FRST Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-01-2015 01
Ran by Carolin (administrator) on CAROLIN on 16-01-2015 17:04:16
Running from C:\Users\Carolin\Desktop
Loaded Profiles: Carolin (Available profiles: UpdatusUser & Carolin & Stefan)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Buhl Data Service GmbH) C:\Program Files (x86)\Buhl\WISO Mein Geld 2014\MG.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13427784 2013-03-18] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1278024 2013-03-08] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3010800 2013-01-17] (Synaptics Incorporated)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1754424 2014-11-14] (Bitdefender)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [BackupNowEZtray] => C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZtray.exe [581624 2013-02-05] (NTI Corporation)
HKLM-x32\...\Run: [EaseUS EPM tray] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 9.3.0\bin\EpmNews.exe [2081792 2013-03-29] (CHENGDU YIWO Tech Development Co., Ltd)
HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [2711576 2014-10-03] (Sony Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5562736 2014-07-22] (Western Digital Technologies, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [131712 2013-01-24] ( (Atheros Communications))
HKU\S-1-5-21-4293654675-2556177190-2138456915-1002\...\Run: [Bitdefender-Geldbörse-Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2014-11-14] (Bitdefender)
HKU\S-1-5-21-4293654675-2556177190-2138456915-1002\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [615256 2014-11-14] (Bitdefender)
HKU\S-1-5-21-4293654675-2556177190-2138456915-1002\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-18\...\Run: [Bitdefender-Geldbörse-Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2014-11-14] (Bitdefender)
HKU\S-1-5-18\...\Run: [Bitdefender-Geldbörse] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-11-14] (Bitdefender)
HKU\S-1-5-18\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [615256 2014-11-14] (Bitdefender)
Startup: C:\Users\Carolin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Carolin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Carolin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about :blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about :blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-4293654675-2556177190-2138456915-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about :blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4293654675-2556177190-2138456915-1002 -> {095A28A6-95D6-4177-98C1-59F03D82324D} URL =
BHO: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll (Bitdefender)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll (Bitdefender)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Carolin\AppData\Roaming\Mozilla\Firefox\Profiles\4saq1g2n.default
FF Homepage: Google.de
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2014-02-26]
FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman [2014-02-26]
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [ccahoghmggldkcdjiebjkidpfongdfbl] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxcr.crx [2014-02-27]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [227456 2013-01-24] (Qualcomm Atheros Commnucations)
S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender\bdparentalservice.exe [77632 2014-11-14] (Bitdefender)
S4 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-27] (Acer Incorporated)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
S4 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [470056 2013-04-30] (Acer Incorporated)
S4 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [662088 2013-03-15] (Acer Incorporated)
S4 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2013-12-17] (WildTangent)
S4 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed]
S4 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736 2013-01-30] (Intel Corporation)
S4 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-06-17] (Acer Incorporate)
S4 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S4 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S4 NitroReaderDriverReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [230416 2013-07-26] (Nitro PDF Software)
S4 NTI BackupNowEZSvr; C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe [46072 2013-02-05] (NTI Corporation)
S4 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [485400 2014-10-03] (Sony Corporation)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320 2014-11-14] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1536624 2014-11-14] (Bitdefender)
S4 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2014-12-02] (Western Digital Technologies, Inc.)
S4 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [296312 2014-07-22] (Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1260120 2014-11-14] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261496 2014-11-14] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [647752 2014-11-14] (BitDefender)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2014-05-27] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
S3 BDSandBox; C:\WINDOWS\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-24] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] () [File not signed]
S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [13896 2013-03-07] () [File not signed]
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] () [File not signed]
S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] () [File not signed]
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2013-01-17] (Synaptics Incorporated)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [419616 2014-11-14] (BitDefender S.R.L.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-16 17:03 - 2015-01-16 17:03 - 00000000 ____D () C:\Users\Carolin\Desktop\FRST-OlderVersion
2015-01-14 21:21 - 2015-01-14 21:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-01-14 16:33 - 2015-01-14 20:35 - 00000382 _____ () C:\WINDOWS\setupact.log
2015-01-14 16:33 - 2015-01-14 16:33 - 00000000 _____ () C:\WINDOWS\setuperr.log
2015-01-14 12:49 - 2015-01-14 12:48 - 00381270 _____ () C:\Users\Carolin\Desktop\1421222456_1_03.xml
2015-01-14 09:16 - 2015-01-14 09:18 - 00039807 _____ () C:\Users\Carolin\Desktop\Addition.txt
2015-01-14 09:13 - 2015-01-16 17:04 - 00016772 _____ () C:\Users\Carolin\Desktop\FRST.txt
2015-01-14 09:13 - 2015-01-16 17:04 - 00000000 ____D () C:\FRST
2015-01-14 09:13 - 2015-01-16 17:03 - 02125312 _____ (Farbar) C:\Users\Carolin\Desktop\FRST64.exe
2015-01-14 07:40 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2015-01-14 07:40 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2015-01-14 07:40 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-01-14 07:40 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-01-14 07:40 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-01-14 07:40 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-01-14 07:40 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2015-01-14 07:40 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2015-01-14 07:39 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-01-14 07:39 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-01-14 07:39 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2015-01-14 07:39 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2015-01-14 07:39 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2015-01-14 07:39 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-01-14 07:39 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2015-01-14 07:39 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2015-01-14 07:39 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-01-14 07:39 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2015-01-14 07:39 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2015-01-14 07:39 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-01-14 07:39 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-01-14 07:39 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-01-14 07:39 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-01-14 07:39 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2015-01-14 07:39 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2015-01-14 07:39 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-01-14 07:39 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-01-14 07:39 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-01-14 07:39 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-01-14 07:39 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2015-01-14 07:39 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-01-13 06:22 - 2015-01-13 06:22 - 00003576 _____ () C:\WINDOWS\System32\Tasks\Bitdefender Auto-Scan
2015-01-10 19:57 - 2015-01-10 19:57 - 00694508 _____ () C:\Users\Carolin\Downloads\FRITZ.Box Fon WLAN 7360 111.06.03-27419LABOR_BETA_10.01.15_1957.export
2015-01-10 19:31 - 2015-01-10 19:31 - 00457652 _____ () C:\Users\Carolin\Desktop\1420902426_1_02.xml
2015-01-10 15:06 - 2015-01-10 15:33 - 00000056 _____ () C:\WINDOWS\system32\bdsandbox.txt
2015-01-10 14:57 - 2015-01-10 14:57 - 05490752 _____ (Secunia) C:\Users\Carolin\Downloads\PSISetup10004.exe
2015-01-10 14:52 - 2015-01-10 14:52 - 00700980 _____ () C:\Users\Carolin\Downloads\adblock_edge-2.0.7-sm+an+tb+fx-windows.zip
2015-01-10 14:46 - 2015-01-10 14:46 - 00000964 _____ () C:\DelFix.txt
2015-01-10 09:06 - 2015-01-14 16:32 - 00007156 _____ () C:\WINDOWS\PFRO.log
2015-01-08 21:15 - 2015-01-10 14:46 - 00000000 ____D () C:\WINDOWS\ERUNT
2015-01-08 20:41 - 2015-01-14 18:41 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-01-08 20:41 - 2015-01-10 14:57 - 00001122 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-01-08 20:41 - 2015-01-10 14:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2015-01-08 20:41 - 2015-01-10 14:57 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2015-01-08 20:41 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-01-08 20:41 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-01-08 20:41 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-01-08 09:02 - 2015-01-08 09:37 - 00000000 ____D () C:\ProgramData\Dumps
2015-01-07 18:58 - 2015-01-07 18:58 - 00003930 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{383E0617-C8B6-4649-8199-915EBE4FC5ED}
2015-01-07 18:58 - 2015-01-07 18:58 - 00000000 __SHD () C:\Users\Stefan\AppData\Local\EmieUserList
2015-01-07 18:58 - 2015-01-07 18:58 - 00000000 __SHD () C:\Users\Stefan\AppData\Local\EmieSiteList
2015-01-07 18:58 - 2015-01-07 18:58 - 00000000 __SHD () C:\Users\Stefan\AppData\Local\EmieBrowserModeList
2015-01-07 18:58 - 2015-01-07 18:58 - 00000000 ____D () C:\Users\Stefan\AppData\Roaming\Macromedia
2015-01-07 18:57 - 2015-01-07 18:58 - 00000000 ____D () C:\Users\Stefan\OneDrive
2015-01-07 18:55 - 2015-01-07 18:55 - 00000000 ____D () C:\Users\Stefan\AppData\Roaming\Synaptics
2015-01-07 18:55 - 2015-01-07 18:55 - 00000000 ____D () C:\Users\Stefan\AppData\Roaming\Sony Corporation
2015-01-07 18:55 - 2015-01-07 18:55 - 00000000 ____D () C:\Users\Stefan\AppData\Roaming\Bitdefender
2015-01-07 18:55 - 2015-01-07 18:55 - 00000000 ____D () C:\Users\Stefan\AppData\Roaming\Atheros
2015-01-07 18:55 - 2015-01-07 18:55 - 00000000 ____D () C:\Users\Stefan\AppData\Roaming\Apple Computer
2015-01-07 18:54 - 2015-01-07 18:54 - 00001418 _____ () C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-07 18:54 - 2015-01-07 18:54 - 00000000 ____D () C:\Users\Stefan\AppData\Roaming\Adobe
2015-01-07 18:54 - 2015-01-07 18:54 - 00000000 ____D () C:\Users\Stefan\AppData\Local\VirtualStore
2015-01-07 18:53 - 2015-01-07 18:56 - 00000000 ____D () C:\Users\Stefan\AppData\Local\Packages
2015-01-07 18:51 - 2015-01-07 18:51 - 00000020 ___SH () C:\Users\Stefan\ntuser.ini
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\Vorlagen
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\Startmenü
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\Netzwerkumgebung
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\Lokale Einstellungen
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\Eigene Dateien
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\Druckumgebung
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\Documents\Eigene Musik
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\Documents\Eigene Bilder
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\AppData\Local\Verlauf
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\AppData\Local\Anwendungsdaten
2015-01-07 18:51 - 2015-01-07 18:51 - 00000000 _SHDL () C:\Users\Stefan\Anwendungsdaten
2015-01-07 18:50 - 2015-01-07 18:57 - 00000000 ____D () C:\Users\Stefan
2015-01-07 18:50 - 2014-11-14 17:57 - 00000000 ___RD () C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-01-07 18:50 - 2014-09-21 13:36 - 00000000 ___RD () C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-01-07 18:50 - 2014-02-22 05:37 - 00000369 _____ () C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-01-07 18:50 - 2014-02-22 05:37 - 00000369 _____ () C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-01-07 18:50 - 2014-01-04 22:51 - 00000000 ____D () C:\Users\Stefan\AppData\Local\Pokki
2015-01-07 18:50 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-07 18:50 - 2013-08-22 16:36 - 00000000 ____D () C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-06 15:57 - 2015-01-06 15:57 - 00000000 ____D () C:\ProgramData\Emsisoft
2015-01-06 14:15 - 2015-01-08 21:07 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-01-06 14:15 - 2015-01-08 11:09 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-01-06 14:15 - 2015-01-06 14:15 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Safer-Networking
2015-01-05 23:31 - 2015-01-05 23:31 - 05249448 _____ (ParetoLogic Inc.) C:\Users\Carolin\Downloads\ParetoLogic PC Health Advisor_de(1).exe
2015-01-05 23:01 - 2015-01-05 23:01 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Mozilla
2015-01-05 22:27 - 2015-01-05 22:27 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Carolin\Downloads\mbam-setup-2.0.4.1028_CB-DL-Manager [1].exe
2015-01-05 22:26 - 2015-01-05 22:26 - 00823792 _____ ( ) C:\Users\Carolin\Downloads\mbam-setup-2.0.4.1028_CB-DL-Manager.exe
2015-01-05 21:30 - 2015-01-05 21:30 - 05317104 _____ (Piriform Ltd) C:\Users\Carolin\Downloads\ccsetup501.exe
2015-01-05 21:27 - 2015-01-05 21:27 - 05249448 _____ (ParetoLogic Inc.) C:\Users\Carolin\Downloads\ParetoLogic PC Health Advisor_de.exe
2015-01-05 20:51 - 2015-01-05 20:51 - 00247236 _____ () C:\Users\Carolin\Downloads\onedrivets (1).diagcab
2015-01-05 20:10 - 2015-01-05 20:51 - 00003382 _____ () C:\WINDOWS\System32\Tasks\START SKYDRIVE
2015-01-05 20:09 - 2015-01-05 20:09 - 00247236 _____ () C:\Users\Carolin\Downloads\onedrivets.diagcab
2015-01-03 12:42 - 2015-01-03 12:42 - 00000000 ____D () C:\Users\Public\Documents\Gnom
2015-01-03 09:22 - 2015-01-04 22:44 - 00000000 ____D () C:\Users\Carolin\Achim
2014-12-27 20:14 - 2014-12-27 20:14 - 00000000 ____D () C:\Analytics
2014-12-27 20:12 - 2014-12-27 20:12 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Western Digital
2014-12-27 20:09 - 2015-01-14 17:40 - 00008192 _____ () C:\WINDOWS\SysWOW64\WDPABKP.dat
2014-12-27 20:09 - 2015-01-05 21:11 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Western_Digital_Technolog
2014-12-27 20:09 - 2015-01-05 21:11 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-27 20:09 - 2015-01-05 21:11 - 00000000 ____D () C:\Program Files\Common Files\Western Digital
2014-12-27 20:09 - 2014-12-27 20:09 - 00000000 ____D () C:\Program Files\Western Digital
2014-12-27 20:04 - 2014-12-27 20:04 - 41112192 _____ () C:\Users\Carolin\Downloads\SmartWare_Windows_Upgrader (1).zip
2014-12-27 20:04 - 2014-12-27 20:04 - 04461527 _____ () C:\Users\Carolin\Downloads\WD_Quick_View_Setup_for_Windows.zip
2014-12-27 13:56 - 2014-12-27 13:58 - 41112192 _____ () C:\Users\Carolin\Downloads\SmartWare_Windows_Upgrader.zip
2014-12-27 13:05 - 2014-12-27 13:05 - 65350992 _____ () C:\Users\Carolin\Downloads\WDMyCloud_win.exe
2014-12-27 13:03 - 2015-01-05 21:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital
2014-12-27 13:03 - 2015-01-05 21:11 - 00000000 ____D () C:\Program Files (x86)\Western Digital
2014-12-27 13:03 - 2014-12-27 13:03 - 65350992 _____ () C:\Users\Carolin\WDMyCloud_win.exe
2014-12-27 13:00 - 2014-12-27 20:09 - 00000000 ____D () C:\ProgramData\Western Digital
2014-12-27 13:00 - 2014-12-27 13:03 - 00001173 _____ () C:\Users\Public\Desktop\WD My Cloud.lnk
2014-12-27 13:00 - 2014-12-27 13:02 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\com.wd.WDMyCloud
2014-12-27 13:00 - 2014-12-27 13:00 - 00000204 _____ () C:\Users\Carolin\Desktop\Lerncenter WD My Cloud.url
2014-12-27 13:00 - 2014-12-27 13:00 - 00000158 _____ () C:\Users\Carolin\Desktop\WD My Cloud – Öffentliche Freigabe.url
2014-12-27 13:00 - 2014-12-27 13:00 - 00000154 _____ () C:\Users\Carolin\Desktop\WD My Cloud-Dashboard.url
2014-12-27 13:00 - 2014-12-27 13:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bonjour-Druckdienste
2014-12-27 13:00 - 2014-12-27 13:00 - 00000000 ____D () C:\Program Files\Bonjour Print Services
2014-12-27 12:49 - 2015-01-05 21:11 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Western Digital
2014-12-27 12:48 - 2014-12-27 12:48 - 71601392 _____ () C:\Users\Carolin\Downloads\mc_windows_setup.exe
2014-12-26 21:04 - 2014-12-26 21:04 - 00001431 _____ () C:\Users\Carolin\Desktop\CopyTrans Control Center.lnk
2014-12-26 21:04 - 2014-12-26 21:04 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Control Center
2014-12-26 21:03 - 2014-12-26 21:04 - 05102256 _____ (WindSolutions) C:\Users\Carolin\Downloads\Install_CopyTransControlCenter.exe
2014-12-26 21:00 - 2014-12-26 21:09 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\WindSolutions
2014-12-26 20:59 - 2014-12-26 21:08 - 00000000 ____D () C:\ProgramData\WindSolutions
2014-12-26 20:58 - 2014-12-26 20:58 - 09280316 _____ () C:\Users\Carolin\Downloads\CopyTransManagerDEv1.013.zip
2014-12-17 16:18 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2014-12-17 16:18 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-16 17:03 - 2014-01-04 22:43 - 01477161 _____ () C:\WINDOWS\WindowsUpdate.log
2015-01-16 16:44 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-01-16 16:02 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-01-16 15:11 - 2014-01-04 23:30 - 00003934 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{D47BDD1F-9221-4378-922D-20DF3289565D}
2015-01-16 11:06 - 2014-01-04 14:27 - 00000000 ____D () C:\Users\Carolin\Documents\WISO Mein Geld
2015-01-16 09:51 - 2014-04-08 16:33 - 00005140 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for CAROLIN-Carolin Carolin
2015-01-16 08:54 - 2014-01-04 11:55 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4293654675-2556177190-2138456915-1002
2015-01-16 08:40 - 2014-01-04 12:01 - 00000000 ___DO () C:\Users\Carolin\SkyDrive
2015-01-15 20:48 - 2014-04-27 20:43 - 00401920 ___SH () C:\Users\Carolin\Thumbs.db
2015-01-15 20:48 - 2014-01-21 20:39 - 01703936 ___SH () C:\Users\Carolin\Desktop\Thumbs.db
2015-01-15 20:34 - 2014-01-04 23:12 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Deployment
2015-01-15 20:30 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-01-14 20:35 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-01-14 19:11 - 2013-08-22 14:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-01-14 08:13 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-01-10 20:44 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2015-01-10 19:52 - 2014-01-13 20:40 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Google
2015-01-10 19:52 - 2014-01-13 20:40 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-10 14:53 - 2014-04-27 21:00 - 00000000 ____D () C:\Users\Carolin\AppData\Temp
2015-01-10 13:03 - 2014-01-04 22:47 - 00000000 ____D () C:\Users\Carolin
2015-01-09 20:19 - 2014-01-26 17:43 - 02090496 ___SH () C:\Users\Carolin\Downloads\Thumbs.db
2015-01-08 09:21 - 2014-02-26 09:52 - 00000000 ____D () C:\ProgramData\BDLogging
2015-01-07 18:55 - 2014-01-04 11:48 - 00000000 ____D () C:\WINDOWS\System32\Tasks\WPD
2015-01-06 17:42 - 2014-06-16 17:26 - 00000000 ____D () C:\schrankplaner
2015-01-06 17:42 - 2013-08-22 15:44 - 00446440 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-01-06 14:12 - 2014-01-04 11:46 - 00000000 ____D () C:\Users\Carolin\AppData\Local\VirtualStore
2015-01-06 12:11 - 2014-01-05 19:38 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Nitro PDF
2015-01-06 01:08 - 2014-11-14 18:04 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-01-06 01:08 - 2014-11-14 18:04 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-05 23:01 - 2014-01-07 18:01 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Mozilla
2015-01-05 21:11 - 2014-02-02 17:23 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\vlc
2015-01-05 20:59 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\registration
2015-01-03 16:10 - 2014-01-05 17:52 - 00000000 ___RD () C:\Users\Carolin\Dropbox
2015-01-03 16:10 - 2014-01-05 17:49 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Dropbox
2015-01-02 17:07 - 2014-08-13 19:08 - 00012795 _____ () C:\Users\Carolin\Documents\Übersicht Planung MM.xlsx
2015-01-02 13:01 - 2014-01-04 15:14 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Apple Computer
2014-12-26 22:02 - 2014-01-04 11:46 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Packages
2014-12-23 12:16 - 2014-01-04 11:57 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-12-22 07:19 - 2013-11-14 08:27 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-22 07:19 - 2013-11-14 08:11 - 00765582 _____ () C:\WINDOWS\system32\perfh007.dat
2014-12-22 07:19 - 2013-11-14 08:11 - 00159366 _____ () C:\WINDOWS\system32\perfc007.dat
2014-12-19 17:59 - 2014-01-05 17:51 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
Files to move or delete:
====================
C:\Users\Carolin\WDMyCloud_win.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-08 08:19
==================== End Of Log ============================
--- --- ---