ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=1670bf6537fb8c41a3a4417d7732d1f6
# engine=18576
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-06-05 04:59:05
# local_time=2014-06-05 06:59:05 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 6083113 73277567 0 0
# scanned=133162
# found=10
# cleaned=10
# scan_time=4305
sh=FA399A74E1D037E836E0E386AF8FE62C1E14D0D9 ft=1 fh=c6b5d98ab23f6683 vn="Win32/FileTypeAssistant.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\File Type Assistant\ftacfg.exe.vir"
sh=AB9A1E20050206A9E4EA3FB7B3C3B9368A8229AF ft=1 fh=574e1d79c18cb087 vn="Variante von Win32/FileTypeAssistant.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\File Type Assistant\TSASetup.exe.vir"
sh=CDFC725B11EEF83C9E35834231F4A70D1D5CB556 ft=1 fh=89f5b5d673baa91f vn="Variante von Win32/FileTypeAssistant.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\File Type Assistant\tsassist.exe.vir"
sh=9ABE489AF3684ABB96AB39F112768F69C83D0F8E ft=1 fh=f7fcd12f54d4e5cc vn="Variante von Win32/SpeedingUpMyPC Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptimizerPro.exe.vir"
sh=1375A8FFF1D262AD65AB09311A91AA9B96E83049 ft=1 fh=72898e0453db9d6a vn="Variante von Win32/SProtector.F evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll.vir"
sh=9F8E488CB68193DABA2E820964EB6BB5B0053BA0 ft=1 fh=5c179f4fc04177a8 vn="Variante von Win64/SProtector.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll.vir"
sh=2F367F244D08950211E4C05FB8EF8E0959BB773A ft=1 fh=20d3e0bbdedcd685 vn="Variante von Win32/AdWare.SpeedingUpMyPC.D Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProLauncher.exe.vir"
sh=AF6978F4185769EEB2798D0CF841A12E1FB8FCB9 ft=0 fh=0000000000000000 vn="JS/Adware.Yontoo.B Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\TK\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\background.html.vir"
sh=5B257B972389986407AE0C0868B52A0EC9376FCB ft=0 fh=0000000000000000 vn="JS/Adware.Yontoo.A Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\TK\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\yl.js.vir"
sh=C91F661BB83D587396B820BA14A0873202FAC0EF ft=1 fh=fa4ef13fc6a0f9db vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\TK\AppData\Local\Temp\nsq7CDD.tmp\Helper.dll"
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=1670bf6537fb8c41a3a4417d7732d1f6
# engine=18723
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-06-15 12:29:07
# local_time=2014-06-15 02:29:07 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 6930915 74125369 0 0
# scanned=131310
# found=6
# cleaned=0
# scan_time=11919
sh=EE0EE8CADC9CDB1BDBF44C8F23972B4553AA0436 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Yontoo\YontooLayers.crx.vir"
sh=71435DDB11E00D0243380C4902324853FE4ECE8F ft=1 fh=12b0cd2dde452d65 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\Users\TK\AppData\Local\Temp\AskSLib.dll"
sh=8A84355FDB33B94E1957EC44F2BC98A807E9A5D4 ft=0 fh=0000000000000000 vn="Variante von Java/Exploit.Agent.PGU Trojaner" ac=I fn="C:\Users\TK\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\6ac31ff1-4fec58b4"
sh=51543215D077E7B8E440F03D285A7C2644E7BFF6 ft=0 fh=0000000000000000 vn="Variante von Java/Exploit.Agent.OYF Trojaner" ac=I fn="C:\Users\TK\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\2a929c08-6c0913aa"
sh=D4F8DDBF278811EFFEBE691410064478D967A72F ft=1 fh=ca3ea310eac2be83 vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\TK\Downloads\pal_install_r101b431.exe"
sh=2BAFCA2C5FD0A10E40FFFB74A25F39652D3646E2 ft=1 fh=7fb814fd3cd07ea5 vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\Users\TK\Downloads\pal_install_r132028.exe"
Results of screen317's Security Check version 0.99.83
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Trojan Remover 6.9.1.2931
Java(TM) 6 Update 20
Java 7 Update 9
Java version out of Date!
Adobe Flash Player 13.0.0.182
Adobe Reader XI
Mozilla Firefox (29.0.1)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-06-2014 02
Ran by TK (administrator) on TK-TOSH on 15-06-2014 14:42:17
Running from C:\Users\TK\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Ritlabs S.R.L.) C:\Program Files (x86)\The Bat!\thebat.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Farbar) C:\Users\TK\Downloads\FRST64(2).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [onlinebrief24-ebdhelper] => C:\Program Files (x86)\onlinebrief24.de\ebdhelper.exe [692224 2012-11-27] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKU\.DEFAULT\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PalTalk.lnk
ShortcutTarget: PalTalk.lnk -> C:\Program Files (x86)\Paltalk Messenger\paltalk.exe (AVM Software Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\TK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PalTalk.lnk
ShortcutTarget: PalTalk.lnk -> C:\Program Files (x86)\Paltalk Messenger\paltalk.exe (AVM Software Inc.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: No Name - {BA425B9D-0611-A015-02D4-58859F6CF49A} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\TK\AppData\Roaming\Mozilla\Firefox\Profiles\d09fueku.default-1397059975359
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\gcswf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.200.2) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U20) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll No File
CHR Plugin: (Chrome NaCl) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (WildTangent Games App Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll No File
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (SoftCouuep) - C:\Users\TK\AppData\Local\Google\Chrome\User Data\Default\Extensions\gofhncoagghbfmbendcamcbekllpjmcb [2014-04-22]
CHR Extension: (Google Wallet) - C:\Users\TK\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
S4 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [102400 2013-08-08] () [File not signed]
S4 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1809920 2010-08-04] (Realsil Microelectronics Inc.) [File not signed]
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
S4 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH)
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-09] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-15 14:40 - 2014-06-15 14:40 - 02081792 _____ (Farbar) C:\Users\TK\Downloads\FRST64(2).exe
2014-06-15 11:13 - 2014-06-15 11:13 - 00001084 _____ () C:\Users\Public\Desktop\FastStone Photo Resizer.lnk
2014-06-15 11:13 - 2014-06-15 11:13 - 00000000 ____D () C:\Users\TK\AppData\Roaming\FastStone
2014-06-15 11:13 - 2014-06-15 11:13 - 00000000 ____D () C:\Users\TK\AppData\Local\FastStone
2014-06-15 11:13 - 2014-06-15 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Photo Resizer
2014-06-15 11:12 - 2014-06-15 11:13 - 00000000 ____D () C:\Program Files (x86)\FastStone Photo Resizer
2014-06-15 11:12 - 2014-06-15 11:12 - 01522679 _____ () C:\Users\TK\Downloads\FSResizerSetup32.exe
2014-06-15 11:07 - 2014-06-15 11:07 - 02347384 _____ (ESET) C:\Users\TK\Downloads\esetsmartinstaller_deu(1).exe
2014-06-15 11:07 - 2014-06-15 11:07 - 00854367 _____ () C:\Users\TK\Desktop\SecurityCheck.exe
2014-06-13 21:36 - 2014-06-13 21:36 - 00000000 ____D () C:\Windows\Paltalk Messenger
2014-06-13 21:35 - 2014-06-13 21:35 - 23649688 _____ () C:\Users\TK\Downloads\pal_install_r101b431.exe
2014-06-12 15:21 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-12 15:21 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-12 15:21 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-12 15:21 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-12 15:21 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-12 15:21 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-12 15:21 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-12 15:21 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-12 15:21 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-12 15:21 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-12 15:21 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-12 15:21 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-12 15:21 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-12 15:21 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-12 15:21 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-12 15:21 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-12 15:21 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-12 15:21 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-12 15:21 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 15:21 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-12 15:21 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-12 15:21 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-12 15:21 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-12 15:21 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-12 15:21 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-12 15:21 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-12 15:21 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-12 15:21 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-12 15:21 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-12 15:21 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-12 15:21 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-12 15:21 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-12 15:21 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-12 15:21 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-12 15:21 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-12 15:21 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-12 15:21 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-12 15:21 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-12 15:21 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-12 15:21 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-12 15:21 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-12 15:21 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-12 15:21 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-12 15:21 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-12 15:21 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-12 15:21 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-12 15:21 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-12 15:21 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-12 15:21 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-12 15:21 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-12 15:21 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-12 15:21 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-12 15:21 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 15:21 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-12 15:21 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 15:21 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 15:21 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 15:21 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 15:21 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-12 15:21 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-12 15:21 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-12 15:21 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-12 15:21 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-12 15:21 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-12 15:20 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-12 15:20 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-12 13:26 - 2014-06-12 13:26 - 00100457 _____ () C:\Users\TK\Downloads\Jenz Forus 171 Cat. schredder brech anlage 2005 Walzenbrecher gebraucht Verkauf (zuidwolde _ Niederlande) - MachineryPark.com.htm
2014-06-12 13:26 - 2014-06-12 13:26 - 00000000 ____D () C:\Users\TK\Downloads\Jenz Forus 171 Cat. schredder brech anlage 2005 Walzenbrecher gebraucht Verkauf (zuidwolde _ Niederlande) - MachineryPark.com-Dateien
2014-06-12 12:35 - 2014-06-12 12:35 - 00052105 _____ () C:\Users\TK\Desktop\o2.odt
2014-06-12 11:53 - 2014-06-12 11:53 - 00000000 _____ () C:\Users\TK\Desktop\Neues Textdokument.txt
2014-06-11 22:49 - 2014-06-11 22:50 - 00000000 ____D () C:\Users\TK\Desktop\Neuer Ordner (2)
2014-06-11 21:46 - 2014-06-11 21:46 - 02081792 _____ (Farbar) C:\Users\TK\Downloads\FRST64(1).exe
2014-06-11 17:34 - 2014-06-11 17:35 - 00000000 ____D () C:\Users\TK\Desktop\sq
2014-06-11 16:35 - 2014-06-11 16:49 - 00001482 _____ () C:\Users\TK\Desktop\giliiii.txt
2014-06-10 15:23 - 2014-06-10 15:23 - 00000000 ____D () C:\Users\TK\Desktop\Neuer Ordner
2014-06-09 15:50 - 2014-06-09 15:50 - 00004138 _____ () C:\Users\TK\Desktop\JRT.txt
2014-06-09 15:46 - 2014-06-09 15:46 - 00001581 _____ () C:\Users\TK\Desktop\AdwCleanedas.txt
2014-06-09 15:27 - 2014-06-09 15:27 - 01333465 _____ () C:\Users\TK\Downloads\adwcleaner_3.212.exe
2014-06-09 15:26 - 2014-06-09 15:26 - 01016261 _____ (Thisisu) C:\Users\TK\Downloads\JRT(2).exe
2014-06-09 15:26 - 2014-06-09 15:26 - 01016261 _____ (Thisisu) C:\Users\TK\Desktop\JRT(3).exe
2014-06-08 16:44 - 2014-06-08 16:44 - 00001150 _____ () C:\Users\TK\Desktop\malware.txt
2014-06-08 13:38 - 2014-06-09 22:49 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-08 13:38 - 2014-06-08 13:38 - 00001069 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-08 13:38 - 2014-06-08 13:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-08 13:37 - 2014-06-08 13:37 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\TK\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-08 13:37 - 2014-06-08 13:37 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-08 13:37 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-08 13:37 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-08 13:31 - 2014-06-08 13:31 - 00070968 _____ () C:\Users\TK\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-08 13:30 - 2014-06-09 15:32 - 00005600 _____ () C:\Windows\PFRO.log
2014-06-08 13:30 - 2014-06-08 13:31 - 00326280 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-08 01:55 - 2014-06-15 00:21 - 00001120 _____ () C:\Windows\setupact.log
2014-06-08 01:55 - 2014-06-08 01:55 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-07 13:51 - 2014-06-13 21:36 - 00001924 _____ () C:\Users\TK\Desktop\Paltalk Messenger.lnk
2014-06-07 13:51 - 2014-06-13 21:36 - 00001120 _____ () C:\Users\TK\Desktop\Upgrade to Paltalk Extreme.lnk
2014-06-07 13:51 - 2014-06-13 21:36 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paltalk Messenger
2014-06-07 13:51 - 2014-06-08 02:09 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Paltalk
2014-06-07 13:50 - 2014-06-13 21:36 - 00000000 ____D () C:\Program Files (x86)\Paltalk Messenger
2014-06-07 13:50 - 2014-06-07 13:50 - 01589176 _____ (AVM Software Inc.) C:\Users\TK\Downloads\pal_install_r132028.exe
2014-06-07 02:41 - 2014-06-07 02:41 - 00018054 _____ () C:\Users\TK\Desktop\posten.txt
2014-06-07 02:36 - 2014-06-07 02:36 - 00018054 _____ () C:\ComboFix.txt
2014-06-07 02:36 - 2014-06-07 02:36 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-07 02:36 - 2014-06-07 02:36 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-07 02:36 - 2014-06-07 02:36 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-07 01:41 - 2014-06-07 01:41 - 05205146 ____R (Swearware) C:\Users\TK\Desktop\ComboFix.exe
2014-06-07 01:40 - 2014-06-07 01:40 - 05205146 _____ (Swearware) C:\Users\TK\Downloads\ComboFix(1).exe
2014-06-07 01:27 - 2014-06-07 01:27 - 00000000 ____D () C:\Users\TK\Downloads\FRST-OlderVersion
2014-06-07 01:25 - 2014-06-07 01:25 - 00001231 _____ () C:\Users\TK\Desktop\Revo Uninstaller.lnk
2014-06-07 01:25 - 2014-06-07 01:25 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-07 01:24 - 2014-06-07 01:24 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\TK\Downloads\revosetup95.exe
2014-06-05 20:46 - 2014-06-05 20:46 - 00000225 _____ () C:\Users\TK\Desktop\laender.txt
2014-06-05 20:40 - 2014-06-05 20:40 - 00033236 _____ () C:\Users\TK\Downloads\Addition.txt
2014-06-05 20:35 - 2014-06-15 14:42 - 00009464 _____ () C:\Users\TK\Downloads\FRST.txt
2014-06-05 20:35 - 2014-06-15 14:42 - 00000000 ____D () C:\FRST
2014-06-05 20:34 - 2014-06-07 01:27 - 02072576 _____ (Farbar) C:\Users\TK\Downloads\FRST64.exe
2014-06-05 17:44 - 2014-06-05 17:44 - 02347384 _____ (ESET) C:\Users\TK\Downloads\esetsmartinstaller_deu.exe
2014-06-05 17:24 - 2014-06-05 17:24 - 01327971 _____ () C:\Users\TK\Downloads\adwcleaner_3.211(2).exe
2014-06-05 17:23 - 2014-06-05 17:23 - 01327971 _____ () C:\Users\TK\Downloads\adwcleaner_3.211(1).exe
2014-06-05 17:21 - 2014-06-05 17:21 - 01016261 _____ (Thisisu) C:\Users\TK\Downloads\JRT_6.1.4.exe
2014-06-05 16:55 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-05 16:55 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-05 16:55 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-05 16:55 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-05 16:55 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-05 16:55 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-05 16:55 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-05 16:55 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-05 16:54 - 2014-06-07 02:36 - 00000000 ____D () C:\Qoobox
2014-06-05 16:53 - 2014-06-07 02:33 - 00000000 ____D () C:\Windows\erdnt
2014-06-05 16:52 - 2014-06-05 16:53 - 05205146 ____R (Swearware) C:\Users\TK\Downloads\ComboFix.exe
2014-06-05 16:24 - 2014-06-05 16:24 - 00023896 _____ () C:\Users\TK\Desktop\atta.txt
2014-06-05 14:16 - 2014-06-05 14:16 - 00368256 _____ (RegNow.com) C:\Users\TK\Downloads\Download_MaxSDDMnew.exe
2014-06-05 12:15 - 2014-06-05 12:15 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\TK\Downloads\avira_de_av_4007782653__ws.exe
2014-06-05 12:05 - 2014-06-05 12:05 - 00000000 ____D () C:\Users\TK\Documents\ProcAlyzer Dumps
2014-06-05 11:56 - 2014-06-05 16:35 - 00000085 _____ () C:\Windows\wininit.ini
2014-06-05 11:55 - 2014-06-05 11:55 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\TK\Downloads\spybot-2.3(3).exe
2014-06-05 11:53 - 2014-06-05 11:54 - 46392681 _____ () C:\Users\TK\Downloads\spybot-2.3(2).exe
2014-06-05 01:15 - 2014-06-05 01:15 - 00000000 _____ () C:\Windows\system32\avgrep.txt
2014-06-05 01:03 - 2014-06-05 01:03 - 00000000 ____D () C:\Users\TK\AppData\Roaming\AVG2014
2014-06-05 01:00 - 2014-06-05 12:41 - 00000000 ____D () C:\ProgramData\AVG2014
2014-06-05 01:00 - 2014-06-05 12:23 - 00000000 ____D () C:\$AVG
2014-06-05 00:57 - 2014-06-05 12:41 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-05 00:57 - 2014-06-05 12:29 - 00000000 ____D () C:\Users\TK\AppData\Local\Avg2014
2014-06-05 00:57 - 2014-06-05 00:57 - 04487240 _____ (AVG Technologies) C:\Users\TK\Downloads\avg_isct_stb_all_2014_4592.exe
2014-06-05 00:57 - 2014-06-05 00:57 - 00000000 ____D () C:\Users\TK\AppData\Local\MFAData
2014-06-05 00:54 - 2014-06-05 00:54 - 00000000 ____D () C:\ProgramData\Licenses
2014-06-05 00:52 - 2014-06-05 00:52 - 00000000 ____D () C:\Users\TK\Documents\Simply Super Software
2014-06-05 00:52 - 2014-06-05 00:52 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Simply Super Software
2014-06-05 00:51 - 2014-06-05 00:53 - 00000000 ____D () C:\Program Files (x86)\Trojan Remover
2014-06-05 00:51 - 2014-06-05 00:51 - 00000000 ____D () C:\ProgramData\Simply Super Software
2014-06-05 00:51 - 2014-06-05 00:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
2014-06-05 00:50 - 2014-06-05 00:50 - 19326400 _____ (Simply Super Software ) C:\Users\TK\Downloads\trjsetup691.exe
2014-06-05 00:50 - 2014-06-05 00:50 - 19326400 _____ (Simply Super Software ) C:\Users\TK\Downloads\trjsetup691(1).exe
2014-06-05 00:27 - 2014-06-05 00:27 - 01016261 _____ (Thisisu) C:\Users\TK\Downloads\JRT(1).exe
2014-06-05 00:25 - 2014-06-05 00:26 - 01327971 _____ () C:\Users\TK\Downloads\adwcleaner_3.211.exe
2014-06-05 00:07 - 2014-06-05 00:07 - 11714981 _____ (Extensoft) C:\Users\TK\Downloads\FreeTaskManager.exe
2014-06-05 00:07 - 2014-06-05 00:07 - 00000000 ____D () C:\ProgramData\TaskManager
2014-06-04 23:40 - 2014-06-04 23:40 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-06-04 23:39 - 2014-06-05 16:39 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-06-04 23:39 - 2014-06-05 16:35 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-06-04 23:38 - 2014-06-04 23:39 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\TK\Downloads\spybot-2.3(1).exe
2014-06-04 23:38 - 2014-06-04 23:38 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\TK\Downloads\spybot-2.3.exe
2014-06-01 23:53 - 2014-06-01 23:53 - 00091185 _____ () C:\Users\TK\Documents\BROSCHURE.odt
2014-05-30 22:40 - 2014-05-30 22:40 - 00000194 _____ () C:\console.log
2014-05-30 01:31 - 2014-05-30 01:31 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-05-29 13:05 - 2014-05-31 10:48 - 00000549 _____ () C:\Users\TK\Desktop\aaaaaaaaaaaaaaaaaaaaa.txt
2014-05-28 20:39 - 2014-06-05 11:44 - 00000000 ____D () C:\Users\TK\Desktop\Henschel Schrottschredderanlage
2014-05-20 18:48 - 2014-05-20 18:49 - 00025088 _____ () C:\Users\TK\Desktop\Pelletieranlage.xls
2014-05-19 15:49 - 2014-05-19 15:49 - 00000000 ____D () C:\Program Files (x86)\HTML-Kit
2014-05-19 15:48 - 2014-05-19 15:49 - 00000000 ____D () C:\Users\TK\Documents\HKToolsTrialSetup
2014-05-19 15:32 - 2014-05-19 15:32 - 00162279 _____ () C:\Users\TK\Downloads\Business_template3.zip
2014-05-17 11:03 - 2014-05-17 11:03 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Windows Live Writer
2014-05-17 11:03 - 2014-05-17 11:03 - 00000000 ____D () C:\Users\TK\AppData\Local\Windows Live Writer
==================== One Month Modified Files and Folders =======
2014-06-15 14:45 - 2014-06-05 20:35 - 00009464 _____ () C:\Users\TK\Downloads\FRST.txt
2014-06-15 14:45 - 2012-09-18 19:41 - 00000000 ____D () C:\Users\TK\AppData\Local\Temp
2014-06-15 14:42 - 2014-06-05 20:35 - 00000000 ____D () C:\FRST
2014-06-15 14:40 - 2014-06-15 14:40 - 02081792 _____ (Farbar) C:\Users\TK\Downloads\FRST64(2).exe
2014-06-15 14:35 - 2012-09-18 20:59 - 00000000 ____D () C:\Users\TK\AppData\Roaming\The Bat!
2014-06-15 13:28 - 2013-09-12 19:58 - 01669827 _____ () C:\Windows\WindowsUpdate.log
2014-06-15 11:13 - 2014-06-15 11:13 - 00001084 _____ () C:\Users\Public\Desktop\FastStone Photo Resizer.lnk
2014-06-15 11:13 - 2014-06-15 11:13 - 00000000 ____D () C:\Users\TK\AppData\Roaming\FastStone
2014-06-15 11:13 - 2014-06-15 11:13 - 00000000 ____D () C:\Users\TK\AppData\Local\FastStone
2014-06-15 11:13 - 2014-06-15 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Photo Resizer
2014-06-15 11:13 - 2014-06-15 11:12 - 00000000 ____D () C:\Program Files (x86)\FastStone Photo Resizer
2014-06-15 11:12 - 2014-06-15 11:12 - 01522679 _____ () C:\Users\TK\Downloads\FSResizerSetup32.exe
2014-06-15 11:07 - 2014-06-15 11:07 - 02347384 _____ (ESET) C:\Users\TK\Downloads\esetsmartinstaller_deu(1).exe
2014-06-15 11:07 - 2014-06-15 11:07 - 00854367 _____ () C:\Users\TK\Desktop\SecurityCheck.exe
2014-06-15 00:21 - 2014-06-08 01:55 - 00001120 _____ () C:\Windows\setupact.log
2014-06-14 23:07 - 2014-05-11 14:05 - 00000000 ____D () C:\Users\TK\Desktop\RECHN
2014-06-13 21:47 - 2009-07-14 06:45 - 00024912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-13 21:47 - 2009-07-14 06:45 - 00024912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-13 21:39 - 2012-12-02 16:07 - 00000106 _____ () C:\Windows\system32\mfilemon.log
2014-06-13 21:39 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-13 21:36 - 2014-06-13 21:36 - 00000000 ____D () C:\Windows\Paltalk Messenger
2014-06-13 21:36 - 2014-06-07 13:51 - 00001924 _____ () C:\Users\TK\Desktop\Paltalk Messenger.lnk
2014-06-13 21:36 - 2014-06-07 13:51 - 00001120 _____ () C:\Users\TK\Desktop\Upgrade to Paltalk Extreme.lnk
2014-06-13 21:36 - 2014-06-07 13:51 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paltalk Messenger
2014-06-13 21:36 - 2014-06-07 13:50 - 00000000 ____D () C:\Program Files (x86)\Paltalk Messenger
2014-06-13 21:36 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-13 21:35 - 2014-06-13 21:35 - 23649688 _____ () C:\Users\TK\Downloads\pal_install_r101b431.exe
2014-06-13 09:46 - 2013-07-25 03:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-13 09:42 - 2012-09-27 20:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-13 09:38 - 2014-05-07 08:37 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-12 21:45 - 2014-05-04 16:44 - 00095501 _____ () C:\Users\TK\Desktop\RECHNUNGSVORLAGE (2).odt
2014-06-12 13:26 - 2014-06-12 13:26 - 00100457 _____ () C:\Users\TK\Downloads\Jenz Forus 171 Cat. schredder brech anlage 2005 Walzenbrecher gebraucht Verkauf (zuidwolde _ Niederlande) - MachineryPark.com.htm
2014-06-12 13:26 - 2014-06-12 13:26 - 00000000 ____D () C:\Users\TK\Downloads\Jenz Forus 171 Cat. schredder brech anlage 2005 Walzenbrecher gebraucht Verkauf (zuidwolde _ Niederlande) - MachineryPark.com-Dateien
2014-06-12 12:35 - 2014-06-12 12:35 - 00052105 _____ () C:\Users\TK\Desktop\o2.odt
2014-06-12 11:53 - 2014-06-12 11:53 - 00000000 _____ () C:\Users\TK\Desktop\Neues Textdokument.txt
2014-06-11 22:50 - 2014-06-11 22:49 - 00000000 ____D () C:\Users\TK\Desktop\Neuer Ordner (2)
2014-06-11 21:46 - 2014-06-11 21:46 - 02081792 _____ (Farbar) C:\Users\TK\Downloads\FRST64(1).exe
2014-06-11 17:35 - 2014-06-11 17:34 - 00000000 ____D () C:\Users\TK\Desktop\sq
2014-06-11 16:49 - 2014-06-11 16:35 - 00001482 _____ () C:\Users\TK\Desktop\giliiii.txt
2014-06-10 22:41 - 2013-07-30 16:17 - 00000000 ____D () C:\Users\TK\Desktop\txt
2014-06-10 15:23 - 2014-06-10 15:23 - 00000000 ____D () C:\Users\TK\Desktop\Neuer Ordner
2014-06-10 15:12 - 2012-09-23 19:01 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Skype
2014-06-10 09:47 - 2012-09-18 19:48 - 00000000 ____D () C:\Users\TK\AppData\Local\VirtualStore
2014-06-09 22:49 - 2014-06-08 13:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-09 15:50 - 2014-06-09 15:50 - 00004138 _____ () C:\Users\TK\Desktop\JRT.txt
2014-06-09 15:46 - 2014-06-09 15:46 - 00001581 _____ () C:\Users\TK\Desktop\AdwCleanedas.txt
2014-06-09 15:32 - 2014-06-08 13:30 - 00005600 _____ () C:\Windows\PFRO.log
2014-06-09 15:30 - 2014-04-23 18:24 - 00000000 ____D () C:\AdwCleaner
2014-06-09 15:27 - 2014-06-09 15:27 - 01333465 _____ () C:\Users\TK\Downloads\adwcleaner_3.212.exe
2014-06-09 15:26 - 2014-06-09 15:26 - 01016261 _____ (Thisisu) C:\Users\TK\Downloads\JRT(2).exe
2014-06-09 15:26 - 2014-06-09 15:26 - 01016261 _____ (Thisisu) C:\Users\TK\Desktop\JRT(3).exe
2014-06-08 16:44 - 2014-06-08 16:44 - 00001150 _____ () C:\Users\TK\Desktop\malware.txt
2014-06-08 13:38 - 2014-06-08 13:38 - 00001069 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-08 13:38 - 2014-06-08 13:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-08 13:38 - 2012-11-10 01:16 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Malwarebytes
2014-06-08 13:38 - 2012-11-10 01:16 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-08 13:37 - 2014-06-08 13:37 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\TK\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-08 13:37 - 2014-06-08 13:37 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-08 13:31 - 2014-06-08 13:31 - 00070968 _____ () C:\Users\TK\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-08 13:31 - 2014-06-08 13:30 - 00326280 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-08 11:13 - 2014-06-12 15:20 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-12 15:20 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-08 02:09 - 2014-06-07 13:51 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Paltalk
2014-06-08 01:55 - 2014-06-08 01:55 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-07 13:51 - 2012-09-18 19:41 - 00000000 ___RD () C:\Users\TK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-07 13:50 - 2014-06-07 13:50 - 01589176 _____ (AVM Software Inc.) C:\Users\TK\Downloads\pal_install_r132028.exe
2014-06-07 02:41 - 2014-06-07 02:41 - 00018054 _____ () C:\Users\TK\Desktop\posten.txt
2014-06-07 02:36 - 2014-06-07 02:36 - 00018054 _____ () C:\ComboFix.txt
2014-06-07 02:36 - 2014-06-07 02:36 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-07 02:36 - 2014-06-07 02:36 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-07 02:36 - 2014-06-07 02:36 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-07 02:36 - 2014-06-05 16:54 - 00000000 ____D () C:\Qoobox
2014-06-07 02:36 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-06-07 02:33 - 2014-06-05 16:53 - 00000000 ____D () C:\Windows\erdnt
2014-06-07 02:32 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-06-07 01:42 - 2013-09-29 22:28 - 00000000 ____D () C:\Program Files (x86)\WinHex
2014-06-07 01:41 - 2014-06-07 01:41 - 05205146 ____R (Swearware) C:\Users\TK\Desktop\ComboFix.exe
2014-06-07 01:41 - 2012-09-18 19:41 - 00000000 ____D () C:\Users\TK
2014-06-07 01:40 - 2014-06-07 01:40 - 05205146 _____ (Swearware) C:\Users\TK\Downloads\ComboFix(1).exe
2014-06-07 01:27 - 2014-06-07 01:27 - 00000000 ____D () C:\Users\TK\Downloads\FRST-OlderVersion
2014-06-07 01:27 - 2014-06-05 20:34 - 02072576 _____ (Farbar) C:\Users\TK\Downloads\FRST64.exe
2014-06-07 01:25 - 2014-06-07 01:25 - 00001231 _____ () C:\Users\TK\Desktop\Revo Uninstaller.lnk
2014-06-07 01:25 - 2014-06-07 01:25 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-07 01:24 - 2014-06-07 01:24 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\TK\Downloads\revosetup95.exe
2014-06-05 20:46 - 2014-06-05 20:46 - 00000225 _____ () C:\Users\TK\Desktop\laender.txt
2014-06-05 20:40 - 2014-06-05 20:40 - 00033236 _____ () C:\Users\TK\Downloads\Addition.txt
2014-06-05 17:58 - 2011-08-22 11:45 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-06-05 17:49 - 2014-05-01 14:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3
2014-06-05 17:49 - 2014-01-26 23:31 - 00000000 ____D () C:\ProgramData\eBay
2014-06-05 17:49 - 2013-06-19 22:59 - 00000000 ____D () C:\Windows\Minidump
2014-06-05 17:48 - 2014-01-26 23:32 - 00001466 _____ () C:\InstallHelper.log
2014-06-05 17:48 - 2012-09-18 19:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay
2014-06-05 17:46 - 2012-11-19 00:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PageBreeze
2014-06-05 17:44 - 2014-06-05 17:44 - 02347384 _____ (ESET) C:\Users\TK\Downloads\esetsmartinstaller_deu.exe
2014-06-05 17:39 - 2013-09-12 16:02 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Dropbox
2014-06-05 17:38 - 2011-08-22 11:51 - 00000000 ____D () C:\Program Files (x86)\Google
2014-06-05 17:24 - 2014-06-05 17:24 - 01327971 _____ () C:\Users\TK\Downloads\adwcleaner_3.211(2).exe
2014-06-05 17:23 - 2014-06-05 17:23 - 01327971 _____ () C:\Users\TK\Downloads\adwcleaner_3.211(1).exe
2014-06-05 17:21 - 2014-06-05 17:21 - 01016261 _____ (Thisisu) C:\Users\TK\Downloads\JRT_6.1.4.exe
2014-06-05 16:53 - 2014-06-05 16:52 - 05205146 ____R (Swearware) C:\Users\TK\Downloads\ComboFix.exe
2014-06-05 16:39 - 2014-06-04 23:39 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-06-05 16:38 - 2013-09-12 11:19 - 00000000 ____D () C:\ProgramData\Avira
2014-06-05 16:37 - 2013-11-16 20:54 - 00000000 ____D () C:\Users\TK\AppData\Roaming\AvitoDvd
2014-06-05 16:37 - 2010-11-21 09:00 - 00000000 ____D () C:\Windows\ShellNew
2014-06-05 16:35 - 2014-06-05 11:56 - 00000085 _____ () C:\Windows\wininit.ini
2014-06-05 16:35 - 2014-06-04 23:39 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-06-05 16:34 - 2013-02-01 19:13 - 00000000 ____D () C:\Program Files (x86)\Stellar Phoenix PDF Password Recovery
2014-06-05 16:34 - 2012-11-10 02:05 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-06-05 16:24 - 2014-06-05 16:24 - 00023896 _____ () C:\Users\TK\Desktop\atta.txt
2014-06-05 14:16 - 2014-06-05 14:16 - 00368256 _____ (RegNow.com) C:\Users\TK\Downloads\Download_MaxSDDMnew.exe
2014-06-05 12:41 - 2014-06-05 01:00 - 00000000 ____D () C:\ProgramData\AVG2014
2014-06-05 12:41 - 2014-06-05 00:57 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-05 12:29 - 2014-06-05 00:57 - 00000000 ____D () C:\Users\TK\AppData\Local\Avg2014
2014-06-05 12:23 - 2014-06-05 01:00 - 00000000 ____D () C:\$AVG
2014-06-05 12:15 - 2014-06-05 12:15 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\TK\Downloads\avira_de_av_4007782653__ws.exe
2014-06-05 12:05 - 2014-06-05 12:05 - 00000000 ____D () C:\Users\TK\Documents\ProcAlyzer Dumps
2014-06-05 11:55 - 2014-06-05 11:55 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\TK\Downloads\spybot-2.3(3).exe
2014-06-05 11:54 - 2014-06-05 11:53 - 46392681 _____ () C:\Users\TK\Downloads\spybot-2.3(2).exe
2014-06-05 11:44 - 2014-05-28 20:39 - 00000000 ____D () C:\Users\TK\Desktop\Henschel Schrottschredderanlage
2014-06-05 02:30 - 2012-09-28 21:32 - 00000000 ____D () C:\Windows\pss
2014-06-05 01:15 - 2014-06-05 01:15 - 00000000 _____ () C:\Windows\system32\avgrep.txt
2014-06-05 01:03 - 2014-06-05 01:03 - 00000000 ____D () C:\Users\TK\AppData\Roaming\AVG2014
2014-06-05 01:02 - 2013-07-20 18:53 - 00000000 ____D () C:\Users\TK\AppData\Roaming\TuneUp Software
2014-06-05 00:57 - 2014-06-05 00:57 - 04487240 _____ (AVG Technologies) C:\Users\TK\Downloads\avg_isct_stb_all_2014_4592.exe
2014-06-05 00:57 - 2014-06-05 00:57 - 00000000 ____D () C:\Users\TK\AppData\Local\MFAData
2014-06-05 00:54 - 2014-06-05 00:54 - 00000000 ____D () C:\ProgramData\Licenses
2014-06-05 00:53 - 2014-06-05 00:51 - 00000000 ____D () C:\Program Files (x86)\Trojan Remover
2014-06-05 00:52 - 2014-06-05 00:52 - 00000000 ____D () C:\Users\TK\Documents\Simply Super Software
2014-06-05 00:52 - 2014-06-05 00:52 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Simply Super Software
2014-06-05 00:51 - 2014-06-05 00:51 - 00000000 ____D () C:\ProgramData\Simply Super Software
2014-06-05 00:51 - 2014-06-05 00:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
2014-06-05 00:50 - 2014-06-05 00:50 - 19326400 _____ (Simply Super Software ) C:\Users\TK\Downloads\trjsetup691.exe
2014-06-05 00:50 - 2014-06-05 00:50 - 19326400 _____ (Simply Super Software ) C:\Users\TK\Downloads\trjsetup691(1).exe
2014-06-05 00:35 - 2012-10-01 00:26 - 00007608 _____ () C:\Users\TK\AppData\Local\Resmon.ResmonCfg
2014-06-05 00:27 - 2014-06-05 00:27 - 01016261 _____ (Thisisu) C:\Users\TK\Downloads\JRT(1).exe
2014-06-05 00:26 - 2014-06-05 00:25 - 01327971 _____ () C:\Users\TK\Downloads\adwcleaner_3.211.exe
2014-06-05 00:07 - 2014-06-05 00:07 - 11714981 _____ (Extensoft) C:\Users\TK\Downloads\FreeTaskManager.exe
2014-06-05 00:07 - 2014-06-05 00:07 - 00000000 ____D () C:\ProgramData\TaskManager
2014-06-04 23:40 - 2014-06-04 23:40 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-06-04 23:39 - 2014-06-04 23:38 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\TK\Downloads\spybot-2.3(1).exe
2014-06-04 23:38 - 2014-06-04 23:38 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\TK\Downloads\spybot-2.3.exe
2014-06-01 23:53 - 2014-06-01 23:53 - 00091185 _____ () C:\Users\TK\Documents\BROSCHURE.odt
2014-06-01 20:26 - 2014-03-28 15:38 - 00000000 ____D () C:\Users\TK\Documents\MyPotos
2014-05-31 18:30 - 2013-04-02 20:15 - 00000000 ____D () C:\Users\TK\Documents\Bandicam
2014-05-31 10:48 - 2014-05-29 13:05 - 00000549 _____ () C:\Users\TK\Desktop\aaaaaaaaaaaaaaaaaaaaa.txt
2014-05-30 22:40 - 2014-05-30 22:40 - 00000194 _____ () C:\console.log
2014-05-30 15:04 - 2010-11-21 08:50 - 00699682 _____ () C:\Windows\system32\perfh007.dat
2014-05-30 15:04 - 2010-11-21 08:50 - 00149790 _____ () C:\Windows\system32\perfc007.dat
2014-05-30 15:04 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-30 12:21 - 2014-06-12 15:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-12 15:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-12 15:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-12 15:21 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-12 15:21 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-12 15:21 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-12 15:21 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-12 15:21 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-12 15:21 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-12 15:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-12 15:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-12 15:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-12 15:21 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-12 15:21 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-12 15:21 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-12 15:21 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-12 15:21 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-12 15:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-12 15:21 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-12 15:21 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-12 15:21 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-12 15:21 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-12 15:21 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-12 15:21 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-12 15:21 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-12 15:21 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-12 15:21 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-12 15:21 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-12 15:21 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-12 15:21 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-12 15:21 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-12 15:21 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-12 15:21 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-12 15:21 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-12 15:21 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-12 15:21 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-12 15:21 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-12 15:21 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-12 15:21 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-12 15:21 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-12 15:21 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-12 15:21 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-12 15:21 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-12 15:21 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-12 15:21 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-12 15:21 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-12 15:21 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-12 15:21 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-12 15:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-12 15:21 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-12 15:21 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-12 15:21 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-30 01:31 - 2014-05-30 01:31 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-05-28 21:55 - 2014-05-09 20:29 - 00000000 ____D () C:\Users\TK\AppData\Local\Windows Live
2014-05-26 12:13 - 2014-04-06 13:59 - 00000000 ____D () C:\Users\TK\Documents\MASCHINENFOTOS
2014-05-20 18:49 - 2014-05-20 18:48 - 00025088 _____ () C:\Users\TK\Desktop\Pelletieranlage.xls
2014-05-19 15:49 - 2014-05-19 15:49 - 00000000 ____D () C:\Program Files (x86)\HTML-Kit
2014-05-19 15:49 - 2014-05-19 15:48 - 00000000 ____D () C:\Users\TK\Documents\HKToolsTrialSetup
2014-05-19 15:32 - 2014-05-19 15:32 - 00162279 _____ () C:\Users\TK\Downloads\Business_template3.zip
2014-05-18 15:28 - 2013-04-21 20:28 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-05-17 21:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-17 19:39 - 2012-09-18 19:48 - 00000000 ___RD () C:\Users\TK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-17 19:15 - 2012-10-25 00:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-17 11:03 - 2014-05-17 11:03 - 00000000 ____D () C:\Users\TK\AppData\Roaming\Windows Live Writer
2014-05-17 11:03 - 2014-05-17 11:03 - 00000000 ____D () C:\Users\TK\AppData\Local\Windows Live Writer
Files to move or delete:
====================
C:\Users\TK\Rar.exe
Some content of TEMP:
====================
C:\Users\TK\AppData\Local\Temp\AskSLib.dll
C:\Users\TK\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-08 14:09
==================== End Of Log ============================
--- --- ---
--- --- ---