79%Liverpool | 29.08.2013 11:31 | Erstmal danke für die schnelle Hilfe:daumenhoc
adwCleaner Code:
# AdwCleaner v3.001 - Report created 29/08/2013 at 12:17:35
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : Stefan - STEFAN-PC
# Running from : C:\Users\Stefan\Downloads\musik erics\Finn NEU!\29dezember\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\Program Files\LyriXeeker
Folder Deleted : C:\Program Files\Common Files\Software Update Utility
Folder Deleted : C:\Users\Stefan\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\Stefan\AppData\Roaming\Babylon
File Deleted : C:\Windows\system32\roboot.exe
File Deleted : C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\searchplugins\11-suche.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\Babylon.xml
File Deleted : C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\foxydeal.sqlite
File Deleted : C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\\invalidprefs.js
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnu.xpt
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.xpt
File Deleted : C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\user.js
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\a68adbb63aea13
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\delta LTD
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Microsoft\Babylon
Key Deleted : HKCU\Software\AppDataLow\Software\lyrixeeker
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Delta
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{83AA2913-C123-4146-85BD-AD8F93971D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Product Deleted : BabylonObjectInstaller
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v23.0.1 (de)
[ File : C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\prefs.js ]
Line Deleted : user_pref("aol_toolbar.surf.date", "177");
Line Deleted : user_pref("aol_toolbar.surf.lastDate", "19");
Line Deleted : user_pref("aol_toolbar.surf.lastMonth", "6");
Line Deleted : user_pref("aol_toolbar.surf.lastYear", "2012");
Line Deleted : user_pref("aol_toolbar.surf.month", "177");
Line Deleted : user_pref("aol_toolbar.surf.prevMonth", "0");
Line Deleted : user_pref("aol_toolbar.surf.total", "177");
Line Deleted : user_pref("aol_toolbar.surf.week", "177");
Line Deleted : user_pref("aol_toolbar.surf.year", "177");
Line Deleted : user_pref("extensions.BabylonToolbar.admin", false);
Line Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Line Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Line Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false);
Line Deleted : user_pref("extensions.BabylonToolbar.id", "a0d2266b000000000000002185e0b02f");
Line Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15549");
Line Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Line Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Line Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Line Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "tb9");
Line Deleted : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://www.google.com/search?babsrc=TB_ggl&q=");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.5.29.1");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.5.29.1");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=113480&tt=3012_1");
Line Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Line Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.29.120:21:44");
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.dfltLng", "de");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.id", "a0d2266b000000000000002185e0b02f");
Line Deleted : user_pref("extensions.delta.instlDay", "15946");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.24.6");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.24.611:01:02");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.24.6");
Line Deleted : user_pref("extensions.delta_i.babExt", "");
Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=119357&tt=280813_ccp&tsp=4989");
Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");
[ File : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\k5fe6lat.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [7922 octets] - [29/08/2013 12:16:59]
AdwCleaner[S0].txt - [7873 octets] - [29/08/2013 12:17:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7933 octets] ##########
junkware removal tool Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.5 (08.28.2013:1)
OS: Windows 7 Professional x86
Ran by Stefan on 29.08.2013 at 12:22:26,58
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e8c0627e-8829-4471-9490-b76174bd4a65}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{e8c0627e-8829-4471-9490-b76174bd4a65}
~~~ Files
Successfully deleted: [File] C:\Windows\System32\Tasks\Lyrics Seeker Update
Successfully deleted: [File] C:\Windows\Tasks\Lyrics Seeker Update.job
~~~ Folders
~~~ FireFox
Successfully deleted: [File] C:\user.js
Emptied folder: C:\Users\Stefan\AppData\Roaming\mozilla\firefox\profiles\suk36vbv.default\minidumps [106 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.08.2013 at 12:25:21,91
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
und
FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-08-2013
Ran by Stefan (administrator) on 29-08-2013 12:26:47
Running from C:\Users\Stefan\Downloads\musik erics\Finn NEU!\29dezember
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
(Micro-Star International Co., Ltd.) C:\Program Files\System Control Manager\MSIService.exe
() C:\Program Files\Hardcopy\hcdll2_ex_Win32.exe
(Micro-Star International Co., Ltd.) C:\Program Files\System Control Manager\MGSysCtrl.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RaUI.exe
(StarWind Software) C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MpCmdRun.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [13797992 2009-09-01] (NVIDIA Corporation)
HKLM\...\Run: [MGSysCtrl] - C:\Program Files\System Control Manager\MGSysCtrl.exe [2080768 2009-10-09] (Micro-Star International Co., Ltd.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-06-20] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
MountPoints2: H - H:\HTC_Sync_Manager_PC.exe
MountPoints2: {2962872d-bdc7-11e2-9828-002185e0b02f} - H:\HTC_Sync_Manager_PC.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default
FF Homepage: google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
FF SearchPlugin: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\searchplugins\aol-search.xml
FF SearchPlugin: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\Extensions\ich@maltegoetz.de
FF Extension: No Name - C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\suk36vbv.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKCU\...\Firefox\Extensions: [{12505464-a1b4-47a9-98ac-e7ed5e887d66}] C:\Program Files\LyricsSeeker\131.xpi
FF Extension: No Name - C:\Program Files\LyricsSeeker\131.xpi
========================== Services (Whitelisted) =================
S2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1435984 2013-05-15] (LogMeIn Inc.)
R2 Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [160768 2009-07-09] (Micro-Star International Co., Ltd.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-06-20] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-06-20] (Microsoft Corporation)
S2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RaRegistry.exe [372736 2011-11-14] (Ralink Technology, Corp.)
S2 RaMediaServer; C:\Program Files\Ralink\Common\RaMediaServer.exe [625728 2011-08-18] ()
R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
==================== Drivers (Whitelisted) ====================
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [63464 2013-01-22] (FTDI Ltd.)
R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R1 HWiNFO32; D:\Anderes\.exe Installationen\HW - Info\HWiNFO32.SYS [19064 2009-07-16] (REALiX(tm))
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [466008 2013-08-29] (Duplex Secure Ltd.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-29 12:22 - 2013-08-29 12:22 - 00000000 ____D C:\Windows\ERUNT
2013-08-29 12:16 - 2013-08-29 12:17 - 00000000 ____D C:\AdwCleaner
2013-08-29 11:38 - 2013-08-29 11:38 - 00000000 ____D C:\Windows\system32\appmgmt
2013-08-29 11:35 - 2013-08-29 11:35 - 00000202 _____ C:\Users\Stefan\defogger_reenable
2013-08-29 11:31 - 2013-08-29 11:31 - 00000000 ____D C:\FRST
2013-08-29 11:17 - 2013-08-29 11:17 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-29 11:16 - 2013-08-29 11:40 - 00000000 ____D C:\Windows\865537E164904193A4B6669C62711852.TMP
2013-08-29 11:16 - 2013-08-29 11:16 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard
2013-08-29 11:04 - 2013-08-29 11:04 - 00001087 _____ C:\Users\Public\Desktop\Alcohol 52%.lnk
2013-08-29 11:03 - 2013-08-29 11:03 - 00000000 ____D C:\Program Files\Alcohol Soft
2013-08-29 11:01 - 2013-08-29 11:01 - 00466008 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys
2013-08-29 11:00 - 2013-08-29 12:19 - 00000366 _____ C:\Windows\Tasks\Lyrics Seeker Update.job
2013-08-29 11:00 - 2013-08-29 11:00 - 00000000 ____D C:\Program Files\LyricsSeeker
2013-08-29 10:43 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2013-08-29 10:43 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2013-08-29 10:43 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2013-08-29 10:43 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2013-08-29 10:43 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2013-08-29 10:43 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2013-08-29 10:43 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2013-08-29 10:43 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2013-08-29 10:43 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2013-08-29 10:43 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2013-08-29 10:43 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2013-08-29 10:43 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2013-08-29 10:43 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2013-08-29 10:43 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2013-08-29 10:43 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2013-08-29 10:43 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2013-08-29 10:43 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2013-08-29 10:43 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2013-08-29 10:43 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2013-08-29 10:43 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2013-08-29 10:43 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2013-08-29 10:43 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2013-08-29 10:43 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2013-08-29 10:43 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2013-08-29 10:43 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2013-08-29 10:43 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2013-08-29 10:43 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2013-08-29 10:43 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2013-08-29 10:43 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2013-08-29 10:43 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2013-08-29 10:43 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2013-08-29 10:43 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2013-08-29 10:43 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2013-08-29 10:43 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2013-08-29 10:43 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2013-08-29 10:43 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2013-08-29 10:43 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2013-08-29 10:43 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2013-08-29 10:43 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2013-08-29 10:43 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2013-08-29 10:43 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2013-08-29 10:43 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2013-08-29 10:43 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2013-08-29 10:43 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2013-08-29 10:43 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2013-08-29 10:43 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2013-08-29 10:43 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2013-08-29 10:43 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2013-08-29 10:43 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2013-08-29 10:43 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2013-08-29 10:43 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2013-08-29 10:43 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2013-08-29 10:43 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2013-08-29 10:43 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2013-08-29 10:43 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2013-08-29 10:43 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2013-08-29 10:43 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2013-08-29 10:43 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2013-08-29 10:43 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2013-08-29 10:43 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2013-08-29 10:43 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2013-08-29 10:42 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2013-08-29 10:42 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2013-08-29 10:42 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2013-08-29 10:42 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2013-08-29 10:42 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2013-08-29 10:42 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2013-08-29 10:42 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2013-08-29 10:42 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2013-08-29 10:42 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2013-08-29 10:42 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2013-08-29 10:42 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2013-08-29 10:42 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2013-08-29 10:42 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2013-08-29 10:42 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2013-08-29 10:42 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2013-08-29 10:42 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2013-08-29 10:42 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2013-08-29 10:42 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2013-08-29 10:42 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2013-08-29 10:42 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2013-08-29 10:40 - 2013-08-29 10:43 - 00000000 ____D C:\Windows\system32\directx
2013-08-29 10:38 - 2013-08-29 10:39 - 00000216 _____ C:\DebugTrace-RockallDLL.log
2013-08-28 21:08 - 2013-08-28 21:09 - 00000000 ____D C:\Program Files\Age of Empires 2
2013-08-28 19:31 - 2013-08-28 19:31 - 00002000 _____ C:\Users\Public\Desktop\The Conquerors.lnk
2013-08-28 18:21 - 2013-08-29 10:50 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-08-28 18:21 - 2013-08-28 18:21 - 00002080 _____ C:\Users\Public\Desktop\Age of Empires II.lnk
2013-08-28 18:20 - 2013-08-28 18:20 - 00000000 ____D C:\Program Files\Microsoft Games
2013-08-28 12:57 - 2013-08-29 12:18 - 00000336 _____ C:\Windows\setupact.log
2013-08-28 12:57 - 2013-08-28 12:57 - 00000000 _____ C:\Windows\setuperr.log
2013-08-27 12:24 - 2013-08-27 12:24 - 00000000 ____D C:\ProgramData\Auslogics
2013-08-27 12:12 - 2013-08-27 12:12 - 00000000 ____D C:\Windows\pss
2013-08-26 12:03 - 2013-08-29 11:03 - 00000000 ____D C:\Users\Stefan\AppData\Local\LogMeIn Hamachi
2013-08-26 12:03 - 2013-08-26 12:03 - 00000000 ____D C:\Program Files\LogMeIn Hamachi
2013-08-25 16:52 - 2013-08-25 16:53 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Mozilla
2013-08-25 16:52 - 2013-08-25 16:52 - 00086144 _____ C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-25 16:52 - 2013-08-25 16:52 - 00000020 ___SH C:\Users\Gast\ntuser.ini
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\Startmenü
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\Netzwerkumgebung
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\Druckumgebung
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\Documents\Eigene Musik
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\Documents\Eigene Bilder
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\AppData\Local\Verlauf
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Apple Computer
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Adobe
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 ____D C:\Users\Gast\AppData\Local\VirtualStore
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 ____D C:\Users\Gast\AppData\Local\Mozilla
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 ____D C:\Users\Gast
2013-08-25 16:52 - 2012-07-21 16:40 - 00000000 ____D C:\Users\Gast\AppData\Local\Microsoft Help
2013-08-25 15:13 - 2013-08-25 16:39 - 00000929 _____ C:\Windows\system32\Drivers\etc\hosts.umbrella
2013-08-25 15:12 - 2013-08-25 15:12 - 00000000 ____D C:\Users\Stefan\.shsh
2013-08-25 14:53 - 2013-08-25 15:04 - 00000000 ____D C:\sn0wbreeze
2013-08-23 17:15 - 2013-08-23 17:15 - 00000000 ____D C:\Users\Stefan\Desktop\4err
2013-08-19 22:07 - 2013-08-19 22:07 - 00001713 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-08-19 22:07 - 2013-08-19 22:07 - 00000000 ____D C:\Program Files\iPod
2013-08-19 22:06 - 2013-08-19 22:07 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-08-19 22:06 - 2013-08-19 22:07 - 00000000 ____D C:\Program Files\iTunes
2013-08-18 00:42 - 2013-08-29 11:00 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-16 03:01 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-16 03:01 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-16 03:01 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-16 03:01 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-16 03:01 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-16 03:01 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-16 03:01 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-16 03:01 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-16 03:01 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-16 03:01 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-16 03:01 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-16 03:01 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-16 03:01 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-16 03:01 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-16 03:01 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-16 03:01 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-15 13:39 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-15 13:39 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-15 13:39 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-15 13:39 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-15 13:39 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-15 13:39 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-15 13:39 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-15 13:39 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-15 13:39 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-15 13:39 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-15 13:39 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-15 13:38 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-13 21:19 - 2013-08-13 21:19 - 00008837 _____ C:\Users\Stefan\AppData\Local\recently-used.xbel
2013-08-12 23:33 - 2013-08-12 23:33 - 01263636 _____ C:\Users\Stefan\QULT-KENNEDYxcf.xcf
2013-08-12 22:59 - 2013-08-13 21:19 - 00000000 ____D C:\Users\Stefan\AppData\Local\gtk-2.0
2013-08-12 22:59 - 2013-08-12 22:59 - 00000000 ____D C:\Users\Stefan\.thumbnails
2013-08-12 22:57 - 2013-08-13 21:20 - 00000000 ____D C:\Users\Stefan\.gimp-2.8
2013-08-12 22:57 - 2013-08-12 22:57 - 00000000 ____D C:\Users\Stefan\AppData\Local\gegl-0.2
2013-08-12 22:36 - 2013-08-12 22:38 - 00000000 ____D C:\Program Files\GIMP 2
2013-08-08 19:04 - 2013-08-10 22:01 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-08-07 01:32 - 2013-08-16 03:06 - 00000000 ____D C:\Windows\system32\MRT
==================== One Month Modified Files and Folders =======
2013-08-29 12:26 - 2009-07-14 06:34 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-29 12:26 - 2009-07-14 06:34 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-29 12:25 - 2013-08-29 12:25 - 00001330 _____ C:\Users\Stefan\Desktop\JRT.txt
2013-08-29 12:23 - 2012-07-19 18:21 - 01716966 _____ C:\Windows\WindowsUpdate.log
2013-08-29 12:22 - 2013-08-29 12:22 - 00000000 ____D C:\Windows\ERUNT
2013-08-29 12:19 - 2013-08-29 11:00 - 00000366 _____ C:\Windows\Tasks\Lyrics Seeker Update.job
2013-08-29 12:18 - 2013-08-28 12:57 - 00000336 _____ C:\Windows\setupact.log
2013-08-29 12:18 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-29 12:17 - 2013-08-29 12:16 - 00000000 ____D C:\AdwCleaner
2013-08-29 11:40 - 2013-08-29 11:16 - 00000000 ____D C:\Windows\865537E164904193A4B6669C62711852.TMP
2013-08-29 11:39 - 2012-07-19 21:37 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-29 11:38 - 2013-08-29 11:38 - 00000000 ____D C:\Windows\system32\appmgmt
2013-08-29 11:36 - 2010-11-20 23:48 - 00015126 _____ C:\Windows\PFRO.log
2013-08-29 11:35 - 2013-08-29 11:35 - 00000202 _____ C:\Users\Stefan\defogger_reenable
2013-08-29 11:35 - 2012-07-19 18:28 - 00000000 ____D C:\Users\Stefan
2013-08-29 11:31 - 2013-08-29 11:31 - 00000000 ____D C:\FRST
2013-08-29 11:17 - 2013-08-29 11:17 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-29 11:16 - 2013-08-29 11:16 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard
2013-08-29 11:04 - 2013-08-29 11:04 - 00001087 _____ C:\Users\Public\Desktop\Alcohol 52%.lnk
2013-08-29 11:03 - 2013-08-29 11:03 - 00000000 ____D C:\Program Files\Alcohol Soft
2013-08-29 11:03 - 2013-08-26 12:03 - 00000000 ____D C:\Users\Stefan\AppData\Local\LogMeIn Hamachi
2013-08-29 11:01 - 2013-08-29 11:01 - 00466008 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys
2013-08-29 11:00 - 2013-08-29 11:00 - 00000000 ____D C:\Program Files\LyricsSeeker
2013-08-29 11:00 - 2013-08-18 00:42 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-29 10:50 - 2013-08-28 18:21 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-08-29 10:43 - 2013-08-29 10:40 - 00000000 ____D C:\Windows\system32\directx
2013-08-29 10:42 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-08-29 10:39 - 2013-08-29 10:38 - 00000216 _____ C:\DebugTrace-RockallDLL.log
2013-08-29 10:38 - 2012-07-19 18:28 - 00000000 ____D C:\Users\Stefan\AppData\Local\VirtualStore
2013-08-29 10:31 - 2012-07-19 21:23 - 00086528 _____ C:\Users\Stefan\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-29 10:29 - 2009-07-14 06:33 - 00344216 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-28 21:09 - 2013-08-28 21:08 - 00000000 ____D C:\Program Files\Age of Empires 2
2013-08-28 19:31 - 2013-08-28 19:31 - 00002000 _____ C:\Users\Public\Desktop\The Conquerors.lnk
2013-08-28 18:21 - 2013-08-28 18:21 - 00002080 _____ C:\Users\Public\Desktop\Age of Empires II.lnk
2013-08-28 18:20 - 2013-08-28 18:20 - 00000000 ____D C:\Program Files\Microsoft Games
2013-08-28 17:40 - 2012-07-19 22:10 - 00000000 ____D C:\Program Files\Steam
2013-08-28 17:40 - 2012-07-19 22:10 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-08-28 12:57 - 2013-08-28 12:57 - 00000000 _____ C:\Windows\setuperr.log
2013-08-27 12:36 - 2013-07-27 18:29 - 00074752 ___SH C:\Users\Stefan\Thumbs.db
2013-08-27 12:24 - 2013-08-27 12:24 - 00000000 ____D C:\ProgramData\Auslogics
2013-08-27 12:23 - 2013-02-24 18:24 - 00000000 ____D C:\Windows\Minidump
2013-08-27 12:12 - 2013-08-27 12:12 - 00000000 ____D C:\Windows\pss
2013-08-27 12:12 - 2012-07-19 22:59 - 00001912 _____ C:\Windows\epplauncher.mif
2013-08-27 12:11 - 2012-07-19 22:58 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-08-26 12:03 - 2013-08-26 12:03 - 00000000 ____D C:\Program Files\LogMeIn Hamachi
2013-08-25 16:53 - 2013-08-25 16:52 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Mozilla
2013-08-25 16:52 - 2013-08-25 16:52 - 00086144 _____ C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-25 16:52 - 2013-08-25 16:52 - 00000020 ___SH C:\Users\Gast\ntuser.ini
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\Startmenü
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\Netzwerkumgebung
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\Druckumgebung
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\Documents\Eigene Musik
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\Documents\Eigene Bilder
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 _SHDL C:\Users\Gast\AppData\Local\Verlauf
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Apple Computer
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Adobe
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 ____D C:\Users\Gast\AppData\Local\VirtualStore
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 ____D C:\Users\Gast\AppData\Local\Mozilla
2013-08-25 16:52 - 2013-08-25 16:52 - 00000000 ____D C:\Users\Gast
2013-08-25 16:39 - 2013-08-25 15:13 - 00000929 _____ C:\Windows\system32\Drivers\etc\hosts.umbrella
2013-08-25 15:12 - 2013-08-25 15:12 - 00000000 ____D C:\Users\Stefan\.shsh
2013-08-25 15:04 - 2013-08-25 14:53 - 00000000 ____D C:\sn0wbreeze
2013-08-23 17:15 - 2013-08-23 17:15 - 00000000 ____D C:\Users\Stefan\Desktop\4err
2013-08-20 20:39 - 2012-07-19 21:37 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-08-20 20:39 - 2012-07-19 21:37 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-08-20 12:19 - 2012-07-19 21:31 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-08-19 22:07 - 2013-08-19 22:07 - 00001713 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-08-19 22:07 - 2013-08-19 22:07 - 00000000 ____D C:\Program Files\iPod
2013-08-19 22:07 - 2013-08-19 22:06 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-08-19 22:07 - 2013-08-19 22:06 - 00000000 ____D C:\Program Files\iTunes
2013-08-19 22:06 - 2012-08-12 14:46 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-08-16 17:41 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-08-16 03:22 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-08-16 03:06 - 2013-08-07 01:32 - 00000000 ____D C:\Windows\system32\MRT
2013-08-16 03:04 - 2012-07-23 08:55 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-16 03:03 - 2010-11-20 23:01 - 01519874 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-13 21:20 - 2013-08-12 22:57 - 00000000 ____D C:\Users\Stefan\.gimp-2.8
2013-08-13 21:19 - 2013-08-13 21:19 - 00008837 _____ C:\Users\Stefan\AppData\Local\recently-used.xbel
2013-08-13 21:19 - 2013-08-12 22:59 - 00000000 ____D C:\Users\Stefan\AppData\Local\gtk-2.0
2013-08-12 23:33 - 2013-08-12 23:33 - 01263636 _____ C:\Users\Stefan\QULT-KENNEDYxcf.xcf
2013-08-12 22:59 - 2013-08-12 22:59 - 00000000 ____D C:\Users\Stefan\.thumbnails
2013-08-12 22:57 - 2013-08-12 22:57 - 00000000 ____D C:\Users\Stefan\AppData\Local\gegl-0.2
2013-08-12 22:38 - 2013-08-12 22:36 - 00000000 ____D C:\Program Files\GIMP 2
2013-08-10 22:01 - 2013-08-08 19:04 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
Files to move or delete:
====================
C:\Users\Stefan\AppData\Local\Temp\AxSFADownloader.exe
C:\Users\Stefan\AppData\Local\Temp\LyriXtmp.exe
C:\Users\Stefan\AppData\Local\Temp\ose00000.exe
C:\Users\Stefan\AppData\Local\Temp\Quarantine.exe
C:\Users\Stefan\AppData\Local\Temp\SHSetup.exe
C:\Users\Stefan\AppData\Local\Temp\uninst1.exe
C:\Users\Stefan\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
C:\Users\Stefan\AppData\Local\Temp\is1988980107\671345_Setup.EXE
C:\Users\Stefan\AppData\Local\Temp\is1988980107\Alcohol52_FE_2.0.2.4713.exe
C:\Users\Stefan\AppData\Local\Temp\is1988980107\DeltaTB.exe
C:\Users\Stefan\AppData\Local\Temp\is1988980107\OptimizerPro.exe
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\BabMaint.exe
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\BExternal.dll
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\BUSolForMontiera.dll
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\BUSolution.dll
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\ccp.exe
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\ChromeToolbarSetup.dll
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\CrxInstaller.dll
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\enhancedNT.dll
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\GUninstaller.exe
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\IEHelper.dll
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\MntrDLLInstall.dll
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\MyDeltaTB.exe
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\Setup.exe
C:\Users\Stefan\AppData\Local\Temp\B13DD31E-BAB0-7891-85A3-A345E8DB759F\Latest\sqlite3.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\CbsProvider.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\CompatProvider.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\DismCore.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\DismCorePS.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\DismHost.exe
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\DismProv.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\DmiProvider.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\FolderProvider.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\IntlProvider.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\LogProvider.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\MsiProvider.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\OSProvider.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\SmiProvider.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\TransmogProvider.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\UnattendProvider.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\wdscore.dll
C:\Users\Stefan\AppData\Local\Temp\AC70272E-FB1F-4BAD-A004-25764813A4AC\WimProvider.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-22 18:05
==================== End Of Log ============================ --- --- ---
grüsse |