wickedsick2k | 04.07.2014 15:35 | Alles wie beschrieben erledigt, hier noch die einzelnen Logfiles:
Fixlog Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:01-07-2014
Ran by Natalie at 2014-07-04 16:23:16 Run:1
Running from C:\Users\Natalie\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
HKU\S-1-5-21-71110408-726262554-3037163554-1001\...\Run: [wkkjkaji] => C:\Users\Natalie\AppData\Local\Bpgd\pgokwyokaji.exe
C:\Users\Natalie\AppData\Local\Bpgd
Reboot:
end
*****************
HKU\S-1-5-21-71110408-726262554-3037163554-1001\Software\Microsoft\Windows\CurrentVersion\Run\\wkkjkaji => value deleted successfully.
C:\Users\Natalie\AppData\Local\Bpgd => Moved successfully.
The system needed a reboot.
==== End of Fixlog ==== FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:01-07-2014
Ran by Natalie (administrator) on SCHNADDL on 04-07-2014 16:26:34
Running from C:\Users\Natalie\Desktop
Platform: Microsoft Windows 8.1 Pro (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\livecomm.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe
(Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Dropbox, Inc.) C:\Users\Natalie\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [835584 2008-01-30] (Synaptics, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-10-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5179408 2014-06-17] (AVG Technologies CZ, s.r.o.)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,"C:\Program Files\NoTilesPlease\ntpload.exe",
HKU\S-1-5-21-71110408-726262554-3037163554-1001\...\Run: [EPSON26D8A9 (Epson Stylus SX235)] => C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_FATIHLE.EXE [212480 2011-01-20] (SEIKO EPSON CORPORATION)
Startup: C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Natalie\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4B00A63109D0CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
URLSearchHook: HKCU - (No Name) - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - No File
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Natalie\AppData\Roaming\Mozilla\Firefox\Profiles\92znsytt.default
FF DefaultSearchEngine: Ask Search
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Natalie\AppData\Roaming\Mozilla\Firefox\Profiles\92znsytt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-12-21]
FF Extension: Greasemonkey - C:\Users\Natalie\AppData\Roaming\Mozilla\Firefox\Profiles\92znsytt.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2012-12-21]
========================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3241488 2014-06-27] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-06-17] (AVG Technologies CZ, s.r.o.)
S3 ScDeviceEnum; C:\WINDOWS\System32\ScDeviceEnum.dll [105472 2013-08-22] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [279784 2014-06-16] (Microsoft Corporation)
S3 WEPHOSTSVC; C:\WINDOWS\system32\wephostsvc.dll [20992 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22224 2014-06-16] (Microsoft Corporation)
S3 workfolderssvc; C:\WINDOWS\system32\workfolderssvc.dll [1210368 2014-06-16] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 athr; C:\WINDOWS\system32\DRIVERS\athwn.sys [2795520 2013-06-18] (Qualcomm Atheros Communications, Inc.)
S0 Avgbootx; C:\WINDOWS\System32\DRIVERS\avgbootx.sys [17424 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [121624 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdriverx.sys [199960 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\WINDOWS\system32\DRIVERS\avgidsshimw8x.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [188696 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [98584 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpx; C:\WINDOWS\system32\DRIVERS\avgwfpx.sys [213784 2014-05-14] (AVG Technologies CZ, s.r.o.)
R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [25600 2014-03-18] (Microsoft Corporation)
S3 GPIO; C:\WINDOWS\System32\drivers\iaiogpio.sys [22016 2013-07-23] (Intel Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [92504 2014-06-16] (Microsoft Corporation)
R0 Wof; C:\WINDOWS\system32\Drivers\Wof.sys [138584 2014-06-16] (Microsoft Corporation)
R3 yukonw8; C:\WINDOWS\system32\DRIVERS\yk63x86.sys [249288 2013-06-18] (Marvell)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-04 16:26 - 2014-07-04 16:27 - 00010285 _____ () C:\Users\Natalie\Desktop\FRST.txt
2014-07-03 20:20 - 2014-07-03 20:20 - 00002085 _____ () C:\Users\Natalie\Desktop\mbam.txt
2014-07-03 20:01 - 2014-07-03 20:19 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-03 20:00 - 2014-07-03 20:00 - 00001068 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-03 20:00 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-07-03 20:00 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-07-03 20:00 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-07-03 19:59 - 2014-07-03 19:59 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Natalie\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-03 18:49 - 2014-07-03 18:49 - 00005046 _____ () C:\Users\Natalie\Desktop\avg scan.csv
2014-07-03 17:55 - 2014-07-03 17:55 - 00021562 _____ () C:\Users\Natalie\Addition.txt
2014-07-03 17:54 - 2014-07-03 17:55 - 00090228 _____ () C:\Users\Natalie\FRST.txt
2014-07-03 17:53 - 2014-07-04 16:26 - 00000000 ____D () C:\FRST
2014-07-03 17:52 - 2014-07-03 17:52 - 00000476 _____ () C:\Users\Natalie\Desktop\defogger_disable.log
2014-07-03 17:52 - 2014-07-03 17:52 - 00000000 _____ () C:\Users\Natalie\defogger_reenable
2014-07-03 17:50 - 2014-07-03 17:50 - 01073664 _____ (Farbar) C:\Users\Natalie\Desktop\FRST.exe
2014-07-03 17:50 - 2014-07-03 17:50 - 00380416 _____ () C:\Users\Natalie\Desktop\v87lo16c.exe
2014-07-03 17:48 - 2014-07-03 17:48 - 00050477 _____ () C:\Users\Natalie\Desktop\Defogger.exe
2014-07-02 22:03 - 2014-07-02 22:03 - 00000967 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\TuneUp Software
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\AVG2014
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-07-02 22:02 - 2014-07-02 22:23 - 00000000 ____D () C:\ProgramData\AVG2014
2014-07-02 22:02 - 2014-07-02 22:02 - 00000000 ___HD () C:\$AVG
2014-07-02 22:01 - 2014-07-02 22:01 - 00000000 ____D () C:\Program Files\AVG
2014-07-02 21:57 - 2014-07-04 16:21 - 00000000 ____D () C:\ProgramData\MFAData
2014-07-02 21:57 - 2014-07-02 22:07 - 00000000 ____D () C:\Users\Natalie\AppData\Local\Avg2014
2014-07-02 21:57 - 2014-07-02 21:57 - 00000000 ____D () C:\Users\Natalie\AppData\Local\MFAData
2014-07-02 21:29 - 2014-07-02 21:30 - 00000000 ___HD () C:\Users\Natalie\AppData\Local\Ebakhwicoj
2014-06-24 19:58 - 2014-06-24 19:59 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-24 15:11 - 2014-06-24 15:11 - 00000000 ___RD () C:\WINDOWS\BrowserChoice
2014-06-17 20:17 - 2014-06-17 20:17 - 00000000 ____D () C:\Users\Natalie\Desktop\Programme
2014-06-17 19:59 - 2014-05-19 07:33 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvcfg.exe
2014-06-17 19:59 - 2014-05-19 07:23 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe
2014-06-17 16:22 - 2014-06-17 16:22 - 00188696 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgldx86.sys
2014-06-17 16:18 - 2014-06-17 16:18 - 00241944 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avglogx.sys
2014-06-17 16:17 - 2014-06-17 16:17 - 00147736 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidshx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00199960 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdriverx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00121624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgdiskx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00098584 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx86.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00027416 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgrkx86.sys
2014-06-17 16:05 - 2014-06-17 16:05 - 00021272 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsshimw8x.sys
2014-06-16 12:46 - 2014-06-16 12:37 - 00000000 ___DC () C:\WINDOWS\Panther
2014-06-16 12:44 - 2014-06-16 12:44 - 17271296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 11725312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 04244992 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-06-16 12:44 - 2014-06-16 12:44 - 01790976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 01143296 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-06-16 12:44 - 2014-06-16 12:44 - 00592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-06-16 12:44 - 2014-06-16 12:44 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-06-16 12:44 - 2014-06-16 12:44 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-06-16 12:43 - 2014-06-16 12:43 - 01871704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-06-16 12:43 - 2014-06-16 12:43 - 01090296 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2014-06-16 12:43 - 2014-06-16 12:43 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-06-16 12:43 - 2014-06-16 12:43 - 00286040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2014-06-16 12:43 - 2014-06-16 12:43 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-06-16 12:43 - 2014-06-16 12:43 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2014-06-16 12:42 - 2014-07-04 16:25 - 00000000 __RDO () C:\Users\Natalie\OneDrive
2014-06-16 12:42 - 2014-06-16 12:42 - 02826240 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-06-16 12:42 - 2014-06-16 12:42 - 01312256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-06-16 12:42 - 2014-06-16 12:42 - 00219992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-06-16 12:42 - 2014-06-16 12:42 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2014-06-16 12:42 - 2014-06-16 12:42 - 00092504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2014-06-16 12:42 - 2014-06-16 12:42 - 00030224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 02270208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 02088160 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2014-06-16 12:41 - 2014-06-16 12:41 - 02030080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01779800 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01679704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 01679128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01351168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01326936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01095488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01037504 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00887296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00863552 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00731648 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2014-06-16 12:41 - 2014-06-16 12:41 - 00731648 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2014-06-16 12:41 - 2014-06-16 12:41 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00491008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2014-06-16 12:41 - 2014-06-16 12:41 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdmTmpl.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00406912 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00390488 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00387210 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-06-16 12:41 - 2014-06-16 12:41 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlangpui.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00376152 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2014-06-16 12:41 - 2014-06-16 12:41 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00355832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00321880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe
2014-06-16 12:41 - 2014-06-16 12:41 - 00283992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2014-06-16 12:41 - 2014-06-16 12:41 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDScDrv.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\spp.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00138584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpnpmgr.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevPropMgr.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00094016 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00092160 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32tm.exe
2014-06-16 12:41 - 2014-06-16 12:41 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\IPMIDrv.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\l2gpstore.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpipreg.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SetNetworkLocation.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxproxy.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00020992 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2014-06-16 12:39 - 2014-06-16 12:39 - 02818048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-06-16 12:39 - 2014-06-16 12:39 - 02366976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 02257608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2014-06-16 12:39 - 2014-06-16 12:39 - 02045440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 01634304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00419928 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00049544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-06-16 12:39 - 2014-06-16 12:39 - 00046512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2014-06-16 12:39 - 2014-06-16 12:39 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2014-06-16 12:39 - 2014-06-16 12:39 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 18755672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 12711424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 05833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 05786968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 05774848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 05104640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 03563008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 03497472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 02144984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 02130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01309184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01210368 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01209616 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01200288 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01167360 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01159520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01089536 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01029120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00834560 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00707048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00672256 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00669856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00629760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00518544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00482416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00406504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00387896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2014-06-16 12:38 - 2014-06-16 12:38 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00333656 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00328984 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00311128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00305768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00294744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00285144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00271192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00264704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00264536 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00240472 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00230808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00229344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00194752 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00178184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00147800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00111528 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00098584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00080032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt_map.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00069632 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\srclient.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\tlscsp.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00026784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt100.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2014-06-16 12:36 - 2014-06-16 12:36 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff
2014-06-16 12:34 - 2014-06-16 12:34 - 00001446 _____ () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-06-16 12:34 - 2014-06-16 12:34 - 00000020 ___SH () C:\Users\Natalie\ntuser.ini
2014-06-16 12:34 - 2014-06-16 12:34 - 00000000 ____D () C:\WINDOWS\system32\XPSViewer
2014-06-16 12:34 - 2014-06-16 12:34 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-06-16 12:34 - 2014-06-16 12:08 - 00000000 ____D () C:\Program Files\MSBuild
2014-06-16 12:34 - 2013-08-03 06:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2014-06-16 12:34 - 2013-08-03 06:41 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2014-06-16 12:34 - 2013-08-03 06:41 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2014-06-16 12:33 - 2014-06-16 11:53 - 00000000 ____D () C:\Recovery
2014-06-16 12:18 - 2014-07-04 16:23 - 01099055 _____ () C:\WINDOWS\WindowsUpdate.log
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-06-16 12:17 - 2014-06-16 12:17 - 00021532 _____ () C:\WINDOWS\system32\emptyregdb.dat
2014-06-16 12:06 - 2014-06-16 12:06 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-06-16 12:01 - 2014-06-16 12:08 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate
2014-06-16 11:59 - 2014-07-04 16:22 - 00000000 ____D () C:\Users\Natalie
2014-06-16 11:59 - 2014-06-16 12:17 - 00038103 _____ () C:\WINDOWS\diagwrn.xml
2014-06-16 11:59 - 2014-06-16 12:17 - 00038103 _____ () C:\WINDOWS\diagerr.xml
2014-06-16 11:59 - 2014-06-16 12:12 - 00000000 ____D () C:\Users\Gast
2014-06-16 11:59 - 2014-06-16 12:01 - 00000000 ___RD () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-16 11:59 - 2014-06-16 12:01 - 00000000 ___RD () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-06-16 11:59 - 2014-06-16 12:00 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-16 11:59 - 2014-06-16 12:00 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Startmenü
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Netzwerkumgebung
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Druckumgebung
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Documents\Eigene Musik
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Documents\Eigene Bilder
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\AppData\Local\Verlauf
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Startmenü
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Netzwerkumgebung
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Druckumgebung
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Musik
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Bilder
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Verlauf
2014-06-16 11:59 - 2014-03-18 10:08 - 00000369 _____ () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-06-16 11:59 - 2014-03-18 10:08 - 00000369 _____ () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-06-16 11:59 - 2014-03-18 10:08 - 00000369 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-06-16 11:59 - 2014-03-18 10:08 - 00000369 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-06-16 11:59 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-06-16 11:59 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-06-16 11:59 - 2013-08-22 10:17 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-06-16 11:59 - 2013-08-22 10:17 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01000.Wdf
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 _____ () C:\WINDOWS\system32\atiicdxx.dat
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 _____ () C:\WINDOWS\ativpsrm.bin
2014-06-16 11:48 - 2014-06-16 11:48 - 00000000 ____D () C:\Program Files\Synaptics
2014-06-16 11:13 - 2014-06-16 12:17 - 00006700 _____ () C:\WINDOWS\comsetup.log
2014-06-08 15:43 - 2014-06-08 15:43 - 00001943 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
2014-06-08 15:43 - 2014-06-08 15:43 - 00001932 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
2014-06-08 15:43 - 2014-06-08 15:43 - 00001866 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
2014-06-08 15:42 - 2014-06-08 15:58 - 00000000 ____D () C:\Program Files\JDownloader
2014-06-08 15:41 - 2014-06-08 15:41 - 00076456 _____ (AppWork GmbH) C:\Users\Natalie\Downloads\WebInstaller.exe
==================== One Month Modified Files and Folders =======
2014-07-04 16:27 - 2014-07-04 16:26 - 00010285 _____ () C:\Users\Natalie\Desktop\FRST.txt
2014-07-04 16:26 - 2014-07-03 17:53 - 00000000 ____D () C:\FRST
2014-07-04 16:25 - 2014-06-16 12:42 - 00000000 __RDO () C:\Users\Natalie\OneDrive
2014-07-04 16:25 - 2013-08-22 09:23 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-07-04 16:24 - 2014-03-18 01:54 - 00002512 _____ () C:\WINDOWS\PFRO.log
2014-07-04 16:23 - 2014-06-16 12:18 - 01099055 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-04 16:23 - 2013-08-22 08:13 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2014-07-04 16:23 - 2012-12-02 12:05 - 00000000 ___RD () C:\Users\Natalie\Dropbox
2014-07-04 16:22 - 2014-06-16 11:59 - 00000000 ____D () C:\Users\Natalie
2014-07-04 16:21 - 2014-07-02 21:57 - 00000000 ____D () C:\ProgramData\MFAData
2014-07-04 00:24 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-07-03 20:20 - 2014-07-03 20:20 - 00002085 _____ () C:\Users\Natalie\Desktop\mbam.txt
2014-07-03 20:19 - 2014-07-03 20:01 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-03 20:17 - 2014-02-09 13:20 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\DropboxMaster
2014-07-03 20:17 - 2012-12-02 11:47 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Dropbox
2014-07-03 20:15 - 2012-07-26 08:53 - 00000000 ____D () C:\WINDOWS\LiveKernelReports
2014-07-03 20:00 - 2014-07-03 20:00 - 00001068 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-03 19:59 - 2014-07-03 19:59 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Natalie\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-03 18:49 - 2014-07-03 18:49 - 00005046 _____ () C:\Users\Natalie\Desktop\avg scan.csv
2014-07-03 18:25 - 2012-12-02 11:45 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-07-03 17:55 - 2014-07-03 17:55 - 00021562 _____ () C:\Users\Natalie\Addition.txt
2014-07-03 17:55 - 2014-07-03 17:54 - 00090228 _____ () C:\Users\Natalie\FRST.txt
2014-07-03 17:52 - 2014-07-03 17:52 - 00000476 _____ () C:\Users\Natalie\Desktop\defogger_disable.log
2014-07-03 17:52 - 2014-07-03 17:52 - 00000000 _____ () C:\Users\Natalie\defogger_reenable
2014-07-03 17:50 - 2014-07-03 17:50 - 01073664 _____ (Farbar) C:\Users\Natalie\Desktop\FRST.exe
2014-07-03 17:50 - 2014-07-03 17:50 - 00380416 _____ () C:\Users\Natalie\Desktop\v87lo16c.exe
2014-07-03 17:48 - 2014-07-03 17:48 - 00050477 _____ () C:\Users\Natalie\Desktop\Defogger.exe
2014-07-03 00:08 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-07-02 23:32 - 2012-12-02 11:44 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-07-02 22:23 - 2014-07-02 22:02 - 00000000 ____D () C:\ProgramData\AVG2014
2014-07-02 22:07 - 2014-07-02 21:57 - 00000000 ____D () C:\Users\Natalie\AppData\Local\Avg2014
2014-07-02 22:07 - 2013-08-22 08:13 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-07-02 22:03 - 2014-07-02 22:03 - 00000967 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\TuneUp Software
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\AVG2014
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-07-02 22:03 - 2012-07-26 08:53 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
2014-07-02 22:02 - 2014-07-02 22:02 - 00000000 ___HD () C:\$AVG
2014-07-02 22:01 - 2014-07-02 22:01 - 00000000 ____D () C:\Program Files\AVG
2014-07-02 21:57 - 2014-07-02 21:57 - 00000000 ____D () C:\Users\Natalie\AppData\Local\MFAData
2014-07-02 21:30 - 2014-07-02 21:29 - 00000000 ___HD () C:\Users\Natalie\AppData\Local\Ebakhwicoj
2014-06-29 12:55 - 2014-03-18 10:04 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-06-29 12:53 - 2013-08-22 09:23 - 00331768 _____ () C:\WINDOWS\setupact.log
2014-06-25 18:23 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-06-24 19:59 - 2014-06-24 19:58 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-24 15:40 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\rescache
2014-06-24 15:12 - 2012-07-26 08:43 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-06-24 15:11 - 2014-06-24 15:11 - 00000000 ___RD () C:\WINDOWS\BrowserChoice
2014-06-17 20:17 - 2014-06-17 20:17 - 00000000 ____D () C:\Users\Natalie\Desktop\Programme
2014-06-17 19:48 - 2013-10-17 20:12 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Samsung
2014-06-17 19:48 - 2012-12-02 12:12 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-06-17 19:48 - 2012-12-02 12:11 - 00000000 ____D () C:\ProgramData\Samsung
2014-06-17 19:48 - 2012-12-02 12:11 - 00000000 ____D () C:\Program Files\Samsung
2014-06-17 16:22 - 2014-06-17 16:22 - 00188696 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgldx86.sys
2014-06-17 16:18 - 2014-06-17 16:18 - 00241944 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avglogx.sys
2014-06-17 16:17 - 2014-06-17 16:17 - 00147736 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidshx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00199960 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdriverx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00121624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgdiskx.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00098584 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx86.sys
2014-06-17 16:06 - 2014-06-17 16:06 - 00027416 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgrkx86.sys
2014-06-17 16:05 - 2014-06-17 16:05 - 00021272 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsshimw8x.sys
2014-06-16 12:53 - 2012-12-02 11:17 - 00000000 ____D () C:\WINDOWS\system32\appmgmt
2014-06-16 12:52 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\restore
2014-06-16 12:44 - 2014-06-16 12:44 - 17271296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 11725312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 04244992 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-06-16 12:44 - 2014-06-16 12:44 - 01790976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 01143296 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-06-16 12:44 - 2014-06-16 12:44 - 00592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-06-16 12:44 - 2014-06-16 12:44 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-06-16 12:44 - 2014-06-16 12:44 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-06-16 12:44 - 2014-06-16 12:44 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-06-16 12:44 - 2013-08-22 10:17 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template
2014-06-16 12:43 - 2014-06-16 12:43 - 01871704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-06-16 12:43 - 2014-06-16 12:43 - 01090296 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2014-06-16 12:43 - 2014-06-16 12:43 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-06-16 12:43 - 2014-06-16 12:43 - 00286040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2014-06-16 12:43 - 2014-06-16 12:43 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-06-16 12:43 - 2014-06-16 12:43 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2014-06-16 12:43 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\WinStore
2014-06-16 12:42 - 2014-06-16 12:42 - 02826240 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-06-16 12:42 - 2014-06-16 12:42 - 01312256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-06-16 12:42 - 2014-06-16 12:42 - 00219992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-06-16 12:42 - 2014-06-16 12:42 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2014-06-16 12:42 - 2014-06-16 12:42 - 00092504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2014-06-16 12:42 - 2014-06-16 12:42 - 00030224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-06-16 12:42 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-16 12:42 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-16 12:42 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Windows Defender
2014-06-16 12:41 - 2014-06-16 12:41 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 02270208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 02088160 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2014-06-16 12:41 - 2014-06-16 12:41 - 02030080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01779800 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01679704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 01679128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01351168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01326936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01095488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 01037504 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00887296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00863552 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00731648 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2014-06-16 12:41 - 2014-06-16 12:41 - 00731648 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2014-06-16 12:41 - 2014-06-16 12:41 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00491008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2014-06-16 12:41 - 2014-06-16 12:41 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdmTmpl.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00406912 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00390488 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00387210 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-06-16 12:41 - 2014-06-16 12:41 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlangpui.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00376152 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2014-06-16 12:41 - 2014-06-16 12:41 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00355832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00321880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe
2014-06-16 12:41 - 2014-06-16 12:41 - 00283992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2014-06-16 12:41 - 2014-06-16 12:41 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDScDrv.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\spp.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00138584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpnpmgr.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevPropMgr.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00094016 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00092160 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32tm.exe
2014-06-16 12:41 - 2014-06-16 12:41 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\IPMIDrv.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\l2gpstore.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpipreg.sys
2014-06-16 12:41 - 2014-06-16 12:41 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SetNetworkLocation.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxproxy.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll
2014-06-16 12:41 - 2014-06-16 12:41 - 00020992 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2014-06-16 12:39 - 2014-06-16 12:39 - 02818048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-06-16 12:39 - 2014-06-16 12:39 - 02366976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 02257608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2014-06-16 12:39 - 2014-06-16 12:39 - 02045440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 01634304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00419928 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-06-16 12:39 - 2014-06-16 12:39 - 00049544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-06-16 12:39 - 2014-06-16 12:39 - 00046512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2014-06-16 12:39 - 2014-06-16 12:39 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2014-06-16 12:39 - 2014-06-16 12:39 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2014-06-16 12:39 - 2013-08-22 10:17 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-06-16 12:39 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\SecureBootUpdates
2014-06-16 12:38 - 2014-06-16 12:38 - 18755672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 12711424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 05833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 05786968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 05774848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 05104640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 03563008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 03497472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 02144984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 02130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01309184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01210368 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01209616 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01200288 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01167360 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01159520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01089536 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 01029120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00834560 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00707048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00672256 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00669856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00629760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00518544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00482416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00406504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00387896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2014-06-16 12:38 - 2014-06-16 12:38 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00333656 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00328984 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00311128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00305768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00294744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00285144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00271192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00264704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00264536 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00240472 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00230808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00229344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00194752 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2014-06-16 12:38 - 2014-06-16 12:38 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00178184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00147800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00111528 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00098584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00080032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt_map.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00069632 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2014-06-16 12:38 - 2014-06-16 12:38 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\srclient.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\tlscsp.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00026784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt100.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll
2014-06-16 12:38 - 2014-06-16 12:38 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2014-06-16 12:38 - 2014-03-18 09:30 - 00000000 ____D () C:\WINDOWS\system32\Drivers\de-DE
2014-06-16 12:38 - 2013-08-22 10:17 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2014-06-16 12:37 - 2014-06-16 12:46 - 00000000 ___DC () C:\WINDOWS\Panther
2014-06-16 12:36 - 2014-06-16 12:36 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff
2014-06-16 12:34 - 2014-06-16 12:34 - 00001446 _____ () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-06-16 12:34 - 2014-06-16 12:34 - 00000020 ___SH () C:\Users\Natalie\ntuser.ini
2014-06-16 12:34 - 2014-06-16 12:34 - 00000000 ____D () C:\WINDOWS\system32\XPSViewer
2014-06-16 12:34 - 2014-06-16 12:34 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-06-16 12:18 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Windows NT
2014-06-16 12:18 - 2013-08-22 08:21 - 00000000 __RHD () C:\Users\Default
2014-06-16 12:17 - 2014-06-16 12:17 - 00021532 _____ () C:\WINDOWS\system32\emptyregdb.dat
2014-06-16 12:17 - 2014-06-16 11:59 - 00038103 _____ () C:\WINDOWS\diagwrn.xml
2014-06-16 12:17 - 2014-06-16 11:59 - 00038103 _____ () C:\WINDOWS\diagerr.xml
2014-06-16 12:17 - 2014-06-16 11:13 - 00006700 _____ () C:\WINDOWS\comsetup.log
2014-06-16 12:17 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\LogFiles
2014-06-16 12:17 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\Registration
2014-06-16 12:15 - 2013-08-22 10:17 - 00000000 __RSD () C:\WINDOWS\Media
2014-06-16 12:15 - 2013-08-22 10:17 - 00000000 __RHD () C:\Users\Public\Libraries
2014-06-16 12:15 - 2013-08-22 08:21 - 00000000 ___RD () C:\Users\Public
2014-06-16 12:12 - 2014-06-16 11:59 - 00000000 ____D () C:\Users\Gast
2014-06-16 12:10 - 2013-08-22 09:22 - 00477584 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-06-16 12:08 - 2014-06-16 12:34 - 00000000 ____D () C:\Program Files\MSBuild
2014-06-16 12:08 - 2014-06-16 12:01 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate
2014-06-16 12:08 - 2014-03-18 09:45 - 00000000 ____D () C:\WINDOWS\ShellNew
2014-06-16 12:08 - 2014-01-18 10:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-06-16 12:08 - 2014-01-17 08:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-06-16 12:08 - 2013-10-10 22:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-06-16 12:08 - 2013-08-29 19:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Müller Foto
2014-06-16 12:08 - 2013-07-24 20:06 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Suite
2014-06-16 12:08 - 2012-12-02 11:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2014-06-16 12:08 - 2012-12-02 11:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-06-16 12:08 - 2012-12-02 11:48 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-06-16 12:08 - 2012-12-02 11:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-06-16 12:08 - 2012-12-02 11:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-06-16 12:08 - 2012-12-02 11:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-06-16 12:08 - 2012-12-02 11:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2014-06-16 12:08 - 2012-12-02 11:45 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-06-16 12:08 - 2012-12-02 11:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-06-16 12:08 - 2012-12-02 11:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-06-16 12:08 - 2012-12-02 11:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView
2014-06-16 12:08 - 2012-12-02 11:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quadsoft NoTilesPlease
2014-06-16 12:07 - 2013-08-22 10:18 - 00004893 _____ () C:\WINDOWS\DtcInstall.log
2014-06-16 12:07 - 2012-07-26 06:43 - 00000000 ____D () C:\Users\Default.migrated
2014-06-16 12:06 - 2014-06-16 12:06 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-06-16 12:06 - 2014-03-18 09:30 - 00000000 ____D () C:\WINDOWS\system32\WCN
2014-06-16 12:06 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\WinBioPlugIns
2014-06-16 12:06 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\spool
2014-06-16 12:06 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\MUI
2014-06-16 12:06 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\IME
2014-06-16 12:06 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\de-DE
2014-06-16 12:05 - 2013-08-22 10:17 - 00000000 __SHD () C:\Program Files\Windows Sidebar
2014-06-16 12:05 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\Help
2014-06-16 12:05 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-06-16 12:05 - 2012-12-02 12:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2014-06-16 12:05 - 2012-12-01 23:12 - 00000000 ____D () C:\ProgramData\PRICache
2014-06-16 12:04 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Common Files\System
2014-06-16 12:04 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-16 12:01 - 2014-06-16 11:59 - 00000000 ___RD () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-16 12:01 - 2014-06-16 11:59 - 00000000 ___RD () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-06-16 12:01 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\Recovery
2014-06-16 12:00 - 2014-06-16 11:59 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-06-16 12:00 - 2014-06-16 11:59 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Startmenü
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Netzwerkumgebung
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Druckumgebung
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Documents\Eigene Musik
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Documents\Eigene Bilder
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\AppData\Local\Verlauf
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Startmenü
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Netzwerkumgebung
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Druckumgebung
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Musik
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Bilder
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Verlauf
2014-06-16 11:53 - 2014-06-16 12:33 - 00000000 ____D () C:\Recovery
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01000.Wdf
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 _____ () C:\WINDOWS\system32\atiicdxx.dat
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 _____ () C:\WINDOWS\ativpsrm.bin
2014-06-16 11:48 - 2014-06-16 11:48 - 00000000 ____D () C:\Program Files\Synaptics
2014-06-16 11:21 - 2012-12-01 23:03 - 01269679 _____ () C:\WINDOWS\WindowsUpdate (1).log
2014-06-16 11:19 - 2009-03-05 19:21 - 00008192 __RSH () C:\BOOTSECT.BAK
2014-06-16 10:49 - 2012-07-26 08:53 - 00000000 ____D () C:\WINDOWS\AUInstallAgent
2014-06-16 06:31 - 2013-08-19 20:55 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-06-16 06:29 - 2012-12-13 21:03 - 92708840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-06-08 21:27 - 2012-12-12 21:01 - 02784768 ___SH () C:\Users\Natalie\Desktop\Thumbs.db
2014-06-08 15:58 - 2014-06-08 15:42 - 00000000 ____D () C:\Program Files\JDownloader
2014-06-08 15:43 - 2014-06-08 15:43 - 00001943 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
2014-06-08 15:43 - 2014-06-08 15:43 - 00001932 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
2014-06-08 15:43 - 2014-06-08 15:43 - 00001866 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
2014-06-08 15:41 - 2014-06-08 15:41 - 00076456 _____ (AppWork GmbH) C:\Users\Natalie\Downloads\WebInstaller.exe
Files to move or delete:
====================
C:\Users\Natalie\netscan.exe
Some content of TEMP:
====================
C:\Users\Natalie\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpydtue8.dll
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-03 19:57
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:01-07-2014
Ran by Natalie at 2014-07-04 16:28:34
Running from C:\Users\Natalie\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: AVG AntiVirus 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}
==================== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM\...\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
2007 Microsoft Office Suite Service Pack 3 (SP3) (Version: - Microsoft) Hidden
Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader XI - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{0592EF96-69D8-4E4B-9CC9-88F58EA86F01}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4716 - AVG Technologies)
AVG 2014 (Version: 14.0.3986 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4716 - AVG Technologies) Hidden
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.3868 - CDBurnerXP)
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
EPSON SX235 Series Printer Uninstall (HKLM\...\EPSON SX235 Series) (Version: - SEIKO EPSON Corporation)
Google Earth (HKLM\...\{3E8A20E1-223F-11E2-9116-B8AC6F98CCE3}) (Version: 7.0.1.8244 - Google)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.35 - Irfan Skiljan)
iTunes (HKLM\...\{E05D82D8-FE70-4228-B073-B0C07FE27595}) (Version: 11.1.1.11 - Apple Inc.)
Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
K-Lite Codec Pack 9.5.5 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 9.5.5 - )
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x86__8wekyb3d8bbwe (x86) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional 2007 (HKLM\...\PROR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.10411.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 30.0 (x86 de) (HKLM\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Müller Foto (HKLM\...\Müller Foto) (Version: 5.0.4 - CEWE COLOR AG u Co. OHG)
Notepad++ (HKLM\...\Notepad++) (Version: 6.2.2 - )
NoTilesPlease Version 1.0.4.3 (HKLM\...\{DCBDAEAB-6AE9-42CC-92A6-9E2E31792FD4}_is1) (Version: 1.0.4.3 - Quadsoft)
Nur Entfernen der CopyTrans Suite möglich (HKCU\...\CopyTrans Suite) (Version: 2.37 - WindSolutions)
Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41417}) (Version: 3.61.0 - dotPDN LLC)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.6.0 - Frank Heindörfer, Philip Chinery)
Skype™ 6.0 (HKLM\...\{1845470B-EB14-4ABC-835B-E36C693DC07D}) (Version: 6.0.126 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 9.1.13.0 - Synaptics)
TeamViewer 7 (HKLM\...\TeamViewer 7) (Version: 7.0.15723 - TeamViewer)
VAIO Energie Verwaltung (HKLM\...\{5F5867F0-2D23-4338-A206-01A76C823924}) (Version: 3.3.0.12190 - Sony Corporation)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.4 (HKLM\...\VLC media player) (Version: 2.0.4 - VideoLAN)
WinRAR 4.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
==================== Restore Points =========================
17-06-2014 17:46:20 Removed Samsung Kies
24-06-2014 13:08:24 Windows Update
24-06-2014 13:09:59 Windows Modules Installer
02-07-2014 20:00:33 Installed AVG 2014
02-07-2014 20:01:32 Installed AVG 2014
==================== Hosts content: ==========================
2013-08-22 08:13 - 2013-08-22 08:13 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {00BC77BF-3352-4FE8-9617-4F1B27BEC19A} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {01BCC00A-C6A8-474C-BA2D-3076F3CE544D} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\WINDOWS\system32\cleanmgr.exe [2014-03-18] (Microsoft Corporation)
Task: {02B97B27-29F3-4F0D-B9D9-1A218C58AD6F} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {03F00483-DFF0-469F-88A0-E7C9E3D9F4A7} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {17233BE9-87E9-40B0-B003-AE9D2B92CBBE} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {247BD142-0549-4E91-84B0-172C25563718} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {2BE65564-89D1-4396-A5CC-D7D9283FC4A1} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {392EB017-207C-42BF-A061-F3BE721F456C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {4B7EF56A-8A42-4BD2-BB5C-7C389AC54A37} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {5700ACE8-D0AF-4BA7-98B6-1033521A877A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {6E84A59B-1863-4B21-8BD8-C9B20FD15484} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {7276DEEA-6ED2-4091-AF19-079E9B8C56C7} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {7C7CF1DA-F461-4850-96B2-ADCA8A67E59C} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {8B5819AE-7B44-478B-A3D3-8846AF160A8F} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {92ED6570-4654-4BFA-9A6C-1084C6939C16} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {997C8BBD-710B-4E66-B5BC-CC09575A58D2} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {9CEE4DCC-1FE8-4B69-A843-9B17C48332AE} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-06-16] (Microsoft Corporation)
Task: {A5D45ED3-F524-4574-8F39-527F3729D1E2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\WINDOWS\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {A8734EF2-F2EB-418C-83A5-1F82BE3C83B8} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated)
Task: {BFA82644-4CCF-4E7B-AFB6-10A75D2E3720} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {C0D0F7C4-419F-41B3-90A2-FE79270B828A} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {CF5A1DDC-D14D-4D59-AD49-A19A645B087B} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DCF55BED-B1DF-4ABF-8D85-6542C7007799} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {E4C8774A-2818-45A4-8A6D-11DDF6348886} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {F3B2EE7D-84A7-4DB4-ADBF-AFF5946E84A3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {F89ED03A-029C-4D8E-9B6D-868369BA6354} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {FAB49829-3EE7-4234-BE84-277862F2A57C} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2013-09-13 19:51 - 2013-09-13 19:51 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-09-13 19:51 - 2013-09-13 19:51 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-07-04 16:26 - 2014-07-04 16:26 - 00043008 _____ () c:\users\natalie\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpydtue8.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Natalie\AppData\Roaming\Dropbox\bin\libcef.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\Natalie\OneDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
HKCU\...\StartupApproved\Run: => "Pokki"
==================== Faulty Device Manager Devices =============
Name: Basissystemgerät
Description: Basissystemgerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/03/2014 06:18:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012298
ID des fehlerhaften Prozesses: 0x7e4
Startzeit der fehlerhaften Anwendung: 0xv87lo16c.exe0
Pfad der fehlerhaften Anwendung: v87lo16c.exe1
Pfad des fehlerhaften Moduls: v87lo16c.exe2
Berichtskennung: v87lo16c.exe3
Vollständiger Name des fehlerhaften Pakets: v87lo16c.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: v87lo16c.exe5
Error: (07/03/2014 06:06:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012298
ID des fehlerhaften Prozesses: 0xebc
Startzeit der fehlerhaften Anwendung: 0xv87lo16c.exe0
Pfad der fehlerhaften Anwendung: v87lo16c.exe1
Pfad des fehlerhaften Moduls: v87lo16c.exe2
Berichtskennung: v87lo16c.exe3
Vollständiger Name des fehlerhaften Pakets: v87lo16c.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: v87lo16c.exe5
Error: (07/03/2014 06:02:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012298
ID des fehlerhaften Prozesses: 0xf7c
Startzeit der fehlerhaften Anwendung: 0xv87lo16c.exe0
Pfad der fehlerhaften Anwendung: v87lo16c.exe1
Pfad des fehlerhaften Moduls: v87lo16c.exe2
Berichtskennung: v87lo16c.exe3
Vollständiger Name des fehlerhaften Pakets: v87lo16c.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: v87lo16c.exe5
Error: (07/03/2014 05:46:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 43109313
Error: (07/03/2014 05:46:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 43109313
Error: (07/03/2014 05:46:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (07/03/2014 05:46:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 17480265
Error: (07/03/2014 05:46:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 17480265
Error: (07/03/2014 05:46:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (07/02/2014 10:52:58 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm LiveComm.exe, Version 17.5.9600.20498 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 7fc
Startzeit: 01cf9636e3ef83b9
Endzeit: 4294967295
Anwendungspfad: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe
Berichts-ID: d764a3d9-022a-11e4-afce-001dbaea63f2
Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ppleae38af2e007f4358a809ac99a64a67c1
System errors:
=============
Error: (07/03/2014 08:24:15 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (07/03/2014 06:54:08 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (07/03/2014 06:18:32 PM) (Source: DCOM) (EventID: 10005) (User: SCHNADDL)
Description: 1084WSearchNicht verfügbar{9E175B68-F52A-11D8-B9A5-505054503030}
Error: (07/03/2014 06:18:31 PM) (Source: DCOM) (EventID: 10005) (User: SCHNADDL)
Description: 1084ShellHWDetectionNicht verfügbar{DD522ACC-F821-461A-A407-50B198B896DC}
Error: (07/03/2014 06:17:50 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" ist vom Dienst "DHCP-Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (07/03/2014 06:17:50 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" ist vom Dienst "DHCP-Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (07/03/2014 06:17:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" ist vom Dienst "DHCP-Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (07/03/2014 06:17:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" ist vom Dienst "DHCP-Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (07/03/2014 06:17:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" ist vom Dienst "DHCP-Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (07/03/2014 06:17:25 PM) (Source: DCOM) (EventID: 10005) (User: SCHNADDL)
Description: 1084ShellHWDetectionNicht verfügbar{DD522ACC-F821-461A-A407-50B198B896DC}
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2014-07-02 21:55:48.018
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-07-02 21:55:47.987
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-07-02 21:55:47.940
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-07-02 21:55:47.893
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-07-02 21:55:47.815
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-07-02 21:55:47.753
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-07-02 21:55:47.690
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-07-02 21:55:47.659
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-07-02 21:55:47.581
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-07-02 21:55:47.503
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Percentage of memory in use: 27%
Total physical RAM: 3039.04 MB
Available physical RAM: 2196.07 MB
Total Pagefile: 3551.04 MB
Available Pagefile: 2693.45 MB
Total Virtual: 2047.88 MB
Available Virtual: 1904.98 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:288.22 GB) (Free:199.01 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: 6C473DE3)
Partition 1: (Not Active) - (Size=10 GB) - (Type=27)
Partition 2: (Active) - (Size=288 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |