Hallo, entschuldigen Sie dass ich mich nicht mehr gemeldet habe, aber mir ging es zu schlecht ich habe Urlaub vorm Computer gemacht...hier das frische FRST
FRST Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-07-2013
Ran by Dust (administrator) on 08-07-2013 10:11:26
Running from C:\allewebprojekte
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\sched.exe
() C:\Programme\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
(Apple Computer, Inc.) C:\Programme\Bonjour\mDNSResponder.exe
(Apache Software Foundation) C:\Programme\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
(Sun Microsystems, Inc.) C:\Programme\Java\jre6\bin\jqs.exe
(Apache Software Foundation) C:\Programme\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
(NVIDIA Corporation) C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Microsoft Corporation) c:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Hewlett-Packard) C:\Programme\HP\HP Software Update\HPWuSchd2.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avgnt.exe
(Sun Microsystems, Inc.) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
(Skype Technologies S.A.) C:\Programme\Skype\Phone\Skype.exe
() C:\Dokumente und Einstellungen\Dust\ceegaix.exe
() c:\dokumente und einstellungen\dust\anwendungsdaten\wmprwise.exe
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corporation) C:\Programme\Microsoft Office\OFFICE11\OUTLOOK.EXE
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqbam08.exe
(Microsoft Corporation) C:\Programme\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Programme\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] RTHDCPL.EXE [x]
HKLM\...\Run: [SkyTel] SkyTel.EXE [x]
HKLM\...\Run: [Alcmtr] ALCMTR.EXE [x]
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [13529088 2008-05-03] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] nwiz.exe /install [x]
HKLM\...\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit [86016 2008-05-03] (NVIDIA Corporation)
HKLM\...\Run: [HP Software Update] C:\Programme\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM\...\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-08] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [254896 2012-09-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe" [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\RECYCLER\S-1-5-18\$d6f0497ef4d323fcbc4a52237e3baa9b\o. ATTENTION! ====> ZeroAccess
HKCU\...\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized [17351304 2011-10-13] (Skype Technologies S.A.)
HKCU\...\Run: [ceegaix] C:\Dokumente und Einstellungen\Dust\ceegaix.exe /w [86016 2013-07-06] ()
HKCU\...\Run: [Microsoft Firewall 2.9] C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\WMPRWISE.EXE [160389 2013-07-06] ()
HKCR\...409d6c4515e9\InprocServer32: [Default-shell32] C:\RECYCLER\S-1-5-21-1275210071-926492609-682003330-1004\$d6f0497ef4d323fcbc4a52237e3baa9b\o. ATTENTION! ====> ZeroAccess?
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programme\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: LeapFTP Internet Explorer Hook - {A5479DA1-7843-43A7-B5C0-BE342C77B629} - C:\PROGRA~1\LEAPFT~1.0\lftpie.dll (LeapWare)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
BHO: No Name - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Programme\PicLensIE\cooliris.dll (Cooliris Inc.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Programme\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKCU -&Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU -&Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
DPF: {0D9392CD-A784-4FCA-9342-0F75F7D7C8CB} hxxp://www.cltnet.de/login/dplaunch.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ipp - No CLSID Value -
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Winsock: Catalog5 04 C:\Programme\Bonjour\mdnsNSP.dll [94208] (Apple Computer, Inc.)
Winsock: Catalog9 01 C:\Programme\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Programme\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 21 C:\Programme\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Mozilla\Firefox\Profiles\bq0opndw.default
FF Homepage: about :home
FF NetworkProxy: "no_proxies_on", "*.local"
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=1.6.0_37 - C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Programme\Microsoft Silverlight\npctrl.1.0.30716.0.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Programme\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Programme\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: SpeedAnalysis.com - C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [jqs@sun.com] C:\Programme\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Programme\Java\jre6\lib\deploy\jqs\ff
========================== Services (Whitelisted) =================
S3 Adobe LM Service; C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2009-03-06] (Adobe Systems)
R2 AdobeActiveFileMonitor4.0; C:\Programme\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe [102400 2005-10-03] ()
R2 AntiVirSchedulerService; C:\Programme\Avira\AntiVir Desktop\sched.exe [86224 2012-05-09] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Programme\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-09] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE [465360 2012-05-09] (Avira Operations GmbH & Co. KG)
S3 Autodesk Licensing Service; C:\Programme\Gemeinsame Dateien\Autodesk Shared\Service\AdskScSrv.exe [77944 2010-12-14] (Autodesk)
R2 Bonjour Service; C:\Programme\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.)
S3 FLEXnet Licensing Service; C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2009-07-18] (Macrovision Europe Ltd.)
R2 ForcewareWebInterface; C:\Programme\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [20543 2006-04-03] (Apache Software Foundation)
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [135664 2010-02-02] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [135664 2010-02-02] (Google Inc.)
S3 gusvc; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [194032 2012-08-21] (Google)
R3 hpqcxs08; C:\Programme\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.)
R2 hpqddsvc; C:\Programme\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.)
S3 IDriverT; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation)
S2 MSSQL$SQLEXPRESS; c:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29178224 2007-02-10] (Microsoft Corporation)
S4 MSSQLServerADHelper; c:\Programme\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45272 2005-10-14] (Microsoft Corporation)
R2 nSvcIp; C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe [131131 2006-07-13] (NVIDIA Corporation)
R2 nSvcLog; C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [65599 2006-07-13] (NVIDIA Corporation)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [89136 2003-07-28] (Microsoft Corporation)
S4 SQLBrowser; c:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe [242544 2007-02-10] (Microsoft Corporation)
R2 SQLWriter; c:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe [89968 2007-02-10] (Microsoft Corporation)
R2 syshost32; C:\WINDOWS\Installer\{AA4EC929-9F4C-F92F-E21B-A65FC2029741}\syshost.exe [55296 2013-07-06] ()
R2 TeamViewer8; C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe [4150112 2013-06-13] (TeamViewer GmbH)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
S2 AviraUpgradeService; "C:\WINDOWS\TEMP\AVSETUP_4f5a43dc\avupgsvc.exe" /TEMPSTART:""C:\WINDOWS\TEMP\AVSETUP_4f5a43dc\setup.exe" /NOTEMPCLEANUP /CROSSUPGRADE" [x]
R2 JavaQuickStarterService; "C:\Programme\Java\jre6\bin\jqs.exe" -service -config "C:\Programme\Java\jre6\lib\deploy\jqs\jqs.conf" [x]
==================== Drivers (Whitelisted) ====================
R2 ASCTRM; C:\Windows\System32\Drivers\ASCTRM.sys [8552 2009-03-05] (Windows (R) 2000 DDK provider)
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [83392 2012-05-09] (Avira GmbH)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137928 2012-05-09] (Avira GmbH)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [36000 2011-09-16] (Avira GmbH)
S3 BVRPMPR5; C:\WINDOWS\system32\drivers\BVRPMPR5.SYS [49904 2008-06-18] (Avanquest Software)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 DCamUSBSQTECH; C:\Windows\System32\Drivers\SQcaptur.sys [29744 2003-10-28] (Service & Quality Technology.)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-14] (Windows (R) Server 2003 DDK provider)
R3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [18688 2001-08-17] (Microsoft Corporation)
S3 NABTSFEC; C:\Windows\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-14] (Microsoft Corporation)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [57856 2006-07-11] (NVIDIA Corporation)
R0 nvgts; C:\Windows\System32\DRIVERS\nvgts.sys [102400 2007-08-09] (NVIDIA Corporation)
R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [20480 2006-07-11] (NVIDIA Corporation)
R3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S3 SLIP; C:\Windows\System32\DRIVERS\SLIP.sys [11136 2008-04-14] (Microsoft Corporation)
S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-10-08] (Avira GmbH)
S3 streamip; C:\Windows\System32\DRIVERS\StreamIP.sys [15232 2008-04-14] (Microsoft Corporation)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2003-01-10] (America Online, Inc.)
S3 WSTCODEC; C:\Windows\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-14] (Microsoft Corporation)
S4 IntelIde; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-06 18:33 - 2013-07-06 18:33 - 00060928 ____A C:\Windows\System32\Drivers\5b1c0562b57cda28.sys
2013-07-06 12:21 - 2013-07-06 12:21 - 00001478 ____A C:\AdwCleaner[S3].txt
2013-07-06 12:20 - 2013-07-06 12:20 - 00000364 ____A C:\AdwCleaner[S2].txt
2013-07-06 11:19 - 2013-07-06 11:19 - 00000000 ____D C:\FRST
2013-07-05 21:46 - 2013-07-05 21:46 - 00000000 ____D C:\Windows\ERUNT
2013-07-05 21:45 - 2013-07-06 12:33 - 00000000 ____D C:\JRT
2013-07-05 21:16 - 2013-07-05 21:16 - 00029922 ____A C:\AdwCleaner[S1].txt
2013-07-05 21:15 - 2013-07-05 21:15 - 00030024 ____A C:\AdwCleaner[R1].txt
2013-07-05 15:00 - 2013-07-05 15:00 - 00012506 ____A C:\Windows\KB2779562.log
2013-07-05 15:00 - 2013-07-05 15:00 - 00000000 __HDC C:\Windows\$NtUninstallKB2802968$
2013-07-05 15:00 - 2013-07-05 15:00 - 00000000 __HDC C:\Windows\$NtUninstallKB2779562$
2013-07-05 15:00 - 2013-07-05 15:00 - 00000000 __HDC C:\Windows\$NtUninstallKB2758857$
2013-07-05 14:59 - 2013-07-05 14:59 - 00000000 __HDC C:\Windows\$NtUninstallKB2780091$
2013-07-05 14:58 - 2013-07-05 14:58 - 00000000 __HDC C:\Windows\$NtUninstallKB2753842-v2$
2013-07-05 14:57 - 2013-07-05 14:58 - 00015709 ____A C:\Windows\KB2753842-v2.log
2013-07-05 14:57 - 2013-07-05 14:57 - 00015666 ____A C:\Windows\KB2807986.log
2013-07-05 14:57 - 2013-07-05 14:57 - 00014415 ____A C:\Windows\KB2820197.log
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2839229$
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2820917$
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2820197$
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2807986$
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2770660$
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2757638$
2013-07-05 14:56 - 2013-07-05 14:56 - 00000000 __HDC C:\Windows\$NtUninstallKB2813345$
2013-07-05 14:56 - 2013-07-05 14:56 - 00000000 __HDC C:\Windows\$NtUninstallKB2749655$
2013-07-05 14:56 - 2013-07-05 14:56 - 00000000 __HDC C:\Windows\$NtUninstallKB2727528$
2013-07-05 14:56 - 2013-07-05 14:56 - 00000000 __HDC C:\Windows\$NtUninstallKB2661254-v2$
2013-07-05 14:55 - 2013-07-05 14:56 - 00014196 ____A C:\Windows\KB2838727-IE8.log
2013-07-05 14:55 - 2013-07-05 14:55 - 00000000 __HDC C:\Windows\$NtUninstallKB2829361$
2013-07-05 12:55 - 2013-07-05 12:57 - 00000664 ____A C:\Windows\System32\d3d9caps.dat
2013-07-05 10:31 - 2013-07-05 15:00 - 00021367 ____A C:\Windows\KB2758857.log
2013-07-05 10:31 - 2013-07-05 15:00 - 00021004 ____A C:\Windows\KB2802968.log
2013-07-05 10:31 - 2013-07-05 14:59 - 00020697 ____A C:\Windows\KB2780091.log
2013-07-05 10:30 - 2013-07-05 14:58 - 00019923 ____A C:\Windows\KB2719985.log
2013-07-05 10:30 - 2013-07-05 14:57 - 00020327 ____A C:\Windows\KB2820917.log
2013-07-05 10:30 - 2013-07-05 14:57 - 00019512 ____A C:\Windows\KB2757638.log
2013-07-05 10:30 - 2013-07-05 14:57 - 00019488 ____A C:\Windows\KB2839229.log
2013-07-05 10:30 - 2013-07-05 14:56 - 00019619 ____A C:\Windows\KB2813345.log
2013-07-05 10:30 - 2013-07-05 14:56 - 00019495 ____A C:\Windows\KB2749655.log
2013-07-05 10:30 - 2013-07-05 14:56 - 00019070 ____A C:\Windows\KB2661254-v2.log
2013-07-05 10:30 - 2013-07-05 14:56 - 00018650 ____A C:\Windows\KB2727528.log
2013-07-05 10:30 - 2013-02-12 02:32 - 00012928 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\usb8023x.sys
2013-07-05 10:29 - 2013-07-05 14:55 - 00013004 ____A C:\Windows\KB2829361.log
2013-07-04 22:49 - 2013-07-04 22:49 - 00006220 ____A C:\Windows\KB946648.log
2013-07-04 22:49 - 2013-07-04 22:49 - 00006020 ____A C:\Windows\KB973687.log
2013-07-04 22:13 - 2013-07-04 22:13 - 00000236 ____A C:\Windows\DtcInstall.log
2013-07-04 22:11 - 2013-07-04 22:13 - 00002162 ____A C:\Windows\wmsetup.log
2013-07-04 22:11 - 2013-07-04 22:11 - 00000187 ____A C:\Windows\spupdsvc.log.1.log
2013-07-04 21:56 - 2013-07-04 21:56 - 00000000 __HDC C:\Windows\$NtUninstallKB956744$
2013-07-04 21:53 - 2013-07-04 22:13 - 00069530 ____A C:\Windows\spupdsvc.log
2013-07-04 21:53 - 2013-07-04 21:53 - 00000173 ____A C:\Windows\cmsetacl.log
2013-07-04 21:52 - 2013-07-04 21:52 - 00000311 ____A C:\Windows\sessmgr.setup.log
2013-07-04 21:52 - 2013-07-04 21:52 - 00000000 ____D C:\Windows\System32\bits
2013-07-04 21:52 - 2008-04-14 07:51 - 00086016 ____C (Sipro Lab Telecom Inc.) C:\Windows\System32\dllcache\sl_anet.acm
2013-07-04 21:52 - 2008-04-14 07:50 - 00294912 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msaud32.acm
2013-07-04 21:52 - 2008-04-14 07:50 - 00290816 ____C (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\System32\dllcache\l3codeca.acm
2013-07-04 21:52 - 2007-06-26 11:30 - 00572557 ____C C:\Windows\System32\dllcache\rtuner.wmv
2013-07-04 21:52 - 2007-06-26 11:30 - 00457607 ____C C:\Windows\System32\dllcache\mdlib.wmv
2013-07-04 21:52 - 2007-06-26 11:30 - 00381425 ____C C:\Windows\System32\dllcache\copycd.wmv
2013-07-04 21:52 - 2007-06-26 11:30 - 00375519 ____C C:\Windows\System32\dllcache\nuskin.wmv
2013-07-04 21:52 - 2007-06-26 11:30 - 00354468 ____C C:\Windows\System32\dllcache\wmpaud1.wav
2013-07-04 21:52 - 2007-06-26 11:30 - 00343204 ____C C:\Windows\System32\dllcache\wmpaud7.wav
2013-07-04 21:52 - 2007-06-26 11:30 - 00343204 ____C C:\Windows\System32\dllcache\wmpaud6.wav
2013-07-04 21:52 - 2007-06-26 11:30 - 00300969 ____C C:\Windows\System32\dllcache\viz.wmv
2013-07-04 21:52 - 2007-06-26 11:30 - 00172196 ____C C:\Windows\System32\dllcache\wmpaud9.wav
2013-07-04 21:52 - 2007-06-26 11:30 - 00172196 ____C C:\Windows\System32\dllcache\wmpaud8.wav
2013-07-04 21:52 - 2007-06-26 11:30 - 00172196 ____C C:\Windows\System32\dllcache\wmpaud3.wav
2013-07-04 21:52 - 2007-06-26 11:30 - 00086196 ____C C:\Windows\System32\dllcache\wmpaud5.wav
2013-07-04 21:52 - 2007-06-26 11:30 - 00086180 ____C C:\Windows\System32\dllcache\wmpaud4.wav
2013-07-04 21:52 - 2007-06-26 11:30 - 00086180 ____C C:\Windows\System32\dllcache\wmpaud2.wav
2013-07-04 21:52 - 2007-06-26 11:30 - 00022060 ____C C:\Windows\System32\dllcache\npds.zip
2013-07-04 21:52 - 2007-06-26 11:30 - 00010457 ____C C:\Windows\System32\dllcache\wmptour.hta
2013-07-04 21:52 - 2007-06-26 11:30 - 00009585 ____C C:\Windows\System32\dllcache\controls.css
2013-07-04 21:52 - 2007-06-26 11:30 - 00008298 ____C C:\Windows\System32\dllcache\contents.htm
2013-07-04 21:52 - 2007-06-26 11:30 - 00006878 ____C C:\Windows\System32\dllcache\controls.js
2013-07-04 21:52 - 2007-06-26 11:30 - 00005971 ____C C:\Windows\System32\dllcache\events.js
2013-07-04 21:52 - 2007-06-26 11:30 - 00003187 ____C C:\Windows\System32\dllcache\tour.js
2013-07-04 21:52 - 2007-06-26 11:30 - 00001771 ____C C:\Windows\System32\dllcache\wmptour.css
2013-07-04 21:52 - 2007-06-26 11:30 - 00001148 ____C C:\Windows\System32\dllcache\snd.htm
2013-07-04 21:52 - 2007-06-26 11:30 - 00000420 ____C C:\Windows\System32\dllcache\wmploc.js
2013-07-04 21:52 - 2007-06-26 11:29 - 00097117 ____C C:\Windows\System32\dllcache\mplayer2.hlp
2013-07-04 21:52 - 2007-06-26 11:29 - 00001885 ____C C:\Windows\System32\dllcache\mplayer2.cnt
2013-07-04 21:52 - 2007-06-26 11:26 - 00000403 ____C C:\Windows\System32\dllcache\npdrmv2.zip
2013-07-04 21:52 - 2007-02-21 10:45 - 00076456 ____C C:\Windows\System32\dllcache\wmplayer.adm
2013-07-04 21:52 - 2007-02-21 10:36 - 00026141 ____C C:\Windows\System32\dllcache\wmplay.chm
2013-07-04 21:52 - 2007-02-21 10:25 - 00660224 ____C C:\Windows\System32\dllcache\wmplayer.chm
2013-07-04 21:52 - 2007-02-21 10:25 - 00184109 ____C C:\Windows\System32\dllcache\compact.wmz
2013-07-04 21:52 - 2007-02-21 10:25 - 00084531 ____C C:\Windows\System32\dllcache\plyr_err.chm
2013-07-04 21:52 - 2007-02-21 10:25 - 00066132 ____C C:\Windows\System32\dllcache\revert.wmz
2013-07-04 21:52 - 2007-02-21 10:25 - 00001476 ____C C:\Windows\System32\dllcache\plylst5.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00001471 ____C C:\Windows\System32\dllcache\plylst6.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00001471 ____C C:\Windows\System32\dllcache\plylst12.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00001469 ____C C:\Windows\System32\dllcache\plylst3.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00001467 ____C C:\Windows\System32\dllcache\plylst4.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00001261 ____C C:\Windows\System32\dllcache\plylst1.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00001055 ____C C:\Windows\System32\dllcache\plylst2.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00001047 ____C C:\Windows\System32\dllcache\plylst7.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00001038 ____C C:\Windows\System32\dllcache\plylst8.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00000807 ____C C:\Windows\System32\dllcache\plylst11.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00000800 ____C C:\Windows\System32\dllcache\plylst10.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00000782 ____C C:\Windows\System32\dllcache\plylst9.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00000779 ____C C:\Windows\System32\dllcache\plylst13.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00000778 ____C C:\Windows\System32\dllcache\plylst14.wpl
2013-07-04 21:52 - 2007-02-21 10:25 - 00000725 ____C C:\Windows\System32\dllcache\plylst15.wpl
2013-07-04 21:49 - 2008-04-14 07:53 - 00278559 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\wmv8ds32.ax
2013-07-04 21:49 - 2008-04-14 07:53 - 00258048 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\wmvds32.ax
2013-07-04 21:49 - 2008-04-14 07:53 - 00221184 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msadds32.ax
2013-07-04 21:49 - 2008-04-14 07:53 - 00069632 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msscds32.ax
2013-07-04 21:49 - 2008-04-14 07:52 - 00303616 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\wmstream.dll
2013-07-04 21:49 - 2008-04-14 07:52 - 00294912 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\dlimport.exe
2013-07-04 21:49 - 2008-04-14 07:51 - 00847898 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msdxm.ocx
2013-07-04 21:49 - 2008-04-14 07:51 - 00004126 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msdxmlc.dll
2013-07-04 21:48 - 2013-07-05 15:00 - 00123654 ____A C:\Windows\FaxSetup.log
2013-07-04 21:48 - 2013-07-05 15:00 - 00059069 ____A C:\Windows\ocgen.log
2013-07-04 21:48 - 2013-07-05 15:00 - 00046238 ____A C:\Windows\tsoc.log
2013-07-04 21:48 - 2013-07-05 15:00 - 00038302 ____A C:\Windows\comsetup.log
2013-07-04 21:48 - 2013-07-05 15:00 - 00022951 ____A C:\Windows\ntdtcsetup.log
2013-07-04 21:48 - 2013-07-05 15:00 - 00018674 ____A C:\Windows\iis6.log
2013-07-04 21:48 - 2013-07-05 15:00 - 00006317 ____A C:\Windows\ocmsn.log
2013-07-04 21:48 - 2013-07-05 15:00 - 00006024 ____A C:\Windows\msgsocm.log
2013-07-04 21:48 - 2013-07-05 15:00 - 00001355 ____A C:\Windows\imsins.log
2013-07-04 21:48 - 2013-07-05 15:00 - 00001355 ____A C:\Windows\imsins.BAK
2013-07-04 21:48 - 2013-07-05 14:58 - 00014614 ____A C:\Windows\updspapi.log
2013-07-04 21:48 - 2006-12-29 00:31 - 00019569 ____A C:\Windows\004243_.tmp
2013-07-04 21:47 - 2013-07-04 21:47 - 00000581 ____A C:\Windows\medctroc.Log
2013-07-04 21:42 - 2013-07-05 22:50 - 00000060 ____A C:\Windows\setupact.log
2013-07-04 21:42 - 2013-07-04 21:42 - 00000000 ____A C:\Windows\setuperr.log
2013-07-04 21:41 - 2013-07-05 15:00 - 00039520 ____A C:\Windows\setupapi.log
2013-07-04 21:41 - 2013-07-04 22:08 - 00331707 ____A C:\Windows\svcpack.log
2013-07-04 20:43 - 2013-07-04 20:43 - 00000000 ____D C:\Windows\pss
2013-07-04 13:38 - 2013-07-04 13:38 - 00003221 ____A C:\Windows\KB935448.log
2013-07-04 13:37 - 2013-07-04 21:56 - 00034059 ____A C:\Windows\KB956744.log
==================== One Month Modified Files and Folders ========
2013-07-08 10:11 - 2011-12-29 17:37 - 00000000 ____D C:\allewebprojekte
2013-07-08 09:54 - 2009-03-04 13:42 - 00000000 ____A C:\Windows\System32\nmp.log
2013-07-08 09:53 - 2009-03-04 13:49 - 00182038 ____A C:\Windows\System32\nvapps.xml
2013-07-08 09:52 - 2010-02-02 12:22 - 00001086 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-08 09:52 - 2009-03-04 13:34 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-08 09:52 - 2009-03-04 13:20 - 00000159 ____A C:\Windows\wiadebug.log
2013-07-08 09:52 - 2009-03-04 13:20 - 00000050 ____A C:\Windows\wiaservc.log
2013-07-08 09:52 - 2008-04-14 14:00 - 00013646 ____A C:\Windows\System32\wpa.dbl
2013-07-06 19:42 - 2010-02-08 13:58 - 02084926 ____A C:\Windows\WindowsUpdate.log
2013-07-06 19:42 - 2010-02-02 12:22 - 00001090 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-06 19:42 - 2009-03-04 13:34 - 00032610 ____A C:\Windows\SchedLgU.Txt
2013-07-06 19:27 - 2012-04-09 12:41 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-06 19:18 - 2009-03-04 13:18 - 00000000 ___RD C:\Programme
2013-07-06 18:38 - 2011-01-11 21:09 - 00000000 ____D C:\Windows\System32\NtmsData
2013-07-06 18:34 - 2009-03-04 13:29 - 00000000 ____D C:\Windows\Registration
2013-07-06 18:33 - 2013-07-06 18:33 - 00060928 ____A C:\Windows\System32\Drivers\5b1c0562b57cda28.sys
2013-07-06 12:33 - 2013-07-05 21:45 - 00000000 ____D C:\JRT
2013-07-06 12:21 - 2013-07-06 12:21 - 00001478 ____A C:\AdwCleaner[S3].txt
2013-07-06 12:20 - 2013-07-06 12:20 - 00000364 ____A C:\AdwCleaner[S2].txt
2013-07-06 11:19 - 2013-07-06 11:19 - 00000000 ____D C:\FRST
2013-07-05 22:50 - 2013-07-04 21:42 - 00000060 ____A C:\Windows\setupact.log
2013-07-05 21:46 - 2013-07-05 21:46 - 00000000 ____D C:\Windows\ERUNT
2013-07-05 21:16 - 2013-07-05 21:16 - 00029922 ____A C:\AdwCleaner[S1].txt
2013-07-05 21:15 - 2013-07-05 21:15 - 00030024 ____A C:\AdwCleaner[R1].txt
2013-07-05 21:06 - 2009-03-04 14:14 - 00000211 _RASH C:\boot.ini
2013-07-05 21:06 - 2008-04-14 14:00 - 00000664 ____A C:\Windows\win.ini
2013-07-05 21:06 - 2008-04-14 14:00 - 00000227 ____A C:\Windows\system.ini
2013-07-05 19:37 - 2009-05-15 19:54 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-05 18:14 - 2009-03-04 13:15 - 01594864 ____A C:\Windows\System32\FNTCACHE.DAT
2013-07-05 15:03 - 2009-03-04 13:18 - 01279496 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-05 15:00 - 2013-07-05 15:00 - 00012506 ____A C:\Windows\KB2779562.log
2013-07-05 15:00 - 2013-07-05 15:00 - 00000000 __HDC C:\Windows\$NtUninstallKB2802968$
2013-07-05 15:00 - 2013-07-05 15:00 - 00000000 __HDC C:\Windows\$NtUninstallKB2779562$
2013-07-05 15:00 - 2013-07-05 15:00 - 00000000 __HDC C:\Windows\$NtUninstallKB2758857$
2013-07-05 15:00 - 2013-07-05 10:31 - 00021367 ____A C:\Windows\KB2758857.log
2013-07-05 15:00 - 2013-07-05 10:31 - 00021004 ____A C:\Windows\KB2802968.log
2013-07-05 15:00 - 2013-07-04 21:48 - 00123654 ____A C:\Windows\FaxSetup.log
2013-07-05 15:00 - 2013-07-04 21:48 - 00059069 ____A C:\Windows\ocgen.log
2013-07-05 15:00 - 2013-07-04 21:48 - 00046238 ____A C:\Windows\tsoc.log
2013-07-05 15:00 - 2013-07-04 21:48 - 00038302 ____A C:\Windows\comsetup.log
2013-07-05 15:00 - 2013-07-04 21:48 - 00022951 ____A C:\Windows\ntdtcsetup.log
2013-07-05 15:00 - 2013-07-04 21:48 - 00018674 ____A C:\Windows\iis6.log
2013-07-05 15:00 - 2013-07-04 21:48 - 00006317 ____A C:\Windows\ocmsn.log
2013-07-05 15:00 - 2013-07-04 21:48 - 00006024 ____A C:\Windows\msgsocm.log
2013-07-05 15:00 - 2013-07-04 21:48 - 00001355 ____A C:\Windows\imsins.log
2013-07-05 15:00 - 2013-07-04 21:48 - 00001355 ____A C:\Windows\imsins.BAK
2013-07-05 15:00 - 2013-07-04 21:41 - 00039520 ____A C:\Windows\setupapi.log
2013-07-05 15:00 - 2009-03-04 14:25 - 00253254 ____A C:\Windows\System32\TZLog.log
2013-07-05 14:59 - 2013-07-05 14:59 - 00000000 __HDC C:\Windows\$NtUninstallKB2780091$
2013-07-05 14:59 - 2013-07-05 10:31 - 00020697 ____A C:\Windows\KB2780091.log
2013-07-05 14:58 - 2013-07-05 14:58 - 00000000 __HDC C:\Windows\$NtUninstallKB2753842-v2$
2013-07-05 14:58 - 2013-07-05 14:57 - 00015709 ____A C:\Windows\KB2753842-v2.log
2013-07-05 14:58 - 2013-07-05 10:30 - 00019923 ____A C:\Windows\KB2719985.log
2013-07-05 14:58 - 2013-07-04 21:48 - 00014614 ____A C:\Windows\updspapi.log
2013-07-05 14:57 - 2013-07-05 14:57 - 00015666 ____A C:\Windows\KB2807986.log
2013-07-05 14:57 - 2013-07-05 14:57 - 00014415 ____A C:\Windows\KB2820197.log
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2839229$
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2820917$
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2820197$
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2807986$
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2770660$
2013-07-05 14:57 - 2013-07-05 14:57 - 00000000 __HDC C:\Windows\$NtUninstallKB2757638$
2013-07-05 14:57 - 2013-07-05 10:30 - 00020327 ____A C:\Windows\KB2820917.log
2013-07-05 14:57 - 2013-07-05 10:30 - 00019512 ____A C:\Windows\KB2757638.log
2013-07-05 14:57 - 2013-07-05 10:30 - 00019488 ____A C:\Windows\KB2839229.log
2013-07-05 14:57 - 2009-03-04 14:19 - 00000000 ___HD C:\Windows\$hf_mig$
2013-07-05 14:56 - 2013-07-05 14:56 - 00000000 __HDC C:\Windows\$NtUninstallKB2813345$
2013-07-05 14:56 - 2013-07-05 14:56 - 00000000 __HDC C:\Windows\$NtUninstallKB2749655$
2013-07-05 14:56 - 2013-07-05 14:56 - 00000000 __HDC C:\Windows\$NtUninstallKB2727528$
2013-07-05 14:56 - 2013-07-05 14:56 - 00000000 __HDC C:\Windows\$NtUninstallKB2661254-v2$
2013-07-05 14:56 - 2013-07-05 14:55 - 00014196 ____A C:\Windows\KB2838727-IE8.log
2013-07-05 14:56 - 2013-07-05 10:30 - 00019619 ____A C:\Windows\KB2813345.log
2013-07-05 14:56 - 2013-07-05 10:30 - 00019495 ____A C:\Windows\KB2749655.log
2013-07-05 14:56 - 2013-07-05 10:30 - 00019070 ____A C:\Windows\KB2661254-v2.log
2013-07-05 14:56 - 2013-07-05 10:30 - 00018650 ____A C:\Windows\KB2727528.log
2013-07-05 14:55 - 2013-07-05 14:55 - 00000000 __HDC C:\Windows\$NtUninstallKB2829361$
2013-07-05 14:55 - 2013-07-05 10:29 - 00013004 ____A C:\Windows\KB2829361.log
2013-07-05 14:55 - 2009-09-12 12:09 - 00000000 ____D C:\Windows\ie8updates
2013-07-05 12:57 - 2013-07-05 12:55 - 00000664 ____A C:\Windows\System32\d3d9caps.dat
2013-07-04 22:49 - 2013-07-04 22:49 - 00006220 ____A C:\Windows\KB946648.log
2013-07-04 22:49 - 2013-07-04 22:49 - 00006020 ____A C:\Windows\KB973687.log
2013-07-04 22:13 - 2013-07-04 22:13 - 00000236 ____A C:\Windows\DtcInstall.log
2013-07-04 22:13 - 2013-07-04 22:11 - 00002162 ____A C:\Windows\wmsetup.log
2013-07-04 22:13 - 2013-07-04 21:53 - 00069530 ____A C:\Windows\spupdsvc.log
2013-07-04 22:13 - 2009-03-04 13:31 - 00316640 ____A C:\Windows\WMSysPr9.prx
2013-07-04 22:11 - 2013-07-04 22:11 - 00000187 ____A C:\Windows\spupdsvc.log.1.log
2013-07-04 22:11 - 2012-12-05 13:41 - 00000090 ____A C:\Windows\System32\spupdwxp.log
2013-07-04 22:09 - 2009-03-04 14:09 - 00000000 ____D C:\Windows\security
2013-07-04 22:08 - 2013-07-04 21:41 - 00331707 ____A C:\Windows\svcpack.log
2013-07-04 21:56 - 2013-07-04 21:56 - 00000000 __HDC C:\Windows\$NtUninstallKB956744$
2013-07-04 21:56 - 2013-07-04 13:37 - 00034059 ____A C:\Windows\KB956744.log
2013-07-04 21:53 - 2013-07-04 21:53 - 00000173 ____A C:\Windows\cmsetacl.log
2013-07-04 21:52 - 2013-07-04 21:52 - 00000311 ____A C:\Windows\sessmgr.setup.log
2013-07-04 21:52 - 2013-07-04 21:52 - 00000000 ____D C:\Windows\System32\bits
2013-07-04 21:52 - 2009-03-04 14:09 - 00000000 ____D C:\Windows\PeerNet
2013-07-04 21:52 - 2009-03-04 14:09 - 00000000 ____D C:\Windows\Help
2013-07-04 21:49 - 2009-03-04 14:09 - 00000000 ____D C:\Windows\System32\usmt
2013-07-04 21:49 - 2009-03-04 13:29 - 00000000 ____D C:\Windows\System32\Restore
2013-07-04 21:49 - 2009-03-04 13:29 - 00000000 ____D C:\Windows\srchasst
2013-07-04 21:48 - 2012-12-05 11:51 - 00000000 __HDC C:\Windows\$NtServicePackUninstall$
2013-07-04 21:48 - 2009-03-04 13:41 - 00000000 ____D C:\Windows\System32\ReinstallBackups
2013-07-04 21:47 - 2013-07-04 21:47 - 00000581 ____A C:\Windows\medctroc.Log
2013-07-04 21:42 - 2013-07-04 21:42 - 00000000 ____A C:\Windows\setuperr.log
2013-07-04 21:16 - 2009-07-28 17:51 - 00000000 ____D C:\Windows\System32\LogFiles
2013-07-04 21:14 - 2009-03-04 14:09 - 00000000 ____D C:\Windows\Provisioning
2013-07-04 20:43 - 2013-07-04 20:43 - 00000000 ____D C:\Windows\pss
2013-07-04 13:38 - 2013-07-04 13:38 - 00003221 ____A C:\Windows\KB935448.log
2013-07-03 13:47 - 2013-03-08 15:19 - 00000000 ____D C:\vue
2013-06-13 10:27 - 2012-04-09 12:41 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-13 10:27 - 2011-12-28 17:10 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-08 21:10 - 2012-12-18 12:10 - 00000000 ____D C:\canopy
2013-06-08 21:00 - 2012-09-12 12:44 - 00000000 ____D C:\dänemark0912
ZeroAccess:
C:\RECYCLER\S-1-5-21-1275210071-926492609-682003330-1004\$d6f0497ef4d323fcbc4a52237e3baa9b
ZeroAccess:
C:\RECYCLER\S-1-5-18\$d6f0497ef4d323fcbc4a52237e3baa9b
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2008-04-14 14:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2008-04-14 14:00] - [2008-04-14 14:00] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2008-04-14 14:00] - [2008-04-14 14:00] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================
--- --- ---