'97 Audio (x32 Version: 5.37) Recuva (Version: 1.48) Resource Hacker Version 3.6.0 (x32) Revo Uninstaller Pro 3.0.7 (Version: 3.0.7) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition Shutdown Timer (Version: 3.3) Skype™ 6.10 (x32 Version: 6.10.104) SmartSound Quicktracks 5 (x32 Version: 5.1.8) Sony Ericsson Update Engine (x32 Version: 2.12.10.19) Sony PC Companion 2.10.136 (x32 Version: 2.10.136) SopCast 3.5.0 (x32 Version: 3.5.0) SpeedFan (remove only) (x32) Steam (x32 Version: 1.0.0.0) SUPER © v2013.build.56+Recorder (2013/07/07) Version v2013.buil (x32 Version: v2013.build.56+Recorder) TmNationsForever Update 2010-03-15 (x32) Turbo Lister 2 (x32 Version: 2.00.0000) UnderCoverXP 1.23 (x32) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition Update for Microsoft Word 2010 (KB2827323) 64-Bit Edition VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) VLC media player 2.1.0 (x32 Version: 2.1.0) VOB2MPG v3 (x32 Version: 3.2.2000) Vsk5Online (x32) WinCDEmu (x32 Version: 3.6) Windows Live Communications Platform (x32 Version: 16.4.3505.0912) Windows Live Essentials (x32 Version: 16.4.3505.0912) Windows Live ID Sign-in Assistant (Version: 7.250.4311.0) Windows Live Installer (x32 Version: 16.4.3505.0912) Windows Live Photo Common (x32 Version: 16.4.3505.0912) Windows Live PIMT Platform (x32 Version: 16.4.3505.0912) Windows Live SOXE (x32 Version: 16.4.3505.0912) Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912) Windows Live UX Platform (x32 Version: 16.4.3505.0912) Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8) WinRAR 5.00 (64-Bit) (Version: 5.00.0) Xilisoft Audio Converter Pro (x32 Version: 6.5.0.20130130) Zattoo4 4.0.5 (x32 Version: 4.0.5) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2011-07-27 16:09 - 2013-03-16 07:36 - 00001790 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 activate.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 activation.guitar-pro.com 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com There are 3 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {0E7FEAFA-95DC-4028-8D08-F5ABE6BA8AAF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {90301DDC-F95C-4AED-98E4-3DFFE3224DF2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd) Task: {AB251AE5-0346-45BE-B4F8-DDA32304D020} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-08] (Adobe Systems Incorporated) Task: {C45A20A4-F802-41C4-A0E0-61782EB3E7D8} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {DBD931B0-97A2-4A13-94A7-85C8454202BE} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-10-19] (AVAST Software) Task: {E4481A1B-37F8-4D18-AC72-7A22B3C5A5CA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {E58844B8-6414-4F9D-A2FD-9F9B98BE58CD} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {E60C85DF-4D61-4C73-BE6A-5443C2FF9104} - \Happy Lyrics Update No Task File Task: {EBFA90EB-D966-4033-96F0-888E4115420A} - System32\Tasks\XboxStatTask => C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe [2009-09-30] (Microsoft Corporation) Task: {FD6F6796-25AC-4D93-90A7-55657124B1C6} - System32\Tasks\AdobeAAMUpdater-1.0-Brotkasten-Uli => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2013-06-03] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-04-04 00:09 - 2013-04-04 00:09 - 04300432 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2013-11-13 18:32 - 2013-11-13 17:18 - 02141184 _____ () C:\Program Files\AVAST Software\Avast\defs\13111302\algo.dll 2011-10-29 22:12 - 2011-10-29 22:12 - 00187392 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\raphook.dll 2007-03-07 13:26 - 2007-03-07 13:26 - 00077824 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\support.dll 2007-03-07 13:25 - 2007-03-07 13:25 - 00024576 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\kbdhook.dll 2005-11-29 18:38 - 2005-11-29 18:38 - 00023552 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\hddtemp.dll 2008-04-09 17:08 - 2008-04-09 17:08 - 00016896 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mg_amdcore.dll 2007-09-14 16:35 - 2007-09-14 16:35 - 00020480 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mg_cpuload.dll 2006-12-26 18:53 - 2006-12-26 18:53 - 00019456 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mg_hdddtemp.dll 2008-04-11 17:33 - 2008-04-11 17:33 - 00020480 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mg_intelcpu.dll 2007-01-03 21:09 - 2007-01-03 21:09 - 00017408 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mg_xvlt.dll 2006-12-25 10:02 - 2006-12-25 10:02 - 00024576 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mongraphsexample.dll 2005-11-29 18:34 - 2005-11-29 18:34 - 00028672 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\pciset.dll 2013-10-19 01:42 - 2013-10-19 01:42 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-10-30 15:33 - 2013-10-30 15:33 - 03368048 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-10-08 18:01 - 2013-10-08 18:01 - 16233864 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData:gs5sys AlternateDataStreams: C:\Users\All Users:gs5sys AlternateDataStreams: C:\Users\Uli:gs5sys AlternateDataStreams: C:\ProgramData\Anwendungsdaten:gs5sys AlternateDataStreams: C:\ProgramData\Application Data:gs5sys AlternateDataStreams: C:\ProgramData\Templates:gs5sys AlternateDataStreams: C:\ProgramData\Vorlagen:gs5sys AlternateDataStreams: C:\ProgramData\Documents\desktop.ini:gs5sys AlternateDataStreams: C:\Users\Public\Documents\desktop.ini:gs5sys AlternateDataStreams: C:\Users\Uli\Anwendungsdaten:gs5sys AlternateDataStreams: C:\Users\Uli\Cookies:gs5sys AlternateDataStreams: C:\Users\Uli\Lokale Einstellungen:gs5sys AlternateDataStreams: C:\Users\Uli\Vorlagen:gs5sys AlternateDataStreams: C:\Users\Uli\Desktop\desktop.ini:gs5sys AlternateDataStreams: C:\Users\Uli\AppData\Local:gs5sys AlternateDataStreams: C:\Users\Uli\AppData\Roaming:gs5sys AlternateDataStreams: C:\Users\Uli\AppData\Local\Anwendungsdaten:gs5sys AlternateDataStreams: C:\Users\Uli\AppData\Local\Verlauf:gs5sys AlternateDataStreams: C:\Users\Uli\Documents\desktop.ini:gs5sys ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/13/2013 11:29:55 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/13/2013 11:21:20 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/13/2013 11:11:27 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/13/2013 11:00:18 PM) (Source: MsiInstaller) (User: Brotkasten) Description: Produkt: Microsoft Fix it 50200 -- Dieses Microsoft-Fix it ist nicht für Ihr Betriebssystem oder Ihre Version der Anwendung vorgesehen. Error: (11/13/2013 10:46:14 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/13/2013 10:42:05 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: wmplayer.exe, Version: 12.0.7601.17514, Zeitstempel: 0x4ce7a485 Name des fehlerhaften Moduls: wmp.dll, Version: 12.0.7601.17514, Zeitstempel: 0x4ce7ba7f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00330810 ID des fehlerhaften Prozesses: 0xe60 Startzeit der fehlerhaften Anwendung: 0xwmplayer.exe0 Pfad der fehlerhaften Anwendung: wmplayer.exe1 Pfad des fehlerhaften Moduls: wmplayer.exe2 Berichtskennung: wmplayer.exe3 Error: (11/13/2013 10:23:47 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/13/2013 10:07:46 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x80040154, Klasse nicht registriert . Vorgang: VSS-Server wird instanziiert Error: (11/13/2013 10:07:46 PM) (Source: VSS) (User: ) Description: Fehler im Volumenschattenkopie-Dienst: Eine vom Volumenschattenkopie-Dienst benötigte kritische Komponente ist nicht registriert. Dies kann geschehen, wenn bei der Windows-Installation oder bei der Installation eines Schattenkopieanbieters ein Fehler aufgetreten ist. Der von CoCreateInstance für die Klasse mit CLSID "{e579ab5f-1cc4-44b4-bed9-de0991ff0623}" und dem Namen "IVssCoordinatorEx2" zurückgegebene Fehler ist [0x80040154, Klasse nicht registriert ]. Vorgang: VSS-Server wird instanziiert Error: (11/13/2013 10:05:19 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. System errors: ============= Error: (11/14/2013 00:10:06 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Update glindorus" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts. Error: (11/14/2013 00:08:11 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SProtection" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (11/13/2013 11:57:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Blockebenen-Sicherungsmodul" wurde mit folgendem Fehler beendet: %%-2147024713 Error: (11/13/2013 11:43:15 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Blockebenen-Sicherungsmodul" wurde mit folgendem Fehler beendet: %%-2147024713 Error: (11/13/2013 11:41:55 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Blockebenen-Sicherungsmodul" wurde mit folgendem Fehler beendet: %%-2147024713 Error: (11/13/2013 11:41:55 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden aufgrund eines E/A-Fehlers auf Volume "C:" abgebrochen. Error: (11/13/2013 11:40:25 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Blockebenen-Sicherungsmodul" wurde mit folgendem Fehler beendet: %%-2147024713 Error: (11/13/2013 11:38:31 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Blockebenen-Sicherungsmodul" wurde mit folgendem Fehler beendet: %%-2147024713 Error: (11/13/2013 11:35:56 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Blockebenen-Sicherungsmodul" wurde mit folgendem Fehler beendet: %%-2147024713 Error: (11/13/2013 11:34:25 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden aufgrund eines E/A-Fehlers auf Volume "C:" abgebrochen. Microsoft Office Sessions: ========================= Error: (11/13/2013 11:29:55 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/13/2013 11:21:20 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/13/2013 11:11:27 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/13/2013 11:00:18 PM) (Source: MsiInstaller)(User: Brotkasten) Description: Produkt: Microsoft Fix it 50200 -- Dieses Microsoft-Fix it ist nicht für Ihr Betriebssystem oder Ihre Version der Anwendung vorgesehen.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (11/13/2013 10:46:14 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/13/2013 10:42:05 PM) (Source: Application Error)(User: ) Description: wmplayer.exe12.0.7601.175144ce7a485wmp.dll12.0.7601.175144ce7ba7fc000000500330810e6001cee0b92d3a8736C:\Program Files (x86)\Windows Media Player\wmplayer.exeC:\Windows\system32\wmp.dll6f95b94f-4cac-11e3-9692-c5d94355def0 Error: (11/13/2013 10:23:47 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/13/2013 10:07:46 PM) (Source: VSS)(User: ) Description: CoCreateInstance0x80040154, Klasse nicht registriert Vorgang: VSS-Server wird instanziiert Error: (11/13/2013 10:07:46 PM) (Source: VSS)(User: ) Description: {e579ab5f-1cc4-44b4-bed9-de0991ff0623}IVssCoordinatorEx20x80040154, Klasse nicht registriert Vorgang: VSS-Server wird instanziiert Error: (11/13/2013 10:05:19 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2013-03-04 19:12:35.358 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-04 19:12:35.311 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-04 19:00:50.281 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-04 19:00:50.234 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-04 18:40:23.078 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-04 18:40:23.000 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-12-21 02:47:14.781 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-12-21 02:47:14.734 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-12-21 01:00:34.734 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-12-21 01:00:34.671 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 48% Total physical RAM: 4094.49 MB Available physical RAM: 2123 MB Total Pagefile: 8187.16 MB Available Pagefile: 6234.89 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (Powerpack!) (Fixed) (Total:465.76 GB) (Free:217.58 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Madmax764112) (CDROM) (Total:3.72 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: C8950CBC) Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
14.11.2013, 01:19 | #4 |
| Lösung: Windows 7 1) Systemwiederherstellungspunkte nach Neustart weg / 2) F8-Menü -> Abgesicherter Modus etc. funktioniert nicht mehr Die Cbs.log von "Sfc/scannow" ist sehr groß, d.h. habe ich sie umbenannt in cbs.7z. Also bitte dann in cbs.log zurückbennen! Scannow konnte Fehler nicht berichtigen. Danke! |
14.11.2013, 10:35 | #5 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Wie Windows 7 1) Systemwiederherstellungspunkte nach Neustart weg / 2) F8-Menü -> Abgesicherter Modus etc. funktioniert nicht mehr Nach Logs von von sfc /scannow hatte ich nicht gefragt, ich wollte wissen ob ein Virenscanner bei dir schon fündig wurde Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
15.11.2013, 01:57 | #6 |
| Wo Windows 7 1) Systemwiederherstellungspunkte nach Neustart weg / 2) F8-Menü -> Abgesicherter Modus etc. funktioniert nicht mehr Lösung! Habe jetzt beide Probleme beseitigt: 1) Reparatur-Installation von der OS-DVD durchgführt -> Systemwiederherstellung behält auch nach Chip-Satz-Treiber Installation etc. und etlichen Neustarts die Wiederherstellungspunkte. 2)Habe im Window 7 "bootmgr" die Zeile <<Displaybootmenu>> entfernt. Jetzt funktioniert der F8-Hotkey beim starten wieder. @ cosinus Ich verlasse mich generell auf die Avast Free-Version, die keine Viren-Funde etc. in der letzten Zeit gemeldet hat. Ich poste hier jetzt nochmal aktuelle FRST-Logs, da ich nicht genau weiß, ob noch etwas zu fixen wäre: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2013 Ran by Uli (administrator) on BROTKASTEN on 15-11-2013 01:34:56 Running from C:\Users\Uli\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe () C:\Program Files\Prio\prio_svc.exe (Ray Adams) C:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [AtiTrayTools] - C:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe [929792 2011-10-29] (Ray Adams) HKCU\...\Run: [CCleaner] - C:\Program Files\CCleaner\CCleaner64.exe [5487384 2013-10-22] (Piriform Ltd) MountPoints2: {d9ed2ab0-76ac-11e2-9921-806e6f6e6963} - D:\setup.exe HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\avastui.exe [3567800 2013-10-19] (AVAST Software) AppInit_DLLs: prio.dll [ ] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x429F5024082ECC01 URLSearchHook: HKCU - (No Name) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {7832C251-89E7-4339-AAFA-6636C77D358A} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {7832C251-89E7-4339-AAFA-6636C77D358A} URL = hxxp://www.google.de/search?q={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll (Adblock Plus) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll (Adblock Plus) DPF: HKLM-x32 {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\..\Interfaces\{1FC3657C-53D8-4032-81FA-8E8100E63CB1}: [NameServer]192.168.1.1 Tcpip\..\Interfaces\{C47208B4-3C5D-4729-BE07-9E6902B174C9}: [NameServer]192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default FF user.js: detected! => C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\user.js FF NetworkProxy: "socks_remote_dns", true FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll No File FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX64.dll No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL No File FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @sun.com/npsopluginmi;version=1.0 - C:\Program Files (x86)\LibreOffice\program () FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll No File FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: adobe.com/AdobeExManCCDetect32 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect32.dll (Adobe Systems) FF Plugin HKCU: adobe.com/AdobeExManCCDetect64 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect64.dll (Adobe Systems) FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\de-pt-beolingus.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\iminent.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\leo-deu-chi.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\leo-deu-fra.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\leo-deu-ita.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\leo-deu-spa.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\leo-por-deu.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\stupidedia-de-at.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\the-pirate-bay.xml FF SearchPlugin: C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\searchplugins\youtube-videosuche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: FoxyProxy Basic - C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\Extensions\foxyproxy@eric.h.jung FF Extension: Adblock Plus - C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: dta - C:\Users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\2uikoixh.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [ealchnonpofjocgofjpopjdoegbbkofj] - C:\Program Files (x86)\HappyLyrics\Chrome.crx ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-10-19] (AVAST Software) S4 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) S3 Droppix Service; C:\Program Files (x86)\Common Files\Droppix\DxService.exe [221184 2009-08-28] (Droppix) R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [1638696 2013-11-05] (O&O Software GmbH) R2 prio_svc; C:\Program Files\Prio\prio_svc.exe [12656 2012-11-08] () S3 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390672 2012-09-11] () ==================== Drivers (Whitelisted) ==================== R3 ALCXWDM; C:\Windows\System32\drivers\RTKVAC64.SYS [3491616 2009-06-19] (Realtek Semiconductor Corp.) S3 AmdTools64; C:\Windows\System32\DRIVERS\AmdTools64.sys [47160 2008-04-28] (AMD, Inc.) R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [139352 2013-03-04] (SlySoft, Inc.) R3 AnyDVD; C:\Windows\SysWow64\Drivers\AnyDVD.sys [139352 2013-03-04] (SlySoft, Inc.) R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-10-19] (AVAST Software) R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [84328 2013-10-19] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-19] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-19] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-10-19] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-11-14] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-10-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-10-19] () S3 atillk64; C:\Program Files (x86)\ATI Winflash\atillk64.sys [14608 2006-07-19] (ATI Technologies Inc.) S3 ATITool; C:\Windows\System32\DRIVERS\ATITool64.sys [30720 2006-11-10] () R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31136 2013-10-02] (REALiX(tm)) R3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [27648 2008-01-19] (Microsoft Corporation) S3 kinonivd; C:\Windows\System32\DRIVERS\kinonivd.sys [2782848 2013-02-26] (Windows (R) Win 7 DDK provider) S3 KINONI_Wave; C:\Windows\System32\drivers\kinonivad.sys [23040 2013-02-26] (Windows (R) Win 7 DDK provider) S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC) S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [12800 2009-02-03] (ZTE Incorporated) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC) S3 athr; system32\DRIVERS\athrx.sys [x] R4 DRIVER_B; \??\C:\Windows\system32\Drivers\DRIVER_BIN64 [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-15 01:34 - 2013-11-15 01:35 - 00013796 _____ C:\Users\Uli\Desktop\FRST.txt 2013-11-15 01:32 - 2013-11-15 01:34 - 00027568 _____ C:\Windows\WindowsUpdate.log 2013-11-15 00:33 - 2013-11-15 00:33 - 00295624 __RSH C:\OVLPQ 2013-11-14 23:34 - 2013-11-14 23:34 - 00024576 _____ C:\Users\Uli\Documents\EasyBCD Backup (2013-11-14).bcd 2013-11-14 23:33 - 2013-11-15 01:25 - 00000000 ____D C:\Program Files (x86)\NeoSmart Technologies 2013-11-14 21:35 - 2013-04-10 00:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-11-14 21:35 - 2013-04-02 23:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-14 20:56 - 2013-11-14 20:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-14 20:56 - 2013-11-14 20:56 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-14 20:56 - 2013-11-14 20:56 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-14 20:56 - 2013-11-14 20:56 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-14 20:56 - 2013-11-14 20:56 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-14 20:56 - 2013-11-14 20:56 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-14 20:56 - 2013-11-14 20:56 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-14 20:56 - 2013-11-14 20:56 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-14 20:56 - 2013-11-14 20:56 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-14 20:56 - 2013-11-14 20:56 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-14 20:53 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-11-14 20:53 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-11-14 20:53 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-11-14 20:53 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-11-14 20:53 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-11-14 20:53 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-11-14 20:53 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-11-14 20:53 - 2013-04-17 08:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-11-14 20:53 - 2013-04-17 07:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-11-14 20:52 - 2012-02-11 07:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2013-11-14 20:52 - 2012-02-11 07:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe 2013-11-14 20:22 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2013-11-14 20:22 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-11-14 20:22 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-11-14 20:22 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2013-11-14 20:22 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2013-11-14 20:22 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-11-14 20:22 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2013-11-14 20:22 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2013-11-14 20:22 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-11-14 20:22 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-11-14 20:22 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2013-11-14 20:22 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2013-11-14 20:22 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-11-14 20:22 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-11-14 20:22 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2013-11-14 20:22 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-11-14 20:22 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-11-14 20:22 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-11-14 20:04 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2013-11-14 20:04 - 2012-08-23 15:12 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\terminpt.sys 2013-11-14 20:04 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2013-11-14 20:04 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2013-11-14 20:04 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2013-11-14 20:04 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2013-11-14 20:04 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2013-11-14 20:04 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-11-14 20:00 - 2010-02-23 09:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe 2013-11-14 19:37 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2013-11-14 19:37 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2013-11-14 19:37 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2013-11-14 19:37 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2013-11-14 19:36 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2013-11-14 19:36 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2013-11-14 19:36 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2013-11-14 19:36 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2013-11-14 19:21 - 2013-01-13 22:17 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 22:17 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 22:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 22:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-11-14 19:21 - 2013-01-13 22:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-11-14 19:21 - 2013-01-13 22:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 22:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 21:35 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 21:35 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 21:35 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 21:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-11-14 19:21 - 2013-01-13 21:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-11-14 19:21 - 2013-01-13 21:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 21:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 21:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 21:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-11-14 19:21 - 2013-01-13 21:22 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-11-14 19:21 - 2013-01-13 21:20 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-11-14 19:21 - 2013-01-13 21:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-11-14 19:21 - 2013-01-13 21:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-11-14 19:21 - 2013-01-13 20:58 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-11-14 19:21 - 2013-01-13 20:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-11-14 19:21 - 2013-01-13 20:53 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-11-14 19:21 - 2013-01-13 20:53 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-11-14 19:21 - 2013-01-13 20:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-11-14 19:21 - 2013-01-13 20:49 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-11-14 19:21 - 2013-01-13 20:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-11-14 19:21 - 2013-01-13 20:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-11-14 19:21 - 2013-01-13 20:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-11-14 19:21 - 2013-01-13 20:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-11-14 19:21 - 2013-01-13 20:37 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-11-14 19:21 - 2013-01-13 20:25 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-11-14 19:21 - 2013-01-13 20:24 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-11-14 19:21 - 2013-01-13 20:24 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2013-11-14 19:21 - 2013-01-13 20:20 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-11-14 19:21 - 2013-01-13 20:20 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-11-14 19:21 - 2013-01-13 20:10 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-11-14 19:21 - 2013-01-13 20:02 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-11-14 19:21 - 2013-01-13 19:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-11-14 19:21 - 2013-01-13 19:32 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-11-14 19:21 - 2013-01-13 19:09 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-11-14 19:21 - 2013-01-13 18:26 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-11-14 19:21 - 2013-01-13 18:05 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-11-14 19:21 - 2013-01-04 07:11 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-11-14 19:21 - 2013-01-04 07:11 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-11-14 19:20 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2013-11-14 19:20 - 2012-03-01 07:33 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-11-14 19:20 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2013-11-14 19:20 - 2012-03-01 06:33 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-11-14 19:20 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll 2013-11-14 19:10 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2013-11-14 19:10 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2013-11-14 19:10 - 2012-05-04 12:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-11-14 19:10 - 2012-05-04 10:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-11-14 19:09 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-14 19:09 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-14 19:09 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-14 19:09 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-14 19:09 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-14 19:09 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-14 19:09 - 2012-04-26 06:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2013-11-14 19:09 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2013-11-14 19:09 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe 2013-11-14 19:03 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-11-14 19:03 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-11-14 19:03 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-11-14 19:03 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-11-14 19:03 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2013-11-14 19:03 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2013-11-14 19:03 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2013-11-14 19:03 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2013-11-14 19:02 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-14 19:02 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-14 19:02 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-11-14 19:02 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-11-14 19:02 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-11-14 19:02 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-11-14 19:02 - 2013-04-12 15:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-11-14 19:02 - 2013-03-19 06:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-11-14 19:02 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2013-11-14 19:02 - 2013-02-27 07:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2013-11-14 19:02 - 2013-02-27 06:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2013-11-14 19:02 - 2012-01-04 11:44 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll 2013-11-14 19:02 - 2012-01-04 09:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll 2013-11-14 19:01 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-14 19:01 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-14 19:01 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-14 19:01 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-14 19:01 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-14 19:01 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-14 19:01 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-14 19:01 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-14 19:01 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-14 19:01 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-14 19:01 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-14 19:01 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-14 19:01 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-14 19:01 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-14 19:01 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-11-14 19:01 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-11-14 19:01 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-11-14 19:01 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-11-14 19:01 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-11-14 19:01 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-11-14 19:01 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-11-14 19:01 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-11-14 19:01 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-11-14 19:01 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-11-14 19:01 - 2013-07-19 02:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-11-14 19:01 - 2013-07-19 02:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-11-14 19:01 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-11-14 19:01 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-11-14 19:01 - 2013-07-09 06:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-11-14 19:01 - 2013-07-09 05:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-11-14 19:01 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-14 19:01 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-11-14 19:01 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-11-14 19:01 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-11-14 19:01 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-11-14 19:01 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-11-14 19:01 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-11-14 19:01 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-11-14 19:01 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-11-14 19:01 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-11-14 19:01 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-11-14 19:01 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-11-14 19:01 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-11-14 19:01 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2013-11-14 19:01 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll 2013-11-14 19:01 - 2012-11-28 23:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2013-11-14 19:01 - 2012-11-01 06:43 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2013-11-14 19:01 - 2012-11-01 06:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2013-11-14 19:01 - 2012-11-01 05:47 - 01389568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2013-11-14 19:01 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-11-14 19:01 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2013-11-14 19:01 - 2011-12-30 07:26 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl 2013-11-14 19:01 - 2011-12-30 06:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl 2013-11-14 19:00 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-11-14 19:00 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-11-14 19:00 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-11-14 19:00 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-11-14 19:00 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-11-14 19:00 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-11-14 19:00 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-11-14 19:00 - 2012-11-01 05:47 - 01236992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2013-11-14 19:00 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2013-11-14 19:00 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2013-11-14 19:00 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2013-11-14 19:00 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2013-11-14 19:00 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2013-11-14 19:00 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2013-11-14 19:00 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2013-11-14 19:00 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2013-11-14 19:00 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2013-11-14 19:00 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2013-11-14 19:00 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2013-11-14 19:00 - 2010-06-26 04:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2013-11-14 19:00 - 2010-06-26 04:24 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2013-11-14 18:59 - 2013-06-15 05:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-11-14 18:59 - 2013-06-04 07:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-11-14 18:59 - 2013-06-04 05:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-11-14 18:59 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2013-11-14 18:59 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2013-11-14 18:59 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2013-11-14 18:59 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2013-11-14 18:59 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2013-11-14 18:59 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2013-11-14 18:59 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2013-11-14 18:59 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2013-11-14 18:59 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2013-11-14 18:59 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2013-11-14 18:59 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2013-11-14 18:59 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2013-11-14 18:59 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2013-11-14 18:59 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2013-11-14 18:59 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2013-11-14 18:59 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2013-11-14 18:59 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2013-11-14 18:59 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2013-11-14 18:59 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2013-11-14 18:59 - 2012-11-22 06:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2013-11-14 18:59 - 2012-11-22 05:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2013-11-14 18:59 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2013-11-14 18:59 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll 2013-11-14 18:59 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2013-11-14 18:59 - 2012-05-01 06:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2013-11-14 18:58 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-11-14 18:58 - 2012-04-28 04:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2013-11-14 18:57 - 2012-11-30 00:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls 2013-11-14 18:57 - 2012-11-30 00:15 - 00420064 _____ C:\Windows\system32\locale.nls 2013-11-14 18:57 - 2012-08-11 01:56 - 00715776 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2013-11-14 18:57 - 2012-08-11 00:56 - 00542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2013-11-14 18:57 - 2012-04-07 13:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2013-11-14 18:57 - 2012-04-07 12:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2013-11-14 18:57 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2013-11-14 18:56 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-14 18:56 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-14 18:56 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-11-14 18:56 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-11-14 18:56 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-11-14 18:56 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-11-14 18:56 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-11-14 18:56 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-11-14 18:56 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-11-14 18:56 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-11-14 18:56 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll 2013-11-14 18:56 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2013-11-14 18:55 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-11-14 18:55 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-11-14 18:55 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-11-14 18:55 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-11-14 18:55 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-11-14 18:55 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-11-14 18:55 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-11-14 18:55 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-11-14 18:55 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2013-11-14 18:55 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2013-11-14 18:55 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll 2013-11-14 18:55 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll 2013-11-14 18:55 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2013-11-14 18:55 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2013-11-14 18:55 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2013-11-14 18:55 - 2012-05-05 09:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2013-11-14 18:55 - 2012-05-05 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2013-11-14 18:55 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2013-11-14 18:55 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll 2013-11-14 18:55 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-11-14 18:54 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2013-11-14 18:54 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-11-14 18:46 - 2013-11-14 18:46 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00376688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2013-11-14 18:46 - 2013-11-14 18:46 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2013-11-14 18:46 - 2013-11-14 18:46 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-11-14 18:43 - 2013-11-14 18:43 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-11-14 18:43 - 2013-11-14 18:43 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-11-14 18:39 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-14 18:39 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-14 18:39 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-14 18:39 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-14 18:39 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-14 18:38 - 2013-11-14 18:38 - 00003502 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-Brotkasten-Uli 2013-11-14 18:35 - 2013-11-14 23:33 - 00132240 _____ C:\Users\Uli\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-14 18:32 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-11-14 18:26 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2013-11-14 18:26 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2013-11-14 18:26 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2013-11-14 18:25 - 2013-11-14 18:25 - 00001547 _____ C:\Users\Uli\Desktop\Windows Media Player.lnk 2013-11-14 18:17 - 2009-06-19 03:45 - 03491616 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVAC64.SYS 2013-11-14 18:17 - 2009-04-14 15:45 - 10975264 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RTLCPL.EXE 2013-11-14 18:17 - 2009-04-14 15:45 - 01519136 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2013-11-14 18:17 - 2009-04-14 15:45 - 01063456 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2013-11-14 18:17 - 2009-04-14 15:45 - 00604704 _____ (Realtek Semiconductor Corp.) C:\Windows\SOUNDMAN.EXE 2013-11-14 18:17 - 2009-04-14 15:45 - 00154144 _____ () C:\Windows\SysWOW64\RTLCPAPI.dll 2013-11-14 18:17 - 2009-04-14 15:45 - 00149536 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2013-11-14 18:17 - 2009-04-14 15:45 - 00141856 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtkCfg.dll 2013-11-14 18:17 - 2009-04-14 15:45 - 00044064 _____ C:\Windows\CPLUtl64.exe 2013-11-14 18:17 - 2009-04-14 15:44 - 19036704 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\ALSNDMGR.CPL 2013-11-14 18:17 - 2009-04-14 15:44 - 00323104 _____ (Realtek Semiconductor Corp.) C:\Windows\AlcRmv64.exe 2013-11-14 18:17 - 2002-02-05 13:54 - 00141016 _____ C:\Windows\SysWOW64\ALSNDMGR.WAV 2013-11-14 18:12 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-11-14 18:12 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-11-14 18:12 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-11-14 18:12 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-11-14 18:12 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-11-14 18:12 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-11-14 18:12 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-11-14 18:11 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-11-14 18:11 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-11-14 18:03 - 2010-08-12 10:14 - 00660072 _____ (NVIDIA Corporation) C:\Windows\system32\nvuninst.exe 2013-11-14 17:40 - 2013-11-14 21:05 - 00001423 _____ C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-14 17:40 - 2013-11-14 17:40 - 00000936 __RSH C:\Users\Uli\ntuser.pol 2013-11-14 17:38 - 2013-11-14 17:38 - 00000020 ___SH C:\Users\Uli\ntuser.ini 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-11-14 09:08 - 2013-11-14 09:08 - 00000000 ____D C:\Users\Default\AppData\Roaming\Juniper Networks 2013-11-14 09:08 - 2013-11-14 09:08 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Juniper Networks 2013-11-14 08:42 - 2013-11-14 17:40 - 00000000 ____D C:\Users\Uli 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Vorlagen 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Startmenü 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Netzwerkumgebung 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Lokale Einstellungen 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Eigene Dateien 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Druckumgebung 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Documents\Eigene Musik 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Documents\Eigene Bilder 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\AppData\Local\Verlauf 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\AppData\Local\Anwendungsdaten 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Anwendungsdaten 2013-11-14 08:42 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-11-14 08:42 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-11-14 08:40 - 2013-11-14 08:40 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_xusb21_01009.Wdf 2013-11-14 08:40 - 2013-11-14 08:40 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-11-14 08:40 - 2013-11-14 08:40 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-11-14 08:38 - 2013-11-14 08:38 - 00000000 ____D C:\Windows\CSC 2013-11-14 08:32 - 2013-11-14 08:32 - 00262144 _____ C:\Windows\system32\config\userdiff 2013-11-14 08:02 - 2013-11-14 08:36 - 00008192 __RSH C:\BOOTSECT.BAK 2013-11-14 00:53 - 2013-11-14 00:53 - 01957794 _____ (Farbar) C:\Users\Uli\Desktop\FRST64.exe 2013-11-14 00:52 - 2013-11-14 00:52 - 00000000 ____D C:\FRST 2013-11-14 00:08 - 2013-11-14 09:05 - 00000000 ____D C:\Users\Uli\AppData\Local\Google 2013-11-14 00:08 - 2013-11-14 00:09 - 00000000 ____D C:\Program Files (x86)\IminentToolbar 2013-11-13 22:48 - 2013-11-13 22:48 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-11-13 21:17 - 2013-11-13 21:17 - 00438658 __RSH C:\LJVEY 2013-11-13 20:43 - 2010-08-12 12:07 - 00350952 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvm62x64.sys 2013-11-13 20:43 - 2010-08-12 11:46 - 00953344 _____ (NVIDIA Corporation) C:\Windows\system32\fdco2.dll 2013-11-13 20:43 - 2010-08-12 10:14 - 00263784 _____ (NVIDIA Corporation) C:\Windows\system32\nvconrm.dll 2013-11-13 20:43 - 2008-08-21 14:15 - 00002306 _____ C:\Windows\system32\nvsmb.nvu 2013-11-13 20:43 - 2008-08-20 17:35 - 00501280 _____ (NVIDIA Corporation) C:\Windows\system32\nvusmb.exe 2013-11-13 20:43 - 2008-08-20 17:35 - 00135680 _____ (NVIDIA Corporation) C:\Windows\system32\NVCOSMB.DLL 2013-11-13 20:43 - 2008-01-17 12:52 - 00130080 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor64.sys 2013-11-13 20:43 - 2008-01-17 12:45 - 00377856 _____ (NVIDIA Corporation) C:\Windows\system32\idecoiins.dll 2013-11-13 20:43 - 2008-01-17 12:45 - 00377856 _____ (NVIDIA Corporation) C:\Windows\system32\idecoi.dll 2013-11-13 18:46 - 2013-11-13 18:47 - 00014781 _____ C:\Windows\system32\oodbs.lor 2013-11-13 06:41 - 2013-11-14 08:54 - 00000000 ____D C:\ProgramData\OO Software 2013-11-13 05:02 - 2013-10-22 13:13 - 00455328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120.dll 2013-11-13 04:59 - 2013-11-13 04:59 - 00970912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120.dll 2013-11-13 04:58 - 2013-04-11 16:12 - 00019392 _____ (Dll-Files.com) C:\Windows\system32\roboot64.exe 2013-11-11 21:56 - 2013-11-11 21:56 - 00000000 ____D C:\Users\Uli\AppData\Local\VirtualStore 2013-11-11 20:59 - 2013-11-14 08:44 - 00000000 ____D C:\Program Files\Adblock Plus for IE 2013-11-11 20:26 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-10 23:08 - 2013-11-10 23:08 - 00002181 _____ C:\Users\Public\Desktop\ENSLAVED Odyssey to the West Premium Edition.lnk 2013-11-09 23:30 - 2013-11-14 08:47 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-11-09 23:25 - 2013-11-07 18:39 - 09764088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 08927704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 08412680 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 08287008 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 07751920 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 06630232 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 01318552 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 01100216 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00115512 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00098496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-11-09 23:25 - 2013-11-07 18:39 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-11-09 23:25 - 2013-11-07 18:24 - 13200896 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-11-09 23:25 - 2013-11-07 18:11 - 00230912 _____ C:\Windows\system32\clinfo.exe 2013-11-09 23:25 - 2013-11-07 18:10 - 29363712 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2013-11-09 23:25 - 2013-11-07 18:10 - 01187342 _____ C:\Windows\system32\amdocl_as64.exe 2013-11-09 23:25 - 2013-11-07 18:10 - 01061902 _____ C:\Windows\system32\amdocl_ld64.exe 2013-11-09 23:25 - 2013-11-07 18:10 - 00995342 _____ C:\Windows\SysWOW64\amdocl_as32.exe 2013-11-09 23:25 - 2013-11-07 18:10 - 00798734 _____ C:\Windows\SysWOW64\amdocl_ld32.exe 2013-11-09 23:25 - 2013-11-07 18:10 - 00100352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2013-11-09 23:25 - 2013-11-07 18:10 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2013-11-09 23:25 - 2013-11-07 18:10 - 00083968 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2013-11-09 23:25 - 2013-11-07 18:10 - 00073728 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2013-11-09 23:25 - 2013-11-07 18:07 - 24846848 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2013-11-09 23:25 - 2013-11-07 18:05 - 00063488 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-11-09 23:25 - 2013-11-07 18:05 - 00057344 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2013-11-09 23:25 - 2013-11-07 18:02 - 00129536 _____ (AMD) C:\Windows\system32\coinst_13.25.18.dll 2013-11-09 23:25 - 2013-11-07 17:44 - 26350592 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-11-09 23:25 - 2013-11-07 17:41 - 00547152 _____ C:\Windows\SysWOW64\atiapfxx.blb 2013-11-09 23:25 - 2013-11-07 17:41 - 00547152 _____ C:\Windows\system32\atiapfxx.blb 2013-11-09 23:25 - 2013-11-07 17:40 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-11-09 23:25 - 2013-11-07 17:40 - 00368640 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-11-09 23:25 - 2013-11-07 17:40 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-11-09 23:25 - 2013-11-07 17:40 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-11-09 23:25 - 2013-11-07 17:40 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-11-09 23:25 - 2013-11-07 17:40 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-11-09 23:25 - 2013-11-07 17:37 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-11-09 23:25 - 2013-11-07 17:26 - 22156288 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-11-09 23:25 - 2013-11-07 17:21 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2013-11-09 23:25 - 2013-11-07 17:21 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2013-11-09 23:25 - 2013-11-07 17:20 - 00585216 _____ (AMD) C:\Windows\system32\atieclxx.exe 2013-11-09 23:25 - 2013-11-07 17:20 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2013-11-09 23:25 - 2013-11-07 17:18 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2013-11-09 23:25 - 2013-11-07 17:09 - 03399312 _____ C:\Windows\system32\atiumd6a.cap 2013-11-09 23:25 - 2013-11-07 17:06 - 00204952 _____ C:\Windows\SysWOW64\ativvsvl.dat 2013-11-09 23:25 - 2013-11-07 17:06 - 00204952 _____ C:\Windows\system32\ativvsvl.dat 2013-11-09 23:25 - 2013-11-07 17:06 - 00157144 _____ C:\Windows\SysWOW64\ativvsva.dat 2013-11-09 23:25 - 2013-11-07 17:06 - 00157144 _____ C:\Windows\system32\ativvsva.dat 2013-11-09 23:25 - 2013-11-07 16:58 - 03433360 _____ C:\Windows\SysWOW64\atiumdva.cap 2013-11-09 23:25 - 2013-11-07 16:50 - 01145344 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00825856 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00100352 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00096768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00074752 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-11-09 23:25 - 2013-11-07 16:50 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2013-11-09 23:25 - 2013-11-07 16:49 - 00624128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-11-09 23:25 - 2013-11-07 16:46 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2013-11-09 23:25 - 2013-09-30 21:48 - 00047887 _____ C:\Windows\atiogl.xml 2013-11-09 23:25 - 2013-09-26 22:14 - 00083552 _____ C:\Windows\system32\ativce02.dat 2013-11-09 23:25 - 2013-09-24 10:21 - 00717907 _____ C:\Windows\system32\atiicdxx.dat 2013-11-09 23:25 - 2013-09-12 17:31 - 00233776 _____ C:\Windows\system32\ativvaxy_cik_nd.dat 2013-11-09 23:25 - 2013-09-12 17:30 - 00234036 _____ C:\Windows\system32\ativvaxy_cik.dat 2013-11-09 23:25 - 2013-04-10 16:34 - 00332800 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODE.exe 2013-11-09 23:25 - 2013-04-10 16:34 - 00118784 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atibtmon.exe 2013-11-09 23:25 - 2013-04-10 16:34 - 00051200 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODCLI.exe 2013-11-09 23:25 - 2011-09-12 23:06 - 00003917 _____ C:\Windows\SysWOW64\atipblag.dat 2013-11-09 23:25 - 2011-09-12 23:06 - 00003917 _____ C:\Windows\system32\atipblag.dat 2013-11-07 12:21 - 2013-11-07 12:21 - 00051200 _____ C:\Windows\system32\kdbsdk64.dll 2013-11-07 12:16 - 2013-11-07 12:16 - 00038912 _____ C:\Windows\SysWOW64\kdbsdk32.dll 2013-11-06 08:18 - 2013-11-11 22:13 - 00294912 ___SH C:\Users\Uli\Desktop\Thumbs.db 2013-11-05 14:57 - 2013-11-05 14:57 - 02843432 _____ (O&O Software GmbH) C:\Windows\system32\ooscrsav.scr 2013-11-05 14:57 - 2013-11-05 14:57 - 00543528 _____ (O&O Software GmbH) C:\Windows\system32\oodssrs.dll 2013-11-05 14:57 - 2013-11-05 14:57 - 00240936 _____ (O&O Software GmbH) C:\Windows\system32\oodbs.exe 2013-11-05 14:57 - 2013-11-05 14:57 - 00011048 _____ (O&O Software GmbH) C:\Windows\system32\oodbsrs.dll 2013-11-05 08:59 - 2013-11-05 08:59 - 00000000 ____D C:\Program Files\ATI Technologies 2013-11-02 15:54 - 2013-11-14 08:54 - 00000000 ____D C:\ProgramData\install_clap 2013-10-31 06:43 - 2013-11-14 08:54 - 00000000 ____D C:\ProgramData\Trymedia 2013-10-30 15:33 - 2013-11-14 08:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-28 01:20 - 2013-11-14 09:05 - 00000000 ____D C:\Users\Uli\AppData\Local\DDMSettings 2013-10-27 04:07 - 2013-11-14 08:54 - 00000000 ____D C:\ProgramData\Steam 2013-10-27 03:18 - 2013-10-27 03:18 - 00000000 ____D C:\AMD 2013-10-27 03:14 - 2013-09-24 15:53 - 00094208 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdW76.sys 2013-10-27 03:14 - 2013-09-24 15:51 - 00110080 _____ (TODO: <Company name>) C:\Windows\system32\DelayAPO.dll 2013-10-21 19:34 - 2013-11-14 08:52 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-21 19:34 - 2013-10-21 19:34 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-21 14:49 - 2013-10-21 14:48 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-21 14:48 - 2013-11-14 08:51 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-21 14:48 - 2013-10-21 14:48 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-21 14:48 - 2013-10-21 14:48 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-21 14:48 - 2013-10-21 14:48 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-21 14:46 - 2013-11-14 08:46 - 00000000 ____D C:\Program Files\Java 2013-10-21 14:46 - 2013-10-21 14:46 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-10-19 02:02 - 2013-11-14 09:05 - 00000000 ____D C:\Users\Uli\AppData\Roaming\AVAST Software |
15.11.2013, 01:59 | #7 |
| Windows 7 1) Systemwiederherstellungspunkte nach Neustart weg / 2) F8-Menü -> Abgesicherter Modus etc. funktioniert nicht mehr Fortsetzung Frst.txt Code:
ATTFilter ==================== One Month Modified Files and Folders ======= 2013-11-15 01:35 - 2013-11-15 01:34 - 00013796 _____ C:\Users\Uli\Desktop\FRST.txt 2013-11-15 01:34 - 2013-11-15 01:32 - 00027568 _____ C:\Windows\WindowsUpdate.log 2013-11-15 01:32 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-11-15 01:31 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-15 01:29 - 2009-07-14 05:45 - 00023632 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-15 01:29 - 2009-07-14 05:45 - 00023632 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-15 01:25 - 2013-11-14 23:33 - 00000000 ____D C:\Program Files (x86)\NeoSmart Technologies 2013-11-15 00:33 - 2013-11-15 00:33 - 00295624 __RSH C:\OVLPQ 2013-11-15 00:23 - 2009-07-14 06:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2013-11-15 00:23 - 2009-07-14 06:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2013-11-15 00:06 - 2011-06-30 06:05 - 00002562 _____ C:\Windows\diagwrn.xml 2013-11-15 00:06 - 2011-06-30 06:05 - 00001908 _____ C:\Windows\diagerr.xml 2013-11-14 23:58 - 2012-12-12 01:14 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-14 23:45 - 2011-04-12 08:43 - 00654150 _____ C:\Windows\system32\perfh007.dat 2013-11-14 23:45 - 2011-04-12 08:43 - 00130022 _____ C:\Windows\system32\perfc007.dat 2013-11-14 23:45 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-14 23:34 - 2013-11-14 23:34 - 00024576 _____ C:\Users\Uli\Documents\EasyBCD Backup (2013-11-14).bcd 2013-11-14 23:33 - 2013-11-14 18:35 - 00132240 _____ C:\Users\Uli\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-14 21:05 - 2013-11-14 17:40 - 00001423 _____ C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-14 21:01 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-14 20:56 - 2013-11-14 20:56 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-14 20:56 - 2013-11-14 20:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-14 20:56 - 2013-11-14 20:56 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-14 20:56 - 2013-11-14 20:56 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-14 20:56 - 2013-11-14 20:56 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-14 20:56 - 2013-11-14 20:56 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-14 20:56 - 2013-11-14 20:56 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-14 20:56 - 2013-11-14 20:56 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-14 20:56 - 2013-11-14 20:56 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-14 20:56 - 2013-11-14 20:56 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-14 20:56 - 2013-11-14 20:56 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-14 20:56 - 2013-11-14 20:56 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-14 20:56 - 2013-11-14 20:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-14 20:47 - 2011-06-18 22:40 - 00000000 ___RD C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-14 20:47 - 2011-06-18 22:40 - 00000000 ___RD C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-11-14 20:44 - 2009-07-14 05:45 - 05092984 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-14 20:41 - 2011-04-12 08:54 - 00000000 ____D C:\Program Files\Windows Journal 2013-11-14 20:41 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-11-14 20:41 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-11-14 20:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-11-14 20:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2013-11-14 20:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK 2013-11-14 20:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR 2013-11-14 19:34 - 2013-08-15 10:58 - 00000000 ____D C:\Windows\system32\MRT 2013-11-14 18:46 - 2013-11-14 18:46 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-11-14 18:46 - 2013-11-14 18:46 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00376688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2013-11-14 18:46 - 2013-11-14 18:46 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2013-11-14 18:46 - 2013-11-14 18:46 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-11-14 18:46 - 2013-11-14 18:46 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-11-14 18:46 - 2013-11-14 18:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-11-14 18:43 - 2013-11-14 18:43 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-11-14 18:43 - 2013-11-14 18:43 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-11-14 18:38 - 2013-11-14 18:38 - 00003502 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-Brotkasten-Uli 2013-11-14 18:38 - 2012-10-01 03:46 - 00000000 ____D C:\Users\Uli\AppData\Local\Adobe 2013-11-14 18:33 - 2011-07-11 05:32 - 00060416 _____ (Realtek Semiconductor Corp.) C:\Windows\ALCFDRTM.VER 2013-11-14 18:25 - 2013-11-14 18:25 - 00001547 _____ C:\Users\Uli\Desktop\Windows Media Player.lnk 2013-11-14 18:20 - 2012-07-06 12:59 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-14 18:20 - 2011-06-19 00:12 - 00000000 ____D C:\Users\Uli\AppData\Roaming\uTorrent 2013-11-14 18:17 - 2012-01-17 03:11 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-11-14 18:17 - 2011-06-19 00:04 - 00000000 ____D C:\Program Files (x86)\Realtek AC97 2013-11-14 18:16 - 2011-06-19 00:03 - 00319488 _____ (Realtek Semiconductor Corp.) C:\Windows\HideWin.exe 2013-11-14 18:11 - 2012-02-23 23:24 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2013-11-14 18:11 - 2012-02-23 23:24 - 00001982 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-11-14 17:46 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\restore 2013-11-14 17:40 - 2013-11-14 17:40 - 00000936 __RSH C:\Users\Uli\ntuser.pol 2013-11-14 17:40 - 2013-11-14 08:42 - 00000000 ____D C:\Users\Uli 2013-11-14 17:38 - 2013-11-14 17:38 - 00000020 ___SH C:\Users\Uli\ntuser.ini 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Vorlagen 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Startmenü 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\ProgramData\Vorlagen 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\ProgramData\Startmenü 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\ProgramData\Favoriten 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\ProgramData\Dokumente 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2013-11-14 17:38 - 2013-11-14 17:38 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2013-11-14 17:38 - 2012-03-01 16:54 - 00000000 __SHD C:\Recovery 2013-11-14 17:38 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2013-11-14 17:38 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Recovery 2013-11-14 17:38 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT 2013-11-14 09:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-14 09:18 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration 2013-11-14 09:14 - 2012-03-01 15:14 - 00023056 _____ C:\Windows\system32\emptyregdb.dat 2013-11-14 09:12 - 2011-06-21 03:31 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform 2013-11-14 09:12 - 2009-07-14 04:20 - 00000000 __RSD C:\Windows\Media 2013-11-14 09:12 - 2009-07-14 04:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2013-11-14 09:08 - 2013-11-14 09:08 - 00000000 ____D C:\Users\Default\AppData\Roaming\Juniper Networks 2013-11-14 09:08 - 2013-11-14 09:08 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Juniper Networks 2013-11-14 09:08 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-11-14 09:08 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-11-14 09:08 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-11-14 09:08 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-11-14 09:06 - 2013-10-11 04:13 - 00000000 ____D C:\Users\Uli\AppData\Roaming\vlc 2013-11-14 09:06 - 2013-09-27 13:08 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Xilisoft 2013-11-14 09:06 - 2013-09-02 00:56 - 00000000 ____D C:\Users\Uli\Documents\Readiris 2013-11-14 09:06 - 2013-07-21 22:21 - 00000000 ____D C:\Users\Uli\Downloads\eMule 2013-11-14 09:06 - 2013-03-26 16:56 - 00000000 ____D C:\Users\Uli\Documents\My Games 2013-11-14 09:06 - 2013-03-18 22:15 - 00000000 ____D C:\Users\Uli\Documents\Aktuelles 2013-11-14 09:06 - 2013-03-08 22:45 - 00000000 ____D C:\Users\Uli\Documents\CyberLink 2013-11-14 09:06 - 2012-11-17 08:37 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Wondershare 2013-11-14 09:06 - 2012-11-15 20:02 - 00000000 ____D C:\Users\Uli\Documents\Poesie 2013-11-14 09:06 - 2012-10-30 02:29 - 00000000 ____D C:\Users\Uli\Documents\AMD Treiber MOD 2013-11-14 09:06 - 2012-10-15 23:54 - 00000000 ____D C:\Users\Uli\Documents\FIFA 13 2013-11-14 09:06 - 2012-01-29 22:28 - 00000000 ____D C:\Users\Uli\Documents\Bios 2013-11-14 09:06 - 2012-01-10 23:59 - 00000000 ____D C:\Users\Uli\Documents\MuseScore 2013-11-14 09:06 - 2011-09-27 17:15 - 00000000 ____D C:\Users\Uli\Documents\Lebenshilfe 2013-11-14 09:06 - 2011-06-28 16:31 - 00000000 ____D C:\Users\Uli\Documents\WG 2013-11-14 09:06 - 2011-06-28 16:03 - 00000000 ____D C:\Users\Uli\Documents\Formelles 2013-11-14 09:06 - 2011-06-27 22:08 - 00000000 ____D C:\Users\Uli\Documents\Music Lyrics & Tabs 2013-11-14 09:06 - 2011-06-20 22:58 - 00000000 ____D C:\Users\Uli\Documents\Monitor 2013-11-14 09:06 - 2011-06-20 17:58 - 00000000 ____D C:\Users\Uli\Documents\FH 2013-11-14 09:06 - 2011-06-19 20:56 - 00000000 ____D C:\Users\Uli\Documents\TrackMania 2013-11-14 09:06 - 2011-06-19 19:17 - 00000000 ____D C:\Users\Uli\Documents\Vsk5Online 2013-11-14 09:06 - 2011-06-18 23:57 - 00000000 ____D C:\Users\Uli\AppData\Roaming\WinRAR 2013-11-14 09:05 - 2013-11-14 00:08 - 00000000 ____D C:\Users\Uli\AppData\Local\Google 2013-11-14 09:05 - 2013-10-28 01:20 - 00000000 ____D C:\Users\Uli\AppData\Local\DDMSettings 2013-11-14 09:05 - 2013-10-19 02:02 - 00000000 ____D C:\Users\Uli\AppData\Roaming\AVAST Software 2013-11-14 09:05 - 2013-09-18 21:07 - 00000000 __RHD C:\Users\Uli\AppData\Roaming\SecuROM 2013-11-14 09:05 - 2013-09-08 22:44 - 00000000 ____D C:\Users\Uli\AppData\Roaming\digital publishing 2013-11-14 09:05 - 2013-09-08 22:43 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\digital publishing 2013-11-14 09:05 - 2013-09-08 20:37 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Edition First Class 2013-11-14 09:05 - 2013-07-03 21:18 - 00000000 ____D C:\Users\Uli\AppData\Roaming\dvdcss 2013-11-14 09:05 - 2013-03-09 06:51 - 00000000 ____D C:\Users\Uli\AppData\Roaming\CyberLink 2013-11-14 09:05 - 2013-02-22 02:02 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Virtual Dub 2013-11-14 09:05 - 2013-02-17 01:16 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOB2MPG v3 2013-11-14 09:05 - 2013-01-16 03:14 - 00000000 ____D C:\Users\Uli\AppData\Local\VS Revo Group 2013-11-14 09:05 - 2013-01-06 03:07 - 00000000 ____D C:\Users\Uli\AppData\Roaming\avidemux 2013-11-14 09:05 - 2012-10-09 03:40 - 00000000 ____D C:\Users\Uli\AppData\Local\Macromedia 2013-11-14 09:05 - 2012-09-26 02:34 - 00000000 ____D C:\Users\Uli\AppData\Local\Windows Live 2013-11-14 09:05 - 2012-09-07 17:22 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool 2013-11-14 09:05 - 2012-08-03 00:49 - 00000000 ____D C:\Users\Uli\AppData\Roaming\DivX 2013-11-14 09:05 - 2012-06-18 03:29 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-11-14 09:05 - 2012-03-27 08:18 - 00000000 ____D C:\Users\Uli\AppData\Local\Tracker Software 2013-11-14 09:05 - 2012-03-02 03:37 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ATI Tray Tools 2013-11-14 09:05 - 2012-02-05 23:41 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Canon 2013-11-14 09:05 - 2012-02-01 00:43 - 00000000 ____D C:\Users\Uli\AppData\Local\Morphyre 2013-11-14 09:05 - 2012-01-10 20:05 - 00000000 ____D C:\Users\Uli\AppData\Roaming\MusE 2013-11-14 09:05 - 2012-01-10 20:04 - 00000000 ____D C:\Users\Uli\AppData\Local\MusE 2013-11-14 09:05 - 2011-11-17 00:50 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-11-14 09:05 - 2011-11-12 18:13 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Origin 2013-11-14 09:05 - 2011-11-12 18:13 - 00000000 ____D C:\Users\Uli\AppData\Local\Origin 2013-11-14 09:05 - 2011-10-31 13:15 - 00000000 ____D C:\Users\Uli\AppData\Local\Microsoft Games 2013-11-14 09:05 - 2011-10-21 16:43 - 00000000 ____D C:\Users\Uli\AppData\Local\O&O 2013-11-14 09:05 - 2011-08-01 03:54 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Sinvise Systems 2013-11-14 09:05 - 2011-07-10 03:15 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-11-14 09:05 - 2011-06-27 15:10 - 00000000 ____D C:\Users\Uli\AppData\Roaming\dvdae 2013-11-14 09:05 - 2011-06-25 15:44 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recuva 2013-11-14 09:05 - 2011-06-22 04:59 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Morphyre Visualizer 2013-11-14 09:05 - 2011-06-21 04:09 - 00000000 ____D C:\Users\Uli\AppData\Local\Zattoo 2013-11-14 09:05 - 2011-06-20 17:22 - 00000000 ____D C:\Users\Uli\AppData\Roaming\BOM 2013-11-14 09:05 - 2011-06-19 05:37 - 00000000 ____D C:\Users\Uli\AppData\Roaming\LibreOffice 2013-11-14 09:05 - 2011-06-19 04:37 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Audacity 2013-11-14 09:05 - 2011-06-19 04:32 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Canneverbe Limited 2013-11-14 09:05 - 2011-06-19 02:40 - 00000000 ____D C:\Users\Uli\AppData\Local\eMule 2013-11-14 09:05 - 2011-06-19 01:32 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft RegScanner 2013-11-14 09:05 - 2011-06-19 01:23 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Skype 2013-11-14 09:05 - 2011-06-19 00:27 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Macromedia 2013-11-14 09:05 - 2011-06-19 00:27 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Adobe 2013-11-14 09:05 - 2011-06-18 23:48 - 00000000 ____D C:\Users\Uli\AppData\Roaming\Mozilla 2013-11-14 09:05 - 2011-06-18 23:48 - 00000000 ____D C:\Users\Uli\AppData\Local\Mozilla 2013-11-14 08:57 - 2013-03-29 19:14 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-11-14 08:57 - 2012-09-26 01:50 - 00000000 ____D C:\Windows\SysWOW64\xlive 2013-11-14 08:57 - 2011-08-07 03:25 - 00000000 ____D C:\Windows\system32\SPReview 2013-11-14 08:57 - 2011-06-19 00:26 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2013-11-14 08:57 - 2011-04-12 08:43 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2013-11-14 08:57 - 2011-04-12 08:43 - 00000000 ____D C:\Windows\SysWOW64\winrm 2013-11-14 08:57 - 2011-04-12 08:43 - 00000000 ____D C:\Windows\SysWOW64\WCN 2013-11-14 08:57 - 2011-04-12 08:43 - 00000000 ____D C:\Windows\SysWOW64\sysprep 2013-11-14 08:57 - 2011-04-12 08:43 - 00000000 ____D C:\Windows\SysWOW64\slmgr 2013-11-14 08:57 - 2011-04-12 08:43 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2013-11-14 08:57 - 2011-04-12 08:43 - 00000000 ____D C:\Windows\system32\winrm 2013-11-14 08:57 - 2011-04-12 08:43 - 00000000 ____D C:\Windows\system32\WCN 2013-11-14 08:57 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2013-11-14 08:57 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\oobe 2013-11-14 08:57 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\MUI 2013-11-14 08:57 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz 2013-11-14 08:57 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism 2013-11-14 08:57 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sysprep 2013-11-14 08:56 - 2013-01-27 03:05 - 00000000 ____D C:\Windows\Profiles\Uli 2013-11-14 08:56 - 2012-03-25 14:08 - 00000000 ____D C:\Windows\pss 2013-11-14 08:56 - 2011-11-13 17:23 - 00000000 ____D C:\Windows\system32\Macromed 2013-11-14 08:56 - 2011-10-21 16:44 - 00000000 ____D C:\Windows\system32\oodag 2013-11-14 08:56 - 2011-07-22 18:18 - 00000000 ____D C:\Windows\Sun 2013-11-14 08:56 - 2011-06-19 00:14 - 00000000 ____D C:\Windows\system32\EventProviders 2013-11-14 08:56 - 2011-04-12 08:54 - 00000000 ____D C:\Windows\ShellNew 2013-11-14 08:56 - 2011-04-12 08:43 - 00000000 ____D C:\Windows\system32\slmgr 2013-11-14 08:56 - 2011-04-12 08:43 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2013-11-14 08:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\oobe 2013-11-14 08:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\MUI 2013-11-14 08:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism 2013-11-14 08:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Speech 2013-11-14 08:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports 2013-11-14 08:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\IME 2013-11-14 08:54 - 2013-11-13 06:41 - 00000000 ____D C:\ProgramData\OO Software 2013-11-14 08:54 - 2013-11-02 15:54 - 00000000 ____D C:\ProgramData\install_clap 2013-11-14 08:54 - 2013-10-31 06:43 - 00000000 ____D C:\ProgramData\Trymedia 2013-11-14 08:54 - 2013-10-27 04:07 - 00000000 ____D C:\ProgramData\Steam 2013-11-14 08:54 - 2013-09-27 13:07 - 00000000 ____D C:\ProgramData\Xilisoft 2013-11-14 08:54 - 2013-09-24 18:12 - 00000000 ____D C:\ProgramData\Caphyon 2013-11-14 08:54 - 2013-09-02 00:24 - 00000000 ____D C:\ProgramData\SafeNet Sentinel 2013-11-14 08:54 - 2013-09-02 00:24 - 00000000 ____D C:\ProgramData\Readiris14Pro 2013-11-14 08:54 - 2013-09-02 00:07 - 00000000 ____D C:\Windows\Downloaded Installations 2013-11-14 08:54 - 2013-05-15 09:58 - 00000000 ____D C:\ProgramData\Orbit 2013-11-14 08:54 - 2013-04-09 21:46 - 00000000 ____D C:\ProgramData\Sony 2013-11-14 08:54 - 2013-03-26 02:17 - 00000000 ____D C:\ProgramData\Droppix 2013-11-14 08:54 - 2013-03-12 23:38 - 00000000 ____D C:\ProgramData\SlySoft 2013-11-14 08:54 - 2013-03-11 20:54 - 00000000 ____D C:\ProgramData\SmartSound Software Inc 2013-11-14 08:54 - 2013-03-09 06:51 - 00000000 ____D C:\ProgramData\CyberLink 2013-11-14 08:54 - 2013-03-08 22:45 - 00000000 ____D C:\Users\Public\CyberLink 2013-11-14 08:54 - 2013-02-19 02:41 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-11-14 08:54 - 2013-02-14 16:56 - 00000000 ___RD C:\Users\Public\Documents\Droppix Label Maker projects 2013-11-14 08:54 - 2013-02-14 16:56 - 00000000 ___RD C:\Users\Public\Documents\Droppix Label Maker Misc 2013-11-14 08:54 - 2013-02-14 15:50 - 00000000 ____D C:\ProgramData\LightScribe 2013-11-14 08:54 - 2013-01-22 01:14 - 00000000 ____D C:\Windows\de 2013-11-14 08:54 - 2012-12-21 23:49 - 00000000 ____D C:\ProgramData\TrackMania 2013-11-14 08:54 - 2012-12-04 20:56 - 00000000 ____D C:\ProgramData\InstallShield 2013-11-14 08:54 - 2012-10-24 04:33 - 00000000 ____D C:\ProgramData\AMD 2013-11-14 08:54 - 2012-10-01 01:59 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-11-14 08:54 - 2012-10-01 01:45 - 00000000 ____D C:\ProgramData\Adobe 2013-11-14 08:54 - 2012-09-07 13:08 - 00000000 ____D C:\ProgramData\Sony Ericsson 2013-11-14 08:54 - 2012-04-29 03:16 - 00000000 ____D C:\ProgramData\Mozilla 2013-11-14 08:54 - 2012-03-25 13:52 - 00000000 __SHD C:\ProgramData\DSS 2013-11-14 08:54 - 2012-03-01 13:27 - 00000000 ____D C:\ProgramData\Canneverbe Limited 2013-11-14 08:54 - 2012-02-21 11:21 - 00000000 ____D C:\Windows\ERDNT 2013-11-14 08:54 - 2012-02-20 20:38 - 00000000 ____D C:\Windows\CheckSur 2013-11-14 08:54 - 2012-02-01 20:28 - 00000000 ____D C:\ProgramData\EPSON 2013-11-14 08:54 - 2011-10-24 16:13 - 00000000 ____D C:\ProgramData\Origin 2013-11-14 08:54 - 2011-10-24 16:12 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-11-14 08:54 - 2011-07-22 18:18 - 00000000 ____D C:\ProgramData\Sun 2013-11-14 08:54 - 2011-06-20 21:45 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-14 08:54 - 2011-06-20 21:33 - 00000000 ____D C:\Windows\AutoKMS 2013-11-14 08:54 - 2011-06-20 17:34 - 00000000 ____D C:\ProgramData\eBay 2013-11-14 08:54 - 2011-06-19 20:29 - 00000000 ____D C:\ProgramData\Vsk5Online 2013-11-14 08:54 - 2011-06-19 02:42 - 00000000 ____D C:\ProgramData\eMule 2013-11-14 08:54 - 2011-06-19 01:23 - 00000000 ____D C:\ProgramData\Skype 2013-11-14 08:54 - 2011-06-19 01:07 - 00000000 ____D C:\ProgramData\DivX 2013-11-14 08:54 - 2011-06-19 00:50 - 00000000 ____D C:\ProgramData\AVAST Software 2013-11-14 08:54 - 2009-07-14 06:37 - 00000000 ____D C:\Windows\DigitalLocker 2013-11-14 08:54 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Cursors 2013-11-14 08:53 - 2013-09-27 13:07 - 00000000 ____D C:\Program Files (x86)\Xilisoft 2013-11-14 08:53 - 2013-04-29 21:02 - 00000000 ____D C:\Program Files (x86)\Virtual Dub 2013-11-14 08:53 - 2013-04-09 21:39 - 00000000 ____D C:\Program Files (x86)\wLite 2013-11-14 08:53 - 2013-02-17 01:16 - 00000000 ____D C:\Program Files (x86)\VOB2MPG 2013-11-14 08:53 - 2012-11-20 22:25 - 00000000 ____D C:\Program Files (x86)\SopCast 2013-11-14 08:53 - 2012-11-17 08:36 - 00000000 ____D C:\Program Files (x86)\Wondershare 2013-11-14 08:53 - 2012-10-09 03:20 - 00000000 ____D C:\Program Files (x86)\uTorrent 2013-11-14 08:53 - 2012-10-08 03:27 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2013-11-14 08:53 - 2012-09-26 02:36 - 00000000 ____D C:\Program Files (x86)\Windows Live 2013-11-14 08:53 - 2011-07-10 03:11 - 00000000 ____D C:\Program Files (x86)\Steam 2013-11-14 08:53 - 2011-06-21 04:09 - 00000000 ____D C:\Program Files (x86)\Zattoo 2013-11-14 08:53 - 2011-06-19 08:58 - 00000000 ____D C:\Program Files (x86)\WinCDEmu 2013-11-14 08:53 - 2011-06-19 05:43 - 00000000 ____D C:\Program Files (x86)\UnderCoverXP 2013-11-14 08:53 - 2011-06-19 02:26 - 00000000 ____D C:\Program Files (x86)\SpeedFan 2013-11-14 08:53 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar 2013-11-14 08:53 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2013-11-14 08:52 - 2013-10-30 15:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-14 08:52 - 2013-10-21 19:34 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-11-14 08:52 - 2013-09-02 00:23 - 00000000 ____D C:\Program Files (x86)\Readiris Pro 14 2013-11-14 08:52 - 2013-06-25 18:09 - 00000000 ____D C:\Program Files (x86)\Metronome Plus 2013-11-14 08:52 - 2013-03-12 23:16 - 00000000 ____D C:\Program Files (x86)\SlySoft 2013-11-14 08:52 - 2013-03-11 20:54 - 00000000 ____D C:\Program Files (x86)\SmartSound Software 2013-11-14 08:52 - 2013-03-05 16:47 - 00000000 ____D C:\Program Files (x86)\Radeon Bios Editor 2013-11-14 08:52 - 2013-01-09 12:07 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8 2013-11-14 08:52 - 2012-11-27 13:35 - 00000000 ____D C:\Program Files (x86)\Resource Hacker 2013-11-14 08:52 - 2012-11-20 16:36 - 00000000 ____D C:\Program Files (x86)\MediaInfo 2013-11-14 08:52 - 2012-09-26 01:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-11-14 08:52 - 2012-09-07 13:06 - 00000000 ____D C:\Program Files (x86)\Sony 2013-11-14 08:52 - 2012-06-19 05:05 - 00000000 ____D C:\Program Files (x86)\Sony Ericsson 2013-11-14 08:52 - 2012-04-29 03:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-14 08:52 - 2012-03-02 03:37 - 00000000 ____D C:\Program Files (x86)\Ray Adams 2013-11-14 08:52 - 2012-02-20 22:03 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2013-11-14 08:52 - 2012-01-10 20:04 - 00000000 ____D C:\Program Files (x86)\MuseScore 2013-11-14 08:52 - 2011-11-15 00:05 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0 2013-11-14 08:52 - 2011-10-24 16:12 - 00000000 ____D C:\Program Files (x86)\Origin 2013-11-14 08:52 - 2011-09-03 23:50 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-11-14 08:52 - 2011-08-27 02:55 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA 2013-11-14 08:52 - 2011-07-11 05:13 - 00000000 ____D C:\Program Files (x86)\OpenAL 2013-11-14 08:52 - 2011-06-22 04:59 - 00000000 ____D C:\Program Files (x86)\Morphyre 2013-11-14 08:52 - 2011-06-21 03:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2013-11-14 08:52 - 2011-06-21 03:25 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-11-14 08:52 - 2011-06-19 05:34 - 00000000 ____D C:\Program Files (x86)\LibreOffice 2013-11-14 08:52 - 2011-06-19 04:38 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2013-11-14 08:52 - 2011-06-19 02:16 - 00000000 ____D C:\Program Files (x86)\Marvell 2013-11-14 08:52 - 2011-06-19 01:32 - 00000000 ____D C:\Program Files (x86)\NirSoft 2013-11-14 08:52 - 2011-06-19 01:23 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-14 08:52 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\MSBuild 2013-11-14 08:51 - 2013-10-21 14:48 - 00000000 ____D C:\Program Files (x86)\Java 2013-11-14 08:51 - 2013-01-15 02:22 - 00000000 ____D C:\Program Files (x86)\GSpot 2013-11-14 08:51 - 2012-07-10 23:34 - 00000000 ____D C:\Program Files (x86)\Google 2013-11-14 08:51 - 2011-11-09 00:41 - 00000000 ____D C:\Program Files (x86)\HD Tune 2013-11-14 08:50 - 2013-09-08 22:42 - 00000000 ____D C:\Program Files (x86)\digital publishing 2013-11-14 08:50 - 2013-07-18 06:42 - 00000000 ____D C:\Program Files (x86)\Eusing Free Registry Cleaner 2013-11-14 08:50 - 2013-07-08 15:51 - 00000000 ____D C:\Program Files (x86)\eRightSoft 2013-11-14 08:50 - 2013-05-27 11:17 - 00000000 ____D C:\Program Files (x86)\DivX 2013-11-14 08:50 - 2013-03-26 02:17 - 00000000 ____D C:\Program Files (x86)\Droppix Label Maker 2013-11-14 08:50 - 2013-01-25 22:00 - 00000000 ____D C:\Program Files (x86)\Ffmpeg For Audacity 2013-11-14 08:50 - 2012-09-05 14:14 - 00000000 ____D C:\Program Files (x86)\Flashtool 2013-11-14 08:50 - 2011-06-20 17:34 - 00000000 ____D C:\Program Files (x86)\eBay 2013-11-14 08:50 - 2011-06-19 17:10 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes 2013-11-14 08:50 - 2011-06-19 05:41 - 00000000 ____D C:\Program Files (x86)\EPSON 2013-11-14 08:50 - 2011-06-19 04:34 - 00000000 ____D C:\Program Files (x86)\DVD Audio Extractor 2013-11-14 08:50 - 2011-06-19 02:40 - 00000000 ____D C:\Program Files (x86)\eMule 2013-11-14 08:47 - 2013-11-09 23:30 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-11-14 08:47 - 2013-09-18 21:14 - 00000000 ____D C:\Program Files (x86)\Alcohol Soft 2013-11-14 08:47 - 2013-06-14 19:43 - 00000000 ____D C:\Program Files (x86)\BRS 2013-11-14 08:47 - 2013-03-09 06:42 - 00000000 ____D C:\Program Files (x86)\Cyberlink 2013-11-14 08:47 - 2013-03-05 16:32 - 00000000 ____D C:\Program Files (x86)\ATI Winflash 2013-11-14 08:47 - 2013-01-18 02:04 - 00000000 ____D C:\Program Files (x86)\AMD Demo - Leo 2013-11-14 08:47 - 2012-12-07 18:03 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-11-14 08:47 - 2012-11-20 14:49 - 00000000 ____D C:\Program Files (x86)\AviSynth 2.5 2013-11-14 08:47 - 2012-10-24 04:30 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-11-14 08:47 - 2012-02-06 02:49 - 00000000 ____D C:\Program Files (x86)\Canon 2013-11-14 08:47 - 2012-01-29 22:26 - 00000000 ____D C:\Program Files (x86)\AwardBIOS Winflash 2013-11-14 08:47 - 2011-06-20 17:22 - 00000000 ____D C:\Program Files (x86)\Biet-O-Matic 2013-11-14 08:47 - 2011-06-19 06:11 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-11-14 08:47 - 2011-06-19 04:36 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-11-14 08:46 - 2013-10-21 14:46 - 00000000 ____D C:\Program Files\Java 2013-11-14 08:46 - 2013-05-22 00:20 - 00000000 ____D C:\Program Files (x86)\abcAVI 2013-11-14 08:46 - 2013-03-09 06:40 - 00000000 ____D C:\Program Files\CyberLink 2013-11-14 08:46 - 2013-02-27 01:30 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-11-14 08:46 - 2013-02-24 02:44 - 00000000 ____D C:\Program Files\OO Software 2013-11-14 08:46 - 2013-01-16 03:19 - 00000000 ____D C:\Program Files\Revo Uninstaller Pro 2013-11-14 08:46 - 2013-01-04 04:50 - 00000000 ____D C:\Program Files\Icaros 2013-11-14 08:46 - 2012-03-15 21:49 - 00000000 ____D C:\Program Files\Tracker Software 2013-11-14 08:46 - 2011-09-04 04:57 - 00000000 ____D C:\Program Files\Sinvise Systems 2013-11-14 08:46 - 2011-06-25 15:44 - 00000000 ____D C:\Program Files\Recuva 2013-11-14 08:46 - 2011-06-21 03:29 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services 2013-11-14 08:46 - 2011-06-21 03:29 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-11-14 08:46 - 2011-06-21 03:27 - 00000000 ____D C:\Program Files\Microsoft Analysis Services 2013-11-14 08:46 - 2011-06-21 03:25 - 00000000 ____D C:\Program Files\Microsoft Office 2013-11-14 08:46 - 2011-06-20 18:06 - 00000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories 2013-11-14 08:46 - 2011-06-19 07:53 - 00000000 ____D C:\Program Files\Prio 2013-11-14 08:46 - 2011-06-19 05:39 - 00000000 ____D C:\Program Files\EPSON 2013-11-14 08:46 - 2011-06-19 01:10 - 00000000 ____D C:\Program Files\DivX 2013-11-14 08:46 - 2011-06-18 23:57 - 00000000 ____D C:\Program Files\WinRAR 2013-11-14 08:46 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2013-11-14 08:46 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2013-11-14 08:46 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Microsoft Games 2013-11-14 08:46 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker 2013-11-14 08:45 - 2013-03-08 02:07 - 00000000 ____D C:\Program Files\Common Files\DESIGNER 2013-11-14 08:45 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System 2013-11-14 08:45 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-11-14 08:44 - 2013-11-11 20:59 - 00000000 ____D C:\Program Files\Adblock Plus for IE 2013-11-14 08:44 - 2013-01-06 03:07 - 00000000 ____D C:\Program Files\Avidemux 2013-11-14 08:44 - 2012-12-07 18:03 - 00000000 ____D C:\Program Files\ATI 2013-11-14 08:44 - 2012-10-01 03:52 - 00000000 ____D C:\Program Files\Adobe 2013-11-14 08:44 - 2012-10-01 03:49 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-11-14 08:44 - 2012-02-23 22:58 - 00000000 ____D C:\Program Files\AVAST Software 2013-11-14 08:44 - 2011-06-20 16:56 - 00000000 ____D C:\Program Files\AC3Filter 2013-11-14 08:44 - 2011-06-19 04:32 - 00000000 ____D C:\Program Files\CDBurnerXP 2013-11-14 08:44 - 2011-06-19 00:22 - 00000000 ____D C:\Program Files\CCleaner 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Vorlagen 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Startmenü 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Netzwerkumgebung 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Lokale Einstellungen 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Eigene Dateien 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Druckumgebung 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Documents\Eigene Musik 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Documents\Eigene Bilder 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\AppData\Local\Verlauf 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\AppData\Local\Anwendungsdaten 2013-11-14 08:42 - 2013-11-14 08:42 - 00000000 _SHDL C:\Users\Uli\Anwendungsdaten 2013-11-14 08:40 - 2013-11-14 08:40 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_xusb21_01009.Wdf 2013-11-14 08:40 - 2013-11-14 08:40 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-11-14 08:40 - 2013-11-14 08:40 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-11-14 08:38 - 2013-11-14 08:38 - 00000000 ____D C:\Windows\CSC 2013-11-14 08:36 - 2013-11-14 08:02 - 00008192 __RSH C:\BOOTSECT.BAK 2013-11-14 08:32 - 2013-11-14 08:32 - 00262144 _____ C:\Windows\system32\config\userdiff 2013-11-14 08:32 - 2009-07-14 05:45 - 00000000 ____D C:\Windows\Setup 2013-11-14 00:53 - 2013-11-14 00:53 - 01957794 _____ (Farbar) C:\Users\Uli\Desktop\FRST64.exe 2013-11-14 00:52 - 2013-11-14 00:52 - 00000000 ____D C:\FRST 2013-11-14 00:09 - 2013-11-14 00:08 - 00000000 ____D C:\Program Files (x86)\IminentToolbar 2013-11-14 00:08 - 2013-05-22 00:57 - 00001530 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-11-13 22:48 - 2013-11-13 22:48 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-11-13 21:17 - 2013-11-13 21:17 - 00438658 __RSH C:\LJVEY 2013-11-13 20:44 - 2011-06-19 00:15 - 00000000 ____D C:\Nvidia 2013-11-13 18:47 - 2013-11-13 18:46 - 00014781 _____ C:\Windows\system32\oodbs.lor 2013-11-13 06:42 - 2013-02-24 01:44 - 00002527 _____ C:\Users\Public\Desktop\O&O Defrag.lnk 2013-11-13 04:59 - 2013-11-13 04:59 - 00970912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120.dll 2013-11-11 22:13 - 2013-11-06 08:18 - 00294912 ___SH C:\Users\Uli\Desktop\Thumbs.db 2013-11-11 21:56 - 2013-11-11 21:56 - 00000000 ____D C:\Users\Uli\AppData\Local\VirtualStore 2013-11-10 23:08 - 2013-11-10 23:08 - 00002181 _____ C:\Users\Public\Desktop\ENSLAVED Odyssey to the West Premium Edition.lnk 2013-11-10 22:47 - 2011-06-19 17:22 - 00000000 ____D C:\Games 2013-11-10 07:53 - 2011-06-20 03:23 - 00006369 _____ C:\Users\Uli\AppData\Roaming\prio.ini 2013-11-10 06:24 - 2011-11-19 04:37 - 00001668 _____ C:\Users\Public\Desktop\Recuva.lnk 2013-11-10 05:10 - 2013-09-13 23:05 - 00000863 _____ C:\Users\Uli\Desktop\µTorrent.lnk 2013-11-10 05:10 - 2013-09-13 23:05 - 00000843 _____ C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2013-11-07 18:39 - 2013-11-09 23:25 - 09764088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 08927704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 08412680 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 08287008 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 07751920 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 06630232 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 01318552 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 01100216 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00115512 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00098496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-11-07 18:39 - 2013-11-09 23:25 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-11-07 18:24 - 2013-11-09 23:25 - 13200896 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-11-07 18:11 - 2013-11-09 23:25 - 00230912 _____ C:\Windows\system32\clinfo.exe 2013-11-07 18:10 - 2013-11-09 23:25 - 29363712 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2013-11-07 18:10 - 2013-11-09 23:25 - 01187342 _____ C:\Windows\system32\amdocl_as64.exe 2013-11-07 18:10 - 2013-11-09 23:25 - 01061902 _____ C:\Windows\system32\amdocl_ld64.exe 2013-11-07 18:10 - 2013-11-09 23:25 - 00995342 _____ C:\Windows\SysWOW64\amdocl_as32.exe 2013-11-07 18:10 - 2013-11-09 23:25 - 00798734 _____ C:\Windows\SysWOW64\amdocl_ld32.exe 2013-11-07 18:10 - 2013-11-09 23:25 - 00100352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2013-11-07 18:10 - 2013-11-09 23:25 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2013-11-07 18:10 - 2013-11-09 23:25 - 00083968 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2013-11-07 18:10 - 2013-11-09 23:25 - 00073728 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2013-11-07 18:07 - 2013-11-09 23:25 - 24846848 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2013-11-07 18:05 - 2013-11-09 23:25 - 00063488 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-11-07 18:05 - 2013-11-09 23:25 - 00057344 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2013-11-07 18:02 - 2013-11-09 23:25 - 00129536 _____ (AMD) C:\Windows\system32\coinst_13.25.18.dll 2013-11-07 17:44 - 2013-11-09 23:25 - 26350592 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-11-07 17:41 - 2013-11-09 23:25 - 00547152 _____ C:\Windows\SysWOW64\atiapfxx.blb 2013-11-07 17:41 - 2013-11-09 23:25 - 00547152 _____ C:\Windows\system32\atiapfxx.blb 2013-11-07 17:40 - 2013-11-09 23:25 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-11-07 17:40 - 2013-11-09 23:25 - 00368640 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-11-07 17:40 - 2013-11-09 23:25 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-11-07 17:40 - 2013-11-09 23:25 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-11-07 17:40 - 2013-11-09 23:25 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-11-07 17:40 - 2013-11-09 23:25 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-11-07 17:37 - 2013-11-09 23:25 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-11-07 17:26 - 2013-11-09 23:25 - 22156288 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-11-07 17:21 - 2013-11-09 23:25 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2013-11-07 17:21 - 2013-11-09 23:25 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2013-11-07 17:20 - 2013-11-09 23:25 - 00585216 _____ (AMD) C:\Windows\system32\atieclxx.exe 2013-11-07 17:20 - 2013-11-09 23:25 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2013-11-07 17:18 - 2013-11-09 23:25 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2013-11-07 17:09 - 2013-11-09 23:25 - 03399312 _____ C:\Windows\system32\atiumd6a.cap 2013-11-07 17:06 - 2013-11-09 23:25 - 00204952 _____ C:\Windows\SysWOW64\ativvsvl.dat 2013-11-07 17:06 - 2013-11-09 23:25 - 00204952 _____ C:\Windows\system32\ativvsvl.dat 2013-11-07 17:06 - 2013-11-09 23:25 - 00157144 _____ C:\Windows\SysWOW64\ativvsva.dat 2013-11-07 17:06 - 2013-11-09 23:25 - 00157144 _____ C:\Windows\system32\ativvsva.dat 2013-11-07 16:58 - 2013-11-09 23:25 - 03433360 _____ C:\Windows\SysWOW64\atiumdva.cap 2013-11-07 16:50 - 2013-11-09 23:25 - 01145344 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00825856 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00100352 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00096768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00074752 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-11-07 16:50 - 2013-11-09 23:25 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2013-11-07 16:49 - 2013-11-09 23:25 - 00624128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-11-07 16:46 - 2013-11-09 23:25 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2013-11-07 16:00 - 2012-01-10 19:35 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-07 12:21 - 2013-11-07 12:21 - 00051200 _____ C:\Windows\system32\kdbsdk64.dll 2013-11-07 12:16 - 2013-11-07 12:16 - 00038912 _____ C:\Windows\SysWOW64\kdbsdk32.dll 2013-11-05 14:57 - 2013-11-05 14:57 - 02843432 _____ (O&O Software GmbH) C:\Windows\system32\ooscrsav.scr 2013-11-05 14:57 - 2013-11-05 14:57 - 00543528 _____ (O&O Software GmbH) C:\Windows\system32\oodssrs.dll 2013-11-05 14:57 - 2013-11-05 14:57 - 00240936 _____ (O&O Software GmbH) C:\Windows\system32\oodbs.exe 2013-11-05 14:57 - 2013-11-05 14:57 - 00011048 _____ (O&O Software GmbH) C:\Windows\system32\oodbsrs.dll 2013-11-05 08:59 - 2013-11-05 08:59 - 00000000 ____D C:\Program Files\ATI Technologies 2013-11-02 16:23 - 2011-06-19 00:22 - 00000876 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-11-01 04:48 - 2013-08-30 23:52 - 00679718 _____ C:\Windows\system32\perfh00A.dat 2013-11-01 04:48 - 2013-08-30 23:52 - 00129614 _____ C:\Windows\system32\perfc00A.dat 2013-10-27 03:18 - 2013-10-27 03:18 - 00000000 ____D C:\AMD 2013-10-23 19:26 - 2011-08-22 14:36 - 00012862 _____ C:\Windows\EPISMG00.SWB 2013-10-22 13:13 - 2013-11-13 05:02 - 00455328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120.dll 2013-10-21 19:34 - 2013-10-21 19:34 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-21 14:48 - 2013-10-21 14:49 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-21 14:48 - 2013-10-21 14:48 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-21 14:48 - 2013-10-21 14:48 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-21 14:48 - 2013-10-21 14:48 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-21 14:46 - 2013-10-21 14:46 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-21 14:46 - 2013-10-21 14:46 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-10-19 01:42 - 2013-03-02 06:05 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-19 01:42 - 2013-03-02 06:05 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-19 01:42 - 2012-02-23 23:24 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-19 01:42 - 2012-02-23 23:24 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-19 01:42 - 2012-02-23 23:24 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-19 01:42 - 2012-02-23 23:24 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-19 01:42 - 2012-02-23 23:24 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-19 01:42 - 2012-02-23 23:23 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-19 01:42 - 2012-02-23 22:58 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-19 01:18 - 2011-06-19 00:52 - 00000000 _____ C:\Windows\SysWOW64\config.nt ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2012-01-10 18:35 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-11-2013 Ran by Uli at 2013-11-15 01:36:40 Running from C:\Users\Uli\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== µTorrent (HKCU Version: 3.4.0.30331) abcAVI (x32) AC3Filter 2.5b (x32 Version: 2.5b) Adblock Plus for IE (32-bit and 64-bit) (Version: 1.1) Adblock Plus for IE (x32 Version: 1.1) Adobe Extension Manager CC (x32 Version: 7.1) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Photoshop CS6 (x32 Version: 13.0) AMD Accelerated Video Transcoding (Version: 13.20.100.31107) AMD APP CPU SDK Runtime (Version: 2.8.1016.5) AMD APP SDK Developer (Version: 2.8.1016.5) AMD APP SDK Runtime (Version: 10.0.1124.2) AMD APP SDK Samples (x32 Version: 2.8.1016.5) AMD AVIVO64 Codecs (Version: 12.5.100.20611) AMD Catalyst Install Manager (Version: 8.0.915.0) AMD Demo - Leo (x32 Version: 1.1) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.81107.1147) AMD Wireless Display v3.0 (Version: 1.0.0.12) AMD Wireless Display v3.0 (Version: 1.0.0.14) AnyDVD (x32 Version: 7.1.6.0) Application Profiles (x32 Version: 2.0.4674.34053) Application Profiles (x32 Version: 2.0.4719.35969) Application Profiles (x32 Version: 2.0.4888.34279) Audacity 2.0.5 (x32 Version: 2.0.5) avast! Free Antivirus (x32 Version: 9.0.2006) Avidemux 2.6 - 64bits (x32 Version: 2.6.6.8941) Avidemux 2.6 (x32 Version: 2.6.1.8321) Biet-O-Matic v2.14.8 (x32 Version: 2.14.8) BioShock 2 (x32 Version: 1.0.0005.131) BioShock Infinite (x32) BioShock Infinite Burial at Sea - Episode 1 (x32 Version: 1) BioShock Infinite Update v1.1.22.55730 1.0 (x32) Caesar IV (x32 Version: 1.2) CanoScan Toolbox Ver4.9 (x32) Catalyst Control Center InstallProxy (x32 Version: 2012.1022.2311.39807) Catalyst Control Center InstallProxy (x32 Version: 2013.1107.1129.20543) CCleaner (Version: 4.07) CDBurnerXP (x32 Version: 4.5.2.4291) CloneDVD2 (x32 Version: 2.9.3.0) CyberLink PowerDirector 11 (Version: 11.0.0.3230) CyberLink PowerDirector 11 (x32 Version: 11.0.0.3230) CyberLink PowerDirector 11 Content Pack Essential (x32 Version: 11) CyberLink PowerDirector 11 Content Pack Premium (x32 Version: 11) D3DX10 (x32 Version: 15.4.2368.0902) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition DHTML Editing Component (x32 Version: 6.02.0001) DivX-Setup (x32 Version: 2.6.1.84) Droppix Label Maker 2.x (x32 Version: 2.9.8) DVD Audio Extractor 6.3.0 (x32) eMule (x32) ENSLAVED: Odyssey to the West Premium Edition (x32) EPSON-Drucker-Software Eusing Free Registry Cleaner (x32) FFmpeg v0.6.2 for Audacity (x32) FIFA 13 (x32 Version: 1.7.0.0) Flashtool (x32 Version: 0.9.0.0) Fotogalerie (x32 Version: 16.4.3505.0912) Google Earth Plug-in (x32 Version: 6.2.2.6613) HD Tune 2.55 (x32) HydraVision (x32 Version: 4.2.248.0) Icaros 2.1.5 (Version: 2.1.5.0) IP Camera DS Filter (x32 Version: 5.5.0.0) Java 7 Update 45 (64-bit) (Version: 7.0.450) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) JDownloader 0.9 (x32 Version: 0.9) LADSPA_plugins-win-0.4.15 (x32) LAME v3.99.3 (for Windows) (x32) LibreOffice 4.0.5.2 (x32 Version: 4.0.5.2) LightScribe System Software (x32 Version: 1.18.26.7) Lyrics Plugin for Windows Media Player (x32 Version: 0.4) Marvell Miniport Driver (x32 Version: 11.45.4.3) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0) Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0) Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Xbox 360 Accessories 1.2 (Version: 1.20.146.0) Microsoft XNA Framework Redistributable 3.1 (x32 Version: 3.1.10527.0) Microsoft XNA Framework Redistributable 4.0 Refresh (x32 Version: 4.0.30901.0) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053) Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000) Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000) Morphyre (x32) Movie Maker (x32 Version: 16.4.3505.0912) Mozilla Firefox 25.0 (x86 de) (x32 Version: 25.0) Mozilla Maintenance Service (x32 Version: 25.0) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT110 (x32 Version: 16.4.1108.0727) MSVCRT110_amd64 (Version: 16.4.1109.0912) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) MSXML 4.0 SP2 Parser und SDK (x32 Version: 4.20.9818.0) MuseScore 1.3 (x32 Version: 1.3.0) neroxml (x32 Version: 1.0.0) Newblue Art Effects for PowerDirector (Version: 2.0) NirSoft RegScanner (x32) NVIDIA Drivers (Version: 1.10.62.40) NVIDIA PhysX (x32 Version: 9.12.1031) O&O Defrag Professional (Version: 17.0.468) OpenAL (x32) Origin (x32 Version: 8.5.0.4550) PDF Settings CS6 (x32 Version: 11.0) PDF-Viewer (Version: 2.5.212.0) PDF-XChange Lite 2012 (Version: 5.0.266.0) PDF-XChange Pro 4.0 (Version: 4.201.201.0) Photo Gallery (x32 Version: 16.4.3505.0912) PowerDirector (Version: 11.0) Prio (Version: 2.0.0.2960) Rapture3D 2.5.6 Game (x32) Ray Adams ATI Tray Tools (x32) Readiris Pro 14 (x32 Version: 14.00.2573) Realtek AC'97 Audio (x32 Version: 5.37) Recuva (Version: 1.48) Resource Hacker Version 3.6.0 (x32) Revo Uninstaller Pro 3.0.7 (Version: 3.0.7) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition Shutdown Timer (Version: 3.3) Skype™ 6.10 (x32 Version: 6.10.104) SmartSound Quicktracks 5 (x32 Version: 5.1.8) Sony Ericsson Update Engine (x32 Version: 2.12.10.19) Sony PC Companion 2.10.136 (x32 Version: 2.10.136) SopCast 3.5.0 (x32 Version: 3.5.0) SpeedFan (remove only) (x32) Steam (x32 Version: 1.0.0.0) SUPER © v2013.build.56+Recorder (2013/07/07) Version v2013.buil (x32 Version: v2013.build.56+Recorder) TmNationsForever Update 2010-03-15 (x32) Turbo Lister 2 (x32 Version: 2.00.0000) UnderCoverXP 1.23 (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition Update for Microsoft Word 2010 (KB2827323) 64-Bit Edition VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) VLC media player 2.1.0 (x32 Version: 2.1.0) VOB2MPG v3 (x32 Version: 3.2.2000) Vsk5Online (x32) WinCDEmu (x32 Version: 3.6) Windows Live Communications Platform (x32 Version: 16.4.3505.0912) Windows Live Essentials (x32 Version: 16.4.3505.0912) Windows Live ID Sign-in Assistant (Version: 7.250.4311.0) Windows Live Installer (x32 Version: 16.4.3505.0912) Windows Live Photo Common (x32 Version: 16.4.3505.0912) Windows Live PIMT Platform (x32 Version: 16.4.3505.0912) Windows Live SOXE (x32 Version: 16.4.3505.0912) Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912) Windows Live UX Platform (x32 Version: 16.4.3505.0912) Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8) WinRAR 5.00 (64-Bit) (Version: 5.00.0) Xilisoft Audio Converter Pro (x32 Version: 6.5.0.20130130) Zattoo4 4.0.5 (x32 Version: 4.0.5) ==================== Restore Points ========================= 14-11-2013 20:35:39 Windows Update 14-11-2013 20:40:29 Neu 15-11-2013 00:28:20 Plumby ==================== Hosts content: ========================== 2011-07-27 16:09 - 2013-03-16 07:36 - 00001790 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 activate.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 activation.guitar-pro.com 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com There are 3 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {01F5F60C-934A-43DA-8805-6F33A76EC791} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe Task: {02BCA020-3F7E-468B-ABD4-5B151F545330} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe Task: {0719C0FE-0BA7-4EDB-96DF-4491928C9A33} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe Task: {0B995FA7-6E28-4570-9767-59C0AA735E94} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe Task: {0E7FEAFA-95DC-4028-8D08-F5ABE6BA8AAF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {1345CC48-6875-4222-B253-5B89DA0D7594} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe Task: {15FC12AA-E955-4E93-9BB5-94EBF8AE50EF} - System32\Tasks\AdobeAAMUpdater-1.0-Brotkasten-Uli => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2013-06-03] (Adobe Systems Incorporated) Task: {21829168-4C21-4733-8F03-6D8DE87EA6DB} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {35F7F919-2DA7-4966-8029-852E1DAB3764} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe Task: {3A089DDE-9116-4F78-873F-16C986D93CF2} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {44735BED-D193-4B39-9C8A-7325C4C314F1} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {4897BA5C-27DC-4748-8249-CED75F674851} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe Task: {4F7F2A3F-B8AE-4FA8-A7BD-DE7522D8BC49} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe Task: {585ACABB-6387-4448-BADF-C637B941D49B} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe Task: {5D32B3BC-4122-44B8-9954-D285B565D36F} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe Task: {90301DDC-F95C-4AED-98E4-3DFFE3224DF2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd) Task: {9D782A93-EB5A-4BF4-83FB-2E7F2198002C} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {A28E751B-7B0C-417A-9A26-81CBE16D9F69} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {AB251AE5-0346-45BE-B4F8-DDA32304D020} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-08] (Adobe Systems Incorporated) Task: {C0FB1E7E-751E-4E5A-8D8D-A0611C70E3A9} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe Task: {C45A20A4-F802-41C4-A0E0-61782EB3E7D8} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {C4E3A8DD-2E68-4797-BBE4-2A82406C4509} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe Task: {D8DA7378-D7CF-4EF0-B55F-5FB7D02039E0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe Task: {DBD931B0-97A2-4A13-94A7-85C8454202BE} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-10-19] (AVAST Software) Task: {DD24E6B9-53C6-4168-B188-DD7DA1D0119F} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {E4481A1B-37F8-4D18-AC72-7A22B3C5A5CA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {E58844B8-6414-4F9D-A2FD-9F9B98BE58CD} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {E5B3ECFD-97C4-4FAE-8B3B-A1BFA8376481} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe Task: {E60C85DF-4D61-4C73-BE6A-5443C2FF9104} - \Happy Lyrics Update No Task File Task: {EBFA90EB-D966-4033-96F0-888E4115420A} - System32\Tasks\XboxStatTask => C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe [2009-09-30] (Microsoft Corporation) Task: {EDA21C4C-9A91-4F53-A381-D26279BE1977} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2013-11-15 01:03 - 2013-11-14 21:51 - 02141184 _____ () C:\Program Files\AVAST Software\Avast\defs\13111401\algo.dll 2011-10-29 22:12 - 2011-10-29 22:12 - 00187392 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\raphook.dll 2007-03-07 13:26 - 2007-03-07 13:26 - 00077824 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\support.dll 2007-03-07 13:25 - 2007-03-07 13:25 - 00024576 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\kbdhook.dll 2005-11-29 18:38 - 2005-11-29 18:38 - 00023552 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\hddtemp.dll 2008-04-09 17:08 - 2008-04-09 17:08 - 00016896 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mg_amdcore.dll 2007-09-14 16:35 - 2007-09-14 16:35 - 00020480 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mg_cpuload.dll 2006-12-26 18:53 - 2006-12-26 18:53 - 00019456 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mg_hdddtemp.dll 2008-04-11 17:33 - 2008-04-11 17:33 - 00020480 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mg_intelcpu.dll 2007-01-03 21:09 - 2007-01-03 21:09 - 00017408 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mg_xvlt.dll 2006-12-25 10:02 - 2006-12-25 10:02 - 00024576 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\mongraphsexample.dll 2005-11-29 18:34 - 2005-11-29 18:34 - 00028672 _____ () C:\Program Files (x86)\Ray Adams\ATI Tray Tools\plugins\pciset.dll 2013-10-19 01:42 - 2013-10-19 01:42 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-10-30 15:33 - 2013-10-30 15:33 - 03368048 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/15/2013 01:32:30 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 01:24:07 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 01:20:22 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 01:17:25 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 01:09:16 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 01:00:25 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 00:36:22 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 00:26:44 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 00:22:08 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 00:15:55 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (11/15/2013 01:33:32 AM) (Source: NVNET) (User: ) Description: NVIDIA nForce 10/100/1000 Mbps Ethernet : Ungültige Netzwerkadresse entdeckt. Error: (11/15/2013 01:32:18 AM) (Source: DCOM) (User: ) Description: {37734C4D-FFA8-4139-9AAC-60FBE55BF3DF} Error: (11/15/2013 01:31:48 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Blockebenen-Sicherungsmodul" wurde mit folgendem Fehler beendet: %%-2147024713 Error: (11/15/2013 01:30:41 AM) (Source: NVNET) (User: ) Description: NVIDIA nForce 10/100/1000 Mbps Ethernet : Ungültige Netzwerkadresse entdeckt. Error: (11/15/2013 01:22:14 AM) (Source: NVNET) (User: ) Description: NVIDIA nForce 10/100/1000 Mbps Ethernet : Ungültige Netzwerkadresse entdeckt. Error: (11/15/2013 01:20:57 AM) (Source: NVNET) (User: ) Description: NVIDIA nForce 10/100/1000 Mbps Ethernet : Ungültige Netzwerkadresse entdeckt. Error: (11/15/2013 01:18:32 AM) (Source: NVNET) (User: ) Description: NVIDIA nForce 10/100/1000 Mbps Ethernet : Ungültige Netzwerkadresse entdeckt. Error: (11/15/2013 01:17:17 AM) (Source: DCOM) (User: ) Description: {37734C4D-FFA8-4139-9AAC-60FBE55BF3DF} Error: (11/15/2013 01:16:47 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Blockebenen-Sicherungsmodul" wurde mit folgendem Fehler beendet: %%-2147024713 Error: (11/15/2013 01:15:35 AM) (Source: NVNET) (User: ) Description: NVIDIA nForce 10/100/1000 Mbps Ethernet : Ungültige Netzwerkadresse entdeckt. Microsoft Office Sessions: ========================= Error: (11/15/2013 01:32:30 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 01:24:07 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 01:20:22 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 01:17:25 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 01:09:16 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 01:00:25 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 00:36:22 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 00:26:44 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 00:22:08 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/15/2013 00:15:55 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2013-03-04 19:12:35.358 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-04 19:12:35.311 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-04 19:00:50.281 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-04 19:00:50.234 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-04 18:40:23.078 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-04 18:40:23.000 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\RASPPPOE.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-12-21 02:47:14.781 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-12-21 02:47:14.734 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-12-21 01:00:34.734 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-12-21 01:00:34.671 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 41% Total physical RAM: 4094.49 MB Available physical RAM: 2404.7 MB Total Pagefile: 8187.16 MB Available Pagefile: 6420.99 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (Powerpack!) (Fixed) (Total:465.76 GB) (Free:224.44 GB) NTFS ==>[Drive with boot components (obtained from BCD)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: C8950CBC) Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
15.11.2013, 10:36 | #8 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7 1) Systemwiederherstellungspunkte nach Neustart weg / 2) F8-Menü -> Abgesicherter Modus etc. funktioniert nicht mehrZitat:
Bitte lesen => http://www.trojaner-board.de/95393-c...-software.html Es geht weiter wenn du alles Illegale entfernt hast. Bei wiederholten Crack/Keygen Verstößen behalte ich es mir vor, den Support einzustellen, d.h. Hilfe nur noch bei der Datensicherung und Neuinstallation des Betriebssystems.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Windows 7 1) Systemwiederherstellungspunkte nach Neustart weg / 2) F8-Menü -> Abgesicherter Modus etc. funktioniert nicht mehr |
funktioniert nicht mehr |