Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-07-2014 01
Ran by ***** (administrator) on ***** on 08-07-2014 13:28:48
Running from C:\Users\*****\Desktop
Platform: Microsoft Windows 8 Pro (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynToshiba.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4620 series\Bin\HPNetworkCommunicatorCom.exe
(Opera Software) C:\Users\*****\AppData\Local\Programs\Opera\opera.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE
() C:\Program Files\KMSpico\RandomFile.exe
(@ByELDI) C:\Program Files\KMSpico\FUJANC.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynToshiba.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\SppExtComObj.Exe
(Microsoft Corporation) C:\Windows\System32\cscript.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4620 series\Bin\HPNetworkCommunicator.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1348904 2008-08-14] (Synaptics, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5179408 2014-06-17] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-561157237-2704851944-98042490-1001\...\Run: [BrowserChoice] => C:\Windows\BrowserChoice\browserchoice.exe [84064 2012-08-15] (Microsoft Corporation)
HKU\S-1-5-21-561157237-2704851944-98042490-1002\...\Run: [HP Officejet 4620 series (NET)] => C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe [1837672 2012-10-17] (Hewlett-Packard Co.)
Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 4620 series (Netzwerk).lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 4620 series (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet 4620 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File)
ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xEFB8C2B5A5E6CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
Toolbar: HKLM - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files\Freemium\Free PDF Perfect\ieagent32.dll (soft Xpansion)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @microsoft.com/Lync,version=15.0 - C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @soft-xpansion/npsxpdf - C:\Program Files\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb [2014-01-27]
FF HKLM\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb [2014-01-27]
FF HKCU\...\Firefox\Extensions: [speedtest4354@BestOffers] - C:\Users\*****\AppData\Roaming\Mozilla\Extensions\speedtest4354@BestOffers
FF Extension: Speed Test 127 - C:\Users\*****\AppData\Roaming\Mozilla\Extensions\speedtest4354@BestOffers [2014-01-27]
========================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3241488 2014-06-27] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-06-17] (AVG Technologies CZ, s.r.o.)
S3 SXDS10; C:\Program Files\Common Files\soft Xpansion\sxds10.exe [234096 2014-01-27] (soft Xpansion)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14480 2014-03-28] (Microsoft Corporation)
S2 Update veberGreat; "C:\Program Files\veberGreat\updateveberGreat.exe" [X]
==================== Drivers (Whitelisted) ====================
R3 athr; C:\WINDOWS\system32\DRIVERS\athr.sys [2273280 2012-06-02] (Qualcomm Atheros Communications, Inc.)
S0 Avgbootx; C:\WINDOWS\System32\DRIVERS\avgbootx.sys [17424 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [121624 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdriverx.sys [199960 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\WINDOWS\system32\DRIVERS\avgidsshimw8x.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [188696 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [98584 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpx; C:\WINDOWS\system32\DRIVERS\avgwfpx.sys [213784 2014-05-14] (AVG Technologies CZ, s.r.o.)
R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [24576 2012-07-26] (Microsoft Corporation)
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [27024 2013-11-01] (Windows (R) Win 7 DDK provider)
S3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [155136 2012-07-26] (Microsoft Corporation)
U3 uxldypob; \??\C:\Users\*****\AppData\Local\Temp\uxldypob.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-08 13:13 - 2014-07-08 13:13 - 00020536 _____ () C:\Users\*****\Desktop\FRST.txt
2014-07-08 13:04 - 2014-07-08 13:04 - 01074688 _____ (Farbar) C:\Users\*****\Downloads\FRST.exe
2014-07-08 12:57 - 2014-07-08 12:57 - 00002224 _____ () C:\Users\*****\Desktop\Gmer.txt
2014-07-08 11:26 - 2014-07-08 11:26 - 00002224 _____ () C:\Users\*****\Desktop\Gmer.txt
2014-07-08 10:36 - 2014-07-08 10:41 - 00021992 _____ () C:\Users\*****\Desktop\Addition.txt
2014-07-08 10:34 - 2014-07-08 13:30 - 00010351 _____ () C:\Users\*****\Desktop\FRST.txt
2014-07-08 10:34 - 2014-07-08 13:28 - 00000000 ____D () C:\FRST
2014-07-08 10:30 - 2014-07-08 10:34 - 00000474 _____ () C:\Users\*****\Desktop\defogger_disable.log
2014-07-08 10:30 - 2014-07-08 10:30 - 00000000 _____ () C:\Users\*****\defogger_reenable
2014-07-08 10:26 - 2014-07-08 10:26 - 00380416 _____ () C:\Users\*****\Desktop\Gmer-19357.exe
2014-07-08 10:22 - 2014-07-08 10:22 - 00050477 _____ () C:\Users\*****\Desktop\Defogger.exe
2014-07-08 10:14 - 2014-07-08 10:14 - 01074688 _____ (Farbar) C:\Users\*****\Desktop\FRST.exe
2014-06-28 10:14 - 2014-05-24 03:27 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-06-28 10:14 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-06-28 10:14 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-06-28 10:14 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-06-28 10:14 - 2014-05-24 03:26 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2014-06-28 10:14 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-06-28 10:14 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-06-28 10:14 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-06-28 10:14 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2014-06-28 10:14 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-06-28 10:14 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-06-28 10:14 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-06-28 10:14 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-06-28 10:14 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-06-28 10:14 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-06-28 10:14 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-06-28 10:14 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2014-06-28 10:14 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-06-28 10:14 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-06-28 10:14 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-06-28 10:14 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-06-28 10:12 - 2014-05-03 06:06 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-06-28 10:12 - 2014-04-30 00:31 - 01075712 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2014-06-28 10:12 - 2014-04-03 11:17 - 01799512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-06-28 10:12 - 2014-04-03 10:47 - 00297304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2014-06-28 10:12 - 2014-04-03 05:09 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2014-06-28 10:12 - 2014-04-01 00:07 - 00387268 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-06-28 10:12 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe
2014-06-28 10:12 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-06-17 16:22 - 2014-06-17 16:22 - 00188696 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgldx86.sys
2014-06-17 16:18 - 2014-06-17 16:18 - 00241944 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avglogx.sys
2014-06-17 16:17 - 2014-06-17 16:17 - 00147736 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidshx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00199960 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdriverx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00121624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgdiskx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00098584 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx86.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00027416 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgrkx86.sys
2014-06-17 16:05 - 2014-06-17 16:05 - 00021272 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsshimw8x.sys
==================== One Month Modified Files and Folders =======
2014-07-08 13:30 - 2014-07-08 10:34 - 00010351 _____ () C:\Users\*****\Desktop\FRST.txt
2014-07-08 13:28 - 2014-07-08 10:34 - 00000000 ____D () C:\FRST
2014-07-08 13:26 - 2014-01-09 23:27 - 00000000 ____D () C:\Program Files\KMSpico
2014-07-08 13:13 - 2014-07-08 13:13 - 00020536 _____ () C:\Users\*****\Desktop\FRST.txt
2014-07-08 13:06 - 2014-01-02 16:52 - 00000000 ____D () C:\ProgramData\AVG2014
2014-07-08 13:04 - 2014-07-08 13:04 - 01074688 _____ (Farbar) C:\Users\*****\Downloads\FRST.exe
2014-07-08 13:02 - 2012-07-26 08:53 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-07-08 12:58 - 2013-11-21 11:34 - 00000000 ____D () C:\Users\*****\AppData\Local\VirtualStore
2014-07-08 12:57 - 2014-07-08 12:57 - 00002224 _____ () C:\Users\*****\Desktop\Gmer.txt
2014-07-08 11:32 - 2014-01-02 15:23 - 00000753 _____ () C:\Users\*****\Desktop\EmsiClean_2014.01.02_14.23.58.txt
2014-07-08 11:26 - 2014-07-08 11:26 - 00002224 _____ () C:\Users\*****\Desktop\Gmer.txt
2014-07-08 10:41 - 2014-07-08 10:36 - 00021992 _____ () C:\Users\*****\Desktop\Addition.txt
2014-07-08 10:34 - 2014-07-08 10:30 - 00000474 _____ () C:\Users\*****\Desktop\defogger_disable.log
2014-07-08 10:30 - 2014-07-08 10:30 - 00000000 _____ () C:\Users\*****\defogger_reenable
2014-07-08 10:26 - 2014-07-08 10:26 - 00380416 _____ () C:\Users\*****\Desktop\Gmer-19357.exe
2014-07-08 10:22 - 2014-07-08 10:22 - 00050477 _____ () C:\Users\*****\Desktop\Defogger.exe
2014-07-08 10:14 - 2014-07-08 10:14 - 01074688 _____ (Farbar) C:\Users\*****\Desktop\FRST.exe
2014-07-08 09:59 - 2012-07-26 06:17 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-07-08 09:58 - 2014-01-02 16:46 - 00000000 ____D () C:\ProgramData\MFAData
2014-07-07 23:19 - 2012-07-26 08:04 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-07-07 23:16 - 2012-07-26 08:53 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-07-07 23:14 - 2014-04-06 21:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-07-07 23:12 - 2012-07-26 08:53 - 00000000 ____D () C:\WINDOWS\system32\de-DE
2014-07-07 23:12 - 2012-07-26 08:53 - 00000000 ____D () C:\WINDOWS\rescache
2014-07-07 23:12 - 2012-07-26 08:53 - 00000000 ____D () C:\WINDOWS\registration
2014-07-07 23:00 - 2013-06-17 17:24 - 01672131 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-07 22:52 - 2012-07-26 08:53 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-07-04 08:35 - 2014-01-02 16:55 - 00000951 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-07-03 11:17 - 2012-07-26 08:53 - 00000000 ____D () C:\WINDOWS\AUInstallAgent
2014-07-01 16:19 - 2014-01-24 20:54 - 00000000 ____D () C:\Users\*****\AppData\Local\CutePDF Writer
2014-07-01 10:57 - 2013-06-17 17:29 - 01745416 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-06-28 10:22 - 2012-07-26 08:43 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-06-28 10:21 - 2013-08-14 09:18 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-06-28 10:17 - 2013-06-18 18:49 - 92708840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-06-17 16:22 - 2014-06-17 16:22 - 00188696 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgldx86.sys
2014-06-17 16:18 - 2014-06-17 16:18 - 00241944 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avglogx.sys
2014-06-17 16:17 - 2014-06-17 16:17 - 00147736 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidshx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00199960 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdriverx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00121624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgdiskx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00098584 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx86.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00027416 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgrkx86.sys
2014-06-17 16:05 - 2014-06-17 16:05 - 00021272 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsshimw8x.sys
2014-06-17 15:39 - 2014-01-27 18:18 - 00000000 ____D () C:\Users\*****\AppData\Local\DownloadGuide
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-07 22:45
==================== End Of Log ============================