Cpt_Chandler | 28.01.2015 17:26 | FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by Dominic (administrator) on DOMINIC-PC on 28-01-2015 16:05:01
Running from C:\Users\Dominic\Downloads
Loaded Profiles: Dominic (Available profiles: Dominic)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfevtps.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\setup\instup.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software)
HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-1934127515-777576594-3349311130-1001\...\MountPoints2: {06572c8f-a665-11e4-9d8b-c0f8da2f4518} - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
HKU\S-1-5-21-1934127515-777576594-3349311130-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startfenster.de
HKU\S-1-5-21-1934127515-777576594-3349311130-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
SearchScopes: HKLM -> DefaultScope {C033D8E6-E3C5-4ED7-A349-ECD1FFC0F607} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {C033D8E6-E3C5-4ED7-A349-ECD1FFC0F607} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1934127515-777576594-3349311130-1001 -> DefaultScope {C033D8E6-E3C5-4ED7-A349-ECD1FFC0F607} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1934127515-777576594-3349311130-1001 -> {C033D8E6-E3C5-4ED7-A349-ECD1FFC0F607} URL = hxxp://www.sm.de/?q={searchTerms}
BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\Program Files\mcafee\msk\mskapbho64.dll ()
BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110413235714.dll (McAfee, Inc.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\Program Files\mcafee\msk\mskapbho.dll ()
BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110413235714.dll (McAfee, Inc.)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-04-14]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-01-27]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.de/", "hxxp://www.google.com/"
CHR Profile: C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (OkayFreedom) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\bckipplcmnfhblnpibpbehenelnkpecd [2015-01-27]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-27]
CHR Extension: (YouTube) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-27]
CHR Extension: (Google-Suche) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-27]
CHR Extension: (AdBlock) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-27]
CHR Extension: (Google Wallet) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-27]
CHR Extension: (Google Mail) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-27]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-01-27]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-27]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 0140251422374920mcinstcleanup; C:\Windows\TEMP\014025~1.EXE [828032 2012-06-14] (McAfee, Inc.)
S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [74912 2011-03-13] (Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-27] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [104416 2015-01-27] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2015-01-27] (Avast Software)
S4 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2009-12-15] (McAfee, Inc.)
S4 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2009-12-15] (McAfee, Inc.)
S4 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [355440 2009-12-15] (McAfee, Inc.)
S4 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [355440 2009-12-15] (McAfee, Inc.)
S4 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [355440 2009-12-15] (McAfee, Inc.)
S4 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [509416 2009-12-31] (McAfee, Inc.)
S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [355440 2009-12-15] (McAfee, Inc.)
S4 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [355440 2009-12-15] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [199032 2010-01-06] (McAfee, Inc.)
S4 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [244840 2010-01-06] (McAfee, Inc.)
R2 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [148520 2010-01-06] (McAfee, Inc.)
S4 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2009-12-15] (McAfee, Inc.)
S4 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
S4 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-27] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2015-01-27] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2015-01-27] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [449936 2015-01-27] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-27] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-27] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-27] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-27] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-27] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-27] ()
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [62416 2010-01-06] (McAfee, Inc.)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [121504 2010-01-06] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [189880 2010-01-06] (McAfee, Inc.)
U3 mfeavfk01; No ImagePath
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [440688 2010-01-06] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [528232 2010-01-06] (McAfee, Inc.)
R1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [75288 2010-01-06] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [93840 2010-01-06] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [279752 2010-01-06] (McAfee, Inc.)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2015-01-27] (Avast Software)
U3 pgliifod; \??\C:\Users\Dominic\AppData\Local\Temp\pgliifod.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-28 16:05 - 2015-01-28 16:07 - 00015979 _____ () C:\Users\Dominic\Downloads\FRST.txt
2015-01-28 16:05 - 2015-01-28 16:05 - 00380416 _____ () C:\Users\Dominic\Downloads\1xfwy44h.exe
2015-01-28 16:04 - 2015-01-28 16:05 - 00000000 ____D () C:\FRST
2015-01-28 16:04 - 2015-01-28 16:04 - 02129920 _____ (Farbar) C:\Users\Dominic\Downloads\FRST64.exe
2015-01-28 16:03 - 2015-01-28 16:03 - 00000476 _____ () C:\Users\Dominic\Downloads\defogger_disable.log
2015-01-28 16:02 - 2015-01-28 16:02 - 00000476 _____ () C:\Users\Dominic\Desktop\defogger_disable.log
2015-01-28 16:02 - 2015-01-28 16:02 - 00000000 _____ () C:\Users\Dominic\defogger_reenable
2015-01-28 16:01 - 2015-01-28 16:01 - 00050477 _____ () C:\Users\Dominic\Downloads\Defogger.exe
2015-01-28 15:43 - 2015-01-28 15:43 - 00000197 _____ () C:\Windows\system32\2015-01-28-14-43-22.003-AvastVBoxSVC.exe-2620.log
2015-01-28 13:44 - 2015-01-28 13:44 - 00000197 _____ () C:\Windows\system32\2015-01-28-12-44-18.019-AvastVBoxSVC.exe-2480.log
2015-01-28 12:23 - 2011-05-24 12:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2015-01-28 12:23 - 2011-05-24 11:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2015-01-28 12:23 - 2011-05-24 11:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2015-01-28 12:23 - 2011-05-24 11:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2015-01-28 12:23 - 2011-05-24 11:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2015-01-28 12:15 - 2011-05-03 06:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-01-28 12:15 - 2011-05-03 05:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-01-28 12:14 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-01-28 12:14 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-01-28 12:11 - 2014-06-05 15:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-01-28 12:11 - 2014-06-05 15:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-01-28 12:11 - 2014-06-05 15:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-01-28 12:11 - 2014-04-12 03:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-01-28 12:11 - 2014-04-12 03:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-01-28 12:11 - 2014-04-12 03:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-01-28 12:11 - 2014-04-12 03:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-01-28 12:11 - 2014-04-12 03:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-01-28 12:11 - 2014-04-12 03:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-01-28 12:11 - 2014-03-04 10:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-01-28 12:11 - 2014-03-04 10:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-01-28 12:11 - 2014-03-04 10:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-01-28 12:11 - 2014-03-04 10:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-01-28 12:11 - 2014-03-04 10:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-01-28 12:11 - 2014-03-04 10:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-01-28 12:11 - 2014-03-04 10:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-01-28 12:11 - 2014-03-04 10:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-01-28 12:11 - 2014-03-04 10:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-01-28 12:11 - 2014-03-04 10:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-01-28 12:11 - 2014-03-04 10:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-01-28 12:11 - 2014-03-04 10:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-01-28 12:11 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-01-28 12:11 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-01-28 12:11 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-01-28 12:01 - 2014-08-23 03:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-01-28 12:01 - 2014-08-23 02:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-01-28 12:01 - 2014-08-23 01:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-01-28 12:00 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2015-01-28 12:00 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2015-01-28 12:00 - 2011-10-15 07:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2015-01-28 12:00 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2015-01-28 11:52 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2015-01-28 11:52 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2015-01-28 11:52 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2015-01-28 11:52 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2015-01-28 11:52 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2015-01-28 11:52 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2015-01-28 11:52 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2015-01-28 11:52 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2015-01-28 11:52 - 2011-02-12 12:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2015-01-28 11:51 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-01-28 11:51 - 2011-02-23 05:56 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-01-28 11:50 - 2011-02-23 05:55 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-01-28 11:50 - 2011-02-23 05:55 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-01-28 11:50 - 2011-02-23 05:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2015-01-28 11:49 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2015-01-28 11:49 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2015-01-28 11:38 - 2015-01-28 11:38 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-28 11:38 - 2015-01-28 11:38 - 00000000 ____D () C:\196b96d90ae088259368
2015-01-28 11:38 - 2014-12-31 13:12 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-28 11:29 - 2015-01-28 11:29 - 00000197 _____ () C:\Windows\system32\2015-01-28-10-29-24.089-AvastVBoxSVC.exe-2524.log
2015-01-28 00:22 - 2015-01-28 15:48 - 00643866 _____ () C:\Windows\system32\perfh007.dat
2015-01-28 00:22 - 2015-01-28 15:48 - 00126394 _____ () C:\Windows\system32\perfc007.dat
2015-01-28 00:22 - 2015-01-28 00:21 - 00295922 _____ () C:\Windows\system32\perfi007.dat
2015-01-28 00:22 - 2015-01-28 00:21 - 00038104 _____ () C:\Windows\system32\perfd007.dat
2015-01-28 00:21 - 2015-01-28 00:21 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
2015-01-28 00:21 - 2015-01-28 00:21 - 00000000 ____D () C:\Windows\SysWOW64\de
2015-01-28 00:21 - 2015-01-28 00:21 - 00000000 ____D () C:\Windows\SysWOW64\0407
2015-01-28 00:21 - 2015-01-28 00:21 - 00000000 ____D () C:\Windows\system32\de
2015-01-28 00:21 - 2015-01-28 00:21 - 00000000 ____D () C:\Windows\system32\0407
2015-01-28 00:12 - 2015-01-28 00:12 - 00000000 ____D () C:\Windows\NAPP_Dism_Log
2015-01-27 23:10 - 2015-01-27 23:10 - 00000197 _____ () C:\Windows\system32\2015-01-27-22-10-21.078-AvastVBoxSVC.exe-3136.log
2015-01-27 21:53 - 2015-01-27 21:53 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2015-01-27 21:45 - 2015-01-27 21:45 - 00000197 _____ () C:\Windows\system32\2015-01-27-20-45-31.082-AvastVBoxSVC.exe-2968.log
2015-01-27 21:09 - 2015-01-27 21:09 - 01054225 _____ () C:\Users\Dominic\Downloads\d3dx9_43.zip
2015-01-27 20:37 - 2015-01-27 20:37 - 00000197 _____ () C:\Windows\system32\2015-01-27-19-37-09.013-AvastVBoxSVC.exe-2772.log
2015-01-27 20:27 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2015-01-27 20:27 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2015-01-27 20:27 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2015-01-27 20:27 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2015-01-27 20:27 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2015-01-27 20:27 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2015-01-27 20:27 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2015-01-27 20:27 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2015-01-27 20:27 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2015-01-27 20:27 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2015-01-27 20:27 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2015-01-27 20:27 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2015-01-27 20:27 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2015-01-27 20:27 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2015-01-27 20:10 - 2015-01-27 20:10 - 05994752 _____ (Wargaming.net ) C:\Users\Dominic\Downloads\WoT_internet_install_eu (1).exe
2015-01-27 19:51 - 2015-01-27 20:25 - 00000000 ___HD () C:\Windows\msdownld.tmp
2015-01-27 19:51 - 2015-01-27 19:51 - 00000773 _____ () C:\Users\Public\Desktop\World of Tanks.lnk
2015-01-27 19:51 - 2015-01-27 19:51 - 00000000 ____D () C:\Windows\SysWOW64\directx
2015-01-27 19:51 - 2015-01-27 19:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2015-01-27 19:49 - 2015-01-27 19:50 - 05994752 _____ (Wargaming.net ) C:\Users\Dominic\Downloads\WoT_internet_install_eu.exe
2015-01-27 19:42 - 2015-01-27 19:42 - 00000247 _____ () C:\Windows\system32\2015-01-27-18-42-26.058-aswFe.exe-4860.log
2015-01-27 19:37 - 2015-01-27 19:42 - 00000247 _____ () C:\Windows\system32\2015-01-27-18-37-26.027-aswFe.exe-4656.log
2015-01-27 19:37 - 2015-01-27 19:37 - 00000197 _____ () C:\Windows\system32\2015-01-27-18-37-19.043-AvastVBoxSVC.exe-4756.log
2015-01-27 19:36 - 2014-12-29 22:15 - 00000034 _____ () C:\Users\Dominic\Desktop\REBELLCHEN.txt
2015-01-27 19:31 - 2015-01-27 19:31 - 00000197 _____ () C:\Windows\system32\2015-01-27-18-31-09.036-AvastVBoxSVC.exe-780.log
2015-01-27 18:45 - 2015-01-27 18:45 - 00000247 _____ () C:\Windows\system32\2015-01-27-17-45-23.009-aswFe.exe-3656.log
2015-01-27 18:32 - 2015-01-27 18:45 - 00000247 _____ () C:\Windows\system32\2015-01-27-17-32-09.011-aswFe.exe-3376.log
2015-01-27 18:32 - 2015-01-27 18:32 - 00000197 _____ () C:\Windows\system32\2015-01-27-17-32-01.004-AvastVBoxSVC.exe-3176.log
2015-01-27 18:18 - 2015-01-27 18:18 - 00001974 _____ () C:\Users\Public\Desktop\Avast Internet Security.lnk
2015-01-27 18:15 - 2015-01-27 18:14 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2015-01-27 18:14 - 2015-01-27 18:14 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-01-27 18:14 - 2015-01-27 18:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-01-27 18:13 - 2015-01-27 18:13 - 00449936 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2015-01-27 18:06 - 2015-01-27 18:08 - 00000000 ____D () C:\Windows\SysWOW64\vbox
2015-01-27 18:06 - 2015-01-27 18:08 - 00000000 ____D () C:\Windows\system32\vbox
2015-01-27 18:05 - 2015-01-27 18:05 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\AVAST Software
2015-01-27 18:04 - 2015-01-28 11:29 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-01-27 18:04 - 2015-01-27 18:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-01-27 18:04 - 2015-01-27 18:04 - 00002251 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-27 18:04 - 2015-01-27 18:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-27 18:04 - 2015-01-23 20:27 - 16153512 _____ (Wargaming.net ) C:\Users\Dominic\Desktop\WOWS_BW_na.exe
2015-01-27 18:04 - 2015-01-16 21:14 - 91670064 _____ (The GIMP Team ) C:\Users\Dominic\Desktop\gimp-2.8.14-setup.exe
2015-01-27 18:04 - 2014-12-20 21:52 - 00394754 _____ () C:\Users\Dominic\Desktop\soundboard-1.0b5-win64.ts3_plugin
2015-01-27 18:03 - 2015-01-28 15:45 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-27 18:03 - 2015-01-28 14:15 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-27 18:03 - 2015-01-27 18:10 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-01-27 18:03 - 2015-01-27 18:10 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-01-27 18:03 - 2015-01-27 18:06 - 00000000 ____D () C:\Users\Dominic\AppData\Local\Google
2015-01-27 18:03 - 2015-01-27 18:03 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-27 18:03 - 2015-01-26 23:09 - 04188536 _____ (Piriform Ltd) C:\Users\Dominic\Desktop\ccsetup501_slim.exe
2015-01-27 18:02 - 2015-01-27 18:16 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2015-01-27 18:02 - 2015-01-27 18:14 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-01-27 18:02 - 2015-01-27 18:14 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-01-27 18:02 - 2015-01-27 18:14 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-01-27 18:02 - 2015-01-27 18:14 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-01-27 18:02 - 2015-01-27 18:14 - 00083280 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2015-01-27 18:02 - 2015-01-27 18:14 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-01-27 18:02 - 2015-01-27 18:14 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-01-27 18:00 - 2015-01-27 18:00 - 00000000 ____D () C:\Program Files\AVAST Software
2015-01-27 17:59 - 2015-01-27 18:00 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-01-27 17:50 - 2015-01-28 12:17 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\TS3Client
2015-01-27 17:50 - 2015-01-27 17:50 - 00000971 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2015-01-27 17:50 - 2015-01-27 17:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2015-01-27 17:50 - 2015-01-27 17:50 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2015-01-27 17:41 - 2015-01-27 17:41 - 00003596 _____ () C:\Windows\System32\Tasks\Maxthon Update
2015-01-27 17:41 - 2015-01-27 17:41 - 00001085 _____ () C:\Users\Public\Desktop\Maxthon Cloud Browser.lnk
2015-01-27 17:41 - 2015-01-27 17:41 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\Maxthon3
2015-01-27 17:41 - 2015-01-27 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxthon Cloud Browser
2015-01-27 17:40 - 2015-01-27 17:41 - 00000000 ____D () C:\Program Files (x86)\Maxthon
2015-01-27 17:36 - 2015-01-27 21:14 - 00000000 ____D () C:\games
2015-01-27 17:32 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2015-01-27 17:32 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2015-01-27 17:32 - 2012-02-17 05:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2015-01-27 17:32 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2015-01-27 17:22 - 2015-01-27 17:54 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\vlc
2015-01-27 17:22 - 2015-01-27 17:22 - 00001070 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2015-01-27 17:22 - 2015-01-27 17:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-01-27 17:21 - 2015-01-27 17:21 - 00001192 _____ () C:\Users\Dominic\Desktop\Startfenster.lnk
2015-01-27 17:21 - 2015-01-27 17:21 - 00001192 _____ () C:\Users\Dominic\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
2015-01-27 17:21 - 2015-01-27 17:21 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2015-01-27 17:21 - 2015-01-27 17:21 - 00000000 ____D () C:\Program Files (x86)\Startfenster
2015-01-27 17:19 - 2015-01-28 15:46 - 00000000 ____D () C:\ProgramData\clear.fi
2015-01-27 17:12 - 2015-01-27 17:12 - 00000000 ____D () C:\Users\Dominic\AppData\Local\EgisTec IPS
2015-01-27 17:10 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-01-27 17:10 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-01-27 17:10 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-01-27 17:10 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-01-27 17:09 - 2015-01-27 17:11 - 00000000 ____D () C:\Users\Dominic\AppData\Local\PowerCinema
2015-01-27 17:09 - 2015-01-27 17:09 - 00001955 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fooz Kids.lnk
2015-01-27 17:09 - 2015-01-27 17:09 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\CyberLink
2015-01-27 17:09 - 2015-01-27 17:09 - 00000000 ____D () C:\Users\Dominic\AppData\Local\Acer
2015-01-27 17:09 - 2015-01-27 17:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-01-27 17:09 - 2015-01-27 17:09 - 00000000 ____D () C:\Program Files\Accessory Store
2015-01-27 17:09 - 2015-01-27 17:09 - 00000000 ____D () C:\Program Files (x86)\OEM
2015-01-27 17:09 - 2014-05-14 17:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-01-27 17:09 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-01-27 17:09 - 2014-05-14 17:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-01-27 17:09 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-01-27 17:09 - 2014-05-14 17:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-01-27 17:09 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-01-27 17:09 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-01-27 17:09 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-01-27 17:09 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-01-27 17:09 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-01-27 17:08 - 2015-01-28 16:02 - 00000000 ____D () C:\Users\Dominic
2015-01-27 17:08 - 2015-01-27 17:20 - 00000000 ____D () C:\Users\Dominic\AppData\Local\Windows Live
2015-01-27 17:08 - 2015-01-27 17:11 - 00001443 _____ () C:\Users\Dominic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-27 17:08 - 2015-01-27 17:11 - 00001409 _____ () C:\Users\Dominic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-01-27 17:08 - 2015-01-27 17:09 - 00059968 _____ () C:\Users\Dominic\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\Vorlagen
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\Startmenü
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\Netzwerkumgebung
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\Lokale Einstellungen
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\Eigene Dateien
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\Druckumgebung
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\Documents\Eigene Musik
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\Documents\Eigene Bilder
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\AppData\Local\Verlauf
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\AppData\Local\Anwendungsdaten
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Dominic\Anwendungsdaten
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\Startmenü
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Programme
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\ProgramData\Startmenü
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\ProgramData\Favoriten
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\ProgramData\Dokumente
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 __SHD () C:\Recovery
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 ____D () C:\Users\Dominic\AppData\Local\VirtualStore
2015-01-27 17:08 - 2015-01-27 17:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Family Protection
2015-01-27 17:08 - 2011-04-14 08:35 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\Macromedia
2015-01-27 17:08 - 2011-04-14 08:35 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\Adobe
2015-01-27 17:08 - 2011-04-14 08:35 - 00000000 ____D () C:\Users\Dominic\AppData\Local\Adobe
2015-01-27 17:08 - 2011-04-14 08:31 - 00000000 ____D () C:\Users\Dominic\AppData\Local\Downloaded Installations
2015-01-27 17:08 - 2010-11-21 03:50 - 00000020 ___SH () C:\Users\Dominic\ntuser.ini
2015-01-27 17:08 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\Dominic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-27 17:08 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\Dominic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-27 16:18 - 2015-01-27 16:18 - 00002490 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2015-01-27 16:13 - 2015-01-27 16:13 - 17773056 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 12268544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 10884096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 09702400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2015-01-27 16:13 - 2015-01-27 16:13 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2015-01-27 16:13 - 2015-01-27 16:13 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-01-27 16:13 - 2015-01-27 16:13 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-01-27 16:13 - 2015-01-27 16:13 - 02303488 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 02136064 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 01797632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 01785344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 01492992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-01-27 16:13 - 2015-01-27 16:13 - 01427456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-01-27 16:13 - 2015-01-27 16:13 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 01344000 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 01126912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 01102336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00818176 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00716800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00697344 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00603648 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00580608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-01-27 16:13 - 2015-01-27 16:13 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-01-27 16:13 - 2015-01-27 16:13 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2015-01-27 16:13 - 2015-01-27 16:13 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00072704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2015-01-27 16:13 - 2015-01-27 16:13 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2015-01-27 16:13 - 2015-01-27 16:13 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2015-01-27 16:13 - 2015-01-27 16:13 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-01-27 16:12 - 2015-01-27 16:14 - 00003758 _____ () C:\Windows\IE9_main.log
2015-01-27 16:07 - 2015-01-27 16:09 - 00000000 ____D () C:\ProgramData\CLSK
2015-01-27 16:07 - 2015-01-27 16:07 - 00003418 _____ () C:\Windows\System32\Tasks\clear.fi
2015-01-27 16:07 - 2015-01-27 16:07 - 00003366 _____ () C:\Windows\System32\Tasks\DMREngine
2015-01-27 16:07 - 2015-01-27 16:07 - 00003348 _____ () C:\Windows\System32\Tasks\clear.fiAgent
2015-01-27 16:05 - 2015-01-27 16:05 - 00000000 ____D () C:\Program Files (x86)\Cyberlink
2015-01-27 16:02 - 2015-01-27 16:09 - 00015219 _____ () C:\ProgramData\ArcadeDeluxe5.log
2015-01-27 16:02 - 2015-01-27 16:09 - 00000000 ____D () C:\ProgramData\Temp
2015-01-27 16:02 - 2015-01-27 16:09 - 00000000 ____D () C:\ProgramData\CyberLink
2015-01-27 15:59 - 2015-01-27 16:07 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\clear.fi
2015-01-27 15:59 - 2015-01-27 15:59 - 00001024 ___RH () C:\Users\Public\Documents\NTILiveUpdateV9.dll
2015-01-27 15:59 - 2015-01-27 15:59 - 00000000 ____D () C:\ProgramData\NTI Launcher
2015-01-27 15:59 - 2015-01-27 15:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Media Maker 9
2015-01-27 15:57 - 2015-01-27 15:57 - 00000000 ____D () C:\ProgramData\FLEXnet
2015-01-27 15:56 - 2015-01-27 15:56 - 00002435 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
2015-01-27 15:56 - 2015-01-27 15:56 - 00001024 ___RH () C:\Users\Public\Documents\NTIMMV9REGET.dll
2015-01-27 15:56 - 2015-01-27 15:56 - 00001024 ___RH () C:\Users\Public\Documents\NTIMMV9Acer.dll
2015-01-27 15:56 - 2015-01-27 15:56 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2015-01-27 15:54 - 2015-01-27 15:54 - 00000000 ____D () C:\ProgramData\Atheros
2015-01-27 15:53 - 2015-01-27 15:53 - 00000000 _____ () C:\Windows\ativpsrm.bin
2015-01-27 15:51 - 2015-01-27 15:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_btath_hcrp_01009.Wdf
2015-01-27 15:49 - 2015-01-27 15:50 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Program
2015-01-27 15:49 - 2015-01-27 15:50 - 00000000 ____D () C:\Program Files (x86)\Bluetooth Suite
2015-01-27 15:47 - 2015-01-27 15:47 - 00000000 ____D () C:\Program Files\CONEXANT
2015-01-27 15:47 - 2010-12-17 00:18 - 00198784 ____N (Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
2015-01-27 15:44 - 2015-01-27 15:44 - 00004786 _____ () C:\Windows\DPINST.LOG
2015-01-27 15:44 - 2015-01-27 15:44 - 00000000 ____D () C:\Program Files\Elantech
2015-01-27 15:43 - 2015-01-27 15:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
2015-01-27 15:43 - 2015-01-27 15:43 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2015-01-27 15:43 - 2010-11-28 04:50 - 00044672 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\usbfilter.sys
2015-01-27 15:41 - 2015-01-27 15:43 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
2015-01-27 15:41 - 2015-01-27 15:41 - 00000000 ____D () C:\Program Files\ATI
2015-01-27 15:40 - 2015-01-27 15:40 - 00000184 _____ () C:\Windows\LMv4.UNI
2015-01-27 15:40 - 2015-01-27 15:40 - 00000000 ____D () C:\Program Files (x86)\Launch Manager
2015-01-27 15:39 - 2015-01-27 15:52 - 00000168 _____ () C:\Windows\Driver_install.log
2015-01-27 15:36 - 2015-01-27 15:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AcerSystem
2015-01-27 15:36 - 2015-01-27 15:36 - 00000000 ____D () C:\ProgramData\EgisTec
2015-01-27 15:36 - 2015-01-27 15:36 - 00000000 ____D () C:\book
2015-01-27 15:31 - 2015-01-28 16:07 - 01827657 _____ () C:\Windows\WindowsUpdate.log
2015-01-27 15:31 - 2011-04-14 08:40 - 00059968 _____ () C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-27 15:31 - 2011-04-14 08:40 - 00059968 _____ () C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-27 15:31 - 2011-04-14 08:35 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-01-27 15:31 - 2011-04-14 08:35 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-01-27 15:31 - 2011-04-14 08:35 - 00000000 ____D () C:\Users\Default\AppData\Local\Adobe
2015-01-27 15:31 - 2011-04-14 08:35 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-01-27 15:31 - 2011-04-14 08:35 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
2015-01-27 15:31 - 2011-04-14 08:35 - 00000000 ____D () C:\Users\Default User\AppData\Local\Adobe
2015-01-27 15:31 - 2011-04-14 08:31 - 00000000 ____D () C:\Users\Default\AppData\Local\Downloaded Installations
2015-01-27 15:31 - 2011-04-14 08:31 - 00000000 ____D () C:\Users\Default User\AppData\Local\Downloaded Installations
2015-01-27 15:31 - 2011-04-14 08:01 - 00000000 ____D () C:\Users\Default\AppData\Local\Windows Live
2015-01-27 15:31 - 2011-04-14 08:01 - 00000000 ____D () C:\Users\Default User\AppData\Local\Windows Live
2015-01-27 15:31 - 2010-11-21 03:51 - 00001449 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-27 15:31 - 2010-11-21 03:51 - 00001449 _____ () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-27 15:31 - 2010-11-21 03:51 - 00001415 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-01-27 15:31 - 2010-11-21 03:51 - 00001415 _____ () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-01-27 15:31 - 2010-11-21 03:50 - 00000020 ___SH () C:\Users\Default\ntuser.ini
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-28 15:48 - 2009-07-14 06:13 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-28 15:48 - 2009-07-14 05:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-28 15:48 - 2009-07-14 05:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-28 15:40 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-28 15:40 - 2009-07-14 05:51 - 00042203 _____ () C:\Windows\setupact.log
2015-01-28 15:40 - 2009-07-14 05:45 - 00269352 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-28 00:25 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\winrm
2015-01-28 00:25 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\WCN
2015-01-28 00:25 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\sysprep
2015-01-28 00:25 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\slmgr
2015-01-28 00:25 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\winrm
2015-01-28 00:25 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\WCN
2015-01-28 00:25 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\slmgr
2015-01-28 00:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\oobe
2015-01-28 00:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2015-01-28 00:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\MUI
2015-01-28 00:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-01-28 00:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\servicing
2015-01-28 00:21 - 2010-11-21 08:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-01-28 00:21 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts
2015-01-28 00:21 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2015-01-28 00:21 - 2009-07-14 06:37 - 00000000 ____D () C:\Windows\DigitalLocker
2015-01-28 00:21 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns
2015-01-28 00:21 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-01-28 00:21 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-01-28 00:21 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Defender
2015-01-28 00:21 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\DVD Maker
2015-01-28 00:21 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2015-01-28 00:21 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-01-28 00:21 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-01-28 00:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Setup
2015-01-28 00:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz
2015-01-28 00:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-01-28 00:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\com
2015-01-28 00:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Setup
2015-01-28 00:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\oobe
2015-01-28 00:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\migwiz
2015-01-28 00:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\com
2015-01-28 00:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\IME
2015-01-28 00:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-28 00:09 - 2009-07-14 06:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2015-01-28 00:09 - 2009-07-14 06:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2015-01-27 20:27 - 2011-04-14 08:01 - 00001770 _____ () C:\Windows\DirectX.log
2015-01-27 18:19 - 2010-11-21 04:47 - 00009390 _____ () C:\Windows\PFRO.log
2015-01-27 17:12 - 2011-04-14 08:33 - 00000000 ____D () C:\ProgramData\oem
2015-01-27 17:12 - 2011-04-14 08:32 - 00018931 _____ () C:\Windows\patch.log
2015-01-27 17:10 - 2011-04-14 08:13 - 00000000 ___HD () C:\OEM
2015-01-27 17:10 - 2011-04-14 07:56 - 00000000 ____D () C:\ProgramData\McAfee
2015-01-27 17:08 - 2011-04-14 07:56 - 00000000 ____D () C:\Program Files (x86)\McAfee
2015-01-27 17:08 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\restore
2015-01-27 17:08 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-01-27 17:08 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Recovery
2015-01-27 17:08 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Windows NT
2015-01-27 17:07 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-01-27 17:07 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2015-01-27 16:39 - 2009-07-14 05:46 - 00004059 _____ () C:\Windows\DtcInstall.log
2015-01-27 16:39 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep
2015-01-27 16:39 - 2007-07-12 02:49 - 00000000 ____D () C:\Windows\Panther
2015-01-27 16:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help
2015-01-27 16:24 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-01-27 16:18 - 2011-04-14 08:06 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-01-27 16:11 - 2011-04-14 08:00 - 00000000 ____D () C:\Program Files\Acer
2015-01-27 16:11 - 2011-04-14 07:36 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-27 16:10 - 2011-04-14 07:59 - 00000000 ____D () C:\Program Files (x86)\Acer
2015-01-27 15:57 - 2011-04-14 08:36 - 00000000 ____D () C:\Program Files (x86)\NTI
2015-01-27 15:50 - 2011-03-13 10:53 - 00246804 _____ () C:\Windows\system32\Drivers\AtherosBt.bin
2015-01-27 15:50 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-27 15:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-01-27 15:36 - 2011-04-14 08:30 - 00000000 ____D () C:\ProgramData\EgisTec IPS
2015-01-27 15:36 - 2011-02-12 04:43 - 00000000 ____D () C:\Windows\DeployWinRE2
2015-01-27 15:35 - 2011-04-14 08:34 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-27 15:35 - 2011-04-14 08:34 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-27 15:31 - 2011-04-14 07:23 - 00003652 _____ () C:\Windows\TSSysprep.log
==================== Files in the root of some directories =======
2015-01-27 16:02 - 2015-01-27 16:09 - 0015219 _____ () C:\ProgramData\ArcadeDeluxe5.log
2011-04-14 07:41 - 2010-03-02 22:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-27 16:39
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 16:03 on 28/01/2015 (Dominic)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-01-28 16:31:39
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5000BPVT-22HXZT1 rev.01.01A01 465,76GB
Running: 1xfwy44h.exe; Driver: C:\Users\Dominic\AppData\Local\Temp\pgliifod.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1612] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076bb87c9 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076b91465 2 bytes [B9, 76]
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076b914bb 2 bytes [B9, 76]
.text ... * 2
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[792] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076bb87c9 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076b91465 2 bytes [B9, 76]
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076b914bb 2 bytes [B9, 76]
.text ... * 2
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0f8da952168
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0f8da952168 (not active ControlSet)
---- EOF - GMER 2.1 ---- |