GMER Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-02-19 09:34:52
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000060 TOSHIBA_ rev.AM00 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Chin\AppData\Local\Temp\kwldqpog.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2772] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000075d88791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2772] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076221465 2 bytes [22, 76]
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2772] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762214bb 2 bytes [22, 76]
.text ... * 2
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2484] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000076221465 2 bytes [22, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2484] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000762214bb 2 bytes [22, 76]
.text ... * 2
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\acb57d00fd20
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\acb57d00fd20 (not active ControlSet)
---- EOF - GMER 2.1 ---- OTL Code:
OTL logfile created on: 19.02.2015 08:53:00 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Chin\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17633)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
6,95 Gb Total Physical Memory | 4,77 Gb Available Physical Memory | 68,64% Memory free
13,90 Gb Paging File | 11,19 Gb Available in Paging File | 80,51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 262,84 Gb Total Space | 98,21 Gb Free Space | 37,36% Space Free | Partition Type: NTFS
Drive H: | 101,26 Gb Total Space | 89,71 Gb Free Space | 88,59% Space Free | Partition Type: NTFS
Drive L: | 101,56 Gb Total Space | 101,35 Gb Free Space | 99,79% Space Free | Partition Type: NTFS
Computer Name: CHIN-LP | User Name: Chin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2015.02.19 08:52:42 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Chin\Downloads\otl.exe
PRC - [2015.02.04 10:02:55 | 000,843,592 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2015.01.27 19:55:31 | 005,227,112 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\avastui.exe
PRC - [2015.01.22 14:11:36 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe
PRC - [2014.12.19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014.06.27 11:52:26 | 002,088,408 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2014.06.24 10:42:12 | 004,101,576 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2014.06.24 10:41:42 | 001,738,168 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2014.04.25 14:12:20 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
========== Modules (No Company Name) ==========
MOD - [2015.02.04 10:02:51 | 009,170,760 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\pdf.dll
MOD - [2015.02.04 10:02:47 | 001,117,512 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\libglesv2.dll
MOD - [2015.02.04 10:02:45 | 000,211,272 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\libegl.dll
MOD - [2015.02.01 12:17:28 | 000,039,200 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
MOD - [2015.01.22 14:11:36 | 038,562,088 | ---- | M] () -- C:\Programme\AVAST Software\Avast\libcef.dll
MOD - [2014.05.24 17:41:24 | 000,892,416 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\libstdc++-6.dll
MOD - [2014.05.24 17:41:24 | 000,091,648 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\libgcc_s_sjlj-1.dll
MOD - [2014.05.13 12:04:48 | 000,167,768 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
MOD - [2014.05.13 12:04:46 | 000,109,400 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2014.05.13 12:04:42 | 000,416,600 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
========== Services (SafeList) ==========
SRV:64bit: - [2015.01.12 03:34:30 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014.11.21 03:12:40 | 000,244,736 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2014.11.12 00:06:52 | 002,449,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe -- (ClickToRunSvc)
SRV - [2015.01.23 23:33:44 | 000,834,752 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2015.01.22 14:11:36 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2015.01.22 14:11:33 | 004,012,248 | ---- | M] (Avast Software) [On_Demand | Running] -- C:\Programme\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe -- (AvastVBoxSvc)
SRV - [2015.01.09 22:45:26 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014.12.19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014.12.13 01:50:38 | 005,132,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2014.04.11 23:08:08 | 000,103,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2014.03.20 23:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014.02.25 22:17:38 | 000,319,104 | ---- | M] (Windows (R) Win 7 DDK provider) [Auto | Running] -- C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe -- (AtherosSvc)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2015.01.23 08:31:47 | 001,050,432 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:64bit: - [2015.01.22 14:11:37 | 000,436,624 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2015.01.22 14:11:37 | 000,267,632 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2015.01.22 14:11:37 | 000,116,728 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2015.01.22 14:11:37 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2015.01.22 14:11:37 | 000,083,280 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2015.01.22 14:11:37 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2015.01.22 14:11:37 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2014.11.21 03:41:36 | 000,294,600 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\amdacpksd.sys -- (amdacpksd)
DRV:64bit: - [2014.11.21 03:40:00 | 018,959,360 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2014.11.21 03:08:54 | 000,589,312 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2014.10.28 14:24:52 | 000,229,056 | ---- | M] (AppEx Networks Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\appexDrv.sys -- (APXACC)
DRV:64bit: - [2014.10.28 00:46:12 | 000,062,152 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdkmpfd.sys -- (amdkmpfd)
DRV:64bit: - [2014.09.23 18:56:58 | 000,083,656 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2014.09.23 18:56:58 | 000,043,720 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2014.06.21 18:01:22 | 000,094,720 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2014.02.25 21:53:00 | 000,597,192 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2014.02.25 21:53:00 | 000,338,120 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2014.02.25 21:53:00 | 000,179,432 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2014.02.25 21:53:00 | 000,137,928 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2014.02.25 21:53:00 | 000,116,424 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:64bit: - [2014.02.25 21:53:00 | 000,089,800 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2014.02.25 21:53:00 | 000,077,464 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2014.02.25 21:53:00 | 000,035,016 | ---- | M] (Qualcomm Atheros) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2014.02.21 00:49:14 | 004,044,800 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2014.02.16 17:23:54 | 000,060,640 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2014.01.14 07:17:20 | 000,466,136 | R--- | M] (Realsil Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPer.sys -- (RTSPER)
DRV:64bit: - [2013.12.18 04:34:38 | 000,888,536 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2013.10.02 03:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013.05.28 09:09:38 | 000,227,648 | ---- | M] (Advanced Micro Devices, INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdxhc.sys -- (amdxhc)
DRV:64bit: - [2013.05.28 09:09:38 | 000,106,816 | ---- | M] (Advanced Micro Devices, INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdhub30.sys -- (amdhub30)
DRV:64bit: - [2012.08.23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2015.01.22 14:11:33 | 000,271,752 | ---- | M] (Avast Software) [Kernel | Auto | Running] -- C:\Programme\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys -- (VBoxAswDrv)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.isUS: false
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:35.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2015.01.28 06:52:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2015.01.22 16:57:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chin\AppData\Roaming\mozilla\Extensions
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Widevine Content Decryption Module (Enabled) = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.758\_platform_specific\win_x86\widevinecdmadapter.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\internal-nacl-plugin
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office 2013 (Enabled) = C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
CHR - plugin: Microsoft Office 2013 (Enabled) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.10_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\clhhggbfdinjmjhajaheehoeibfljjno\0.4.0_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkfhfaphfkopdgpbfkebjfcblcafcmpi\13.6_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme\4.2.1_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fepbnnnkkadjhjahcafoaglimekefifl\2.15.2_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\iooicodkiihhpojmmeghjclgihfjdjhj\10.5.1.8_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd\2015.120.1719.1_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn\2015.1.27.2_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ompiailgknfdndiefoaoiligalphfdae\2.6.8_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\6.3_0\
CHR - Extension: No name found = C:\Users\Chin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (no name) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - No CLSID value found.
O2:64bit: - BHO: (no name) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - No CLSID value found.
O2:64bit: - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (no name) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - No CLSID value found.
O2 - BHO: (no name) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - No CLSID value found.
O2 - BHO: (no name) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - No CLSID value found.
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [Raptr] C:\Program Files (x86)\Raptr\raptrstub.exe (Raptr, Inc)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [AppEx Accelerator UI] C:\Program Files\AMD Quick Stream\AMDQuickStream.exe (AppEx Networks Corporation)
O4 - HKCU..\Run: [ownCloud] H:\ownCloud-programm\owncloud.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: BtvStack = "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe" (Atheros Communications)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - Reg Error: Key error. File not found
O9:64bit: - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - Reg Error: Key error. File not found
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{558B2D36-464B-4563-A132-078D59DF9DC0}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7AD4139E-C256-49B9-8F93-856DF49D335A}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\osf - No CLSID value found
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Programme\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Programme\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Programme\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{018f8c7e-a236-11e4-9cc9-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{018f8c7e-a236-11e4-9cc9-806e6f6e6963}\Shell\AutoRun\command - "" = D:\wubi.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2015.02.18 19:56:39 | 000,129,752 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015.02.18 19:56:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2015.02.18 19:56:24 | 000,093,400 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2015.02.18 19:56:24 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2015.02.18 19:56:24 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2015.02.18 19:56:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2015.02.18 19:56:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015.02.17 12:30:28 | 000,000,000 | R--D | C] -- C:\Users\Chin\Dropbox
[2015.02.17 12:29:16 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2015.02.17 12:26:50 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Dropbox
[2015.02.12 12:11:38 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2015.02.12 12:11:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla FTP Client
[2015.02.12 08:50:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2015.02.12 08:50:39 | 000,021,040 | ---- | C] (Safer Networking Limited) -- C:\Windows\SysNative\sdnclean64.exe
[2015.02.12 08:50:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2015.02.12 08:50:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2015.02.11 22:03:59 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\CrashDumps
[2015.02.11 12:51:00 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\calibre-cache
[2015.02.11 12:43:27 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\calibre
[2015.02.11 12:42:33 | 000,000,000 | ---D | C] -- C:\Program Files\Calibre2
[2015.02.11 12:42:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management
[2015.02.08 14:54:09 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Bluetooth Folder
[2015.02.07 19:46:12 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\vlc
[2015.02.03 11:53:07 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Telekom
[2015.02.01 18:17:33 | 000,000,000 | ---D | C] -- C:\Users\Chin\Desktop\franzstrich.de
[2015.01.28 12:55:30 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\Diagnostics
[2015.01.27 18:07:51 | 000,000,000 | ---D | C] -- C:\Users\Chin\owncloud
[2015.01.27 18:02:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ownCloud
[2015.01.27 00:32:02 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\FileZilla
[2015.01.26 19:50:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Writer
[2015.01.26 19:50:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ImageWriter
[2015.01.26 14:54:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Gibraltar
[2015.01.26 14:50:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2015.01.26 14:50:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2015.01.26 14:39:10 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Benutzerdefinierte Office-Vorlagen
[2015.01.26 13:30:30 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\Swiss Academic Software
[2015.01.26 13:10:25 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Zimmermann
[2015.01.26 13:10:06 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Zeitschriften
[2015.01.26 13:10:05 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Wohnung
[2015.01.26 13:10:05 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Weihnachtsfeier Psychos 2011
[2015.01.26 13:10:05 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Wahlen
[2015.01.26 13:10:05 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Wachstumsökonomie
[2015.01.26 13:10:05 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\VPV-Versicherung
[2015.01.26 13:10:04 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Vortrag Projektmanagement
[2015.01.26 13:10:02 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Volition
[2015.01.26 13:10:00 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Versicherung Schadensfall Hunde
[2015.01.26 13:09:42 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Two Worlds Saves
[2015.01.26 13:09:42 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Trainingsplan
[2015.01.26 13:09:42 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Tattoo
[2015.01.26 13:09:42 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Tagung Nürnberg
[2015.01.26 13:09:42 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\StudIp
[2015.01.26 13:09:41 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Square Enix
[2015.01.26 13:09:41 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\SPSSInc
[2015.01.26 13:09:28 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Software Download
[2015.01.26 13:09:28 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Simpol
[2015.01.26 13:09:01 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\self-html
[2015.01.26 13:09:01 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Schadensfall Post
[2015.01.26 13:09:01 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Runes of Magic
[2015.01.26 13:09:00 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\route
[2015.01.26 13:08:57 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\rom
[2015.01.26 13:08:57 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Rentenversicherung
[2015.01.26 13:08:56 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Pronto-Pizza
[2015.01.26 13:08:56 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Praktikumsbericht
[2015.01.26 13:08:55 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Praktikum Psychatrie
[2015.01.26 13:08:55 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Praktikum
[2015.01.26 13:08:53 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Praktikum BW
[2015.01.26 13:08:53 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\postbank
[2015.01.26 13:08:53 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\PersBackup
[2015.01.26 13:08:51 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\pebl-exp.0.11
[2015.01.26 13:07:34 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Outlook-Dateien
[2015.01.26 13:07:31 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\OpenOffice.org 3.3 (de) Installation Files
[2015.01.26 13:07:30 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\OneNote-Notizbücher
[2015.01.26 13:07:30 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\oma tele
[2015.01.26 13:07:30 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Nexus Mod Manager
[2015.01.26 13:07:17 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\My Digital Editions
[2015.01.26 13:07:17 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Mietvertrag Lessingstr. 20
[2015.01.26 13:07:17 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Microsoft office Rechnung
[2015.01.26 13:07:17 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\michael
[2015.01.26 13:07:17 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Meine Datenquellen
[2015.01.26 13:07:13 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Loge
[2015.01.26 13:06:54 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\League of Legends
[2015.01.26 13:06:54 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Kündigung McFit
[2015.01.26 13:06:54 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Kündigung LaFamilia
[2015.01.26 13:06:54 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Kindergeld
[2015.01.26 13:06:54 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Karten
[2015.01.26 13:06:54 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\kalender
[2015.01.26 13:06:53 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Integrales Forum
[2015.01.26 13:06:53 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\HUK
[2015.01.26 13:06:53 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\HTML
[2015.01.26 13:06:53 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\font
[2015.01.26 13:06:53 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Fahrraddiebstahl Tabea
[2015.01.26 13:05:44 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Exes
[2015.01.26 13:05:30 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Evernote
[2015.01.26 13:05:19 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Erasmus
[2015.01.26 13:05:18 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\DVDVideoSoft
[2015.01.26 13:05:13 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\DIE SIEDLER - DEdK
[2015.01.26 13:05:13 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Deutschland Stipendium
[2015.01.26 13:05:13 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\DayZ
[2015.01.26 13:05:13 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Criterion Games
[2015.01.26 13:05:12 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\cleverfit halle
[2015.01.26 13:04:54 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\CCleaner
[2015.01.26 13:02:04 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Calibre-Springer
[2015.01.26 13:01:01 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Calibre-Bibliothek
[2015.01.26 13:00:56 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Bund Überbleibsel
[2015.01.26 13:00:56 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Bücherliste
[2015.01.26 13:00:39 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Bücher
[2015.01.26 13:00:39 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Briefe
[2015.01.26 13:00:38 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\BlackBerry
[2015.01.26 13:00:38 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\BKK
[2015.01.26 13:00:37 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Bewerbungsunterlagen generell
[2015.01.26 13:00:37 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Bewerbung Praktikum Bundeswehr Königsbrück
[2015.01.26 13:00:37 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Bewerbung Master
[2015.01.26 13:00:37 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Bewerbung Klinik Bernbrug
[2015.01.26 13:00:37 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Beschäftigung Bib Brandbergweg
[2015.01.26 13:00:37 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Befragung Offshore
[2015.01.26 13:00:35 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Bayreuth
[2015.01.26 13:00:35 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Banished
[2015.01.26 13:00:34 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Bafög
[2015.01.26 13:00:34 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Backups
[2015.01.26 13:00:05 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Artikel
[2015.01.26 13:00:05 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\ADAC
[2015.01.26 12:56:30 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Swiss Academic Software
[2015.01.26 12:56:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Swiss Academic Software
[2015.01.26 12:56:30 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\Citavi 4
[2015.01.26 12:43:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citavi 4
[2015.01.26 12:42:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Citavi 4
[2015.01.26 12:40:32 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\Downloaded Installations
[2015.01.24 09:19:18 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\EFSoftware
[2015.01.24 09:14:04 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2015.01.24 08:57:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Total Commander
[2015.01.24 08:56:04 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\Adobe
[2015.01.24 08:53:04 | 000,000,000 | ---D | C] -- C:\Users\Chin\.spss
[2015.01.24 08:53:03 | 000,000,000 | ---D | C] -- C:\Users\Chin\Application Data
[2015.01.24 08:53:00 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\javasharedresources
[2015.01.24 08:49:42 | 000,000,000 | ---D | C] -- C:\ProgramData\SafeNet Sentinel
[2015.01.24 08:49:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\IBM
[2015.01.24 08:49:11 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Zero G Registry
[2015.01.24 08:49:10 | 000,000,000 | -H-D | C] -- C:\Users\Chin\InstallAnywhere
[2015.01.24 08:48:32 | 000,000,000 | ---D | C] -- C:\ProgramData\SPSS
[2015.01.24 08:48:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IBM SPSS Statistics
[2015.01.24 08:47:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\IBM
[2015.01.24 08:47:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IBM
[2015.01.23 18:13:08 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\BigHugeEngine
[2015.01.23 13:03:05 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\My Games
[2015.01.23 11:41:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2015.01.23 11:41:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2015.01.23 11:29:41 | 000,000,000 | -HSD | C] -- C:\Users\Chin\AppData\Local\EmieUserList
[2015.01.23 11:29:41 | 000,000,000 | -HSD | C] -- C:\Users\Chin\AppData\Local\EmieSiteList
[2015.01.23 11:29:41 | 000,000,000 | -HSD | C] -- C:\Users\Chin\AppData\Local\EmieBrowserModeList
[2015.01.23 11:10:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved
[2015.01.23 11:10:00 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\library_dir
[2015.01.23 11:08:26 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Raptr
[2015.01.23 11:08:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Raptr
[2015.01.23 11:08:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Quick Stream
[2015.01.23 11:08:09 | 000,000,000 | ---D | C] -- C:\Program Files\AMD Quick Stream
[2015.01.23 09:31:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2015.01.23 09:09:50 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1991-06.com.microsoft
[2015.01.23 09:09:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2015.01.23 09:03:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
[2015.01.23 09:00:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office 15
[2015.01.22 23:10:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2015.01.22 23:06:00 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2015.01.22 22:16:55 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\KeePass
[2015.01.22 22:08:10 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\KeePass
[2015.01.22 22:00:01 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps
[2015.01.22 21:36:30 | 000,000,000 | ---D | C] -- C:\Users\Chin\Documents\keepass save
[2015.01.22 21:10:15 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\BMExplorer
[2015.01.22 21:09:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Atheros
[2015.01.22 21:09:41 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Atheros
[2015.01.22 21:09:27 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Adobe
[2015.01.22 20:29:55 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2015.01.22 20:27:41 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2015.01.22 20:26:11 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2015.01.22 20:25:12 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2015.01.22 18:24:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Atheros
[2015.01.22 18:23:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\QCA_Bluetooth
[2015.01.22 18:23:26 | 000,000,000 | ---D | C] -- C:\ProgramData\{EB5F5A55-037A-4E47-806B-2C8AA9374701}
[2015.01.22 18:22:05 | 004,044,800 | ---- | C] (Qualcomm Atheros Communications, Inc.) -- C:\Windows\SysNative\drivers\athrx.sys
[2015.01.22 18:22:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Qualcomm Atheros
[2015.01.22 18:19:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Qualcomm Atheros
[2015.01.22 17:13:12 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Thunderbird
[2015.01.22 17:13:12 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\Thunderbird
[2015.01.22 17:12:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2015.01.22 17:12:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2015.01.22 17:12:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2015.01.22 17:10:08 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2015.01.22 17:09:44 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[2015.01.22 17:08:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2015.01.22 17:08:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2015.01.22 17:08:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2015.01.22 17:06:27 | 000,116,224 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll
[2015.01.22 17:05:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KeePass Password Safe 2
[2015.01.22 17:05:53 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll
[2015.01.22 17:04:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2015.01.22 16:57:03 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Mozilla
[2015.01.22 16:57:03 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\Mozilla
[2015.01.22 15:08:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2015.01.22 15:08:55 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2015.01.22 14:33:48 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
[2015.01.22 14:12:44 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\AVAST Software
[2015.01.22 14:12:42 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\vbox
[2015.01.22 14:12:42 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\vbox
[2015.01.22 14:12:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2015.01.22 14:11:55 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\Google
[2015.01.22 14:11:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2015.01.22 14:11:41 | 001,050,432 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsnx.sys
[2015.01.22 14:11:41 | 000,436,624 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2015.01.22 14:11:41 | 000,116,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2015.01.22 14:11:41 | 000,093,568 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2015.01.22 14:11:41 | 000,083,280 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2015.01.22 14:11:40 | 000,364,512 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2015.01.22 14:11:37 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2015.01.22 14:11:16 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2015.01.22 14:08:57 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2015.01.22 14:06:23 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\sda
[2015.01.22 14:06:08 | 000,466,136 | R--- | C] (Realsil Semiconductor Corporation) -- C:\Windows\SysNative\drivers\RtsPer.sys
[2015.01.22 14:01:50 | 000,888,536 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys
[2015.01.22 14:01:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2015.01.22 14:01:39 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2015.01.22 13:55:20 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2015.01.22 13:50:39 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\ATI
[2015.01.22 13:50:39 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\ATI
[2015.01.22 13:50:39 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2015.01.22 13:50:28 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\AppEx Networks
[2015.01.22 13:48:51 | 000,229,056 | ---- | C] (AppEx Networks Corporation) -- C:\Windows\SysNative\drivers\appexDrv.sys
[2015.01.22 13:48:51 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\Programs
[2015.01.22 13:48:50 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2015.01.22 13:48:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2015.01.22 13:48:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2015.01.22 13:48:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
[2015.01.22 13:46:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2015.01.22 13:46:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD
[2015.01.22 13:44:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2015.01.22 13:43:19 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2015.01.22 13:43:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2015.01.22 13:42:57 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2015.01.22 13:41:56 | 000,000,000 | ---D | C] -- C:\AMD
[2015.01.22 13:37:25 | 000,000,000 | R--D | C] -- C:\Users\Chin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2015.01.22 13:37:25 | 000,000,000 | R--D | C] -- C:\Users\Chin\Searches
[2015.01.22 13:37:25 | 000,000,000 | R--D | C] -- C:\Users\Chin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2015.01.22 13:37:12 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Identities
[2015.01.22 13:37:09 | 000,000,000 | R--D | C] -- C:\Users\Chin\Contacts
[2015.01.22 13:37:07 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\VirtualStore
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Vorlagen
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\AppData\Local\Verlauf
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\AppData\Local\Temporary Internet Files
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Startmenü
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\SendTo
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Recent
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Netzwerkumgebung
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Lokale Einstellungen
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Documents\Eigene Videos
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Documents\Eigene Musik
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Eigene Dateien
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Documents\Eigene Bilder
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Druckumgebung
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Cookies
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\AppData\Local\Anwendungsdaten
[2015.01.22 13:36:56 | 000,000,000 | -HSD | C] -- C:\Users\Chin\Anwendungsdaten
[2015.01.22 13:36:55 | 000,000,000 | --SD | C] -- C:\Users\Chin\AppData\Roaming\Microsoft
[2015.01.22 13:36:55 | 000,000,000 | R--D | C] -- C:\Users\Chin\Videos
[2015.01.22 13:36:55 | 000,000,000 | R--D | C] -- C:\Users\Chin\Saved Games
[2015.01.22 13:36:55 | 000,000,000 | R--D | C] -- C:\Users\Chin\Pictures
[2015.01.22 13:36:55 | 000,000,000 | R--D | C] -- C:\Users\Chin\Music
[2015.01.22 13:36:55 | 000,000,000 | R--D | C] -- C:\Users\Chin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2015.01.22 13:36:55 | 000,000,000 | R--D | C] -- C:\Users\Chin\Links
[2015.01.22 13:36:55 | 000,000,000 | R--D | C] -- C:\Users\Chin\Favorites
[2015.01.22 13:36:55 | 000,000,000 | R--D | C] -- C:\Users\Chin\Downloads
[2015.01.22 13:36:55 | 000,000,000 | R--D | C] -- C:\Users\Chin\Documents
[2015.01.22 13:36:55 | 000,000,000 | R--D | C] -- C:\Users\Chin\Desktop
[2015.01.22 13:36:55 | 000,000,000 | R--D | C] -- C:\Users\Chin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2015.01.22 13:36:55 | 000,000,000 | -H-D | C] -- C:\Users\Chin\AppData
[2015.01.22 13:36:55 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\Temp
[2015.01.22 13:36:55 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Local\Microsoft
[2015.01.22 13:36:55 | 000,000,000 | ---D | C] -- C:\Users\Chin\AppData\Roaming\Media Center Programs
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\Recovery
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\Programme
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2015.01.22 13:36:46 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
========== Files - Modified Within 30 Days ==========
[2015.02.19 08:43:33 | 000,015,472 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015.02.19 08:43:33 | 000,015,472 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015.02.19 08:36:19 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015.02.19 08:35:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015.02.19 08:35:42 | 1303,138,303 | -HS- | M] () -- C:\hiberfil.sys
[2015.02.19 08:11:14 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\spu_storage.bin
[2015.02.19 07:58:05 | 001,619,284 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015.02.19 07:58:05 | 000,699,342 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2015.02.19 07:58:05 | 000,654,140 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015.02.19 07:58:05 | 000,149,450 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2015.02.19 07:58:05 | 000,122,012 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015.02.19 07:29:04 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015.02.18 19:57:04 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015.02.12 14:37:21 | 000,167,520 | ---- | M] () -- C:\Users\Chin\Desktop\JRSM Open-2014-McMurtry-.pdf
[2015.02.11 13:17:23 | 000,437,584 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2015.02.03 19:04:22 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2015.01.28 13:26:41 | 000,000,600 | ---- | M] () -- C:\Users\Chin\AppData\Local\PUTTY.RND
[2015.01.24 08:46:54 | 000,001,025 | ---- | M] () -- C:\Windows\SysWow64\sysprs7.tgz
[2015.01.24 08:46:54 | 000,001,025 | ---- | M] () -- C:\Windows\SysWow64\sysprs7.dll
[2015.01.24 08:46:54 | 000,000,219 | ---- | M] () -- C:\Windows\SysWow64\lsprst7.tgz
[2015.01.24 08:46:54 | 000,000,205 | ---- | M] () -- C:\Windows\SysWow64\lsprst7.dll
[2015.01.24 08:46:54 | 000,000,016 | -H-- | M] () -- C:\Windows\SysWow64\servdat.slm
[2015.01.23 18:21:36 | 001,593,564 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2015.01.23 08:31:47 | 001,050,432 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsnx.sys
[2015.01.22 20:32:12 | 000,056,735 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2015.01.22 20:32:12 | 000,056,735 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2015.01.22 19:56:29 | 000,016,284 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2015.01.22 19:56:26 | 000,016,284 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2015.01.22 18:25:35 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf
[2015.01.22 18:16:49 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2015.01.22 14:11:37 | 000,436,624 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2015.01.22 14:11:37 | 000,364,512 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2015.01.22 14:11:37 | 000,267,632 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2015.01.22 14:11:37 | 000,116,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2015.01.22 14:11:37 | 000,093,568 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2015.01.22 14:11:37 | 000,083,280 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2015.01.22 14:11:37 | 000,065,776 | ---- | M] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2015.01.22 14:11:37 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2015.01.22 14:11:37 | 000,029,208 | ---- | M] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2015.01.22 13:49:57 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
========== Files Created - No Company Name ==========
[2015.02.12 14:37:20 | 000,167,520 | ---- | C] () -- C:\Users\Chin\Desktop\JRSM Open-2014-McMurtry-.pdf
[2015.02.12 08:50:47 | 000,001,395 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2015.02.03 19:04:22 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2015.01.27 18:03:29 | 000,000,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ownCloud.lnk
[2015.01.26 23:07:27 | 000,000,600 | ---- | C] () -- C:\Users\Chin\AppData\Local\PUTTY.RND
[2015.01.26 13:10:02 | 000,408,046 | ---- | C] () -- C:\Users\Chin\Documents\V-Kg5-Einkuenfte.pdf
[2015.01.26 13:10:01 | 041,307,085 | R--- | C] () -- C:\Users\Chin\Documents\VirtualCD 8.0.0.2 + Keyg.rar
[2015.01.26 13:10:01 | 000,357,459 | ---- | C] () -- C:\Users\Chin\Documents\V-Kg1-Antrag.pdf
[2015.01.26 13:10:01 | 000,028,260 | ---- | C] () -- C:\Users\Chin\Documents\Versicherungsbestätigung.pdf
[2015.01.26 13:10:00 | 000,040,893 | ---- | C] () -- C:\Users\Chin\Documents\Unbenannt.wma
[2015.01.26 13:09:43 | 1028,653,056 | ---- | C] () -- C:\Users\Chin\Documents\ubuntu-14.04.1-desktop-amd64.iso
[2015.01.26 13:09:42 | 000,063,567 | ---- | C] () -- C:\Users\Chin\Documents\studip.ics
[2015.01.26 13:08:57 | 000,195,738 | ---- | C] () -- C:\Users\Chin\Documents\retour best secret.pdf
[2015.01.26 13:08:53 | 001,335,612 | ---- | C] () -- C:\Users\Chin\Documents\perso.odg
[2015.01.26 13:08:53 | 000,256,510 | ---- | C] () -- C:\Users\Chin\Documents\Perso.pdf
[2015.01.26 13:08:53 | 000,063,691 | ---- | C] () -- C:\Users\Chin\Documents\Postbank Überweisung Katleen Müller.pdf
[2015.01.26 13:08:50 | 005,303,303 | ---- | C] () -- C:\Users\Chin\Documents\papa kindergeld.odg
[2015.01.26 13:08:50 | 002,332,652 | ---- | C] () -- C:\Users\Chin\Documents\papa kindergeld.pdf
[2015.01.26 13:07:30 | 000,164,508 | ---- | C] () -- C:\Users\Chin\Documents\Notenspiegel 051013.pdf
[2015.01.26 13:07:17 | 000,117,623 | ---- | C] () -- C:\Users\Chin\Documents\Modulschein Franz Strich.pdf
[2015.01.26 13:07:13 | 000,072,837 | ---- | C] () -- C:\Users\Chin\Documents\Lebenslauf 1.0 ohne Bild 072612.pdf
[2015.01.26 13:06:54 | 000,011,956 | ---- | C] () -- C:\Users\Chin\Documents\Kündigung Wohnung.odt
[2015.01.26 13:06:53 | 009,123,877 | ---- | C] () -- C:\Users\Chin\Documents\Fit ohne Geräte_ Trainieren mit dem eigenen Körpergewicht - Clark, Joshua.epub
[2015.01.26 13:06:53 | 000,055,445 | ---- | C] () -- C:\Users\Chin\Documents\Imma WiSe 20142015_neu.pdf
[2015.01.26 13:06:53 | 000,055,439 | ---- | C] () -- C:\Users\Chin\Documents\Imma WiSe 20142015.pdf
[2015.01.26 13:06:53 | 000,055,438 | ---- | C] () -- C:\Users\Chin\Documents\Imma SoSe 2014 (2).pdf
[2015.01.26 13:06:53 | 000,042,933 | ---- | C] () -- C:\Users\Chin\Documents\Imma WiSe 20122013.pdf
[2015.01.26 13:06:53 | 000,042,932 | ---- | C] () -- C:\Users\Chin\Documents\Imma WiSe 20122013 (2).pdf
[2015.01.26 13:06:53 | 000,042,816 | ---- | C] () -- C:\Users\Chin\Documents\Imma WiSe 20132014_Master.pdf
[2015.01.26 13:06:53 | 000,042,748 | ---- | C] () -- C:\Users\Chin\Documents\Imma WiSe 20132014.pdf
[2015.01.26 13:06:53 | 000,042,743 | ---- | C] () -- C:\Users\Chin\Documents\Imma SoSe 2014.pdf
[2015.01.26 13:06:53 | 000,042,743 | ---- | C] () -- C:\Users\Chin\Documents\Imma SoSe 2013_02.pdf
[2015.01.26 13:06:53 | 000,042,743 | ---- | C] () -- C:\Users\Chin\Documents\Imma SoSe 2013.pdf
[2015.01.26 13:06:53 | 000,042,696 | ---- | C] () -- C:\Users\Chin\Documents\Imma SoSe 02062012.pdf
[2015.01.26 13:06:53 | 000,042,692 | ---- | C] () -- C:\Users\Chin\Documents\Imma WiSe 20112012.pdf
[2015.01.26 13:06:53 | 000,035,588 | ---- | C] () -- C:\Users\Chin\Documents\Fahrplan 7 Kröllwitz - Fiete-Schulz-Straße.pdf
[2015.01.26 13:06:52 | 000,021,932 | ---- | C] () -- C:\Users\Chin\Documents\Fahrplan 5 Steintor - Kröllwitz.pdf
[2015.01.26 13:05:19 | 993,792,096 | ---- | C] () -- C:\Users\Chin\Documents\EsPeEsEs 21.zip
[2015.01.26 13:05:19 | 000,970,871 | ---- | C] () -- C:\Users\Chin\Documents\Einkünfte.pdf
[2015.01.26 13:05:12 | 000,000,143 | ---- | C] () -- C:\Users\Chin\Documents\Click Here to Pre-Order Red Alert 3.url
[2015.01.26 13:00:37 | 000,275,447 | ---- | C] () -- C:\Users\Chin\Documents\BA-Zeugnis.pdf
[2015.01.26 13:00:37 | 000,081,045 | ---- | C] () -- C:\Users\Chin\Documents\best secret Rechnung 201011.pdf
[2015.01.26 13:00:05 | 002,583,170 | ---- | C] () -- C:\Users\Chin\Documents\20140501_084147.jpg
[2015.01.26 13:00:05 | 001,567,313 | ---- | C] () -- C:\Users\Chin\Documents\20140501_084116.jpg
[2015.01.26 13:00:05 | 000,087,749 | ---- | C] () -- C:\Users\Chin\Documents\Amazon.de - Rücksendezentrum.pdf
[2015.01.26 13:00:05 | 000,015,504 | ---- | C] () -- C:\Users\Chin\Documents\anschreiben 901011.odt
[2015.01.26 13:00:05 | 000,012,606 | ---- | C] () -- C:\Users\Chin\Documents\101814.kdbx
[2015.01.26 13:00:05 | 000,012,014 | ---- | C] () -- C:\Users\Chin\Documents\092014.kdbx
[2015.01.24 08:46:54 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.tgz
[2015.01.24 08:46:54 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2015.01.24 08:46:54 | 000,000,219 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.tgz
[2015.01.24 08:46:54 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll
[2015.01.24 08:46:54 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\servdat.slm
[2015.01.23 11:42:18 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2015.01.22 22:49:32 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2015.01.22 20:32:01 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2015.01.22 20:31:56 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2015.01.22 20:26:52 | 1303,138,303 | -HS- | C] () -- C:\hiberfil.sys
[2015.01.22 19:56:29 | 000,016,284 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2015.01.22 19:56:26 | 000,016,284 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2015.01.22 18:25:35 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf
[2015.01.22 18:16:49 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2015.01.22 18:16:33 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2015.01.22 17:12:08 | 000,002,102 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2015.01.22 17:07:43 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd
[2015.01.22 17:05:57 | 000,001,121 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk
[2015.01.22 17:05:27 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml
[2015.01.22 17:05:01 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml
[2015.01.22 17:05:01 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml
[2015.01.22 17:03:18 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml
[2015.01.22 16:59:02 | 000,001,110 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015.01.22 16:59:01 | 000,001,106 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015.01.22 14:11:41 | 000,267,632 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2015.01.22 14:11:41 | 000,065,776 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2015.01.22 14:11:41 | 000,029,208 | ---- | C] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2015.01.22 13:49:57 | 000,065,536 | ---- | C] () -- C:\Windows\SysNative\spu_storage.bin
[2015.01.22 13:49:57 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2015.01.22 13:45:52 | 001,593,564 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2015.01.22 13:37:27 | 000,001,413 | ---- | C] () -- C:\Users\Chin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014.11.21 03:35:54 | 000,073,216 | ---- | C] () -- C:\Windows\SysWow64\hsaumd.dll
[2014.11.21 03:35:42 | 001,947,136 | ---- | C] () -- C:\Windows\SysWow64\hsaservices.dll
[2014.11.21 03:34:56 | 000,392,192 | ---- | C] () -- C:\Windows\SysWow64\newhsacore.dll
[2014.11.21 03:33:08 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2014.11.21 03:33:08 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2014.11.21 03:16:24 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2014.11.21 03:16:24 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2014.11.20 21:35:00 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014.06.25 03:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014.06.25 02:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2015.01.22 14:12:44 | 000,000,000 | ---D | M] -- C:\Users\Chin\AppData\Roaming\AVAST Software
[2015.02.11 12:59:06 | 000,000,000 | ---D | M] -- C:\Users\Chin\AppData\Roaming\calibre
[2015.02.19 07:11:38 | 000,000,000 | ---D | M] -- C:\Users\Chin\AppData\Roaming\Dropbox
[2015.01.24 09:19:18 | 000,000,000 | ---D | M] -- C:\Users\Chin\AppData\Roaming\EFSoftware
[2015.02.12 17:35:11 | 000,000,000 | ---D | M] -- C:\Users\Chin\AppData\Roaming\FileZilla
[2015.02.18 19:54:28 | 000,000,000 | ---D | M] -- C:\Users\Chin\AppData\Roaming\KeePass
[2015.01.23 11:10:00 | 000,000,000 | ---D | M] -- C:\Users\Chin\AppData\Roaming\library_dir
[2015.02.19 08:05:11 | 000,000,000 | ---D | M] -- C:\Users\Chin\AppData\Roaming\Raptr
[2015.02.09 17:47:31 | 000,000,000 | ---D | M] -- C:\Users\Chin\AppData\Roaming\Swiss Academic Software
[2015.01.22 17:13:12 | 000,000,000 | ---D | M] -- C:\Users\Chin\AppData\Roaming\Thunderbird
========== Purity Check ==========
< End of report > Code:
OTL Extras logfile created on: 19.02.2015 08:53:00 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Chin\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17633)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
6,95 Gb Total Physical Memory | 4,77 Gb Available Physical Memory | 68,64% Memory free
13,90 Gb Paging File | 11,19 Gb Available in Paging File | 80,51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 262,84 Gb Total Space | 98,21 Gb Free Space | 37,36% Space Free | Partition Type: NTFS
Drive H: | 101,26 Gb Total Space | 89,71 Gb Free Space | 88,59% Space Free | Partition Type: NTFS
Drive L: | 101,56 Gb Total Space | 101,35 Gb Free Space | 99,79% Space Free | Partition Type: NTFS
Computer Name: CHIN-LP | User Name: Chin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{12709624-FE90-4E40-AA0B-2388C9312EE0}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\outlook.exe |
"{2816A60A-799E-4402-936F-DD3F99953C8B}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04053C63-9C9A-40E4-B73D-8F003F33C446}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\modlauncher.exe |
"{05BED579-482F-4A26-A712-087EDEFF5E8C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\koareckoning\reckoning.exe |
"{06E7B0F0-52FD-469D-8FFD-CA889C5C0701}" = protocol=6 | dir=in | app=c:\program files\microsoft office 15\root\office15\lync.exe |
"{09A8921D-765C-45A8-AE57-1FFB48D66307}" = protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\lync.exe |
"{0A68D474-386E-482A-8D7C-39D7011B7D2C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\modlauncher.exe |
"{0B58FFC7-79C2-41C4-8223-9765F0E47CA3}" = protocol=17 | dir=in | app=c:\users\chin\appdata\roaming\dropbox\bin\dropbox.exe |
"{5C9BBBE6-BE37-4BF0-9B13-E2DDC62E3D3A}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe |
"{636EFAB3-5803-4B39-B4FE-22DD60C87F60}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\banished\application-steam-x64.exe |
"{66409F19-931E-4383-8E64-2BEED35FD0A8}" = protocol=17 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{6B6771DC-D428-4361-A539-AED9CCDD3439}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{7C5A87D8-1AB6-4BA0-A5E9-F21634625C3A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\koareckoning\reckoning.exe |
"{7F753CF3-83EE-44A2-BF82-6336AAB91F86}" = protocol=17 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{8484278E-31E6-451E-92DA-8541108CD5C5}" = protocol=6 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{96CCDC50-580B-4F9F-80A9-503437C4D7F3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\banished\application-steam-x64.exe |
"{BC3A8499-B9F3-401F-B31A-A0C8B494C598}" = protocol=6 | dir=in | app=c:\users\chin\appdata\roaming\dropbox\bin\dropbox.exe |
"{C25DF78F-3F95-42A7-9A61-AE83FF503208}" = protocol=6 | dir=in | app=c:\program files\microsoft office 15\root\office15\ucmapi.exe |
"{D257544E-E7DE-40FF-BE2B-EB12F8A862E7}" = protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\ucmapi.exe |
"{D2E27B6B-1A24-4638-B3C0-419FDB44E4ED}" = protocol=6 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{D35BCB63-8FB7-40F8-A204-F5E1F033FBF7}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe |
"{D76F3D0E-458F-491B-86C0-4E3877C9FD9C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe |
"{DBD767B3-A10D-49D5-B7FD-25F9479A0E3C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{EBD0B0E5-1C68-4CAC-979D-60AAF5EB2626}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe |
"{F399F7FD-B73D-48D9-A722-BD99D821E1DA}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr.exe |
"{F76BEC88-0BD7-4AFE-A1F8-AFA5277F2E19}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr.exe |
"TCP Query User{1D1138C7-F3E3-43CB-8D74-D3B9C161C17B}C:\program files (x86)\ibm\spss\statistics\19\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ibm\spss\statistics\19\jre\bin\javaw.exe |
"TCP Query User{3F0FD984-32CA-414D-8701-168C15038B3B}C:\program files (x86)\ibm\spss\statistics\19\stats.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ibm\spss\statistics\19\stats.exe |
"TCP Query User{4A54B8C3-D910-476D-8898-CFBA9444F99D}C:\users\chin\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\chin\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{655FBA66-F425-463E-AB6C-2B4C9B7CBDB3}C:\program files (x86)\ibm\spss\statistics\19\stats.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ibm\spss\statistics\19\stats.exe |
"TCP Query User{84F83C38-5D51-4ACA-84E8-1566624420B8}C:\program files (x86)\ibm\spss\statistics\19\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ibm\spss\statistics\19\jre\bin\javaw.exe |
"TCP Query User{906F101D-EAE5-44AC-91C3-4F49907FE2BB}C:\program files (x86)\total commander\totalcmd.exe" = protocol=6 | dir=in | app=c:\program files (x86)\total commander\totalcmd.exe |
"UDP Query User{4D5F4DED-11B5-4745-B58C-1D1A393B9B5F}C:\program files (x86)\ibm\spss\statistics\19\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ibm\spss\statistics\19\jre\bin\javaw.exe |
"UDP Query User{58B6EC9B-E915-4BFE-B924-D874588C0B64}C:\program files (x86)\ibm\spss\statistics\19\stats.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ibm\spss\statistics\19\stats.exe |
"UDP Query User{6869BAE7-9887-4A3E-8915-5D52599CAD9A}C:\program files (x86)\ibm\spss\statistics\19\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ibm\spss\statistics\19\jre\bin\javaw.exe |
"UDP Query User{894CFEB3-5509-4E98-9952-98F3CBB1A8BC}C:\users\chin\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\chin\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{89BB6768-155B-42A5-BFC0-8C24441ABE87}C:\program files (x86)\ibm\spss\statistics\19\stats.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ibm\spss\statistics\19\stats.exe |
"UDP Query User{E46A867C-F7D5-4DF4-841C-406E28C1A7C9}C:\program files (x86)\total commander\totalcmd.exe" = protocol=17 | dir=in | app=c:\program files (x86)\total commander\totalcmd.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1DB0C90B-2A9F-3A1E-B1DF-616C5A2A1417}" = Microsoft .NET Framework 4.5.2 (DEU)
"{26784146-6E05-3FF9-9335-786C7C0FB5BE}" = Microsoft .NET Framework 4.5.2
"{2C637DB1-3E0A-4089-8366-C6C0B01E5C2B}" = AMD Steady Video Plug-In
"{426582A8-202F-D13C-8BD5-F00551BAFC93}" = AMD Wireless Display v3.0
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8F2415FA-72F2-F029-0450-4EB2FAE484C5}" = AMD Accelerated Video Transcoding
"{90150000-008F-0000-1000-0000000FF1CE}" = Office 15 Click-to-Run Licensing Component
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031" = Microsoft .NET Framework 4.5.2 (Deutsch)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.2
"{994A15FB-0FA3-455E-8161-A558C7BC4A73}" = calibre 64bit
"{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64)
"{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727
"{D5A2E1F8-66E3-FBB5-7F83-78D7EFE0E347}" = ACP Application
"{DBAFD1B4-DDC5-DD01-D1C4-E7AEB5139097}" = AMD Fuel
"{E9EED4AE-682B-4501-9574-D09A21717599}_is1" = AMD Quick Stream
"{F2A7CE36-57BF-5C86-952D-90DBF3746D82}" = AMD Catalyst Install Manager
"{F6BF49D7-479E-23FE-A8A9-63D193D05697}" = AMD Drag and Drop Transcoding
"{F7FE0989-5F4C-3499-B78F-A63E942D100B}" = ccc-utility64
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.71.1
"ProPlusRetail - de-de" = Microsoft Office Professional Plus 2013 - de-de
"VLC media player" = VLC media player
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06C43FAA-7226-41EF-A05E-9AE0AA849FFE}" = IBM SPSS Statistics 19
"{0FE3F13F-8A37-46BA-F973-762F81E833C3}" = CCC Help French
"{11087D24-567D-7D88-69C6-D7A08B5F4C47}" = Catalyst Control Center - Branding
"{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
"{1543E140-FADF-9E99-D388-4435C2FBC55E}" = CCC Help Chinese Standard
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros WLAN and Bluetooth Client Installation Program
"{2C9A2369-162D-7AD7-D50F-5F59CEC8A046}" = CCC Help Danish
"{2D61415B-F99C-8161-F452-760B6E441428}" = CCC Help Hungarian
"{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727
"{339647D6-A277-974F-FF29-83CA6284559B}" = CCC Help German
"{4BD8FB0D-9407-429D-C412-FAE0A318A8AE}" = CCC Help Polish
"{4D594F78-0C6D-1442-61CC-94D735FEC05D}" = CCC Help English
"{5958C669-28BF-D667-A004-E6FBF448027D}" = CCC Help Spanish
"{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}" = Realtek Card Reader
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{637B1239-84B7-0B0F-2549-7020CA57C831}" = CCC Help Thai
"{6AE0A655-9BB8-460E-1956-ED37E3B221FA}" = CCC Help Greek
"{6B254D2F-6F6F-5455-DD3B-E71E5C1C0C9A}" = AMD Catalyst Control Center
"{7481E13B-EC16-1B14-0E32-E88165CD4C57}" = Catalyst Control Center Graphics Previews Common
"{7ABA4B54-3672-0548-C1CC-97405F767061}" = CCC Help Russian
"{7f51bdb9-ee21-49ee-94d6-90afc321780e}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
"{7FE73251-50FA-E864-67EB-19C4BC7AA1C9}" = CCC Help Portuguese
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{894CBED0-8225-D59B-5632-D01B14C6D520}" = CCC Help Norwegian
"{8BD7C51C-0CC4-3E28-CFDC-F7D4C5583783}" = CCC Help Finnish
"{8ECCC07B-83E3-3877-26DF-815CD2B30749}" = CCC Help Italian
"{900FD4B9-9C27-D907-36E7-E9CCF170E2FC}" = Catalyst Control Center InstallProxy
"{90150000-008C-0000-0000-0000000FF1CE}" = Office 15 Click-to-Run Extensibility Component
"{90150000-008C-0407-0000-0000000FF1CE}" = Office 15 Click-to-Run Localization Component
"{988949CE-DE9A-D187-A010-22B9085FB813}" = CCC Help Swedish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A85092B2-8FB5-5A8C-B27A-69A3D78979D8}" = CCC Help Korean
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-0804-1033-1959-001802114130}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.10) - Deutsch
"{B1977E93-5FC0-0BA4-2D5A-D3E69870C7D4}" = CCC Help Chinese Traditional
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{BBC9BF50-A35D-B0C2-9117-F3CA2F6BB64A}" = CCC Help Czech
"{CC0A85B2-734A-45B3-B678-05F6A6499AC7}" = Citavi 4
"{D074CE74-912A-4AD3-A0BF-3937D9D01F17}_is1" = Win32DiskImager version 0.9.5
"{D0FD2FF9-1BE9-E729-3878-9A603B5F1529}" = Catalyst Control Center Localization All
"{D94F2DE6-55B4-B211-A381-54089BC791A0}" = CCC Help Japanese
"{EEFDBD75-0BD9-AC5F-8F61-903C6A19C0ED}" = CCC Help Dutch
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FB415F81-DC5E-ED99-D2FE-3DC4D88BCA58}" = CCC Help Turkish
"{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Avast" = Avast Free Antivirus
"Google Chrome" = Google Chrome
"KeePassPasswordSafe2_is1" = KeePass Password Safe 2.28
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware Version 2.0.4.1028
"Mozilla Thunderbird 31.4.0 (x86 de)" = Mozilla Thunderbird 31.4.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Raptr" = Raptr
"Steam" = Steam
"Steam App 102500" = Kingdoms of Amalur: Reckoning™
"Steam App 200710" = Torchlight II
"Steam App 242920" = Banished
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"FileZilla Client" = FileZilla Client 3.10.1.1
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 27.01.2015 14:01:56 | Computer Name = Chin-LP | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
(x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack.dll". Fehler in Manifest- oder Richtliniendatei
"C:\Program Files (x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack.dll" in Zeile 19.
Der
Wert "6.0.0.6u9b41" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error - 27.01.2015 14:02:18 | Computer Name = Chin-LP | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\microsoft
office 15\root\office15\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei
"c:\program files\microsoft office 15\root\office15\UccApi.DLL" in Zeile 1. Die
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten
Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition:
UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0". Verwenden Sie
das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error - 29.01.2015 15:06:51 | Computer Name = Chin-LP | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
(x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack200.exe". Fehler in Manifest- oder Richtliniendatei
"C:\Program Files (x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack200.exe" in Zeile
19. Der Wert "6.0.0.6u9b41" des "version"-Attributs im assemblyIdentity-Element ist
ungültig.
Error - 29.01.2015 15:07:19 | Computer Name = Chin-LP | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
(x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack.dll". Fehler in Manifest- oder Richtliniendatei
"C:\Program Files (x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack.dll" in Zeile 19.
Der
Wert "6.0.0.6u9b41" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error - 29.01.2015 15:07:42 | Computer Name = Chin-LP | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\microsoft
office 15\root\office15\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei
"c:\program files\microsoft office 15\root\office15\UccApi.DLL" in Zeile 1. Die
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten
Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition:
UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0". Verwenden Sie
das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error - 03.02.2015 15:29:49 | Computer Name = Chin-LP | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: svchost.exe_SysMain, Version: 6.1.7600.16385,
Zeitstempel: 0x4a5bc3c1 Name des fehlerhaften Moduls: sysmain.dll, Version: 6.1.7601.17514,
Zeitstempel: 0x4ce7c9db Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000004f55
ID
des fehlerhaften Prozesses: 0x198 Startzeit der fehlerhaften Anwendung: 0x01d03f8f6c6cf007
Pfad
der fehlerhaften Anwendung: C:\Windows\System32\svchost.exe Pfad des fehlerhaften
Moduls: c:\windows\system32\sysmain.dll Berichtskennung: 04392488-abdb-11e4-8976-f0761c341ab8
Error - 11.02.2015 17:03:55 | Computer Name = Chin-LP | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: owncloud.exe, Version: 0.0.0.0, Zeitstempel:
0x5492c052 Name des fehlerhaften Moduls: libowncloudsync.dll, Version: 0.0.0.0,
Zeitstempel: 0x5492c037 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0007ab97 ID des fehlerhaften
Prozesses: 0xbe0 Startzeit der fehlerhaften Anwendung: 0x01d0463c6a40060c Pfad der
fehlerhaften Anwendung: H:\ownCloud-programm\owncloud.exe Pfad des fehlerhaften
Moduls: H:\ownCloud-programm\libowncloudsync.dll Berichtskennung: 7cf255dd-b231-11e4-9492-f0761c341ab8
Error - 14.02.2015 04:22:27 | Computer Name = Chin-LP | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
(x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack200.exe". Fehler in Manifest- oder Richtliniendatei
"C:\Program Files (x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack200.exe" in Zeile
19. Der Wert "6.0.0.6u9b41" des "version"-Attributs im assemblyIdentity-Element ist
ungültig.
Error - 14.02.2015 04:23:08 | Computer Name = Chin-LP | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
(x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack.dll". Fehler in Manifest- oder Richtliniendatei
"C:\Program Files (x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack.dll" in Zeile 19.
Der
Wert "6.0.0.6u9b41" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error - 14.02.2015 04:23:43 | Computer Name = Chin-LP | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files\microsoft
office 15\root\office15\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei
"c:\program files\microsoft office 15\root\office15\UccApi.DLL" in Zeile 1. Die
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten
Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition:
UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0". Verwenden Sie
das Programm "sxstrace.exe" für eine detaillierte Diagnose.
[ System Events ]
Error - 19.02.2015 02:10:18 | Computer Name = Chin-LP | Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert: 48. Der interne Fehlerstatus
lautet: 552.
Error - 19.02.2015 02:10:18 | Computer Name = Chin-LP | Source = Schannel | ID = 36882
Description = Das vom Remoteserver erhaltene Zertifikat wurde von einer nicht vertrauenswürdigen
Zertifizierungsstelle ausgestellt. Aus diesem Grund können keine der im Zertifikat
enthalten Daten verifiziert werden. Fehler bei der SSL-Verbindungsanforderung.
Die angehängten Daten enthalten das Serverzertifikat.
Error - 19.02.2015 02:10:19 | Computer Name = Chin-LP | Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert: 48. Der interne Fehlerstatus
lautet: 552.
Error - 19.02.2015 02:10:19 | Computer Name = Chin-LP | Source = Schannel | ID = 36882
Description = Das vom Remoteserver erhaltene Zertifikat wurde von einer nicht vertrauenswürdigen
Zertifizierungsstelle ausgestellt. Aus diesem Grund können keine der im Zertifikat
enthalten Daten verifiziert werden. Fehler bei der SSL-Verbindungsanforderung.
Die angehängten Daten enthalten das Serverzertifikat.
Error - 19.02.2015 03:03:43 | Computer Name = Chin-LP | Source = DCOM | ID = 10010
Description =
Error - 19.02.2015 03:05:00 | Computer Name = Chin-LP | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
Spybot-S&D 2 Scanner Service erreicht.
Error - 19.02.2015 03:05:00 | Computer Name = Chin-LP | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden
Fehlers nicht gestartet: %%1053
Error - 19.02.2015 03:11:00 | Computer Name = Chin-LP | Source = DCOM | ID = 10010
Description =
Error - 19.02.2015 03:36:25 | Computer Name = Chin-LP | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
Spybot-S&D 2 Scanner Service erreicht.
Error - 19.02.2015 03:36:25 | Computer Name = Chin-LP | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden
Fehlers nicht gestartet: %%1053
< End of report > MWB Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 19.02.2015
Scan Time: 09:48:48
Logfile: MWB.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.19.04
Rootkit Database: v2015.02.03.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Chin
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 328710
Time Elapsed: 16 min, 32 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 1
PUP.Optional.Downloader, C:\$Recycle.Bin\S-1-5-21-2240681411-2449356942-1176590736-1000\$R8MARW8.exe, , [371945dbdeac979f408bf230a55de719],
Physical Sectors: 0
(No malicious items detected)
(end) Vielen Dank schonmal für Eure Hilfe. Vielleicht bin ich auch überängstlich, aber ich mache mir einfach Sorgen. |