|
Plagegeister aller Art und deren Bekämpfung: Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr anWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
29.01.2014, 13:29 | #1 | |
| Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Hallo, Ich habe das Problem das ich in Firefox keine weiterführende Links (zum öffnen von Bildern oder z.Bsp. Kleinanzeigen) anklicken kann. Außerdem öffnet er plötzlich popups zu AdFly obwol ein Adblocker instaliert ist. Auch die Avira Toolbar ist jedesmal beim Neustart des rechners deaktiviert. Ein Bekannter riet mir Malwarebytes zu instalieren und auszuführen. Das habe ich auch getan. Es hat 6 Funde gefunden und gelöscht (Logfile weiter unten). als dann das Problem mit Firefox weiter bestand wurde ir geraten Windows zu reparieren mittels Instalations DVD. Auch das habe ich getan nur leider ist das Problem dadurch nicht weg. Nun habe ich das Forum hier gefunden und glaube das meine Aktionen vieleicht nicht so klug waren. Das Problem besteht übrigen nur in Frefox. Ich wollte über Firefox hier meine Problem schreiben jedoch geht das nicht weil immer die Meldunbg kommt das nicht genug Wörter (min 3) im Komentarfeld stehen müssen. Es sind ja aber offensichtlich mehr. Vileicht hängt das ja auch damit zusammen. Ich habe folgende Programme instaliert: Win 7 Professional sp1 Avira Antivir Suite (bezahl Version) Spyboot Malwarebytes Testversion Hier die Logfile von dem Fund: Zitat:
Auch Antivir zeigt nichts an. Ich wäre euch echt dankbar wenn Ihr mir helfen könnt. Gruß Patrick |
29.01.2014, 13:57 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
29.01.2014, 14:24 | #3 |
| Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Danke für die schnelle Antwort. In Ativir ist kein Fund aufgelistet und es gab auch keine Meldung. Und Malwarebyte hatte nur einmal einen Fund den dan Löschen lies. Danach kam nix mehr. Ander Virenprogramme habe ich nicht instaliert.
__________________Spyboot hat noch Logfiles. Ich weis nicht welche du brauchst. Älter als 3 Tage habe ich weggelassen. Code:
ATTFilter RootAlyzer Quick Scan Results Dateien im Windows-Verzeichnis ---------------------------------------- 1 versteckte von 112 Dateien wurden entdeckt. Versteckte Dateien:version C:\Windows\version ======================================== Dateien im Systemverzeichnis ---------------------------------------- 2 versteckte von 2510 Dateien wurden entdeckt. Versteckte Dateien:伆,煰ア¬ C:\Windows\System32\伆 C:\Windows\System32\煰ア¬ ======================================== Systemweite Starteinträge ---------------------------------------- Keine versteckten Einträge gefunden. ======================================== Winlogon-Einträge ---------------------------------------- Keine versteckten Einträge gefunden. ======================================== Versteckte Prozesse (mittels Handles) ---------------------------------------- 0 Handle-Prozess-IDs für 68 Prozesse. Keine versteckten Prozesse entdeckt. ======================================== Versteckte Prozesse (mittels Threads) ---------------------------------------- 68 Prozesse überprüft. Keine versteckten Prozesse entdeckt. ======================================== Master Boot Records ---------------------------------------- 2 MBRs überprüft. Unbekannte MBRs: PhysicalDrive1 PhysicalDrive1 ======================================== Code:
ATTFilter Search results from Spybot - Search & Destroy 25.01.2014 12:21:19 Scan took 00:13:50. 23 items found. Babylon.Toolbar: [SBI $DEB52F26] Program directory (Directory, nothing done) C:\ProgramData\Babylon\ Babylon.Toolbar: [SBI $DEB52F26] Program directory (Directory, nothing done) C:\Users\Patrick Polzyn\AppData\Roaming\Babylon\ Directory.subfile=C:\Users\Patrick Polzyn\AppData\Roaming\Babylon\log_file.txt Directory.subfile.size=3051 Directory.subfile.md5=91E363FA6C22F0C0AA174C1DBAD01FA8 Directory.subfile.filedate=1380293971 Directory.subfile.filedatetext=2013-09-27 15:59:31 Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent MS Direct3D: [SBI $7FB7B83F] Most recent application (Registry Change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done) HKEY_USERS\.DEFAULT\Software\Microsoft\Direct3D\MostRecentApplication\Name MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Direct3D\MostRecentApplication\Name MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done) HKEY_USERS\S-1-5-18\Software\Microsoft\Direct3D\MostRecentApplication\Name MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry Change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name Windows.OpenWith: [SBI $286A25C6] Open with list - .ACE extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ACE\OpenWithList Windows.OpenWith: [SBI $59A5380C] Open with list - .ACF extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ACF\OpenWithList Windows.OpenWith: [SBI $F7204896] Open with list - .AVI extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AVI\OpenWithList Windows.OpenWith: [SBI $691C1B44] Open with list - .BIN extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BIN\OpenWithList Windows.OpenWith: [SBI $A1C94E79] Open with list - .BMP extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\OpenWithList Windows Explorer: [SBI $AA0766B5] Stream history (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry Change, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows Media\WMSDK\General\ComputerName Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry Change, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows Media\WMSDK\General\UniqueID Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry Value, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber WinRAR: [SBI $0B56E92B] Recent file list (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\WinRAR\ArcHistory WinRAR: [SBI $B510882E] Extraction directory history (Registry Key, nothing done) HKEY_USERS\S-1-5-21-3036222249-3704697464-1483458611-1000\Software\WinRAR\DialogEditHistory\ExtrPath Verlauf: [SBI $49804B54] Browser: History (4) (Browser: History, nothing done) Cookie: [SBI $49804B54] Browser: Cookie (63) (Browser: Cookie, nothing done) --- Spybot - Search & Destroy version: 2.0.12.131 DLL (build: 20121113) --- 2012-11-13 blindman.exe (2.0.12.151) 2012-11-13 explorer.exe (2.0.12.173) 2012-11-13 SDBootCD.exe (2.0.12.109) 2012-11-13 SDCleaner.exe (2.0.12.110) 2012-11-13 SDDelFile.exe (2.0.12.94) 2012-11-13 SDFiles.exe (2.0.12.135) 2012-11-13 SDFileScanHelper.exe (2.0.12.1) 2012-11-13 SDFSSvc.exe (2.0.12.205) 2012-11-13 SDImmunize.exe (2.0.12.130) 2012-11-13 SDLogReport.exe (2.0.12.107) 2012-11-13 SDPESetup.exe (2.0.12.3) 2012-11-13 SDPEStart.exe (2.0.12.86) 2012-11-13 SDPhoneScan.exe (2.0.12.27) 2012-11-13 SDPRE.exe (2.0.12.13) 2012-11-13 SDPrepPos.exe (2.0.12.10) 2012-11-13 SDQuarantine.exe (2.0.12.103) 2012-11-13 SDRootAlyzer.exe (2.0.12.116) 2012-11-13 SDSBIEdit.exe (2.0.12.39) 2012-11-13 SDScan.exe (2.0.12.173) 2012-11-13 SDScript.exe (2.0.12.53) 2012-11-13 SDSettings.exe (2.0.12.130) 2012-11-13 SDShred.exe (2.0.12.105) 2012-11-13 SDSysRepair.exe (2.0.12.101) 2012-11-13 SDTools.exe (2.0.12.150) 2012-11-13 SDTray.exe (2.0.12.127) 2012-11-13 SDUpdate.exe (2.0.12.89) 2012-11-13 SDUpdSvc.exe (2.0.12.76) 2012-11-13 SDWelcome.exe (2.0.12.126) 2012-11-13 SDWSCSvc.exe (2.0.12.2) 2013-01-16 unins000.exe (51.1052.0.0) 1999-12-02 xcacls.exe 2012-08-23 borlndmm.dll (10.0.2288.42451) 2012-09-05 DelZip190.dll (1.9.0.107) 2012-09-10 libeay32.dll (1.0.0.4) 2012-09-10 libssl32.dll (1.0.0.4) 2012-11-13 SDAdvancedCheckLibrary.dll (2.0.12.98) 2012-11-13 SDECon32.dll (2.0.12.113) 2012-11-13 SDECon64.dll (2.0.12.113) 2012-11-13 SDEvents.dll (2.0.12.2) 2012-11-13 SDFileScanLibrary.dll (2.0.12.9) 2012-11-13 SDHelper.dll (2.0.12.88) 2012-11-13 SDImmunizeLibrary.dll (2.0.12.2) 2012-11-13 SDLists.dll (2.0.12.4) 2012-11-13 SDResources.dll (2.0.12.7) 2012-11-13 SDScanLibrary.dll (2.0.12.131) 2012-11-13 SDTasks.dll (2.0.12.15) 2012-11-13 SDWinLogon.dll (2.0.12.0) 2012-08-23 sqlite3.dll 2012-09-10 ssleay32.dll (1.0.0.4) 2012-11-13 Tools.dll (2.0.12.36) 2012-11-13 UninsSrv.dll (2.0.12.52) 2012-12-18 Includes\Adware.sbi (*) 2013-05-27 Includes\AdwareC.sbi (*) 2010-08-13 Includes\Cookies.sbi (*) 2012-11-14 Includes\Dialer.sbi (*) 2012-11-14 Includes\DialerC.sbi (*) 2012-11-14 Includes\HeavyDuty.sbi (*) 2012-11-14 Includes\Hijackers.sbi (*) 2012-11-14 Includes\HijackersC.sbi (*) 2012-11-14 Includes\iPhone.sbi (*) 2012-11-14 Includes\Keyloggers.sbi (*) 2012-12-18 Includes\KeyloggersC.sbi (*) 2013-05-28 Includes\Malware.sbi (*) 2013-05-28 Includes\MalwareC.sbi (*) 2012-11-14 Includes\PUPS.sbi (*) 2013-05-21 Includes\PUPSC.sbi (*) 2012-11-14 Includes\Security.sbi (*) 2012-11-14 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2013-05-21 Includes\Spyware.sbi (*) 2013-05-07 Includes\SpywareC.sbi (*) 2011-06-07 Includes\Tracks.sbi (*) 2012-11-19 Includes\Tracks.uti (*) 2013-01-16 Includes\Trojans.sbi (*) 2013-05-12 Includes\TrojansC-02.sbi (*) 2013-05-28 Includes\TrojansC-03.sbi (*) 2013-03-13 Includes\TrojansC-04.sbi (*) 2013-05-07 Includes\TrojansC-05.sbi (*) 2013-04-18 Includes\TrojansC.sbi (*) FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 01 Ran by Patrick Polzyn (administrator) on PATRICKPOLZYN on 29-01-2014 14:08:49 Running from C:\Users\Patrick Polzyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYPJZKPN Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Realtek) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe (Realtek) C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\RtlService.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Microsoft Corporation) C:\Windows\System32\LogonUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (Autodesk, Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ServiceLocator.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Toolbar.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (Farbar) C:\Users\Patrick Polzyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYPJZKPN\FRST64[1].exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor) HKLM-x32\...\Run: [ADSK DLMSession] - C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1641368 2013-02-01] (Autodesk, Inc.) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1778640 2013-12-20] (APN) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1815976 2014-01-27] (Valve Corporation) HKU\Administrator\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516096 2010-11-21] (Microsoft Corporation) HKU\UpdatusUser\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKU\UpdatusUser\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1815976 2014-01-27] (Valve Corporation) HKU\UpdatusUser\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516096 2010-11-21] (Microsoft Corporation) AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-10-27] (NVIDIA Corporation) AppInit_DLLs: C:\PROGRA~1\LUCIDL~1\VIRTU\APPINI~1.DLL => C:\Program Files\Lucidlogix Technologies\VIRTU\appinit_dll.dll [188704 2011-08-08] (Lucidlogix Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=647ABC5FF40E1A85&affID=119357&tt=250913_nocpn&tsp=5018 SearchScopes: HKCU - {5296BDA4-2B7E-4BA6-967A-DEDF0C5EF2FE} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=7779cf80-3995-4fa9-88b1-c1c49f097328&apn_sauid=9188E539-ADAA-4997-8E35-E120D657C537 BHO: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.) BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll No File BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GbR) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default FF user.js: detected! => C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\user.js FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\searchplugins\askcom.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Garmin Communicator - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013-11-19] FF Extension: WOT - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26] FF Extension: DownloadHelper - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013-08-27] FF Extension: Easy YouTube MP3 Downloader - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\5@thumbpro.net.xpi [2013-06-26] FF Extension: Adblock Plus Pop-up Addon - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\adblockpopups@jessehakanen.net.xpi [2012-10-29] FF Extension: MP3 Download! - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\anthonyytmp3download@gmail.com.xpi [2013-06-26] FF Extension: InvisibleHand - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\canitbecheaper@trafficbroker.co.uk.xpi [2012-10-18] FF Extension: YouTube to MP3 - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\info@sharkcube.com.xpi [2013-06-26] FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\toolbar_AVIRA-V7C@apn.ask.com.xpi [2013-12-20] FF Extension: NoScript - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-25] FF Extension: Adblock Plus - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-10-30] FF Extension: DownThemAll! - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2012-10-30] FF Extension: QuickJava - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi [2012-10-18] FF Extension: JavaScript Debugger - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi [2012-10-18] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-01-06] ==================== Services (Whitelisted) ================= S4 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-22] (Adobe Systems) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [908856 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-12] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-17] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.) S4 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [393032 2013-06-19] (BlueStack Systems, Inc.) S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384840 2013-06-19] (BlueStack Systems, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 mi-raysat_3dsmax2014_64; C:\Program Files\Autodesk\3ds Max 2014\NVIDIA\Satellite\raysat_3dsmax2014_64server.exe [86016 2011-09-15] () S4 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR) S4 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR) R2 Realtek11nSU; C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [45056 2010-01-21] (Realtek) R2 RealtekPCIE; C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\RtlService.exe [45056 2010-01-21] (Realtek) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-17] (Avira Operations GmbH & Co. KG) R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [70984 2013-06-19] (BlueStack Systems) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-01-18] (FNet Co., Ltd.) S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 rtl819xpn64; C:\Windows\System32\DRIVERS\rtl819xp.sys [622624 2010-02-01] (Realtek Semiconductor Corporation ) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S4 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [68608 2005-08-10] (Protection Technology) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-29 14:06 - 2014-01-29 14:08 - 00000000 ____D C:\FRST 2014-01-29 11:24 - 2014-01-29 11:27 - 00009302 _____ C:\Windows\IE10_main.log 2014-01-29 10:54 - 2014-01-29 10:54 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\AskPartnerNetwork 2014-01-29 10:46 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2014-01-29 10:46 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2014-01-29 10:41 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2014-01-29 10:25 - 2011-11-19 15:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-01-29 10:25 - 2011-11-19 15:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-01-29 04:21 - 2014-01-28 21:06 - 00000000 ____D C:\Windows\Panther 2014-01-29 04:18 - 2014-01-29 04:18 - 00262144 _____ C:\Windows\system32\config\userdiff 2014-01-29 04:18 - 2011-02-16 03:16 - 00000029 ___RH C:\Windows\version 2014-01-29 04:18 - 2011-02-16 03:16 - 00000013 ____R C:\Windows\csup.txt 2014-01-29 04:17 - 2014-01-29 13:20 - 00696132 _____ C:\Windows\system32\perfh007.dat 2014-01-29 04:17 - 2014-01-29 13:20 - 00147428 _____ C:\Windows\system32\perfc007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00295922 _____ C:\Windows\system32\perfi007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00038104 _____ C:\Windows\system32\perfd007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\0407 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\0407 2014-01-29 04:09 - 2014-01-28 20:35 - 00000000 ___HD C:\$WINDOWS.~Q 2014-01-29 03:51 - 2014-01-29 03:58 - 00000000 ___HD C:\$INPLACE.~TR 2014-01-28 21:13 - 2014-01-29 11:05 - 01588294 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-28 21:10 - 2014-01-28 21:10 - 00001443 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-28 21:10 - 2014-01-28 21:10 - 00001409 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-01-28 21:06 - 2014-01-28 21:06 - 00000020 ___SH C:\Users\Patrick Polzyn\ntuser.ini 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Favoriten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Dokumente 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2014-01-28 20:55 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2014-01-28 20:55 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2014-01-28 20:55 - 2012-02-17 05:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-01-28 20:55 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2014-01-28 20:47 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-01-28 20:47 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-01-28 20:47 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-01-28 20:47 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-01-28 20:47 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-01-28 20:47 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-01-28 20:47 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-01-28 20:46 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-01-28 20:46 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-01-28 19:27 - 2014-01-28 21:06 - 00000000 ____D C:\Users\Patrick Polzyn 2014-01-28 19:27 - 2014-01-28 20:18 - 00000000 ____D C:\Users\Administrator 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Anwendungsdaten 2014-01-28 19:27 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 19:27 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 19:27 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 19:27 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 19:27 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 19:27 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 19:26 - 2014-01-28 19:59 - 00000000 ____D C:\ProgramData\EPSON 2014-01-28 19:26 - 2014-01-28 19:37 - 00000000 ____D C:\Program Files\Common Files\EPSON 2014-01-28 19:26 - 2014-01-28 19:26 - 00001355 _____ C:\Windows\TSSysprep.log 2014-01-28 19:25 - 2014-01-29 13:27 - 01184019 _____ C:\Windows\WindowsUpdate.log 2014-01-28 19:25 - 2014-01-29 13:13 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-28 19:25 - 2014-01-28 19:59 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2014-01-28 19:25 - 2014-01-28 19:40 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-28 19:25 - 2014-01-28 19:37 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files\Realtek 2014-01-28 19:25 - 2013-10-23 09:20 - 06669600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 03489568 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 03426956 _____ C:\Windows\system32\nvcoproc.bin 2014-01-28 19:25 - 2013-10-23 09:20 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-01-28 19:25 - 2013-10-23 09:20 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-01-28 19:24 - 2014-01-28 19:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-01-28 18:22 - 2014-01-28 20:35 - 00006773 _____ C:\Windows\comsetup.log 2014-01-27 18:55 - 2014-01-28 20:20 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Malwarebytes 2014-01-27 18:55 - 2014-01-28 19:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-27 18:55 - 2014-01-28 19:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-27 18:55 - 2014-01-27 18:56 - 00000000 ____D C:\AdwCleaner 2014-01-27 18:55 - 2014-01-27 18:55 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-27 18:55 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-27 18:35 - 2014-01-28 19:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-27 18:35 - 2014-01-27 18:35 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-27 13:54 - 2014-01-28 19:58 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2014-01-27 13:54 - 2014-01-28 19:38 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork 2014-01-27 12:41 - 2014-01-27 12:41 - 02278856 _____ C:\Users\Patrick Polzyn\Downloads\avira_pc_cleaner_de.exe 2014-01-27 12:41 - 2014-01-27 12:41 - 00002049 _____ C:\Users\Patrick Polzyn\Desktop\Entfernen des Avira PC Cleaners.lnk 2014-01-27 12:41 - 2014-01-27 12:41 - 00001993 _____ C:\Users\Patrick Polzyn\Desktop\Avira PC Cleaner.lnk 2014-01-27 08:39 - 2014-01-27 08:39 - 00000262 _____ C:\Users\Patrick Polzyn\Desktop\Run.lnk 2014-01-26 16:28 - 2014-01-28 19:58 - 00000000 ____D C:\ProgramData\APN 2014-01-26 10:06 - 2014-01-26 10:06 - 23867560 _____ (Mozilla) C:\Users\Patrick Polzyn\Downloads\Firefox Setup 26.0.exe 2014-01-25 14:02 - 2014-01-25 14:02 - 00004540 _____ C:\Users\Patrick Polzyn\Documents\cc_20140125_140224.reg 2014-01-25 12:10 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\LicenseCrawler 2014-01-24 18:27 - 2014-01-24 18:27 - 00316109 _____ C:\Users\Patrick Polzyn\Desktop\Grenzsteine_DE-PL.rwp 2014-01-24 16:33 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\PR_PKP_infra_02 2014-01-24 16:30 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\ZestawSieciTrakcyjnejPKP 2014-01-13 16:45 - 2014-01-13 16:45 - 00001566 _____ C:\Users\Patrick Polzyn\Desktop\railworks - Verknüpfung.lnk 2014-01-11 19:27 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Developer Docs 2014-01-08 20:18 - 2012-09-10 20:42 - 00275899 _____ C:\Users\Patrick Polzyn\Desktop\DR-So2_und_So7-Tafeln.rwp 2014-01-05 10:14 - 2014-01-05 10:14 - 00115592 _____ C:\Users\Patrick Polzyn\Documents\cc_20140105_101436.reg ==================== One Month Modified Files and Folders ======= 2014-01-29 14:08 - 2014-01-29 14:06 - 00000000 ____D C:\FRST 2014-01-29 14:07 - 2013-02-19 15:30 - 00001126 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-29 13:59 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2014-01-29 13:58 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\WCN 2014-01-29 13:58 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2014-01-29 13:58 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\MUI 2014-01-29 13:58 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism 2014-01-29 13:58 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\com 2014-01-29 13:50 - 2012-12-28 16:57 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-29 13:27 - 2014-01-28 19:25 - 01184019 _____ C:\Windows\WindowsUpdate.log 2014-01-29 13:21 - 2009-07-14 05:45 - 00025680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-29 13:21 - 2009-07-14 05:45 - 00025680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-29 13:20 - 2014-01-29 04:17 - 00696132 _____ C:\Windows\system32\perfh007.dat 2014-01-29 13:20 - 2014-01-29 04:17 - 00147428 _____ C:\Windows\system32\perfc007.dat 2014-01-29 13:20 - 2009-07-14 06:13 - 01611160 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-29 13:15 - 2013-02-19 15:30 - 00001122 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-29 13:15 - 2012-10-17 16:30 - 00000000 ____D C:\Program Files (x86)\Steam 2014-01-29 13:14 - 2013-06-21 17:35 - 00000441 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2014-01-29 13:13 - 2014-01-28 19:25 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-29 13:13 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-29 13:13 - 2009-07-14 05:51 - 01260976 _____ C:\Windows\setupact.log 2014-01-29 13:13 - 2009-07-14 05:45 - 00367024 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-29 12:56 - 2010-11-21 08:17 - 00000000 ____D C:\Program Files\Windows Journal 2014-01-29 12:56 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2014-01-29 12:56 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2014-01-29 12:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2014-01-29 12:56 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System 2014-01-29 11:27 - 2014-01-29 11:24 - 00009302 _____ C:\Windows\IE10_main.log 2014-01-29 11:05 - 2014-01-28 21:13 - 01588294 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-29 10:54 - 2014-01-29 10:54 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\AskPartnerNetwork 2014-01-29 10:13 - 2010-11-21 04:47 - 00012266 _____ C:\Windows\PFRO.log 2014-01-29 04:21 - 2009-07-14 06:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2014-01-29 04:21 - 2009-07-14 06:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2014-01-29 04:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\oobe 2014-01-29 04:18 - 2014-01-29 04:18 - 00262144 _____ C:\Windows\system32\config\userdiff 2014-01-29 04:18 - 2009-07-14 05:45 - 00000000 ____D C:\Windows\Setup 2014-01-29 04:17 - 2014-01-29 04:17 - 00295922 _____ C:\Windows\system32\perfi007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00038104 _____ C:\Windows\system32\perfd007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\0407 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\0407 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\winrm 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\WCN 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\sysprep 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\slmgr 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\winrm 2014-01-29 04:17 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\slmgr 2014-01-29 04:17 - 2009-07-14 06:37 - 00000000 ____D C:\Windows\DigitalLocker 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Setup 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\oobe 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\MUI 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\com 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Setup 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\migwiz 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\servicing 2014-01-29 04:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\IME 2014-01-29 03:58 - 2014-01-29 03:51 - 00000000 ___HD C:\$INPLACE.~TR 2014-01-28 21:39 - 2012-12-17 08:18 - 00002070 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2014-01-28 21:10 - 2014-01-28 21:10 - 00001443 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-28 21:10 - 2014-01-28 21:10 - 00001409 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-01-28 21:10 - 2012-10-16 20:34 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-28 21:10 - 2012-10-16 20:34 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-28 21:06 - 2014-01-29 04:21 - 00000000 ____D C:\Windows\Panther 2014-01-28 21:06 - 2014-01-28 21:06 - 00000020 ___SH C:\Users\Patrick Polzyn\ntuser.ini 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Favoriten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Dokumente 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2014-01-28 21:06 - 2014-01-28 19:27 - 00000000 ____D C:\Users\Patrick Polzyn 2014-01-28 21:06 - 2012-04-13 19:07 - 00000000 __SHD C:\Recovery 2014-01-28 21:06 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-28 21:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Recovery 2014-01-28 21:06 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT 2014-01-28 20:46 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\restore 2014-01-28 20:46 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration 2014-01-28 20:35 - 2014-01-29 04:09 - 00000000 ___HD C:\$WINDOWS.~Q 2014-01-28 20:35 - 2014-01-28 18:22 - 00006773 _____ C:\Windows\comsetup.log 2014-01-28 20:31 - 2012-11-17 11:29 - 00023056 _____ C:\Windows\system32\emptyregdb.dat 2014-01-28 20:30 - 2013-01-16 09:56 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2014-01-28 20:25 - 2013-09-26 08:08 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-01-28 20:25 - 2009-07-14 05:46 - 00005157 _____ C:\Windows\DtcInstall.log 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 20:22 - 2013-06-12 17:36 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\TomTom 2014-01-28 20:22 - 2013-05-26 12:12 - 00000000 ___RD C:\Users\Patrick Polzyn\Dropbox 2014-01-28 20:22 - 2013-01-26 12:04 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\SimCity 2014-01-28 20:22 - 2012-12-10 19:33 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\SelfMV 2014-01-28 20:22 - 2012-10-17 16:11 - 00000000 ____D C:\Users\Patrick Polzyn\Lucidlogix 2014-01-28 20:22 - 2012-10-17 16:11 - 00000000 ____D C:\Users\Patrick Polzyn\dwhelper 2014-01-28 20:21 - 2014-01-25 12:10 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\LicenseCrawler 2014-01-28 20:21 - 2014-01-24 16:33 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\PR_PKP_infra_02 2014-01-28 20:21 - 2014-01-24 16:30 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\ZestawSieciTrakcyjnejPKP 2014-01-28 20:21 - 2014-01-11 19:27 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Developer Docs 2014-01-28 20:21 - 2013-12-12 18:30 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Camera 2014-01-28 20:21 - 2013-11-23 19:18 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\daten von justin usb 2014-01-28 20:21 - 2013-11-23 18:23 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\eRightSoft 2014-01-28 20:21 - 2013-11-23 14:34 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Dateien für Streckenprojekt 2014-01-28 20:21 - 2013-11-13 17:45 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Dokumente Viktor 2014-01-28 20:21 - 2013-11-10 18:15 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\usb stick christoph 2014-01-28 20:21 - 2013-11-04 17:47 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Inventor Server x64 3dsMax 2014-01-28 20:21 - 2013-09-27 16:04 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\PC Speed Maximizer 2014-01-28 20:21 - 2013-07-08 16:19 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Bilder Verkauf 2014-01-28 20:21 - 2013-06-12 18:57 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Bandicam 2014-01-28 20:21 - 2013-06-12 17:36 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\TomTom 2014-01-28 20:21 - 2013-03-14 15:56 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\WinRAR 2014-01-28 20:21 - 2013-02-26 15:34 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3DCrafter 9.2 2014-01-28 20:21 - 2013-01-26 11:48 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Origin 2014-01-28 20:21 - 2013-01-22 10:59 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\AdobeStockPhotos 2014-01-28 20:21 - 2013-01-18 13:24 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3dsMaxDesign 2014-01-28 20:21 - 2013-01-06 19:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\PDF Architect 2014-01-28 20:21 - 2013-01-06 19:22 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\pdfforge 2014-01-28 20:21 - 2012-12-09 12:06 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\samsung 2014-01-28 20:21 - 2012-12-09 12:06 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Samsung 2014-01-28 20:21 - 2012-10-18 18:39 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\OpenOffice.org 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Inventor 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\4A Games 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3dsMax 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3DCrafter 9.1 2014-01-28 20:20 - 2014-01-27 18:55 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Malwarebytes 2014-01-28 20:20 - 2013-11-15 18:28 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RW_Tools 2014-01-28 20:20 - 2013-09-28 06:50 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FAKEFACTORY CM2013 2014-01-28 20:20 - 2013-06-26 12:43 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\DVDVideoSoft 2014-01-28 20:20 - 2013-06-21 17:49 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Azureus 2014-01-28 20:20 - 2013-06-12 18:58 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\BANDISOFT 2014-01-28 20:20 - 2013-06-09 16:44 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Garmin 2014-01-28 20:20 - 2013-05-26 12:11 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-28 20:20 - 2013-05-26 12:08 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Dropbox 2014-01-28 20:20 - 2013-05-15 19:08 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\3DTrains 2014-01-28 20:20 - 2013-03-14 15:56 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-01-28 20:20 - 2013-02-17 14:17 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rail Simulator Packager Manager 2014-01-28 20:20 - 2013-01-27 19:27 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Apple Computer 2014-01-28 20:20 - 2013-01-06 19:22 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\APP_NAME_NON_STRING 2014-01-28 20:20 - 2013-01-06 14:43 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\#Startup# 2014-01-28 20:20 - 2012-12-17 08:23 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Avira 2014-01-28 20:20 - 2012-12-11 14:30 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\InstallShield 2014-01-28 20:20 - 2012-12-06 11:07 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\EPSON 2014-01-28 20:20 - 2012-11-29 14:28 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Autodesk 2014-01-28 20:20 - 2012-11-18 19:39 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Need for Speed World 2014-01-28 20:20 - 2012-11-13 18:23 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Foxit Software 2014-01-28 20:20 - 2012-10-17 18:59 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\NVIDIA 2014-01-28 20:20 - 2012-10-17 16:44 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-01-28 20:20 - 2012-10-16 21:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Macromedia 2014-01-28 20:20 - 2012-10-16 21:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Adobe 2014-01-28 20:20 - 2012-10-16 20:37 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla 2014-01-28 20:19 - 2013-10-20 14:22 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\RailSimulator.com 2014-01-28 20:19 - 2013-06-13 15:40 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Windows Live 2014-01-28 20:19 - 2013-06-12 17:36 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\TomTom 2014-01-28 20:19 - 2013-02-19 15:30 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Google 2014-01-28 20:19 - 2013-02-13 11:55 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Autodesk, Inc 2014-01-28 20:19 - 2013-01-26 11:47 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Origin 2014-01-28 20:19 - 2013-01-22 11:28 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\gegl-0.2 2014-01-28 20:19 - 2013-01-18 13:37 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\backburner 2014-01-28 20:19 - 2013-01-18 11:38 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\cFos 2014-01-28 20:19 - 2012-12-09 12:07 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Samsung 2014-01-28 20:19 - 2012-12-09 12:03 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\NVIDIA 2014-01-28 20:19 - 2012-12-09 12:00 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Downloaded Installations 2014-01-28 20:19 - 2012-11-29 14:45 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Autodesk 2014-01-28 20:19 - 2012-11-18 18:06 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Electronic_Arts_Inc 2014-01-28 20:19 - 2012-10-18 10:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Nexway 2014-01-28 20:19 - 2012-10-16 21:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Macromedia 2014-01-28 20:19 - 2012-10-16 20:37 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Mozilla 2014-01-28 20:19 - 2012-10-16 20:34 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\VirtualStore 2014-01-28 20:18 - 2014-01-28 19:27 - 00000000 ____D C:\Users\Administrator 2014-01-28 20:18 - 2013-12-01 19:19 - 00000000 ____D C:\Users\Administrator\AppData\Local\Autodesk 2014-01-28 20:18 - 2013-09-09 16:05 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\APP_NAME_NON_STRING 2014-01-28 20:18 - 2013-09-09 16:03 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia 2014-01-28 20:18 - 2013-09-09 16:03 - 00000000 ____D C:\Users\Administrator\AppData\Local\Macromedia 2014-01-28 20:18 - 2013-09-09 16:03 - 00000000 ____D C:\Users\Administrator\AppData\Local\DoNotTrackPlus 2014-01-28 20:18 - 2013-09-09 16:03 - 00000000 ____D C:\Users\Administrator\AppData\Local\AskToolbar 2014-01-28 20:18 - 2013-09-09 16:02 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Mozilla 2014-01-28 20:18 - 2013-09-09 16:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\Mozilla 2014-01-28 20:18 - 2013-09-09 15:25 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Avira 2014-01-28 20:18 - 2013-09-09 15:21 - 00000000 ____D C:\Users\Administrator\Documents\4a games 2014-01-28 20:18 - 2013-06-21 17:31 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-28 20:18 - 2013-06-21 17:31 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-28 20:18 - 2013-06-21 17:31 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe 2014-01-28 20:18 - 2013-02-13 11:44 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Akamai 2014-01-28 20:18 - 2013-01-27 13:41 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Apple 2014-01-28 20:18 - 2013-01-22 11:36 - 00000000 ____D C:\Users\Patrick Polzyn\.thumbnails 2014-01-28 20:18 - 2013-01-22 11:28 - 00000000 ____D C:\Users\Patrick Polzyn\.gimp-2.8 2014-01-28 20:18 - 2013-01-22 10:47 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Adobe 2014-01-28 20:18 - 2013-01-06 11:20 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\AskToolbar 2014-01-28 20:18 - 2012-12-25 15:12 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\4A Games 2014-01-28 20:18 - 2012-10-17 16:09 - 00000000 ____D C:\Users\Patrick Polzyn\.swt 2014-01-28 20:00 - 2013-07-16 17:58 - 00000000 ____D C:\Windows\Uninstall 2014-01-28 20:00 - 2013-01-18 12:01 - 00000000 ____D C:\Windows\system32\appmgmt 2014-01-28 20:00 - 2012-12-14 21:02 - 00000000 ____D C:\Windows\pss 2014-01-28 20:00 - 2012-10-16 21:15 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2014-01-28 20:00 - 2012-10-16 21:15 - 00000000 ____D C:\Windows\system32\Macromed 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2014-01-28 19:59 - 2014-01-28 19:26 - 00000000 ____D C:\ProgramData\EPSON 2014-01-28 19:59 - 2014-01-28 19:25 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2014-01-28 19:59 - 2014-01-27 18:55 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-28 19:59 - 2013-06-13 15:43 - 00000000 ____D C:\Windows\de 2014-01-28 19:59 - 2013-06-12 17:38 - 00000000 ____D C:\ProgramData\TomTom 2014-01-28 19:59 - 2013-05-30 08:09 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-28 19:59 - 2013-05-15 19:08 - 00000000 ____D C:\Windows\3DTrains 2014-01-28 19:59 - 2013-01-26 11:47 - 00000000 ____D C:\ProgramData\Origin 2014-01-28 19:59 - 2013-01-22 10:46 - 00000000 ____D C:\Users\Public\Documents\Adobe PDF 2014-01-28 19:59 - 2013-01-18 11:59 - 00000000 _RSHD C:\ProgramData\Key-Base 2014-01-28 19:59 - 2013-01-18 11:38 - 00000000 ____D C:\ProgramData\FNET 2014-01-28 19:59 - 2013-01-16 09:56 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2014-01-28 19:59 - 2012-12-17 08:10 - 00000000 ____D C:\Windows\erdnt 2014-01-28 19:59 - 2012-12-09 12:05 - 00000000 ____D C:\ProgramData\Samsung 2014-01-28 19:59 - 2012-11-29 14:45 - 00000000 ____D C:\ProgramData\FLEXnet 2014-01-28 19:59 - 2012-10-17 18:52 - 00000000 ____D C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP 2014-01-28 19:59 - 2012-10-16 21:37 - 00000000 ____D C:\Users\Public\Documents\S.T.A.L.K.E.R. - Call of Pripyat 2014-01-28 19:59 - 2012-10-16 21:06 - 00000000 ____D C:\ProgramData\Sun 2014-01-28 19:59 - 2012-10-16 20:37 - 00000000 ____D C:\ProgramData\Mozilla 2014-01-28 19:59 - 2010-11-21 08:16 - 00000000 ___RD C:\Users\Public\Recorded TV 2014-01-28 19:59 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries 2014-01-28 19:59 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports 2014-01-28 19:58 - 2014-01-27 13:54 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2014-01-28 19:58 - 2014-01-26 16:28 - 00000000 ____D C:\ProgramData\APN 2014-01-28 19:58 - 2013-11-04 15:25 - 00000000 ____D C:\ProgramData\Applications 2014-01-28 19:58 - 2013-06-26 17:22 - 00000000 ____D C:\ProgramData\BlueStacksSetup 2014-01-28 19:58 - 2013-06-26 17:22 - 00000000 ____D C:\ProgramData\BlueStacks 2014-01-28 19:58 - 2013-06-13 15:42 - 00000000 ____D C:\Program Files (x86)\Windows Live 2014-01-28 19:58 - 2013-01-27 13:41 - 00000000 ____D C:\ProgramData\Apple Computer 2014-01-28 19:58 - 2013-01-27 13:40 - 00000000 ____D C:\ProgramData\Apple 2014-01-28 19:58 - 2013-01-18 11:38 - 00000000 ____D C:\ProgramData\cFos 2014-01-28 19:58 - 2012-11-29 14:28 - 00000000 ____D C:\ProgramData\Autodesk 2014-01-28 19:58 - 2012-11-18 18:04 - 00000000 ____D C:\ProgramData\Electronic Arts 2014-01-28 19:58 - 2012-10-16 21:48 - 00000000 ____D C:\ProgramData\Avira 2014-01-28 19:58 - 2012-10-16 21:15 - 00000000 ____D C:\ProgramData\Adobe 2014-01-28 19:58 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\XFastUsb 2014-01-28 19:58 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\Vuze 2014-01-28 19:40 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-28 19:40 - 2014-01-27 18:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-28 19:40 - 2014-01-27 18:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-28 19:40 - 2013-12-21 16:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-28 19:40 - 2013-12-12 19:39 - 00000000 ____D C:\Program Files (x86)\MyFree Codec 2014-01-28 19:40 - 2013-06-13 15:43 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2014-01-28 19:40 - 2013-03-13 22:09 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2014-01-28 19:40 - 2013-02-20 20:21 - 00000000 ____D C:\Program Files (x86)\Foxit Software 2014-01-28 19:40 - 2013-02-20 18:40 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 2014-01-28 19:40 - 2013-02-19 15:30 - 00000000 ____D C:\Program Files (x86)\Google 2014-01-28 19:40 - 2013-01-27 13:41 - 00000000 ____D C:\Program Files (x86)\QuickTime 2014-01-28 19:40 - 2013-01-26 11:47 - 00000000 ____D C:\Program Files (x86)\Origin 2014-01-28 19:40 - 2013-01-23 12:02 - 00000000 ____D C:\Program Files (x86)\Magical Jelly Bean 2014-01-28 19:40 - 2013-01-22 10:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2014-01-28 19:40 - 2013-01-22 10:58 - 00000000 ____D C:\Program Files (x86)\MSECache 2014-01-28 19:40 - 2013-01-16 09:55 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-01-28 19:40 - 2013-01-06 19:22 - 00000000 ____D C:\Program Files (x86)\PDFCreator 2014-01-28 19:40 - 2013-01-06 19:22 - 00000000 ____D C:\Program Files (x86)\PDF Architect 2014-01-28 19:40 - 2012-12-09 12:07 - 00000000 ____D C:\Program Files (x86)\MarkAny 2014-01-28 19:40 - 2012-12-09 12:05 - 00000000 ____D C:\Program Files (x86)\Samsung 2014-01-28 19:40 - 2012-11-30 17:24 - 00000000 ____D C:\Program Files (x86)\Rail Simulator 2014-01-28 19:40 - 2012-10-18 11:18 - 00000000 ____D C:\Program Files (x86)\Fire Department 3 2014-01-28 19:40 - 2012-10-16 21:06 - 00000000 ____D C:\Program Files (x86)\Java 2014-01-28 19:40 - 2012-10-16 21:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2014-01-28 19:40 - 2012-10-16 21:00 - 00000000 ____D C:\Program Files (x86)\REALTEK 2014-01-28 19:40 - 2012-10-16 20:44 - 00000000 ____D C:\Program Files (x86)\Intel 2014-01-28 19:39 - 2013-11-07 18:38 - 00000000 ____D C:\Program Files (x86)\Convar 2014-01-28 19:39 - 2013-06-26 12:43 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2014-01-28 19:39 - 2013-01-18 11:34 - 00000000 ____D C:\Program Files (x86)\Etron Technology 2014-01-28 19:39 - 2012-11-18 18:04 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2014-01-28 19:39 - 2012-10-18 11:22 - 00000000 ____D C:\Program Files (x86)\Fire Department 2 2014-01-28 19:39 - 2012-10-16 21:16 - 00000000 ____D C:\Program Files (x86)\epson 2014-01-28 19:39 - 2012-10-16 20:45 - 00000000 ____D C:\Program Files (x86)\CyberLink 2014-01-28 19:39 - 2012-10-16 20:45 - 00000000 ____D C:\Program Files (x86)\Creative 2014-01-28 19:38 - 2014-01-27 13:54 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork 2014-01-28 19:38 - 2013-11-23 18:24 - 00000000 ____D C:\Program Files (x86)\AviSynth 2.5 2014-01-28 19:38 - 2013-06-26 17:23 - 00000000 ____D C:\Program Files (x86)\BlueStacks 2014-01-28 19:38 - 2013-06-12 18:57 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1 2014-01-28 19:38 - 2013-06-12 18:57 - 00000000 ____D C:\Program Files (x86)\Bandicam 2014-01-28 19:38 - 2013-02-26 15:33 - 00000000 ____D C:\Program Files (x86)\3DCrafter 92 2014-01-28 19:38 - 2013-02-24 15:53 - 00000000 ____D C:\Program Files (x86)\7-Zip 2014-01-28 19:38 - 2013-01-27 13:40 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2014-01-28 19:38 - 2013-01-18 13:07 - 00000000 ____D C:\Program Files (x86)\Autodesk 2014-01-28 19:38 - 2012-12-17 08:17 - 00000000 ____D C:\Program Files (x86)\Avira 2014-01-28 19:38 - 2012-10-16 20:45 - 00000000 ____D C:\Program Files (x86)\Cisco 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\bitComposer Games 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\ASRock Utility 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\Adobe 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\3DCrafter 9 2014-01-28 19:37 - 2014-01-28 19:26 - 00000000 ____D C:\Program Files\Common Files\EPSON 2014-01-28 19:37 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2014-01-28 19:37 - 2013-11-07 18:31 - 00000000 ____D C:\Program Files\Recuva 2014-01-28 19:37 - 2013-03-14 15:55 - 00000000 ____D C:\Program Files\WinRAR 2014-01-28 19:37 - 2013-03-13 22:09 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2014-01-28 19:37 - 2013-02-13 11:25 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared 2014-01-28 19:37 - 2013-01-22 11:16 - 00000000 ____D C:\Program Files\GIMP 2 2014-01-28 19:37 - 2013-01-18 11:35 - 00000000 ____D C:\Program Files\Lucidlogix Technologies 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Steam 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\postureAgent 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Java 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Intel 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\InstallShield 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Etron Technology 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Epson Software 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\epson 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared 2014-01-28 19:37 - 2012-10-17 16:09 - 00000000 ____D C:\Program Files\CyberLink 2014-01-28 19:37 - 2012-10-17 16:09 - 00000000 ____D C:\Program Files\Creative 2014-01-28 19:37 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\EXPERTool 2014-01-28 19:37 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2014-01-28 19:36 - 2013-02-24 16:03 - 00000000 ____D C:\Program Files\CCleaner 2014-01-28 19:36 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR 2014-01-28 19:36 - 2012-10-17 16:09 - 00000000 ____D C:\Program Files\Cisco 2014-01-28 19:36 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\bitComposer Games 2014-01-28 19:34 - 2013-02-13 11:24 - 00000000 ____D C:\Program Files\Autodesk 2014-01-28 19:29 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\ASRock Utility 2014-01-28 19:29 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\Adobe 2014-01-28 19:29 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\3DCrafter 9 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Anwendungsdaten 2014-01-28 19:26 - 2014-01-28 19:26 - 00001355 _____ C:\Windows\TSSysprep.log 2014-01-28 19:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sysprep 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files\Realtek 2014-01-28 19:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Help 2014-01-28 19:24 - 2014-01-28 19:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-01-28 19:23 - 2010-11-21 08:17 - 00000000 ____D C:\Windows\CSC 2014-01-28 18:47 - 2013-01-23 13:15 - 00700540 _____ C:\Windows\WindowsUpdate (1).log 2014-01-28 18:08 - 2012-11-17 10:13 - 00001890 _____ C:\Windows\diagwrn.xml 2014-01-28 18:08 - 2012-11-17 10:13 - 00001890 _____ C:\Windows\diagerr.xml 2014-01-27 19:01 - 2013-09-27 15:59 - 00000000 ____D C:\ProgramData\DSearchLink 2014-01-27 18:56 - 2014-01-27 18:55 - 00000000 ____D C:\AdwCleaner 2014-01-27 18:55 - 2014-01-27 18:55 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-27 18:35 - 2014-01-27 18:35 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-27 12:41 - 2014-01-27 12:41 - 02278856 _____ C:\Users\Patrick Polzyn\Downloads\avira_pc_cleaner_de.exe 2014-01-27 12:41 - 2014-01-27 12:41 - 00002049 _____ C:\Users\Patrick Polzyn\Desktop\Entfernen des Avira PC Cleaners.lnk 2014-01-27 12:41 - 2014-01-27 12:41 - 00001993 _____ C:\Users\Patrick Polzyn\Desktop\Avira PC Cleaner.lnk 2014-01-27 08:39 - 2014-01-27 08:39 - 00000262 _____ C:\Users\Patrick Polzyn\Desktop\Run.lnk 2014-01-26 11:28 - 2013-01-11 09:36 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Debugmode 2014-01-26 11:28 - 2013-01-11 09:36 - 00000000 ____D C:\Program Files (x86)\DebugMode 2014-01-26 11:22 - 2013-11-23 18:23 - 00000000 ____D C:\Program Files (x86)\eRightSoft 2014-01-26 10:06 - 2014-01-26 10:06 - 23867560 _____ (Mozilla) C:\Users\Patrick Polzyn\Downloads\Firefox Setup 26.0.exe 2014-01-25 14:02 - 2014-01-25 14:02 - 00004540 _____ C:\Users\Patrick Polzyn\Documents\cc_20140125_140224.reg 2014-01-24 18:27 - 2014-01-24 18:27 - 00316109 _____ C:\Users\Patrick Polzyn\Desktop\Grenzsteine_DE-PL.rwp 2014-01-16 08:36 - 2013-08-14 19:12 - 00000000 ____D C:\Windows\system32\MRT 2014-01-13 16:45 - 2014-01-13 16:45 - 00001566 _____ C:\Users\Patrick Polzyn\Desktop\railworks - Verknüpfung.lnk 2014-01-05 10:14 - 2014-01-05 10:14 - 00115592 _____ C:\Users\Patrick Polzyn\Documents\cc_20140105_101436.reg Some content of TEMP: ==================== C:\Users\Patrick Polzyn\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-29 13:48 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-01-2014 01 Ran by Patrick Polzyn at 2014-01-29 14:10:59 Running from C:\Users\Patrick Polzyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYPJZKPN Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== 3DCrafter (x32 Version: 9.2.2.1546 - Amabilis Software) 7-Zip 9.20 (x32 Version: - ) Adobe AIR (x32 Version: 1.0.4990 - Adobe Systems Inc.) Adobe AIR (x32 Version: 1.0.8.4990 - Adobe Systems Inc.) Hidden Adobe Bridge 1.0 (x32 Version: 001.000.001 - Adobe Systems) Hidden Adobe Common File Installer (x32 Version: 1.00.001 - Adobe System Incorporated) Hidden Adobe Creative Suite 2 (x32 Version: - ) Adobe Flash Player 11 ActiveX (x32 Version: 11.6.602.180 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Help Center 1.0 (x32 Version: 1.0.1 - Adobe Systems) Hidden Adobe Photoshop CS2 (x32 Version: 9.0 - Adobe Systems, Inc.) Hidden Adobe Reader XI (11.0.02) - Deutsch (x32 Version: 11.0.02 - Adobe Systems Incorporated) Adobe Stock Photos 1.0 (x32 Version: 1.0.1 - Adobe Systems) Hidden Akamai NetSession Interface (HKCU Version: - Akamai Technologies, Inc) Akamai NetSession Interface Service (x32 Version: - Akamai Technologies, Inc) Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.) ASRock App Charger v1.0.4 (Version: - ASRock Inc.) ASRock InstantBoot v1.29 (x32 Version: - ) AutoCAD 2011 - Deutsch (Version: 18.1.49.0 - Autodesk) AutoCAD 2011 - Deutsch (Version: 18.1.49.0 - Autodesk) Hidden AutoCAD 2011 Language Pack - Deutsch (Version: 18.1.49.0 - Autodesk) Hidden Autodesk 3ds Max 2014 (Version: 16.2.475.0 - Autodesk) Autodesk 3ds Max 2014 (Version: 16.2.475.0 - Autodesk) Hidden Autodesk 3ds Max 2014 64-bit Populate Data (Version: 1.0.0.1 - Autodesk) Autodesk 3ds Max 2014 SP2 (Version: 16.2.475.0 - Autodesk) Autodesk Backburner 2014 (x32 Version: 14.0.0.0 - Autodesk, Inc.) Autodesk Composite 2014 (Version: 9.0.0.0 - Autodesk) Autodesk Composite 2014 (Version: 9.0.0.0 - Autodesk) Hidden Autodesk Design Review 2013 (x32 Version: 13.0.0.82 - Autodesk, Inc.) Autodesk Design Review 2013 (x32 Version: 13.0.0.82 - Autodesk, Inc.) Hidden Autodesk DirectConnect 2014 64-bit (Version: 8.0.56.1 - Autodesk) Autodesk DirectConnect 2014 64-bit (Version: 8.0.56.1 - Autodesk) Hidden Autodesk Download Manager (x32 Version: 2.0.6.0 - Autodesk, Inc.) Autodesk Essential Skills Movies for 3ds Max 2014 64-bit (Version: 1.2.0.0 - Autodesk) Autodesk FBX Plugin 2009.4 - 3ds Max Design 2010 (x32 Version: - Autodesk) Autodesk Inventor Server Engine for 3ds Max 2014 64-bit (Version: 16.0 - Autodesk) Autodesk Material Library 2011 Base Image library (x32 Version: 2.0.0.49 - Autodesk) Autodesk Material Library 2011 Medium Image library (x32 Version: 2.0.0.49 - Autodesk) Autodesk Material Library 2014 (x32 Version: 4.0.32.600 - Autodesk) Autodesk Material Library Base Resolution Image Library 2014 (x32 Version: 4.0.32.600 - Autodesk) Autodesk Material Library Medium Resolution Image Library 2014 (x32 Version: 4.0.32.600 - Autodesk) Autodesk Revit Interoperability for 3ds Max 2014 (Version: 13.02.15161 - Autodesk) Autodesk Revit Interoperability for 3ds Max 2014 (Version: 13.02.15161 - Autodesk) Hidden Avira Antivirus Suite (x32 Version: 14.0.2.286 - Avira) Avira SearchFree Toolbar (x32 Version: 12.10.0.2951 - APN, LLC) Avira Update Manager (x32 Version: - Avira Operations GmbH & Co. KG) Bandicam (x32 Version: 1.8.8.365 - Bandisoft.com) Bandisoft MPEG-1 Decoder (x32 Version: - Bandisoft.com) BlueStacks App Player (x32 Version: 0.7.14.901 - BlueStack Systems, Inc.) BlueStacks Notification Center (x32 Version: 0.7.14.901 - BlueStack Systems, Inc.) CCleaner (Version: 3.27 - Piriform) Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.) Counter-Strike: Source (x32 Version: - Valve) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKCU Version: 2.0.22 - Dropbox, Inc.) EPSON BX305 Plus Series Printer Uninstall (Version: - SEIKO EPSON Corporation) EPSON Scan (x32 Version: - Seiko Epson Corporation) Etron USB3.0 Host Controller (x32 Version: 0.104 - Etron Technology) Hidden FAKEFACTORY Cinematic Mod 2013 (x32 Version: alpha1 - FAKEFACTORY) Fire Department 2 (x32 Version: - Nexway) Fire Department 3 (x32 Version: - Nexway) Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Foxit Reader (x32 Version: 5.4.5.124 - Foxit Corporation) Fraps (x32 Version: - ) Free YouTube to MP3 Converter version 3.12.4.622 (x32 Version: 3.12.4.622 - DVDVideoSoft Ltd.) GIMP 2.8.2 (Version: 2.8.2 - The GIMP Team) Google Earth (x32 Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Half-Life 2 (x32 Version: - Valve) Half-Life 2: Deathmatch (x32 Version: - Valve) Half-Life 2: Episode One (x32 Version: - Valve) Half-Life 2: Episode Two (x32 Version: - Valve) Half-Life 2: Lost Coast (x32 Version: - Valve) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (x32 Version: 9.17.10.3347 - Intel Corporation) Java 7 Update 25 (x32 Version: 7.0.250 - Oracle) Java Auto Updater (x32 Version: 2.1.9.5 - Sun Microsystems, Inc.) Hidden Left 4 Dead 2 (x32 Version: - Valve) Magical Jelly Bean KeyFinder (x32 Version: 2.0.9.8 - Magical Jelly Bean) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) Metro: Last Light (x32 Version: - 4A Games) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: - ) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Word Viewer 2003 (x32 Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) MyFreeCodec (HKCU Version: - ) Need For Speed™ World (x32 Version: 1.0.0.1229 - Electronic Arts) NVIDIA 3D Vision Controller-Treiber 310.90 (Version: 310.90 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 331.65 (Version: 331.65 - NVIDIA Corporation) NVIDIA GeForce Experience 1.0 (BETA) (Version: 1.0 (BETA) - NVIDIA Corporation) NVIDIA Grafiktreiber 331.65 (Version: 331.65 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.12.1031 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3165 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden NVIDIA Update 2.47.55 (Version: 2.47.55 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 2.47.55 - NVIDIA Corporation) Hidden OpenOffice.org 3.4.1 (x32 Version: 3.41.9593 - Apache Software Foundation) Origin (x32 Version: 9.1.11.2678 - Electronic Arts, Inc.) PC Inspector smart recovery (x32 Version: 4.50 - ) PDF Architect (x32 Version: 1.0.41.8362 - pdfforge) PDFCreator (x32 Version: 1.6.1 - pdfforge) Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden QuickTime (x32 Version: 7.73.80.64 - Apple Inc.) Realtek Ethernet Controller Driver (x32 Version: 7.44.421.2011 - Realtek) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6392 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver and Utility (x32 Version: 1.00.0148 - REALTEK Semiconductor Corp.) REALTEK Wireless LAN Driver and Utility (x32 Version: 1.00.0149 - REALTEK Semiconductor Corp.) Recuva (Version: 1.48 - Piriform) RW_Tools V4 (HKCU Version: - ) RW_Tools V5 (HKCU Version: - ) Samsung Kies (x32 Version: 2.6.1.13105_6 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.6.1.13105_6 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (Version: 1.5.29.0 - SAMSUNG Electronics Co., Ltd.) Source SDK (x32 Version: - Valve) Source SDK Base 2006 (x32 Version: - Valve) Source SDK Base 2007 (x32 Version: - Valve) Source SDK Base 2013 Multiplayer (x32 Version: - ) Source SDK Base 2013 Singleplayer (x32 Version: - ) Spybot - Search & Destroy (x32 Version: 2.0.12 - Safer-Networking Ltd.) Steam (x32 Version: 1.0.0.0 - Valve Corporation) Suite Specific (x32 Version: 2.0.0 - Adobe Systems, Incorporated) Hidden Train Simulator 2013 (x32 Version: - RailSimulator.com) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation) VIRTU 1.2.106 (Version: 1.2.106 - Lucfidlogix Technologies LTD) Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden WinRAR 4.20 (64-Bit) (Version: 4.20.0 - win.rar GmbH) World Landscapes (x32 Version: 1.08.06.12 - Freeware Edition - 3DTrains) XFastUsb (x32 Version: - ) ==================== Restore Points ========================= 28-01-2014 20:07:07 Windows Update 28-01-2014 20:11:27 Windows Update 29-01-2014 09:55:52 Windows Update 29-01-2014 12:55:05 Sprachpaketdeinstallation ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {141D7D2D-F5DD-42AA-9478-03E012705B4C} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {1E51A613-D59D-4205-BF8F-51554967374E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-19] (Google Inc.) Task: {29DF561B-38D6-48B7-AFA3-C595D37393EF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {51209254-6434-406A-811F-8996321AF8B6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-15] (Adobe Systems Incorporated) Task: {7864BE98-96CC-4B56-8402-B3C7AF2CF0C1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {8B54751B-3428-4E3D-A76C-BDA48081BD6F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-19] (Google Inc.) Task: {EBC9CD4D-AEB8-4257-BCCE-EDD08C172F22} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {EDAA0A35-A9BD-416F-8B03-143F7C405A0D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-28 19:25 - 2013-10-23 09:20 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2012-11-19 08:33 - 2012-11-19 08:33 - 00070264 _____ () C:\Windows\system32\bdmpega64.acm 2013-11-07 01:52 - 2013-11-07 01:52 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-12-17 08:17 - 2014-01-27 18:36 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2013-01-16 09:55 - 2012-11-13 14:06 - 00108960 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-01-16 09:55 - 2012-11-13 14:06 - 00416160 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-01-16 09:55 - 2012-11-13 14:06 - 00158624 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-01-16 09:55 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-01-16 09:55 - 2012-11-13 14:06 - 00528288 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl 2012-10-16 21:00 - 2009-12-09 20:20 - 00126976 _____ () C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\EnumDevLib.dll 2012-10-18 10:55 - 2009-12-09 20:20 - 00126976 _____ () C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\EnumDevLib.dll 2013-01-16 09:55 - 2012-11-13 14:06 - 00554400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Realtek RTL8190 802.11n Wireless LAN (Mini-)PCI NIC Description: Realtek RTL8190 802.11n Wireless LAN (Mini-)PCI NIC Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Realtek Semiconductor Corp. Service: rtl819xpn64 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/29/2014 01:56:03 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName1". Die Einstellung "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName" ist nicht registriert. Error: (01/29/2014 01:52:47 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/29/2014 01:51:08 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "FARO.LS,processorArchitecture="x86",publicKeyToken="1d23f5635ba800ab",type="win32",version="1.1.406.58"1". Die abhängige Assemblierung "FARO.LS,processorArchitecture="x86",publicKeyToken="1d23f5635ba800ab",type="win32",version="1.1.406.58"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/29/2014 01:14:02 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/29/2014 01:14:02 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName1". Die Einstellung "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName" ist nicht registriert. Error: (01/29/2014 01:13:54 PM) (Source: RaySat_3dsmax2014_64 Server) (User: ) Description: (1507) getservbyname: Der angeforderte Name ist gültig, es wurden jedoch keine Daten des angeforderten Typs gefunden. (0x2afc) Error: (01/29/2014 00:58:49 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/29/2014 00:58:47 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName1". Die Einstellung "hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayName" ist nicht registriert. Error: (01/29/2014 00:58:34 PM) (Source: RaySat_3dsmax2014_64 Server) (User: ) Description: (1507) getservbyname: Der angeforderte Name ist gültig, es wurden jedoch keine Daten des angeforderten Typs gefunden. (0x2afc) Error: (01/29/2014 00:51:03 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2862152) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework 3.5.1 unter Windows 7 und Windows Server 2008 R2 SP1 für x64-basierte Systeme (KB2736422) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-Systeme (KB2698365) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2834886) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework 3.5.1 unter Windows 7 und Windows Server 2008 R2 für x64-basierte Systeme (KB2832414) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Update für Microsoft .NET Framework 3.5.1 unter Windows 7 und Windows Server 2008 R2 SP1 für x64-basierte Systeme (KB2836943) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2876284) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2619339) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2564958) Error: (01/29/2014 01:17:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2511455) Microsoft Office Sessions: ========================= Error: (01/29/2014 01:56:03 PM) (Source: SideBySide)(User: ) Description: hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayNamec:\program files (x86)\spybot - search & destroy 2\SDWSCSvc.exe Error: (01/29/2014 01:52:47 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Autodesk\Composite2014\python\lib\distutils\command\wininst-8_d.exe Error: (01/29/2014 01:51:08 PM) (Source: SideBySide)(User: ) Description: FARO.LS,processorArchitecture="x86",publicKeyToken="1d23f5635ba800ab",type="win32",version="1.1.406.58"C:\Program Files\Autodesk\AutoCAD 2011\FaroImporter.exe Error: (01/29/2014 01:14:02 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/29/2014 01:14:02 PM) (Source: SideBySide)(User: ) Description: hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayNameC:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe Error: (01/29/2014 01:13:54 PM) (Source: RaySat_3dsmax2014_64 Server)(User: ) Description: (1507) getservbyname: Der angeforderte Name ist gültig, es wurden jedoch keine Daten des angeforderten Typs gefunden. (0x2afc) Error: (01/29/2014 00:58:49 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/29/2014 00:58:47 PM) (Source: SideBySide)(User: ) Description: hxxp://schemas.microsoft.com/SMI/2005/WindowsSettings^antispywareProductDisplayNameC:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe Error: (01/29/2014 00:58:34 PM) (Source: RaySat_3dsmax2014_64 Server)(User: ) Description: (1507) getservbyname: Der angeforderte Name ist gültig, es wurden jedoch keine Daten des angeforderten Typs gefunden. (0x2afc) Error: (01/29/2014 00:51:03 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2013-03-24 09:31:23.563 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:23.547 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:21.252 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:21.236 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:18.702 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:18.683 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:15.223 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:15.205 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:12.456 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-24 09:31:12.440 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 32% Total physical RAM: 8104.67 MB Available physical RAM: 5457.57 MB Total Pagefile: 16207.54 MB Available Pagefile: 13105.45 MB Total Virtual: 8192 MB Available Virtual: 8191.78 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:938.54 GB) (Free:565.53 GB) NTFS Drive f: (Volume) (Fixed) (Total:924.37 GB) (Free:783.57 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 861EACED) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=939 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=924 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Gruß |
29.01.2014, 15:11 | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Spybot ist Müll, deinstallieren, das Tool bringt niix Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
29.01.2014, 15:27 | #5 |
| Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Das Programm habe ich weil ich in der Ausbildung bin kostenlos. Ist ein Privater rechner. Das Programm ist aber auf meinen Namen und Adresse regestriert. Ist das Programm ein Problem? |
29.01.2014, 15:33 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Wieso glauben alle immer gleich an ein Problem, diese Software ist kein Problem, aber nicht gerade so eine die Lieschen Müller vorinstalliert auf ihrem Home-Rechner findet. Deswegen kann man hier gewerbliche Nutzung vermuten und deswegen frage ich immer nach. Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ --> Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an |
29.01.2014, 16:10 | #7 |
| Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Ich habe das Tool instaliert und den Scan laufen lassen. Jetzt ist er fertig hat aber nichts gefunden. Habe die Datei gefunden. Muste das Program erst schließen. Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1009 www.malwarebytes.org Database version: v2014.01.29.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Patrick Polzyn :: PATRICKPOLZYN [administrator] 29.01.2014 15:47:29 mbar-log-2014-01-29 (15-47-29).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 325742 Time elapsed: 11 minute(s), 27 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
29.01.2014, 16:19 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
29.01.2014, 19:24 | #9 |
| Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an So hier nun die Log Files der drei Programme: JRT Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Professional x64 Ran by Patrick Polzyn on 29.01.2014 at 19:10:14,50 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5296BDA4-2B7E-4BA6-967A-DEDF0C5EF2FE} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" ~~~ FireFox Successfully deleted the following from C:\Users\Patrick Polzyn\AppData\Roaming\mozilla\firefox\profiles\ryyx8uo6.default\prefs.js user_pref("extensions.AVIRA-V7C.com.avira.dnt.rules", "\"{\\\"Version\\\":39,\\\"Companies\\\":[{\\\"company\\\":\\\"Google Inc\\\",\\\"rules\\\":[{\\\"name\\\":\\\"Google Ana user_pref("extensions.AVIRA-V7C.domain", "\"avira.search.ask.com\""); Emptied folder: C:\Users\Patrick Polzyn\AppData\Roaming\mozilla\firefox\profiles\ryyx8uo6.default\minidumps [106 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 29.01.2014 at 19:15:00,09 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 01 Ran by Patrick Polzyn (administrator) on PATRICKPOLZYN on 29-01-2014 19:19:26 Running from C:\Users\Patrick Polzyn\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Realtek) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe (Realtek) C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\RtlService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Autodesk, Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\RtWLan.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Toolbar.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor) HKLM-x32\...\Run: [ADSK DLMSession] - C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1641368 2013-02-01] (Autodesk, Inc.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1815976 2014-01-27] (Valve Corporation) HKU\Administrator\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516096 2010-11-21] (Microsoft Corporation) HKU\UpdatusUser\...\Run: [Spybot-S&D Cleaning] - "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean HKU\UpdatusUser\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1815976 2014-01-27] (Valve Corporation) HKU\UpdatusUser\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516096 2010-11-21] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.) Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Garmin Communicator - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013-11-19] FF Extension: WOT - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26] FF Extension: DownloadHelper - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013-08-27] FF Extension: Easy YouTube MP3 Downloader - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\5@thumbpro.net.xpi [2013-06-26] FF Extension: Adblock Plus Pop-up Addon - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\adblockpopups@jessehakanen.net.xpi [2012-10-29] FF Extension: MP3 Download! - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\anthonyytmp3download@gmail.com.xpi [2013-06-26] FF Extension: InvisibleHand - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\canitbecheaper@trafficbroker.co.uk.xpi [2012-10-18] FF Extension: YouTube to MP3 - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\info@sharkcube.com.xpi [2013-06-26] FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\toolbar_AVIRA-V7C@apn.ask.com.xpi [2013-12-20] FF Extension: NoScript - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-25] FF Extension: Adblock Plus - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-10-30] FF Extension: DownThemAll! - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2012-10-30] FF Extension: QuickJava - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi [2012-10-18] FF Extension: JavaScript Debugger - C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\Extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi [2012-10-18] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-01-06] ==================== Services (Whitelisted) ================= S4 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-22] (Adobe Systems) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [908856 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-12] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-17] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.) S4 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [393032 2013-06-19] (BlueStack Systems, Inc.) S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384840 2013-06-19] (BlueStack Systems, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 mi-raysat_3dsmax2014_64; C:\Program Files\Autodesk\3ds Max 2014\NVIDIA\Satellite\raysat_3dsmax2014_64server.exe [86016 2011-09-15] () S4 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR) S4 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR) R2 Realtek11nSU; C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [45056 2010-01-21] (Realtek) R2 RealtekPCIE; C:\Program Files (x86)\REALTEK\819xP Wireless LAN Utility\RtlService.exe [45056 2010-01-21] (Realtek) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-17] (Avira Operations GmbH & Co. KG) R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [70984 2013-06-19] (BlueStack Systems) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-01-18] (FNet Co., Ltd.) S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 rtl819xpn64; C:\Windows\System32\DRIVERS\rtl819xp.sys [622624 2010-02-01] (Realtek Semiconductor Corporation ) S4 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [68608 2005-08-10] (Protection Technology) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-29 19:19 - 2014-01-29 19:19 - 02079744 _____ (Farbar) C:\Users\Patrick Polzyn\Desktop\FRST64.exe 2014-01-29 19:19 - 2014-01-29 19:19 - 00015897 _____ C:\Users\Patrick Polzyn\Desktop\FRST.txt 2014-01-29 19:15 - 2014-01-29 19:15 - 00001624 _____ C:\Users\Patrick Polzyn\Desktop\JRT.txt 2014-01-29 19:10 - 2014-01-29 19:10 - 00000000 ____D C:\Windows\ERUNT 2014-01-29 19:09 - 2014-01-29 19:09 - 01037068 _____ (Thisisu) C:\Users\Patrick Polzyn\Desktop\JRT.exe 2014-01-29 17:15 - 2010-02-23 09:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe 2014-01-29 17:07 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2014-01-29 17:07 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2014-01-29 17:07 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2014-01-29 17:07 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2014-01-29 17:07 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2014-01-29 17:07 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2014-01-29 17:07 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2014-01-29 17:07 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2014-01-29 17:01 - 2012-03-01 07:38 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2014-01-29 17:01 - 2012-03-01 06:37 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2014-01-29 16:51 - 2014-01-29 16:51 - 01166132 _____ C:\Users\Patrick Polzyn\Desktop\adwcleaner.exe 2014-01-29 15:47 - 2014-01-29 16:10 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-01-29 15:47 - 2014-01-29 15:47 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-01-29 15:46 - 2014-01-29 15:46 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-01-29 15:45 - 2014-01-29 16:10 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\mbar 2014-01-29 15:44 - 2014-01-29 15:44 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Patrick Polzyn\Desktop\mbar-1.07.0.1009.exe 2014-01-29 14:06 - 2014-01-29 19:19 - 00000000 ____D C:\FRST 2014-01-29 11:24 - 2014-01-29 17:24 - 00018807 _____ C:\Windows\IE10_main.log 2014-01-29 10:54 - 2014-01-29 10:54 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\AskPartnerNetwork 2014-01-29 10:46 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-01-29 10:46 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2014-01-29 10:46 - 2013-04-12 15:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-01-29 10:46 - 2013-02-15 07:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-01-29 10:46 - 2013-02-15 07:06 - 03717632 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-01-29 10:46 - 2013-02-15 07:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2014-01-29 10:46 - 2013-02-15 05:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-01-29 10:46 - 2013-02-15 05:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2014-01-29 10:46 - 2013-02-15 04:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-01-29 10:46 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2014-01-29 10:46 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2014-01-29 10:46 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2014-01-29 10:46 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2014-01-29 10:46 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2014-01-29 10:46 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2014-01-29 10:46 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll 2014-01-29 10:46 - 2012-01-04 11:44 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll 2014-01-29 10:46 - 2012-01-04 09:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll 2014-01-29 10:46 - 2011-10-26 06:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2014-01-29 10:46 - 2011-10-26 06:25 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-01-29 10:46 - 2011-10-26 05:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2014-01-29 10:46 - 2011-10-26 05:32 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-01-29 10:46 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2014-01-29 10:46 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2014-01-29 10:45 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-29 10:45 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-29 10:45 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-29 10:45 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-29 10:45 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-29 10:45 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-29 10:45 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-29 10:45 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-01-29 10:45 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-01-29 10:45 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2014-01-29 10:45 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2014-01-29 10:45 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-01-29 10:45 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-01-29 10:45 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-01-29 10:45 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-01-29 10:45 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-01-29 10:45 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-01-29 10:45 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-01-29 10:45 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-01-29 10:45 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-01-29 10:45 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-01-29 10:45 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-01-29 10:45 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-01-29 10:45 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-01-29 10:45 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-01-29 10:45 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2014-01-29 10:45 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2014-01-29 10:45 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-01-29 10:45 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-01-29 10:45 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2014-01-29 10:45 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2014-01-29 10:45 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2014-01-29 10:45 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2014-01-29 10:45 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2014-01-29 10:45 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2014-01-29 10:45 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2014-01-29 10:45 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2014-01-29 10:45 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2014-01-29 10:45 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2014-01-29 10:45 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2014-01-29 10:45 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2014-01-29 10:45 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2014-01-29 10:45 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2014-01-29 10:45 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2014-01-29 10:45 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2014-01-29 10:45 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2014-01-29 10:45 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2014-01-29 10:45 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2014-01-29 10:45 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2014-01-29 10:45 - 2012-06-09 06:43 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-01-29 10:45 - 2012-06-09 05:41 - 12873728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-01-29 10:45 - 2012-04-26 06:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-01-29 10:45 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2014-01-29 10:45 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe 2014-01-29 10:45 - 2011-12-30 07:26 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl 2014-01-29 10:45 - 2011-12-30 06:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl 2014-01-29 10:45 - 2011-03-11 07:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2014-01-29 10:45 - 2011-03-11 07:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2014-01-29 10:45 - 2011-03-11 06:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2014-01-29 10:45 - 2011-03-11 06:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2014-01-29 10:44 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2014-01-29 10:44 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2014-01-29 10:44 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2014-01-29 10:44 - 2013-07-09 06:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-01-29 10:44 - 2013-07-09 05:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-01-29 10:44 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2014-01-29 10:44 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2014-01-29 10:44 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2014-01-29 10:44 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2014-01-29 10:44 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2014-01-29 10:44 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2014-01-29 10:44 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2014-01-29 10:44 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2014-01-29 10:44 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2014-01-29 10:44 - 2013-06-15 05:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-01-29 10:44 - 2013-06-04 07:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-01-29 10:44 - 2013-06-04 05:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-01-29 10:44 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2014-01-29 10:44 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll 2014-01-29 10:44 - 2012-11-28 23:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2014-01-29 10:44 - 2012-11-22 06:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-01-29 10:44 - 2012-11-22 05:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-01-29 10:44 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2014-01-29 10:44 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll 2014-01-29 10:44 - 2012-11-01 06:43 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-01-29 10:44 - 2012-11-01 06:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-01-29 10:44 - 2012-11-01 05:47 - 01389568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-01-29 10:44 - 2012-11-01 05:47 - 01236992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-01-29 10:44 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2014-01-29 10:44 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2014-01-29 10:44 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2014-01-29 10:44 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2014-01-29 10:44 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2014-01-29 10:44 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2014-01-29 10:44 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2014-01-29 10:44 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2014-01-29 10:44 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2014-01-29 10:44 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2014-01-29 10:44 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2014-01-29 10:44 - 2012-05-01 06:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2014-01-29 10:44 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2014-01-29 10:44 - 2011-04-29 04:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2014-01-29 10:44 - 2011-04-29 04:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2014-01-29 10:44 - 2011-04-29 04:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2014-01-29 10:44 - 2011-04-22 23:15 - 00027520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-01-29 10:44 - 2011-03-03 07:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2014-01-29 10:44 - 2011-03-03 07:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2014-01-29 10:44 - 2011-03-03 07:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe 2014-01-29 10:44 - 2011-03-03 06:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2014-01-29 10:44 - 2011-03-03 06:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe 2014-01-29 10:44 - 2010-06-26 04:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-01-29 10:44 - 2010-06-26 04:24 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-01-29 10:43 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-29 10:43 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-29 10:43 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-01-29 10:43 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-01-29 10:43 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-01-29 10:43 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2014-01-29 10:43 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-01-29 10:43 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2014-01-29 10:43 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-01-29 10:43 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-01-29 10:43 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-01-29 10:43 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2014-01-29 10:43 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-01-29 10:43 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2014-01-29 10:43 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-01-29 10:43 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-01-29 10:43 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-01-29 10:43 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-01-29 10:43 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2014-01-29 10:43 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2014-01-29 10:43 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2014-01-29 10:43 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2014-01-29 10:43 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2014-01-29 10:43 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2014-01-29 10:43 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2014-01-29 10:43 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2014-01-29 10:43 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2014-01-29 10:43 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2014-01-29 10:43 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2014-01-29 10:43 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2014-01-29 10:43 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2014-01-29 10:43 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2014-01-29 10:43 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2014-01-29 10:43 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2014-01-29 10:43 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2014-01-29 10:43 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2014-01-29 10:43 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2014-01-29 10:43 - 2012-11-30 06:45 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-01-29 10:43 - 2012-11-30 06:45 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-01-29 10:43 - 2012-11-30 06:43 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-01-29 10:43 - 2012-11-30 00:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls 2014-01-29 10:43 - 2012-11-30 00:15 - 00420064 _____ C:\Windows\system32\locale.nls 2014-01-29 10:43 - 2012-08-11 01:56 - 00715776 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-01-29 10:43 - 2012-08-11 00:56 - 00542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-01-29 10:43 - 2012-04-28 04:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-01-29 10:43 - 2012-04-07 13:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-01-29 10:43 - 2012-04-07 12:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-01-29 10:43 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2014-01-29 10:43 - 2011-08-17 06:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2014-01-29 10:43 - 2011-08-17 06:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax 2014-01-29 10:43 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll 2014-01-29 10:43 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax 2014-01-29 10:42 - 2013-11-02 03:28 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-29 10:42 - 2013-11-02 03:28 - 01188864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-29 10:42 - 2013-11-02 03:28 - 00134144 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-29 10:42 - 2013-11-02 03:26 - 09073152 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-29 10:42 - 2013-11-02 03:26 - 00735232 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-29 10:42 - 2013-11-02 03:26 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-29 10:42 - 2013-11-02 03:25 - 12295168 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-29 10:42 - 2013-11-02 03:25 - 02458112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-29 10:42 - 2013-11-02 03:25 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-29 10:42 - 2013-11-02 03:25 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-29 10:42 - 2013-11-02 03:07 - 01232896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-01-29 10:42 - 2013-11-02 03:07 - 00981504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-01-29 10:42 - 2013-11-02 03:07 - 00132096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-01-29 10:42 - 2013-11-02 03:04 - 06039552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-01-29 10:42 - 2013-11-02 03:04 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-29 10:42 - 2013-11-02 03:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-01-29 10:42 - 2013-11-02 03:04 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-01-29 10:42 - 2013-11-02 03:03 - 11020800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-01-29 10:42 - 2013-11-02 03:03 - 02078208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-01-29 10:42 - 2013-11-02 03:03 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-01-29 10:42 - 2013-11-02 02:30 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-29 10:42 - 2013-11-02 02:13 - 01638912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-01-29 10:42 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-01-29 10:42 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-01-29 10:42 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2014-01-29 10:42 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2014-01-29 10:42 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2014-01-29 10:42 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2014-01-29 10:42 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2014-01-29 10:42 - 2013-01-03 07:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2014-01-29 10:42 - 2012-11-23 04:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2014-01-29 10:42 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll 2014-01-29 10:42 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2014-01-29 10:42 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2014-01-29 10:42 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll 2014-01-29 10:42 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll 2014-01-29 10:42 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2014-01-29 10:42 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2014-01-29 10:42 - 2012-06-16 06:16 - 00609792 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-29 10:42 - 2012-06-16 06:15 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-29 10:42 - 2012-06-16 05:26 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-29 10:42 - 2012-06-16 05:26 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-01-29 10:42 - 2012-05-05 09:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2014-01-29 10:42 - 2012-05-05 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2014-01-29 10:42 - 2011-05-24 12:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll 2014-01-29 10:42 - 2011-05-24 11:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll 2014-01-29 10:42 - 2011-05-24 11:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll 2014-01-29 10:42 - 2011-05-24 11:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll 2014-01-29 10:42 - 2011-05-24 11:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe 2014-01-29 10:42 - 2011-02-18 11:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe 2014-01-29 10:42 - 2011-02-18 06:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe 2014-01-29 10:42 - 2011-02-05 18:10 - 00642944 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2014-01-29 10:42 - 2011-02-05 18:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2014-01-29 10:42 - 2011-02-05 18:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2014-01-29 10:42 - 2011-02-05 18:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2014-01-29 10:42 - 2011-02-05 18:06 - 00605552 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2014-01-29 10:42 - 2011-02-05 18:06 - 00566208 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2014-01-29 10:42 - 2011-02-05 18:06 - 00518672 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2014-01-29 10:41 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2014-01-29 10:41 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-01-29 10:41 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2014-01-29 10:41 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2014-01-29 10:41 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2014-01-29 10:41 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2014-01-29 10:41 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2014-01-29 10:41 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2014-01-29 10:41 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2014-01-29 10:41 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2014-01-29 10:41 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2014-01-29 10:41 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2014-01-29 10:41 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2014-01-29 10:41 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2014-01-29 10:41 - 2013-08-27 10:01 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2014-01-29 10:41 - 2013-08-27 10:01 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2014-01-29 10:41 - 2013-08-27 09:21 - 01077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2014-01-29 10:41 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-01-29 10:41 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2014-01-29 10:41 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2014-01-29 10:41 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2014-01-29 10:41 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2014-01-29 10:41 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2014-01-29 10:41 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll 2014-01-29 10:41 - 2011-10-15 07:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2014-01-29 10:41 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2014-01-29 10:41 - 2011-08-27 06:37 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-01-29 10:41 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll 2014-01-29 10:41 - 2011-08-27 05:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-01-29 10:41 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll 2014-01-29 10:41 - 2011-05-03 06:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2014-01-29 10:41 - 2011-05-03 05:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2014-01-29 10:41 - 2011-02-23 05:56 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2014-01-29 10:41 - 2011-02-23 05:55 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2014-01-29 10:41 - 2011-02-23 05:55 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2014-01-29 10:41 - 2011-02-23 05:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys 2014-01-29 10:41 - 2011-02-12 12:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe 2014-01-29 10:41 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2014-01-29 10:25 - 2011-11-19 15:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-01-29 10:25 - 2011-11-19 15:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-01-29 04:21 - 2014-01-28 21:06 - 00000000 ____D C:\Windows\Panther 2014-01-29 04:18 - 2014-01-29 04:18 - 00262144 _____ C:\Windows\system32\config\userdiff 2014-01-29 04:18 - 2011-02-16 03:16 - 00000029 ___RH C:\Windows\version 2014-01-29 04:18 - 2011-02-16 03:16 - 00000013 ____R C:\Windows\csup.txt 2014-01-29 04:17 - 2014-01-29 19:14 - 00696132 _____ C:\Windows\system32\perfh007.dat 2014-01-29 04:17 - 2014-01-29 19:14 - 00147428 _____ C:\Windows\system32\perfc007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00295922 _____ C:\Windows\system32\perfi007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00038104 _____ C:\Windows\system32\perfd007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\0407 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\0407 2014-01-29 04:09 - 2014-01-28 20:35 - 00000000 ___HD C:\$WINDOWS.~Q 2014-01-29 03:51 - 2014-01-29 03:58 - 00000000 ___HD C:\$INPLACE.~TR 2014-01-28 21:13 - 2014-01-29 11:05 - 01588294 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-28 21:10 - 2014-01-28 21:10 - 00001443 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-28 21:10 - 2014-01-28 21:10 - 00001409 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-01-28 21:06 - 2014-01-28 21:06 - 00000020 ___SH C:\Users\Patrick Polzyn\ntuser.ini 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Favoriten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Dokumente 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2014-01-28 20:55 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2014-01-28 20:55 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2014-01-28 20:55 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2014-01-28 20:47 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-01-28 20:47 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-01-28 20:47 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-01-28 20:47 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-01-28 20:47 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-01-28 20:47 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-01-28 20:47 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-01-28 20:46 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-01-28 20:46 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-01-28 19:27 - 2014-01-28 21:06 - 00000000 ____D C:\Users\Patrick Polzyn 2014-01-28 19:27 - 2014-01-28 20:18 - 00000000 ____D C:\Users\Administrator 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Anwendungsdaten 2014-01-28 19:27 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 19:27 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 19:27 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 19:27 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 19:27 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 19:27 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 19:26 - 2014-01-28 19:59 - 00000000 ____D C:\ProgramData\EPSON 2014-01-28 19:26 - 2014-01-28 19:37 - 00000000 ____D C:\Program Files\Common Files\EPSON 2014-01-28 19:26 - 2014-01-28 19:26 - 00001355 _____ C:\Windows\TSSysprep.log 2014-01-28 19:25 - 2014-01-29 19:13 - 01268074 _____ C:\Windows\WindowsUpdate.log 2014-01-28 19:25 - 2014-01-29 19:07 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-28 19:25 - 2014-01-28 19:59 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2014-01-28 19:25 - 2014-01-28 19:40 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-28 19:25 - 2014-01-28 19:37 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files\Realtek 2014-01-28 19:25 - 2013-10-23 09:20 - 06669600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 03489568 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 03426956 _____ C:\Windows\system32\nvcoproc.bin 2014-01-28 19:25 - 2013-10-23 09:20 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-01-28 19:25 - 2013-10-23 09:20 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-01-28 19:25 - 2013-10-23 09:20 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-01-28 19:24 - 2014-01-28 19:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-01-28 18:22 - 2014-01-28 20:35 - 00006773 _____ C:\Windows\comsetup.log 2014-01-27 18:55 - 2014-01-29 19:05 - 00000000 ____D C:\AdwCleaner 2014-01-27 18:55 - 2014-01-28 20:20 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Malwarebytes 2014-01-27 18:55 - 2014-01-28 19:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-27 18:55 - 2014-01-28 19:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-27 18:55 - 2014-01-27 18:55 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-27 18:55 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-27 18:35 - 2014-01-28 19:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-27 18:35 - 2014-01-27 18:35 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-27 13:54 - 2014-01-28 19:58 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2014-01-27 13:54 - 2014-01-28 19:38 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork 2014-01-27 12:41 - 2014-01-27 12:41 - 02278856 _____ C:\Users\Patrick Polzyn\Downloads\avira_pc_cleaner_de.exe 2014-01-27 12:41 - 2014-01-27 12:41 - 00002049 _____ C:\Users\Patrick Polzyn\Desktop\Entfernen des Avira PC Cleaners.lnk 2014-01-27 12:41 - 2014-01-27 12:41 - 00001993 _____ C:\Users\Patrick Polzyn\Desktop\Avira PC Cleaner.lnk 2014-01-27 08:39 - 2014-01-27 08:39 - 00000262 _____ C:\Users\Patrick Polzyn\Desktop\Run.lnk 2014-01-26 10:06 - 2014-01-26 10:06 - 23867560 _____ (Mozilla) C:\Users\Patrick Polzyn\Downloads\Firefox Setup 26.0.exe 2014-01-25 14:02 - 2014-01-25 14:02 - 00004540 _____ C:\Users\Patrick Polzyn\Documents\cc_20140125_140224.reg 2014-01-25 12:10 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\LicenseCrawler 2014-01-24 18:27 - 2014-01-24 18:27 - 00316109 _____ C:\Users\Patrick Polzyn\Desktop\Grenzsteine_DE-PL.rwp 2014-01-24 16:33 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\PR_PKP_infra_02 2014-01-24 16:30 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\ZestawSieciTrakcyjnejPKP 2014-01-13 16:45 - 2014-01-13 16:45 - 00001566 _____ C:\Users\Patrick Polzyn\Desktop\railworks - Verknüpfung.lnk 2014-01-11 19:27 - 2014-01-28 20:21 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Developer Docs 2014-01-08 20:18 - 2012-09-10 20:42 - 00275899 _____ C:\Users\Patrick Polzyn\Desktop\DR-So2_und_So7-Tafeln.rwp 2014-01-05 10:14 - 2014-01-05 10:14 - 00115592 _____ C:\Users\Patrick Polzyn\Documents\cc_20140105_101436.reg ==================== One Month Modified Files and Folders ======= 2014-01-29 19:19 - 2014-01-29 19:19 - 02079744 _____ (Farbar) C:\Users\Patrick Polzyn\Desktop\FRST64.exe 2014-01-29 19:19 - 2014-01-29 19:19 - 00015897 _____ C:\Users\Patrick Polzyn\Desktop\FRST.txt 2014-01-29 19:19 - 2014-01-29 14:06 - 00000000 ____D C:\FRST 2014-01-29 19:19 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-29 19:15 - 2014-01-29 19:15 - 00001624 _____ C:\Users\Patrick Polzyn\Desktop\JRT.txt 2014-01-29 19:14 - 2014-01-29 04:17 - 00696132 _____ C:\Windows\system32\perfh007.dat 2014-01-29 19:14 - 2014-01-29 04:17 - 00147428 _____ C:\Windows\system32\perfc007.dat 2014-01-29 19:14 - 2014-01-28 19:25 - 01268074 _____ C:\Windows\WindowsUpdate.log 2014-01-29 19:14 - 2009-07-14 06:13 - 01611160 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-29 19:14 - 2009-07-14 05:45 - 00025680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-29 19:14 - 2009-07-14 05:45 - 00025680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-29 19:10 - 2014-01-29 19:10 - 00000000 ____D C:\Windows\ERUNT 2014-01-29 19:09 - 2014-01-29 19:09 - 01037068 _____ (Thisisu) C:\Users\Patrick Polzyn\Desktop\JRT.exe 2014-01-29 19:08 - 2013-06-21 17:35 - 00000439 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2014-01-29 19:08 - 2013-02-19 15:30 - 00001122 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-29 19:07 - 2014-01-28 19:25 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-29 19:07 - 2012-10-17 16:30 - 00000000 ____D C:\Program Files (x86)\Steam 2014-01-29 19:07 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-29 19:07 - 2009-07-14 05:51 - 01275560 _____ C:\Windows\setupact.log 2014-01-29 19:05 - 2014-01-27 18:55 - 00000000 ____D C:\AdwCleaner 2014-01-29 19:01 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2014-01-29 19:00 - 2012-10-16 20:34 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-29 19:00 - 2012-10-16 20:34 - 00000000 ___RD C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-29 18:58 - 2013-01-16 09:55 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-01-29 18:58 - 2010-11-21 04:47 - 00012616 _____ C:\Windows\PFRO.log 2014-01-29 18:58 - 2009-07-14 05:45 - 00368424 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-29 17:46 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2014-01-29 17:46 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2014-01-29 17:46 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2014-01-29 17:46 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System 2014-01-29 17:45 - 2010-11-21 08:17 - 00000000 ____D C:\Program Files\Windows Journal 2014-01-29 17:45 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\winrm 2014-01-29 17:45 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\WCN 2014-01-29 17:45 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\sysprep 2014-01-29 17:45 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\slmgr 2014-01-29 17:45 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2014-01-29 17:45 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\winrm 2014-01-29 17:45 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\WCN 2014-01-29 17:45 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\slmgr 2014-01-29 17:45 - 2010-11-21 08:06 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2014-01-29 17:45 - 2009-07-14 06:37 - 00000000 ____D C:\Windows\DigitalLocker 2014-01-29 17:45 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2014-01-29 17:45 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2014-01-29 17:45 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker 2014-01-29 17:45 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar 2014-01-29 17:45 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Setup 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\oobe 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\MUI 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\com 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sysprep 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Setup 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\MUI 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\migwiz 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\com 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\servicing 2014-01-29 17:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\IME 2014-01-29 17:24 - 2014-01-29 11:24 - 00018807 _____ C:\Windows\IE10_main.log 2014-01-29 17:07 - 2013-02-19 15:30 - 00001126 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-29 16:51 - 2014-01-29 16:51 - 01166132 _____ C:\Users\Patrick Polzyn\Desktop\adwcleaner.exe 2014-01-29 16:50 - 2012-12-28 16:57 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-29 16:10 - 2014-01-29 15:47 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-01-29 16:10 - 2014-01-29 15:45 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\mbar 2014-01-29 15:47 - 2014-01-29 15:47 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-01-29 15:46 - 2014-01-29 15:46 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-01-29 15:44 - 2014-01-29 15:44 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Patrick Polzyn\Desktop\mbar-1.07.0.1009.exe 2014-01-29 11:05 - 2014-01-28 21:13 - 01588294 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-29 10:54 - 2014-01-29 10:54 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\AskPartnerNetwork 2014-01-29 04:21 - 2009-07-14 06:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2014-01-29 04:21 - 2009-07-14 06:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2014-01-29 04:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\oobe 2014-01-29 04:18 - 2014-01-29 04:18 - 00262144 _____ C:\Windows\system32\config\userdiff 2014-01-29 04:18 - 2009-07-14 05:45 - 00000000 ____D C:\Windows\Setup 2014-01-29 04:17 - 2014-01-29 04:17 - 00295922 _____ C:\Windows\system32\perfi007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00038104 _____ C:\Windows\system32\perfd007.dat 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\SysWOW64\0407 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\de 2014-01-29 04:17 - 2014-01-29 04:17 - 00000000 ____D C:\Windows\system32\0407 2014-01-29 04:17 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2014-01-29 03:58 - 2014-01-29 03:51 - 00000000 ___HD C:\$INPLACE.~TR 2014-01-28 21:39 - 2012-12-17 08:18 - 00002070 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2014-01-28 21:10 - 2014-01-28 21:10 - 00001443 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-28 21:10 - 2014-01-28 21:10 - 00001409 _____ C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-01-28 21:06 - 2014-01-29 04:21 - 00000000 ____D C:\Windows\Panther 2014-01-28 21:06 - 2014-01-28 21:06 - 00000020 ___SH C:\Users\Patrick Polzyn\ntuser.ini 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Vorlagen 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Startmenü 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Favoriten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Dokumente 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2014-01-28 21:06 - 2014-01-28 21:06 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2014-01-28 21:06 - 2014-01-28 19:27 - 00000000 ____D C:\Users\Patrick Polzyn 2014-01-28 21:06 - 2012-04-13 19:07 - 00000000 __SHD C:\Recovery 2014-01-28 21:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Recovery 2014-01-28 21:06 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT 2014-01-28 20:46 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\restore 2014-01-28 20:46 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration 2014-01-28 20:35 - 2014-01-29 04:09 - 00000000 ___HD C:\$WINDOWS.~Q 2014-01-28 20:35 - 2014-01-28 18:22 - 00006773 _____ C:\Windows\comsetup.log 2014-01-28 20:31 - 2012-11-17 11:29 - 00023056 _____ C:\Windows\system32\emptyregdb.dat 2014-01-28 20:30 - 2013-01-16 09:56 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2014-01-28 20:25 - 2013-09-26 08:08 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-01-28 20:25 - 2009-07-14 05:46 - 00005157 _____ C:\Windows\DtcInstall.log 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-28 20:25 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-28 20:22 - 2013-06-12 17:36 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\TomTom 2014-01-28 20:22 - 2013-05-26 12:12 - 00000000 ___RD C:\Users\Patrick Polzyn\Dropbox 2014-01-28 20:22 - 2013-01-26 12:04 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\SimCity 2014-01-28 20:22 - 2012-12-10 19:33 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\SelfMV 2014-01-28 20:22 - 2012-10-17 16:11 - 00000000 ____D C:\Users\Patrick Polzyn\Lucidlogix 2014-01-28 20:22 - 2012-10-17 16:11 - 00000000 ____D C:\Users\Patrick Polzyn\dwhelper 2014-01-28 20:21 - 2014-01-25 12:10 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\LicenseCrawler 2014-01-28 20:21 - 2014-01-24 16:33 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\PR_PKP_infra_02 2014-01-28 20:21 - 2014-01-24 16:30 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\ZestawSieciTrakcyjnejPKP 2014-01-28 20:21 - 2014-01-11 19:27 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Developer Docs 2014-01-28 20:21 - 2013-12-12 18:30 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Camera 2014-01-28 20:21 - 2013-11-23 19:18 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\daten von justin usb 2014-01-28 20:21 - 2013-11-23 18:23 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\eRightSoft 2014-01-28 20:21 - 2013-11-23 14:34 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Dateien für Streckenprojekt 2014-01-28 20:21 - 2013-11-13 17:45 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Dokumente Viktor 2014-01-28 20:21 - 2013-11-10 18:15 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\usb stick christoph 2014-01-28 20:21 - 2013-11-04 17:47 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Inventor Server x64 3dsMax 2014-01-28 20:21 - 2013-07-08 16:19 - 00000000 ____D C:\Users\Patrick Polzyn\Desktop\Bilder Verkauf 2014-01-28 20:21 - 2013-06-12 18:57 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Bandicam 2014-01-28 20:21 - 2013-06-12 17:36 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\TomTom 2014-01-28 20:21 - 2013-03-14 15:56 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\WinRAR 2014-01-28 20:21 - 2013-02-26 15:34 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3DCrafter 9.2 2014-01-28 20:21 - 2013-01-26 11:48 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Origin 2014-01-28 20:21 - 2013-01-22 10:59 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\AdobeStockPhotos 2014-01-28 20:21 - 2013-01-18 13:24 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3dsMaxDesign 2014-01-28 20:21 - 2013-01-06 19:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\PDF Architect 2014-01-28 20:21 - 2012-12-09 12:06 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\samsung 2014-01-28 20:21 - 2012-12-09 12:06 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Samsung 2014-01-28 20:21 - 2012-10-18 18:39 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\OpenOffice.org 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\Inventor 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\4A Games 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3dsMax 2014-01-28 20:21 - 2012-10-17 16:35 - 00000000 ____D C:\Users\Patrick Polzyn\Documents\3DCrafter 9.1 2014-01-28 20:20 - 2014-01-27 18:55 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Malwarebytes 2014-01-28 20:20 - 2013-11-15 18:28 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RW_Tools 2014-01-28 20:20 - 2013-09-28 06:50 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FAKEFACTORY CM2013 2014-01-28 20:20 - 2013-06-26 12:43 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\DVDVideoSoft 2014-01-28 20:20 - 2013-06-21 17:49 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Azureus 2014-01-28 20:20 - 2013-06-12 18:58 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\BANDISOFT 2014-01-28 20:20 - 2013-06-09 16:44 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Garmin 2014-01-28 20:20 - 2013-05-26 12:11 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-28 20:20 - 2013-05-26 12:08 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Dropbox 2014-01-28 20:20 - 2013-05-15 19:08 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\3DTrains 2014-01-28 20:20 - 2013-03-14 15:56 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-01-28 20:20 - 2013-02-17 14:17 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rail Simulator Packager Manager 2014-01-28 20:20 - 2013-01-27 19:27 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Apple Computer 2014-01-28 20:20 - 2013-01-06 19:22 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\APP_NAME_NON_STRING 2014-01-28 20:20 - 2013-01-06 14:43 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\#Startup# 2014-01-28 20:20 - 2012-12-17 08:23 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Avira 2014-01-28 20:20 - 2012-12-11 14:30 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\InstallShield 2014-01-28 20:20 - 2012-12-06 11:07 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\EPSON 2014-01-28 20:20 - 2012-11-29 14:28 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Autodesk 2014-01-28 20:20 - 2012-11-18 19:39 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Need for Speed World 2014-01-28 20:20 - 2012-11-13 18:23 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Foxit Software 2014-01-28 20:20 - 2012-10-17 18:59 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\NVIDIA 2014-01-28 20:20 - 2012-10-17 16:44 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-01-28 20:20 - 2012-10-16 21:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Macromedia 2014-01-28 20:20 - 2012-10-16 21:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Adobe 2014-01-28 20:20 - 2012-10-16 20:37 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla 2014-01-28 20:19 - 2013-10-20 14:22 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\RailSimulator.com 2014-01-28 20:19 - 2013-06-13 15:40 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Windows Live 2014-01-28 20:19 - 2013-06-12 17:36 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\TomTom 2014-01-28 20:19 - 2013-02-19 15:30 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Google 2014-01-28 20:19 - 2013-02-13 11:55 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Autodesk, Inc 2014-01-28 20:19 - 2013-01-26 11:47 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Origin 2014-01-28 20:19 - 2013-01-22 11:28 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\gegl-0.2 2014-01-28 20:19 - 2013-01-18 13:37 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\backburner 2014-01-28 20:19 - 2013-01-18 11:38 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\cFos 2014-01-28 20:19 - 2012-12-09 12:07 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Samsung 2014-01-28 20:19 - 2012-12-09 12:03 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\NVIDIA 2014-01-28 20:19 - 2012-12-09 12:00 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Downloaded Installations 2014-01-28 20:19 - 2012-11-29 14:45 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Autodesk 2014-01-28 20:19 - 2012-11-18 18:06 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Electronic_Arts_Inc 2014-01-28 20:19 - 2012-10-18 10:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Nexway 2014-01-28 20:19 - 2012-10-16 21:24 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Macromedia 2014-01-28 20:19 - 2012-10-16 20:37 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Mozilla 2014-01-28 20:19 - 2012-10-16 20:34 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\VirtualStore 2014-01-28 20:18 - 2014-01-28 19:27 - 00000000 ____D C:\Users\Administrator 2014-01-28 20:18 - 2013-12-01 19:19 - 00000000 ____D C:\Users\Administrator\AppData\Local\Autodesk 2014-01-28 20:18 - 2013-09-09 16:05 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\APP_NAME_NON_STRING 2014-01-28 20:18 - 2013-09-09 16:03 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia 2014-01-28 20:18 - 2013-09-09 16:03 - 00000000 ____D C:\Users\Administrator\AppData\Local\Macromedia 2014-01-28 20:18 - 2013-09-09 16:03 - 00000000 ____D C:\Users\Administrator\AppData\Local\DoNotTrackPlus 2014-01-28 20:18 - 2013-09-09 16:02 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Mozilla 2014-01-28 20:18 - 2013-09-09 16:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\Mozilla 2014-01-28 20:18 - 2013-09-09 15:25 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Avira 2014-01-28 20:18 - 2013-09-09 15:21 - 00000000 ____D C:\Users\Administrator\Documents\4a games 2014-01-28 20:18 - 2013-06-21 17:31 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-28 20:18 - 2013-06-21 17:31 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-28 20:18 - 2013-06-21 17:31 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe 2014-01-28 20:18 - 2013-02-13 11:44 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Akamai 2014-01-28 20:18 - 2013-01-27 13:41 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Apple 2014-01-28 20:18 - 2013-01-22 11:36 - 00000000 ____D C:\Users\Patrick Polzyn\.thumbnails 2014-01-28 20:18 - 2013-01-22 11:28 - 00000000 ____D C:\Users\Patrick Polzyn\.gimp-2.8 2014-01-28 20:18 - 2013-01-22 10:47 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\Adobe 2014-01-28 20:18 - 2012-12-25 15:12 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Local\4A Games 2014-01-28 20:18 - 2012-10-17 16:09 - 00000000 ____D C:\Users\Patrick Polzyn\.swt 2014-01-28 20:00 - 2013-07-16 17:58 - 00000000 ____D C:\Windows\Uninstall 2014-01-28 20:00 - 2013-01-18 12:01 - 00000000 ____D C:\Windows\system32\appmgmt 2014-01-28 20:00 - 2012-12-14 21:02 - 00000000 ____D C:\Windows\pss 2014-01-28 20:00 - 2012-10-16 21:15 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2014-01-28 20:00 - 2012-10-16 21:15 - 00000000 ____D C:\Windows\system32\Macromed 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR 2014-01-28 20:00 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2014-01-28 19:59 - 2014-01-28 19:26 - 00000000 ____D C:\ProgramData\EPSON 2014-01-28 19:59 - 2014-01-28 19:25 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2014-01-28 19:59 - 2014-01-27 18:55 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-28 19:59 - 2013-06-13 15:43 - 00000000 ____D C:\Windows\de 2014-01-28 19:59 - 2013-06-12 17:38 - 00000000 ____D C:\ProgramData\TomTom 2014-01-28 19:59 - 2013-05-30 08:09 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-28 19:59 - 2013-05-15 19:08 - 00000000 ____D C:\Windows\3DTrains 2014-01-28 19:59 - 2013-01-26 11:47 - 00000000 ____D C:\ProgramData\Origin 2014-01-28 19:59 - 2013-01-22 10:46 - 00000000 ____D C:\Users\Public\Documents\Adobe PDF 2014-01-28 19:59 - 2013-01-18 11:59 - 00000000 _RSHD C:\ProgramData\Key-Base 2014-01-28 19:59 - 2013-01-18 11:38 - 00000000 ____D C:\ProgramData\FNET 2014-01-28 19:59 - 2013-01-16 09:56 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2014-01-28 19:59 - 2012-12-17 08:10 - 00000000 ____D C:\Windows\erdnt 2014-01-28 19:59 - 2012-12-09 12:05 - 00000000 ____D C:\ProgramData\Samsung 2014-01-28 19:59 - 2012-11-29 14:45 - 00000000 ____D C:\ProgramData\FLEXnet 2014-01-28 19:59 - 2012-10-17 18:52 - 00000000 ____D C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP 2014-01-28 19:59 - 2012-10-16 21:37 - 00000000 ____D C:\Users\Public\Documents\S.T.A.L.K.E.R. - Call of Pripyat 2014-01-28 19:59 - 2012-10-16 21:06 - 00000000 ____D C:\ProgramData\Sun 2014-01-28 19:59 - 2012-10-16 20:37 - 00000000 ____D C:\ProgramData\Mozilla 2014-01-28 19:59 - 2010-11-21 08:16 - 00000000 ___RD C:\Users\Public\Recorded TV 2014-01-28 19:59 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries 2014-01-28 19:59 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports 2014-01-28 19:58 - 2014-01-27 13:54 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2014-01-28 19:58 - 2013-11-04 15:25 - 00000000 ____D C:\ProgramData\Applications 2014-01-28 19:58 - 2013-06-26 17:22 - 00000000 ____D C:\ProgramData\BlueStacksSetup 2014-01-28 19:58 - 2013-06-26 17:22 - 00000000 ____D C:\ProgramData\BlueStacks 2014-01-28 19:58 - 2013-06-13 15:42 - 00000000 ____D C:\Program Files (x86)\Windows Live 2014-01-28 19:58 - 2013-01-27 13:41 - 00000000 ____D C:\ProgramData\Apple Computer 2014-01-28 19:58 - 2013-01-27 13:40 - 00000000 ____D C:\ProgramData\Apple 2014-01-28 19:58 - 2013-01-18 11:38 - 00000000 ____D C:\ProgramData\cFos 2014-01-28 19:58 - 2012-11-29 14:28 - 00000000 ____D C:\ProgramData\Autodesk 2014-01-28 19:58 - 2012-11-18 18:04 - 00000000 ____D C:\ProgramData\Electronic Arts 2014-01-28 19:58 - 2012-10-16 21:48 - 00000000 ____D C:\ProgramData\Avira 2014-01-28 19:58 - 2012-10-16 21:15 - 00000000 ____D C:\ProgramData\Adobe 2014-01-28 19:58 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\XFastUsb 2014-01-28 19:40 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-28 19:40 - 2014-01-27 18:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-28 19:40 - 2014-01-27 18:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-28 19:40 - 2013-12-21 16:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-28 19:40 - 2013-06-13 15:43 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2014-01-28 19:40 - 2013-03-13 22:09 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2014-01-28 19:40 - 2013-02-20 20:21 - 00000000 ____D C:\Program Files (x86)\Foxit Software 2014-01-28 19:40 - 2013-02-20 18:40 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 2014-01-28 19:40 - 2013-02-19 15:30 - 00000000 ____D C:\Program Files (x86)\Google 2014-01-28 19:40 - 2013-01-27 13:41 - 00000000 ____D C:\Program Files (x86)\QuickTime 2014-01-28 19:40 - 2013-01-26 11:47 - 00000000 ____D C:\Program Files (x86)\Origin 2014-01-28 19:40 - 2013-01-23 12:02 - 00000000 ____D C:\Program Files (x86)\Magical Jelly Bean 2014-01-28 19:40 - 2013-01-22 10:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2014-01-28 19:40 - 2013-01-22 10:58 - 00000000 ____D C:\Program Files (x86)\MSECache 2014-01-28 19:40 - 2013-01-06 19:22 - 00000000 ____D C:\Program Files (x86)\PDFCreator 2014-01-28 19:40 - 2013-01-06 19:22 - 00000000 ____D C:\Program Files (x86)\PDF Architect 2014-01-28 19:40 - 2012-12-09 12:07 - 00000000 ____D C:\Program Files (x86)\MarkAny 2014-01-28 19:40 - 2012-12-09 12:05 - 00000000 ____D C:\Program Files (x86)\Samsung 2014-01-28 19:40 - 2012-11-30 17:24 - 00000000 ____D C:\Program Files (x86)\Rail Simulator 2014-01-28 19:40 - 2012-10-18 11:18 - 00000000 ____D C:\Program Files (x86)\Fire Department 3 2014-01-28 19:40 - 2012-10-16 21:06 - 00000000 ____D C:\Program Files (x86)\Java 2014-01-28 19:40 - 2012-10-16 21:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2014-01-28 19:40 - 2012-10-16 21:00 - 00000000 ____D C:\Program Files (x86)\REALTEK 2014-01-28 19:40 - 2012-10-16 20:44 - 00000000 ____D C:\Program Files (x86)\Intel 2014-01-28 19:39 - 2013-11-07 18:38 - 00000000 ____D C:\Program Files (x86)\Convar 2014-01-28 19:39 - 2013-06-26 12:43 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2014-01-28 19:39 - 2013-01-18 11:34 - 00000000 ____D C:\Program Files (x86)\Etron Technology 2014-01-28 19:39 - 2012-11-18 18:04 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2014-01-28 19:39 - 2012-10-18 11:22 - 00000000 ____D C:\Program Files (x86)\Fire Department 2 2014-01-28 19:39 - 2012-10-16 21:16 - 00000000 ____D C:\Program Files (x86)\epson 2014-01-28 19:39 - 2012-10-16 20:45 - 00000000 ____D C:\Program Files (x86)\CyberLink 2014-01-28 19:39 - 2012-10-16 20:45 - 00000000 ____D C:\Program Files (x86)\Creative 2014-01-28 19:38 - 2014-01-27 13:54 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork 2014-01-28 19:38 - 2013-11-23 18:24 - 00000000 ____D C:\Program Files (x86)\AviSynth 2.5 2014-01-28 19:38 - 2013-06-26 17:23 - 00000000 ____D C:\Program Files (x86)\BlueStacks 2014-01-28 19:38 - 2013-06-12 18:57 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1 2014-01-28 19:38 - 2013-06-12 18:57 - 00000000 ____D C:\Program Files (x86)\Bandicam 2014-01-28 19:38 - 2013-02-26 15:33 - 00000000 ____D C:\Program Files (x86)\3DCrafter 92 2014-01-28 19:38 - 2013-02-24 15:53 - 00000000 ____D C:\Program Files (x86)\7-Zip 2014-01-28 19:38 - 2013-01-27 13:40 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2014-01-28 19:38 - 2013-01-18 13:07 - 00000000 ____D C:\Program Files (x86)\Autodesk 2014-01-28 19:38 - 2012-12-17 08:17 - 00000000 ____D C:\Program Files (x86)\Avira 2014-01-28 19:38 - 2012-10-16 20:45 - 00000000 ____D C:\Program Files (x86)\Cisco 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\bitComposer Games 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\ASRock Utility 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\Adobe 2014-01-28 19:38 - 2012-10-16 20:43 - 00000000 ____D C:\Program Files (x86)\3DCrafter 9 2014-01-28 19:37 - 2014-01-28 19:26 - 00000000 ____D C:\Program Files\Common Files\EPSON 2014-01-28 19:37 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2014-01-28 19:37 - 2013-11-07 18:31 - 00000000 ____D C:\Program Files\Recuva 2014-01-28 19:37 - 2013-03-14 15:55 - 00000000 ____D C:\Program Files\WinRAR 2014-01-28 19:37 - 2013-03-13 22:09 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2014-01-28 19:37 - 2013-02-13 11:25 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared 2014-01-28 19:37 - 2013-01-22 11:16 - 00000000 ____D C:\Program Files\GIMP 2 2014-01-28 19:37 - 2013-01-18 11:35 - 00000000 ____D C:\Program Files\Lucidlogix Technologies 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Steam 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\postureAgent 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Java 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\Intel 2014-01-28 19:37 - 2012-10-17 16:12 - 00000000 ____D C:\Program Files\Common Files\InstallShield 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Etron Technology 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Epson Software 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\epson 2014-01-28 19:37 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared 2014-01-28 19:37 - 2012-10-17 16:09 - 00000000 ____D C:\Program Files\CyberLink 2014-01-28 19:37 - 2012-10-17 16:09 - 00000000 ____D C:\Program Files\Creative 2014-01-28 19:37 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\EXPERTool 2014-01-28 19:37 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2014-01-28 19:36 - 2013-02-24 16:03 - 00000000 ____D C:\Program Files\CCleaner 2014-01-28 19:36 - 2012-10-17 16:11 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR 2014-01-28 19:36 - 2012-10-17 16:09 - 00000000 ____D C:\Program Files\Cisco 2014-01-28 19:36 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\bitComposer Games 2014-01-28 19:34 - 2013-02-13 11:24 - 00000000 ____D C:\Program Files\Autodesk 2014-01-28 19:29 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\ASRock Utility 2014-01-28 19:29 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\Adobe 2014-01-28 19:29 - 2012-10-17 16:06 - 00000000 ____D C:\Program Files\3DCrafter 9 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Patrick Polzyn\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Vorlagen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Startmenü 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Netzwerkumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Lokale Einstellungen 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Eigene Dateien 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Druckumgebung 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-01-28 19:27 - 2014-01-28 19:27 - 00000000 _SHDL C:\Users\Administrator\Anwendungsdaten 2014-01-28 19:26 - 2014-01-28 19:26 - 00001355 _____ C:\Windows\TSSysprep.log 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2014-01-28 19:25 - 2014-01-28 19:25 - 00000000 ____D C:\Program Files\Realtek 2014-01-28 19:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Help 2014-01-28 19:24 - 2014-01-28 19:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-01-28 19:23 - 2010-11-21 08:17 - 00000000 ____D C:\Windows\CSC 2014-01-28 18:47 - 2013-01-23 13:15 - 00700540 _____ C:\Windows\WindowsUpdate (1).log 2014-01-28 18:08 - 2012-11-17 10:13 - 00001890 _____ C:\Windows\diagwrn.xml 2014-01-28 18:08 - 2012-11-17 10:13 - 00001890 _____ C:\Windows\diagerr.xml 2014-01-27 18:55 - 2014-01-27 18:55 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-27 18:35 - 2014-01-27 18:35 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-27 12:41 - 2014-01-27 12:41 - 02278856 _____ C:\Users\Patrick Polzyn\Downloads\avira_pc_cleaner_de.exe 2014-01-27 12:41 - 2014-01-27 12:41 - 00002049 _____ C:\Users\Patrick Polzyn\Desktop\Entfernen des Avira PC Cleaners.lnk 2014-01-27 12:41 - 2014-01-27 12:41 - 00001993 _____ C:\Users\Patrick Polzyn\Desktop\Avira PC Cleaner.lnk 2014-01-27 08:39 - 2014-01-27 08:39 - 00000262 _____ C:\Users\Patrick Polzyn\Desktop\Run.lnk 2014-01-26 11:28 - 2013-01-11 09:36 - 00000000 ____D C:\Users\Patrick Polzyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Debugmode 2014-01-26 11:28 - 2013-01-11 09:36 - 00000000 ____D C:\Program Files (x86)\DebugMode 2014-01-26 11:22 - 2013-11-23 18:23 - 00000000 ____D C:\Program Files (x86)\eRightSoft 2014-01-26 10:06 - 2014-01-26 10:06 - 23867560 _____ (Mozilla) C:\Users\Patrick Polzyn\Downloads\Firefox Setup 26.0.exe 2014-01-25 14:02 - 2014-01-25 14:02 - 00004540 _____ C:\Users\Patrick Polzyn\Documents\cc_20140125_140224.reg 2014-01-24 18:27 - 2014-01-24 18:27 - 00316109 _____ C:\Users\Patrick Polzyn\Desktop\Grenzsteine_DE-PL.rwp 2014-01-16 09:59 - 2010-11-21 04:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-01-16 08:36 - 2013-08-14 19:12 - 00000000 ____D C:\Windows\system32\MRT 2014-01-13 16:45 - 2014-01-13 16:45 - 00001566 _____ C:\Users\Patrick Polzyn\Desktop\railworks - Verknüpfung.lnk 2014-01-05 10:14 - 2014-01-05 10:14 - 00115592 _____ C:\Users\Patrick Polzyn\Documents\cc_20140105_101436.reg Some content of TEMP: ==================== C:\Users\Patrick Polzyn\AppData\Local\Temp\avgnt.exe C:\Users\Patrick Polzyn\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-29 13:48 ==================== End Of Log ============================ Gruß Pollle |
29.01.2014, 19:25 | #10 |
| Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Hier noch vom ADWCleaner-hatte oben nicht mehr mit rein gepasst. Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 29/01/2014 um 19:04:53 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Patrick Polzyn - PATRICKPOLZYN # Gestartet von : C:\Users\Patrick Polzyn\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\DSearchLink Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Ordner Gelöscht : C:\Program Files (x86)\myfree codec Ordner Gelöscht : C:\Program Files (x86)\Vuze Ordner Gelöscht : C:\Users\Patrick Polzyn\AppData\Local\AskToolbar Ordner Gelöscht : C:\Users\Patrick Polzyn\AppData\Roaming\pdfforge Ordner Gelöscht : C:\Users\Patrick Polzyn\Documents\PC Speed Maximizer Ordner Gelöscht : C:\Users\Administrator\AppData\Local\AskToolbar Datei Gelöscht : C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\invalidprefs.js Datei Gelöscht : C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\searchplugins\Askcom.xml Datei Gelöscht : C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : HKCU\Software\APN PIP Schlüssel Gelöscht : HKCU\Software\BabSolution Schlüssel Gelöscht : HKCU\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\Software\Myfree Codec Schlüssel Gelöscht : HKLM\Software\PIP Schlüssel Gelöscht : HKLM\Software\Uniblue\DriverScanner Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec ***** [ Browser ] ***** -\\ Internet Explorer v8.0.7601.17514 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Patrick Polzyn\AppData\Roaming\Mozilla\Firefox\Profiles\ryyx8uo6.default\prefs.js ] Zeile gelöscht : user_pref("extensions.AVIRA-V7C.apn.tldcache", "{\"date\":1390835475477,\"domainList\":[\"ac\",\"com.ac\",\"edu.ac\",\"gov.ac\",\"net.ac\",\"mil.ac\",\"org.ac\",\"ad\",\"nom.ad\",\"ae\",\"co.ae\",\"ne[...] Zeile gelöscht : user_pref("extensions.delta.admin", false); Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst"); Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de"); Zeile gelöscht : user_pref("extensions.delta.excTlbr", false); Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true); Zeile gelöscht : user_pref("extensions.delta.id", "647afa2d000000000000bc5ff40e1a85"); Zeile gelöscht : user_pref("extensions.delta.instlDay", "15975"); Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst"); Zeile gelöscht : user_pref("extensions.delta.newTab", false); Zeile gelöscht : user_pref("extensions.delta.prdct", "delta"); Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta"); Zeile gelöscht : user_pref("extensions.delta.rvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", ""); Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6"); Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.616:59:23"); Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6"); Zeile gelöscht : user_pref("extensions.delta_i.babExt", ""); Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=119357&tt=250913_nocpn&tsp=5018"); Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss"); [ Datei : C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\7x3cebdy.default\prefs.js ] Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", ""); ************************* AdwCleaner[R0].txt - [9110 octets] - [27/01/2014 18:55:47] AdwCleaner[R1].txt - [7971 octets] - [29/01/2014 19:00:53] AdwCleaner[S0].txt - [7473 octets] - [29/01/2014 19:04:53] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7533 octets] ########## |
29.01.2014, 23:21 | #11 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
30.01.2014, 17:37 | #12 |
| Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Malewarebytes hat nix gefunden. Der Scan von dem ESET Scaner hat ganz schön lange gedauert. Hier der LOG Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=6fa29e0ded2b6545ad3571dc7d6ea677 # engine=16865 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-30 04:25:49 # local_time=2014-01-30 05:25:49 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 78261 142728999 0 0 # scanned=572263 # found=0 # cleaned=0 # scan_time=13652 |
30.01.2014, 20:29 | #13 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Log von MBAM trotzdem immer posten
__________________ Logfiles bitte immer in CODE-Tags posten |
31.01.2014, 12:09 | #14 |
| Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Wuste ich nicht. Hier die LOG Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.30.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Patrick Polzyn :: PATRICKPOLZYN [Administrator] Schutz: Aktiviert 30.01.2014 13:28:13 mbam-log-2014-01-30 (13-28-13).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 255475 Laufzeit: 4 Minute(n), 22 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
31.01.2014, 12:12 | #15 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an Gut, MBAM war aktuell TFC - Temp File Cleaner Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
Sieht soweit ok aus Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie ) Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird. Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Firefox leitet auf AdFly Seite weiter und nimmt Links nicht mehr an |
adfly, administrator, anzeige, autostart, dateien, explorer, folge, forum, hängt, leitet, logfile, malwarebytes, neustart, popups, problem, programme, pup.optional.babylon.a, pup.optional.delta.a, pup.optional.installcore.a, pup.optional.opencandy, pup.optional.opencandy.a, pup.optional.softonic.a, pup.optional.startpage.a, seite, windows, öffnet |