Und Teil 2:
Code:
Alles auswählen Aufklappen ATTFilter
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-30 12:17 - 2014-03-30 12:17 - 00837112 _____ () C:\windows\Minidump\033014-33234-01.dmp
2014-03-30 12:16 - 2014-03-30 12:16 - 1439110558 _____ () C:\windows\MEMORY.DMP
2014-03-30 02:06 - 2014-03-30 02:06 - 02347384 _____ (ESET) C:\Users\dkoen_000\Downloads\esetsmartinstaller_enu.exe
2014-03-30 01:57 - 2014-03-30 01:57 - 00001139 _____ () C:\Users\dkoen_000\Downloads\MBAM.txt
2014-03-30 01:27 - 2014-03-30 01:27 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-03-30 01:26 - 2014-03-30 01:26 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\dkoen_000\Downloads\revosetup95.exe
2014-03-30 00:58 - 2014-03-30 00:58 - 00043283 _____ () C:\Users\dkoen_000\Downloads\Addition.txt
2014-03-30 00:36 - 2014-03-30 12:24 - 00016679 _____ () C:\Users\dkoen_000\Downloads\FRST.txt
2014-03-30 00:35 - 2014-03-30 00:35 - 02157056 _____ (Farbar) C:\Users\dkoen_000\Downloads\FRST64.exe
2014-03-29 23:57 - 2014-03-29 23:57 - 00000000 ___SH () C:\DkHyperbootSync
2014-03-29 21:56 - 2014-03-29 21:56 - 00004766 _____ () C:\Users\dkoen_000\Documents\cc_20140329_205634.reg
2014-03-29 21:39 - 2014-03-29 21:55 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
2014-03-29 21:39 - 2014-01-19 09:38 - 00270496 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-03-29 21:38 - 2014-03-30 04:50 - 00097265 _____ () C:\windows\WindowsUpdate.log
2014-03-29 21:32 - 2014-03-29 21:32 - 00009192 _____ () C:\Users\dkoen_000\Documents\install.txt
2014-03-29 21:31 - 2014-03-29 21:31 - 00003928 _____ () C:\Users\dkoen_000\Documents\cc_20140329_203150.reg
2014-03-29 21:21 - 2014-03-29 21:11 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-03-29 21:12 - 2014-03-29 21:25 - 00127268 _____ () C:\zoek-results.log
2014-03-29 21:11 - 2014-03-29 21:16 - 00000000 ____D () C:\zoek_backup
2014-03-29 20:51 - 2014-03-30 12:24 - 00000000 ____D () C:\FRST
2014-03-29 19:29 - 2014-03-29 19:29 - 00004644 _____ () C:\Users\dkoen_000\Documents\cc_20140329_182942.reg
2014-03-29 18:42 - 2014-03-30 01:47 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-29 18:42 - 2014-03-29 18:42 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-29 18:42 - 2014-03-29 18:42 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-03-29 18:42 - 2014-03-05 10:26 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-03-29 18:42 - 2014-03-05 10:26 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-03-29 18:42 - 2014-03-05 10:26 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-03-29 18:27 - 2014-03-29 18:27 - 00020850 _____ () C:\Users\dkoen_000\Documents\cc_20140329_172727.reg
2014-03-29 18:27 - 2014-03-29 18:27 - 00000342 _____ () C:\Users\dkoen_000\Documents\cc_20140329_172740.reg
2014-03-29 18:18 - 2014-03-29 18:18 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-03-29 18:18 - 2014-03-29 18:18 - 00000000 _____ () C:\autoexec.bat
2014-03-29 18:17 - 2014-03-29 18:36 - 00000000 ____D () C:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-03-29 17:49 - 2014-03-29 17:49 - 00000000 ____D () C:\windows\ERUNT
2014-03-29 17:41 - 2014-03-29 17:47 - 00000000 ___RD () C:\windows\BrowserChoice
2014-03-29 17:36 - 2014-03-29 17:36 - 01038974 _____ (Thisisu) C:\Users\dkoen_000\Downloads\JRT.exe
2014-03-29 17:30 - 2014-03-29 17:30 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Foxit Software
2014-03-29 16:05 - 2014-03-29 16:05 - 00104680 _____ () C:\Users\dkoen_000\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-29 16:05 - 2014-03-29 16:05 - 00000000 ____D () C:\Users\dkoen_000\Documents\Neuer Ordner
2014-03-29 16:05 - 2014-03-29 16:05 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\PDF Architect
2014-03-29 15:13 - 2014-03-29 15:13 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-03-29 15:13 - 2014-03-29 15:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-03-29 15:07 - 2014-03-29 15:07 - 00000000 ____D () C:\windows\system32\MRT
2014-03-29 15:07 - 2014-02-04 20:09 - 88567024 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-03-28 23:57 - 2014-03-28 23:57 - 00367200 _____ (Acronis) C:\windows\system32\Drivers\afcdp.sys
2014-03-28 23:57 - 2014-03-28 23:57 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\F6C2F7B5-D690-4C9B-92B9-12944FA97007
2014-03-28 23:52 - 2014-03-28 23:52 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Acronis
2014-03-28 23:50 - 2014-03-28 23:58 - 00000000 ____D () C:\ProgramData\Acronis
2014-03-28 23:50 - 2014-03-28 23:57 - 01464096 _____ (Acronis International GmbH) C:\windows\system32\Drivers\tdrpman.sys
2014-03-28 23:50 - 2014-03-28 23:50 - 01120032 _____ (Acronis International GmbH) C:\windows\system32\Drivers\tib.sys
2014-03-28 23:50 - 2014-03-28 23:50 - 00269600 _____ (Acronis International GmbH) C:\windows\system32\Drivers\snapman.sys
2014-03-28 23:50 - 2014-03-28 23:50 - 00198432 _____ (Acronis International GmbH) C:\windows\system32\Drivers\tib_mounter.sys
2014-03-28 23:50 - 2014-03-28 23:50 - 00116000 _____ (Acronis International GmbH) C:\windows\system32\Drivers\fltsrv.sys
2014-03-28 23:50 - 2014-03-28 23:50 - 00000000 ____D () C:\Program Files (x86)\Acronis
2014-03-28 23:05 - 2014-03-28 23:05 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\IDT
2014-03-28 21:39 - 2014-03-29 17:27 - 00013389 _____ () C:\Users\dkoen_000\Documents\Umzugsservice.xlsx
2014-03-28 21:39 - 2014-03-28 22:05 - 00000000 ____D () C:\Users\dkoen_000\Documents\Persönlich
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\webkit
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Versicherungen
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Unfall 14.11.2011
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\TT259_Lead_Vocals_EZmix_Pack
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\TT205_EZX_Pop_Update
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\TT205_EZX_Pop_MIDI
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Toontrack
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Telefon
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Teisco
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Strom
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Stock
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Soltau
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Shopping
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Santorin 2005
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\samsung
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Planet Crown
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\PDF-Dateien
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Outlook-Dateien
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\OneNote-Notizbücher
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Nokia Suite
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\NeroVision
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Native Instruments
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Muttern
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Job
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\iZotope Ozone Presets
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\IK Multimedia
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\mobackups
2014-03-28 21:39 - 2014-03-27 18:03 - 600147313 _____ () C:\Users\dkoen_000\Documents\Thunderbird 3.1.4 (de) - 2014-03-27.pcv
2014-03-28 21:39 - 2014-02-28 20:44 - 00019575 _____ () C:\Users\dkoen_000\Documents\Zählerstand.xlsx
2014-03-28 21:39 - 2013-12-09 19:59 - 00033569 _____ () C:\Users\dkoen_000\Documents\Telefonvergleich.xlsx
2014-03-28 21:39 - 2012-09-09 00:12 - 00024576 _____ () C:\Users\dkoen_000\Documents\sfg_Aufträge.xls
2014-03-28 21:39 - 2012-04-16 18:34 - 00019456 _____ () C:\Users\dkoen_000\Documents\Stromverbrauch.xls
2014-03-28 21:39 - 2012-02-12 11:01 - 00013824 _____ () C:\Users\dkoen_000\Documents\Rauchfrei.xls
2014-03-28 21:39 - 2010-12-30 13:35 - 00003037 _____ () C:\Users\dkoen_000\Documents\NL_Test.csv
2014-03-28 21:39 - 2005-12-05 22:13 - 00017328 _____ () C:\Users\dkoen_000\Documents\ISO1.nri
2014-03-28 21:39 - 2004-01-25 22:31 - 00244422 _____ () C:\Users\dkoen_000\Documents\Nova Scotia Bilder.nri
2014-03-28 21:39 - 2003-11-16 21:07 - 00058332 _____ () C:\Users\dkoen_000\Documents\Nova Scotia 2003.nri
2014-03-28 21:38 - 2014-03-29 16:05 - 00000000 ____D () C:\Users\dkoen_000\Documents\Geld
2014-03-28 21:38 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Homepage
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Haus
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Hagstrom
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Gesundheit
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\FFOutput
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Falk
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\EZmix_WIN
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Excel
2014-03-28 21:38 - 2013-11-11 12:29 - 2954103586 _____ () C:\Users\dkoen_000\Documents\FalkData.zip
2014-03-28 21:38 - 2012-09-22 08:47 - 00040960 _____ () C:\Users\dkoen_000\Documents\Getränkemarktvergleich_2012.05.13.xls
2014-03-28 21:38 - 2011-06-23 21:34 - 00068096 _____ () C:\Users\dkoen_000\Documents\Gewicht_20110106.xls
2014-03-28 21:38 - 2010-09-16 22:33 - 00044544 _____ () C:\Users\dkoen_000\Documents\Gewicht_20100527.xls
2014-03-28 21:38 - 2009-10-02 21:22 - 00031232 _____ () C:\Users\dkoen_000\Documents\Gewicht_20090712.xls
2014-03-28 21:36 - 2014-03-28 21:36 - 00000000 ____D () C:\Users\dkoen_000\Documents\Eigene eBooks
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\eBay
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\DSSPlayer
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\DSL
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Comedy
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Coaching
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Checklisten
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Best Service
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Auto
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Anti-Stress
2014-03-28 21:31 - 2014-03-28 13:06 - 00014722 _____ () C:\Users\dkoen_000\Documents\cc_20140328_120603.reg
2014-03-28 21:31 - 2014-03-05 14:31 - 00241136 _____ () C:\Users\dkoen_000\Documents\cc_20140305_133057.reg
2014-03-28 21:31 - 2013-11-14 00:47 - 00069356 _____ () C:\Users\dkoen_000\Documents\cc_20131113_234700.reg
2014-03-28 21:31 - 2013-11-14 00:47 - 00000442 _____ () C:\Users\dkoen_000\Documents\cc_20131113_234731.reg
2014-03-28 21:31 - 2013-09-22 00:04 - 00004404 _____ () C:\Users\dkoen_000\Documents\cc_20130922_000356.reg
2014-03-28 21:31 - 2013-09-07 13:10 - 00030916 _____ () C:\Users\dkoen_000\Documents\cc_20130907_131043.reg
2014-03-28 21:31 - 2013-08-03 14:54 - 00013316 _____ () C:\Users\dkoen_000\Documents\cc_20130803_145449.reg
2014-03-28 21:31 - 2013-07-03 20:01 - 00033720 _____ () C:\Users\dkoen_000\Documents\cc_20130703_200132.reg
2014-03-28 21:31 - 2013-06-16 21:46 - 00030813 _____ () C:\Users\dkoen_000\Documents\Diät_2013.xlsx
2014-03-28 21:31 - 2013-05-25 17:04 - 00076384 _____ () C:\Users\dkoen_000\Documents\cc_20130525_170433.reg
2014-03-28 21:31 - 2013-04-07 16:36 - 00009522 _____ () C:\Users\dkoen_000\Documents\Dedi wird 50.xlsx
2014-03-28 21:31 - 2013-02-12 01:07 - 00038768 _____ () C:\Users\dkoen_000\Documents\cc_20130212_000735.reg
2014-03-28 21:31 - 2012-09-15 09:32 - 00032412 _____ () C:\Users\dkoen_000\Documents\Diät_2012.xlsx
2014-03-28 21:31 - 2012-08-26 14:38 - 02160459 _____ () C:\Users\dkoen_000\Documents\Attachments.zip
2014-03-28 21:31 - 2012-08-18 10:29 - 00079360 _____ () C:\Users\dkoen_000\Documents\Diät_2012.xls
2014-03-28 21:31 - 2012-07-08 19:16 - 00001326 _____ () C:\Users\dkoen_000\Documents\cc_20120708_191653.reg
2014-03-28 21:31 - 2012-07-08 19:10 - 00003660 _____ () C:\Users\dkoen_000\Documents\cc_20120708_191053.reg
2014-03-28 21:31 - 2012-07-08 00:22 - 00002404 _____ () C:\Users\dkoen_000\Documents\cc_20120708_002154.reg
2014-03-28 21:31 - 2012-06-24 00:49 - 00022034 _____ () C:\Users\dkoen_000\Documents\cc_20120624_004858.reg
2014-03-28 21:31 - 2012-05-28 00:17 - 00000672 _____ () C:\Users\dkoen_000\Documents\cc_20120528_001707.reg
2014-03-28 21:31 - 2012-05-28 00:17 - 00000326 _____ () C:\Users\dkoen_000\Documents\cc_20120528_001728.reg
2014-03-28 21:31 - 2012-05-28 00:16 - 00029624 _____ () C:\Users\dkoen_000\Documents\cc_20120528_001639.reg
2014-03-28 21:31 - 2012-04-21 12:03 - 00000332 _____ () C:\Users\dkoen_000\Documents\cc_20120421_120330.reg
2014-03-28 21:31 - 2012-04-21 12:02 - 00015192 _____ () C:\Users\dkoen_000\Documents\cc_20120421_120252.reg
2014-03-28 21:31 - 2012-03-02 23:30 - 00017508 _____ () C:\Users\dkoen_000\Documents\cc_20120302_223005.reg
2014-03-28 21:31 - 2012-03-01 22:42 - 00069162 _____ () C:\Users\dkoen_000\Documents\cc_20120301_214205.reg
2014-03-28 21:31 - 2007-12-06 23:32 - 00026112 _____ () C:\Users\dkoen_000\Documents\Diät.xls
2014-03-28 21:31 - 2007-07-21 12:07 - 00020480 _____ () C:\Users\dkoen_000\Documents\Diascans.xls
2014-03-28 21:31 - 2003-10-21 02:00 - 00004329 _____ () C:\Users\dkoen_000\Documents\Canada.nra
2014-03-28 20:49 - 2014-01-08 03:46 - 00325464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBXHCI.SYS
2014-03-28 20:49 - 2014-01-08 03:41 - 01530712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2014-03-28 20:49 - 2014-01-08 03:41 - 00382808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2014-03-28 20:49 - 2014-01-04 17:54 - 00138240 _____ () C:\windows\system32\OEMLicense.dll
2014-03-28 20:49 - 2014-01-04 17:08 - 00103936 _____ () C:\windows\SysWOW64\OEMLicense.dll
2014-03-28 20:49 - 2014-01-04 16:08 - 00206336 _____ (Microsoft Corporation) C:\windows\system32\WSClient.dll
2014-03-28 20:49 - 2014-01-04 15:53 - 00174592 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSClient.dll
2014-03-28 20:49 - 2014-01-03 01:54 - 00461312 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll
2014-03-28 20:49 - 2014-01-03 01:48 - 00336896 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsGdiConverter.dll
2014-03-28 20:49 - 2014-01-01 03:55 - 01720560 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2014-03-28 20:49 - 2014-01-01 03:52 - 00481944 _____ (Microsoft Corporation) C:\windows\system32\mfsvr.dll
2014-03-28 20:49 - 2014-01-01 02:56 - 01472048 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2014-03-28 20:49 - 2014-01-01 02:55 - 00381168 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsvr.dll
2014-03-28 20:49 - 2014-01-01 01:59 - 00802816 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFMediaEngine.dll
2014-03-28 20:49 - 2014-01-01 01:57 - 01214976 _____ (Microsoft Corporation) C:\windows\system32\schedsvc.dll
2014-03-28 20:49 - 2014-01-01 01:56 - 00960512 _____ (Microsoft Corporation) C:\windows\system32\MFMediaEngine.dll
2014-03-28 20:49 - 2013-12-31 01:34 - 00218112 _____ (Microsoft Corporation) C:\windows\SysWOW64\sti.dll
2014-03-28 20:49 - 2013-12-31 01:33 - 00770560 _____ (Microsoft Corporation) C:\windows\SysWOW64\ReAgent.dll
2014-03-28 20:49 - 2013-12-31 01:32 - 00303616 _____ (Microsoft Corporation) C:\windows\system32\sti.dll
2014-03-28 20:49 - 2013-12-31 01:31 - 00947712 _____ (Microsoft Corporation) C:\windows\system32\reseteng.dll
2014-03-28 20:49 - 2013-12-31 01:31 - 00914944 _____ (Microsoft Corporation) C:\windows\system32\ReAgent.dll
2014-03-28 20:49 - 2013-12-27 17:09 - 00419160 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
2014-03-28 20:49 - 2013-12-27 10:57 - 00842752 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.dll
2014-03-28 20:49 - 2013-12-27 10:57 - 00628736 _____ (Microsoft Corporation) C:\windows\system32\SettingSyncHost.exe
2014-03-28 20:49 - 2013-12-27 10:23 - 00749056 _____ (Microsoft Corporation) C:\windows\system32\SettingSyncCore.dll
2014-03-28 20:49 - 2013-12-27 09:03 - 00630272 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsSpellCheckingFacility.dll
2014-03-28 20:49 - 2013-12-27 09:03 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSyncHost.exe
2014-03-28 20:49 - 2013-12-27 08:37 - 00588800 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSyncCore.dll
2014-03-28 20:49 - 2013-12-21 09:21 - 00376320 _____ (Microsoft Corporation) C:\windows\system32\pnrpsvc.dll
2014-03-28 20:49 - 2013-12-17 09:21 - 00408576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdbss.sys
2014-03-28 20:49 - 2013-12-14 08:31 - 13949440 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Xaml.dll
2014-03-28 20:49 - 2013-12-14 08:19 - 18576384 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Xaml.dll
2014-03-28 20:49 - 2013-12-13 12:54 - 00131160 _____ (Microsoft Corporation) C:\windows\system32\easinvoker.exe
2014-03-28 20:49 - 2013-12-13 08:36 - 00178176 _____ (Microsoft Corporation) C:\windows\system32\easwrt.dll
2014-03-28 20:49 - 2013-12-13 07:32 - 00140800 _____ (Microsoft Corporation) C:\windows\SysWOW64\easwrt.dll
2014-03-28 20:49 - 2013-12-09 10:05 - 21199256 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2014-03-28 20:49 - 2013-12-09 06:51 - 18643560 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2014-03-28 20:49 - 2013-11-04 13:50 - 02143744 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
2014-03-28 20:49 - 2013-11-04 03:30 - 01765376 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2014-03-28 20:49 - 2013-10-05 16:21 - 02140888 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2014-03-28 20:49 - 2013-10-05 16:21 - 00516496 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2014-03-28 20:49 - 2013-10-05 14:05 - 01765384 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d11.dll
2014-03-28 20:49 - 2013-10-05 14:05 - 00406400 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxgi.dll
2014-03-28 20:48 - 2013-09-26 08:34 - 00688640 _____ (Microsoft Corporation) C:\windows\system32\MrmIndexer.dll
2014-03-28 20:48 - 2013-09-26 08:34 - 00515072 _____ (Microsoft Corporation) C:\windows\SysWOW64\MrmIndexer.dll
2014-03-28 20:47 - 2013-10-23 13:29 - 00044936 _____ (Microsoft Corporation) C:\windows\system32\wldp.dll
2014-03-28 20:47 - 2013-10-23 13:21 - 00155480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2014-03-28 20:47 - 2013-10-23 13:13 - 00171864 _____ (Microsoft Corporation) C:\windows\system32\kd_02_8086.dll
2014-03-28 20:47 - 2013-10-22 09:55 - 02328872 _____ (Microsoft Corporation) C:\windows\explorer.exe
2014-03-28 20:47 - 2013-10-22 08:03 - 02065448 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
2014-03-28 20:47 - 2013-10-22 07:15 - 00558080 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2014-03-28 20:47 - 2013-10-22 06:04 - 00618496 _____ (Microsoft Corporation) C:\windows\SysWOW64\apphelp.dll
2014-03-28 20:47 - 2013-10-22 05:56 - 00186880 _____ (Microsoft Corporation) C:\windows\system32\WorkFoldersShell.dll
2014-03-28 20:47 - 2013-10-22 05:44 - 00761856 _____ (Microsoft Corporation) C:\windows\system32\WorkfoldersControl.dll
2014-03-28 20:47 - 2013-10-22 04:38 - 01362944 _____ (Microsoft Corporation) C:\windows\SysWOW64\user32.dll
2014-03-28 20:47 - 2013-10-22 04:22 - 00381952 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2014-03-28 20:47 - 2013-10-22 04:13 - 01704448 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2014-03-28 20:47 - 2013-10-22 03:53 - 01584128 _____ (Microsoft Corporation) C:\windows\system32\workfolderssvc.dll
2014-03-28 20:47 - 2013-10-19 06:48 - 00607744 _____ (Microsoft Corporation) C:\windows\system32\comdlg32.dll
2014-03-28 20:47 - 2013-10-19 06:03 - 00531968 _____ (Microsoft Corporation) C:\windows\SysWOW64\comdlg32.dll
2014-03-28 20:47 - 2013-10-19 05:26 - 01231360 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.dll
2014-03-28 20:47 - 2013-10-19 05:14 - 00888832 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.dll
2014-03-28 20:47 - 2013-10-16 11:34 - 00518656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WWAHost.exe
2014-03-28 20:47 - 2013-10-16 11:33 - 00631296 _____ (Microsoft Corporation) C:\windows\system32\WWAHost.exe
2014-03-28 20:47 - 2013-10-13 05:06 - 00258904 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdyboost.sys
2014-03-28 20:47 - 2013-10-13 04:43 - 00708616 _____ (Microsoft Corporation) C:\windows\system32\iuilp.dll
2014-03-28 20:47 - 2013-10-10 18:26 - 00317616 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2014-03-28 20:47 - 2013-10-10 18:26 - 00104320 _____ (Microsoft Corporation) C:\windows\system32\ncryptsslp.dll
2014-03-28 20:47 - 2013-10-10 16:53 - 00235960 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2014-03-28 20:47 - 2013-10-10 16:53 - 00088272 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncryptsslp.dll
2014-03-28 20:47 - 2013-10-10 13:53 - 00160768 _____ (Microsoft Corporation) C:\windows\system32\AppxAllUserStore.dll
2014-03-28 20:47 - 2013-10-10 13:38 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2014-03-28 20:47 - 2013-10-10 13:21 - 00139776 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxAllUserStore.dll
2014-03-28 20:47 - 2013-10-08 12:28 - 00523096 _____ (Microsoft Corporation) C:\windows\system32\Drivers\acpi.sys
2014-03-28 20:47 - 2013-10-08 08:46 - 00113152 _____ (Microsoft Corporation) C:\windows\system32\shsetup.dll
2014-03-28 20:47 - 2013-10-08 07:58 - 00094208 _____ (Microsoft Corporation) C:\windows\SysWOW64\shsetup.dll
2014-03-28 20:47 - 2013-10-08 07:50 - 00656384 _____ (Microsoft Corporation) C:\windows\system32\dnsapi.dll
2014-03-28 20:47 - 2013-10-08 07:48 - 00255488 _____ (Microsoft Corporation) C:\windows\system32\dnsrslvr.dll
2014-03-28 20:47 - 2013-10-08 07:15 - 00492544 _____ (Microsoft Corporation) C:\windows\SysWOW64\dnsapi.dll
2014-03-28 20:47 - 2013-10-08 07:09 - 01160704 _____ (Microsoft Corporation) C:\windows\system32\Windows.Web.Http.dll
2014-03-28 20:47 - 2013-10-08 06:50 - 00903168 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
2014-03-28 20:47 - 2013-10-08 06:50 - 00762368 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Web.Http.dll
2014-03-28 20:47 - 2013-10-07 09:21 - 00054776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2014-03-28 20:47 - 2013-10-07 04:13 - 03532288 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2014-03-28 20:47 - 2013-10-05 17:25 - 00057176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\stornvme.sys
2014-03-28 20:47 - 2013-10-05 16:21 - 00699840 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2014-03-28 20:47 - 2013-10-05 14:05 - 00578952 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10level9.dll
2014-03-28 20:47 - 2013-10-05 13:01 - 00454656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2014-03-28 20:47 - 2013-10-05 11:36 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2014-03-28 20:47 - 2013-10-05 11:18 - 01011712 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2014-03-28 20:47 - 2013-10-05 11:07 - 00830464 _____ (Microsoft Corporation) C:\windows\system32\samsrv.dll
2014-03-28 20:47 - 2013-10-05 10:56 - 01147904 _____ (Microsoft Corporation) C:\windows\system32\UIAutomationCore.dll
2014-03-28 20:47 - 2013-10-05 10:55 - 00226304 _____ (Microsoft Corporation) C:\windows\system32\miutils.dll
2014-03-28 20:47 - 2013-10-05 10:40 - 00795648 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll
2014-03-28 20:47 - 2013-10-05 10:24 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\miutils.dll
2014-03-28 20:47 - 2013-10-05 10:21 - 00920064 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAutomationCore.dll
2014-03-28 20:47 - 2013-10-05 10:15 - 00286208 _____ (Microsoft Corporation) C:\windows\system32\pcsvDevice.dll
2014-03-28 20:47 - 2013-10-05 09:43 - 00578560 _____ (Microsoft Corporation) C:\windows\system32\Windows.Networking.BackgroundTransfer.dll
2014-03-28 20:47 - 2013-10-05 09:35 - 00411648 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2014-03-28 20:47 - 2013-10-04 10:10 - 00533504 _____ (Microsoft Corporation) C:\windows\system32\AppReadiness.dll
2014-03-28 20:47 - 2013-09-19 09:19 - 00117760 _____ (Microsoft Corporation) C:\windows\system32\WorkFoldersRes.dll
2014-03-28 20:47 - 2013-09-19 08:27 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\WorkFolders.exe
2014-03-28 20:47 - 2013-09-19 08:23 - 00117760 _____ (Microsoft Corporation) C:\windows\SysWOW64\WorkFoldersRes.dll
2014-03-28 20:47 - 2013-09-17 11:06 - 01067080 _____ (Microsoft Corporation) C:\windows\system32\mfasfsrcsnk.dll
2014-03-28 20:47 - 2013-09-17 11:06 - 00465960 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2014-03-28 20:47 - 2013-09-17 08:31 - 00883184 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfasfsrcsnk.dll
2014-03-28 20:47 - 2013-09-17 08:31 - 00326024 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2014-03-28 20:47 - 2013-09-17 06:37 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\dafBth.dll
2014-03-28 20:47 - 2013-09-14 16:07 - 02134120 _____ (Microsoft Corporation) C:\windows\system32\d3d9.dll
2014-03-28 20:47 - 2013-09-14 16:00 - 00391512 _____ (Microsoft Corporation) C:\windows\system32\tsmf.dll
2014-03-28 20:47 - 2013-09-14 14:39 - 01799944 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d9.dll
2014-03-28 20:47 - 2013-09-14 14:33 - 00345552 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsmf.dll
2014-03-28 20:47 - 2013-09-14 12:05 - 00338944 _____ (Microsoft Corporation) C:\windows\system32\rdpclip.exe
2014-03-28 20:47 - 2013-09-14 11:11 - 00433664 _____ (Microsoft Corporation) C:\windows\system32\ipnathlp.dll
2014-03-28 20:47 - 2013-09-13 10:22 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\ftp.exe
2014-03-28 20:47 - 2013-09-13 09:47 - 00049152 _____ (Microsoft Corporation) C:\windows\SysWOW64\ftp.exe
2014-03-28 20:47 - 2013-09-12 10:45 - 00101888 _____ (Microsoft Corporation) C:\windows\system32\eappgnui.dll
2014-03-28 20:47 - 2013-09-12 10:08 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\eapp3hst.dll
2014-03-28 20:47 - 2013-09-12 10:08 - 00103424 _____ (Microsoft Corporation) C:\windows\system32\WiFiDisplay.dll
2014-03-28 20:47 - 2013-09-12 10:02 - 00093184 _____ (Microsoft Corporation) C:\windows\SysWOW64\eappgnui.dll
2014-03-28 20:47 - 2013-09-12 09:44 - 00331776 _____ (Microsoft Corporation) C:\windows\system32\eapphost.dll
2014-03-28 20:47 - 2013-09-12 09:37 - 00245248 _____ (Microsoft Corporation) C:\windows\SysWOW64\eapp3hst.dll
2014-03-28 20:47 - 2013-09-12 09:37 - 00184832 _____ (Microsoft Corporation) C:\windows\system32\dafWfdProvider.dll
2014-03-28 20:47 - 2013-09-12 09:21 - 00262144 _____ (Microsoft Corporation) C:\windows\SysWOW64\eapphost.dll
2014-03-28 20:47 - 2013-09-12 09:16 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\eappcfg.dll
2014-03-28 20:47 - 2013-09-12 09:01 - 00272896 _____ (Microsoft Corporation) C:\windows\SysWOW64\eappcfg.dll
2014-03-28 20:47 - 2013-09-10 06:52 - 00132608 _____ (Microsoft Corporation) C:\windows\system32\msched.dll
2014-03-28 20:45 - 2013-12-09 02:34 - 01227264 _____ (Microsoft Corporation) C:\windows\system32\mispace.dll
2014-03-28 20:45 - 2013-12-09 02:04 - 00980480 _____ (Microsoft Corporation) C:\windows\SysWOW64\mispace.dll
2014-03-28 20:45 - 2013-11-27 17:34 - 03210528 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2014-03-28 20:45 - 2013-11-27 17:27 - 00809872 _____ (Microsoft Corporation) C:\windows\system32\mfmp4srcsnk.dll
2014-03-28 20:45 - 2013-11-27 16:00 - 00663680 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmp4srcsnk.dll
2014-03-28 20:45 - 2013-11-27 15:47 - 02804528 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2vdec.dll
2014-03-28 20:45 - 2013-11-27 14:02 - 00142848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ipnat.sys
2014-03-28 20:45 - 2013-11-27 12:24 - 00306688 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2014-03-28 20:45 - 2013-11-27 11:46 - 00273920 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2014-03-28 20:45 - 2013-11-27 11:41 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\psmsrv.dll
2014-03-28 20:45 - 2013-11-27 11:17 - 00263168 _____ (Microsoft Corporation) C:\windows\system32\bisrv.dll
2014-03-28 20:45 - 2013-11-27 11:10 - 00273408 _____ (Microsoft Corporation) C:\windows\system32\Windows.Graphics.dll
2014-03-28 20:45 - 2013-11-27 10:58 - 01503232 _____ (Microsoft Corporation) C:\windows\system32\wlansvc.dll
2014-03-28 20:45 - 2013-11-27 10:56 - 00218112 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Graphics.dll
2014-03-28 20:45 - 2013-11-26 15:20 - 01399176 _____ (Microsoft Corporation) C:\windows\system32\winmde.dll
2014-03-28 20:45 - 2013-11-26 15:20 - 01374384 _____ (Microsoft Corporation) C:\windows\system32\wmpmde.dll
2014-03-28 20:45 - 2013-11-26 13:44 - 01204968 _____ (Microsoft Corporation) C:\windows\SysWOW64\winmde.dll
2014-03-28 20:45 - 2013-11-25 03:45 - 00142680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2014-03-28 20:45 - 2013-11-25 03:32 - 01119064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2014-03-28 20:45 - 2013-11-25 01:30 - 00513536 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-03-28 20:45 - 2013-11-25 01:28 - 00589824 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-03-28 20:45 - 2013-11-23 14:47 - 00032088 _____ (Microsoft Corporation) C:\windows\system32\ploptin.dll
2014-03-28 20:45 - 2013-11-23 09:13 - 00024064 _____ (Microsoft Corporation) C:\windows\system32\bi.dll
2014-03-28 20:45 - 2013-11-23 09:13 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\BtaMPM.sys
2014-03-28 20:45 - 2013-11-23 09:08 - 00403456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2014-03-28 20:45 - 2013-11-23 06:50 - 00282112 _____ (Microsoft Corporation) C:\windows\system32\SystemEventsBrokerServer.dll
2014-03-28 20:45 - 2013-11-23 05:19 - 02617344 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2014-03-28 20:45 - 2013-11-23 05:15 - 02295808 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2014-03-28 20:45 - 2013-11-21 08:58 - 00207872 _____ (Microsoft Corporation) C:\windows\system32\deviceregistration.dll
2014-03-28 20:45 - 2013-11-21 08:26 - 01415680 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2014-03-28 20:45 - 2013-11-15 16:59 - 00470016 _____ (Microsoft Corporation) C:\windows\system32\mfds.dll
2014-03-28 20:45 - 2013-11-15 16:25 - 00433664 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfds.dll
2014-03-28 20:45 - 2013-11-15 16:08 - 00202240 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
2014-03-28 20:45 - 2013-11-15 15:24 - 00834048 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2014-03-28 20:45 - 2013-10-31 02:29 - 00745336 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2014-03-28 20:45 - 2013-10-31 01:41 - 00552624 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2014-03-28 20:45 - 2013-09-21 09:17 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\BulkOperationHost.exe
2014-03-28 20:45 - 2013-09-21 07:20 - 00369664 _____ (Microsoft Corporation) C:\windows\system32\wlanmsm.dll
2014-03-28 20:45 - 2013-09-21 07:09 - 00300544 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanmsm.dll
2014-03-28 20:42 - 2013-10-10 12:34 - 01085952 _____ (Microsoft Corporation) C:\windows\system32\twinui.appcore.dll
2014-03-28 20:42 - 2013-10-10 12:27 - 00869888 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.appcore.dll
2014-03-28 20:41 - 2013-11-11 04:48 - 00039768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\intelpep.sys
2014-03-28 20:41 - 2013-11-09 08:37 - 01756160 _____ (Microsoft Corporation) C:\windows\system32\WMPDMC.exe
2014-03-28 20:41 - 2013-11-09 07:56 - 01391104 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPDMC.exe
2014-03-28 20:41 - 2013-11-08 12:26 - 00358896 _____ (Microsoft Corporation) C:\windows\system32\dcomp.dll
2014-03-28 20:41 - 2013-11-08 06:43 - 00254464 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentClient.dll
2014-03-28 20:41 - 2013-11-08 06:16 - 00225792 _____ (Microsoft Corporation) C:\windows\SysWOW64\dcomp.dll
2014-03-28 20:41 - 2013-11-08 06:15 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppXDeploymentClient.dll
2014-03-28 20:41 - 2013-11-08 05:41 - 01302528 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentServer.dll
2014-03-28 20:41 - 2013-11-08 05:14 - 00922624 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentExtensions.dll
2014-03-28 20:41 - 2013-11-05 16:19 - 00566784 _____ (Microsoft Corporation) C:\windows\system32\wpncore.dll
2014-03-28 20:41 - 2013-11-04 15:07 - 01843712 _____ (Microsoft Corporation) C:\windows\system32\Display.dll
2014-03-28 20:41 - 2013-11-04 12:32 - 02570240 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers.dll
2014-03-28 20:41 - 2013-11-04 04:28 - 01816576 _____ (Microsoft Corporation) C:\windows\SysWOW64\Display.dll
2014-03-28 20:41 - 2013-11-01 13:39 - 00086872 _____ (Microsoft Corporation) C:\windows\system32\Drivers\pdc.sys
2014-03-28 20:41 - 2013-11-01 08:08 - 00747008 _____ (Microsoft Corporation) C:\windows\system32\wlidcli.dll
2014-03-28 20:41 - 2013-11-01 07:57 - 00544768 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlidcli.dll
2014-03-28 20:41 - 2013-10-31 02:58 - 00372568 _____ (Microsoft Corporation) C:\windows\system32\Drivers\spaceport.sys
2014-03-28 20:41 - 2013-10-31 02:42 - 07399256 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2014-03-28 20:41 - 2013-10-26 03:54 - 00146776 _____ (Microsoft Corporation) C:\windows\system32\Drivers\SerCx2.sys
2014-03-28 20:41 - 2013-10-24 11:31 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\CredentialMigrationHandler.dll
2014-03-28 20:41 - 2013-10-24 11:12 - 00027136 _____ (Microsoft Corporation) C:\windows\SysWOW64\CredentialMigrationHandler.dll
2014-03-28 20:41 - 2013-10-17 13:21 - 02896896 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll
2014-03-28 20:41 - 2013-10-17 12:36 - 02266624 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll
2014-03-28 20:39 - 2013-09-25 12:25 - 00783504 _____ (Microsoft Corporation) C:\windows\system32\mfnetcore.dll
2014-03-28 20:39 - 2013-09-25 10:58 - 00648648 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfnetcore.dll
2014-03-28 20:39 - 2013-09-24 07:54 - 02050560 _____ (Microsoft Corporation) C:\windows\system32\SRH.dll
2014-03-28 20:39 - 2013-09-24 07:10 - 01741824 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRH.dll
2014-03-28 20:39 - 2013-09-24 07:05 - 01245696 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2014-03-28 20:39 - 2013-09-24 05:56 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\Windows.Networking.BackgroundTransfer.ContentPrefetchTask.dll
2014-03-28 20:39 - 2013-09-21 13:48 - 00534048 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2014-03-28 20:39 - 2013-09-21 12:53 - 01534504 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2014-03-28 20:39 - 2013-09-21 12:53 - 00934856 _____ (Microsoft Corporation) C:\windows\system32\mfsrcsnk.dll
2014-03-28 20:39 - 2013-09-21 12:53 - 00366688 _____ (Microsoft Corporation) C:\windows\system32\msvproc.dll
2014-03-28 20:39 - 2013-09-21 12:45 - 00171968 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2014-03-28 20:39 - 2013-09-21 11:23 - 00427096 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2014-03-28 20:39 - 2013-09-21 11:12 - 01092896 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2014-03-28 20:39 - 2013-09-21 11:09 - 00796928 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsrcsnk.dll
2014-03-28 20:39 - 2013-09-21 09:58 - 00675328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2014-03-28 20:39 - 2013-09-21 09:50 - 00240128 _____ (Microsoft Corporation) C:\windows\system32\WinSCard.dll
2014-03-28 20:39 - 2013-09-21 08:33 - 11366912 _____ (Microsoft Corporation) C:\windows\system32\glcndFilter.dll
2014-03-28 20:39 - 2013-09-21 07:59 - 00940544 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2014-03-28 20:39 - 2013-09-21 07:57 - 00363520 _____ (Microsoft Corporation) C:\windows\system32\livessp.dll
2014-03-28 20:39 - 2013-09-21 07:56 - 08712704 _____ (Microsoft Corporation) C:\windows\SysWOW64\glcndFilter.dll
2014-03-28 20:39 - 2013-09-21 07:38 - 00365568 _____ (Microsoft Corporation) C:\windows\system32\wcmsvc.dll
2014-03-28 20:39 - 2013-09-21 07:34 - 01555456 _____ (Microsoft Corporation) C:\windows\system32\wlidsvc.dll
2014-03-28 20:39 - 2013-09-21 07:31 - 00756224 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2014-03-28 20:39 - 2013-09-21 07:26 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\vpnike.dll
2014-03-28 20:39 - 2013-09-21 07:10 - 12028416 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2014-03-28 20:39 - 2013-09-21 07:05 - 08875008 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2014-03-28 20:39 - 2013-09-21 06:44 - 01662464 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Immersive.dll
2014-03-28 20:39 - 2013-09-21 06:39 - 01455616 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Immersive.dll
2014-03-28 20:39 - 2013-09-19 07:08 - 01150976 _____ (Microsoft Corporation) C:\windows\system32\Windows.Globalization.dll
2014-03-28 20:39 - 2013-09-19 07:01 - 00401920 _____ (Microsoft Corporation) C:\windows\system32\wlidprov.dll
2014-03-28 20:39 - 2013-09-19 06:37 - 00802816 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Globalization.dll
2014-03-28 20:39 - 2013-09-19 06:32 - 00314368 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlidprov.dll
2014-03-28 20:39 - 2013-09-19 06:27 - 01730560 _____ (Microsoft Corporation) C:\windows\system32\dui70.dll
2014-03-28 20:39 - 2013-09-19 06:27 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Windows.Security.Authentication.OnlineId.dll
2014-03-28 20:39 - 2013-09-19 06:11 - 01344000 _____ (Microsoft Corporation) C:\windows\SysWOW64\dui70.dll
2014-03-28 20:39 - 2013-09-19 06:10 - 00524288 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2014-03-28 20:39 - 2013-09-19 05:59 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\twinapi.dll
2014-03-28 20:39 - 2013-09-19 05:55 - 00552448 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinapi.dll
2014-03-28 20:39 - 2013-09-19 05:32 - 00570880 _____ (Microsoft Corporation) C:\windows\system32\SettingSync.dll
2014-03-28 20:39 - 2013-09-17 07:00 - 00453632 _____ (Microsoft Corporation) C:\windows\system32\wbiosrvc.dll
2014-03-28 20:39 - 2013-09-12 09:37 - 00459776 _____ (Microsoft Corporation) C:\windows\system32\wcncsvc.dll
2014-03-28 20:39 - 2013-09-04 07:47 - 00492032 _____ (Microsoft Corporation) C:\windows\system32\tpmvsc.dll
2014-03-28 20:38 - 2013-09-26 11:20 - 00556032 _____ (Microsoft Corporation) C:\windows\system32\recimg.exe
2014-03-28 20:38 - 2013-09-26 09:32 - 00638464 _____ (Microsoft Corporation) C:\windows\system32\wimgapi.dll
2014-03-28 20:38 - 2013-09-26 09:14 - 00528896 _____ (Microsoft Corporation) C:\windows\SysWOW64\wimgapi.dll
2014-03-28 20:38 - 2013-09-25 09:32 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\BthRadioMedia.dll
2014-03-28 20:38 - 2013-09-25 07:40 - 00098304 _____ (Microsoft Corporation) C:\windows\system32\windows.immersiveshell.serviceprovider.dll
2014-03-28 20:38 - 2013-09-24 08:55 - 00284160 _____ (Microsoft Corporation) C:\windows\system32\mcbuilder.exe
2014-03-28 20:38 - 2013-09-24 07:59 - 00253952 _____ (Microsoft Corporation) C:\windows\SysWOW64\mcbuilder.exe
2014-03-28 20:38 - 2013-09-21 14:10 - 00579416 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys
2014-03-28 20:38 - 2013-09-21 14:10 - 00236376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\sdbus.sys
2014-03-28 20:38 - 2013-09-21 14:10 - 00151384 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dumpsd.sys
2014-03-28 20:38 - 2013-09-21 13:50 - 00528048 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2014-03-28 20:38 - 2013-09-21 13:48 - 00123480 _____ (Microsoft Corporation) C:\windows\system32\dwmapi.dll
2014-03-28 20:38 - 2013-09-21 12:56 - 00101208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2014-03-28 20:38 - 2013-09-21 11:23 - 00098104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmapi.dll
2014-03-28 20:38 - 2013-09-21 11:09 - 00312936 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvproc.dll
2014-03-28 20:38 - 2013-09-21 09:57 - 00207360 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2014-03-28 20:38 - 2013-09-21 09:55 - 00097280 _____ (Microsoft Corporation) C:\windows\system32\Drivers\agilevpn.sys
2014-03-28 20:38 - 2013-09-21 08:55 - 00168448 _____ (Microsoft Corporation) C:\windows\SysWOW64\WinSCard.dll
2014-03-28 20:38 - 2013-09-21 08:01 - 00200704 _____ (Microsoft Corporation) C:\windows\system32\ReInfo.dll
2014-03-28 20:38 - 2013-09-21 07:43 - 00194560 _____ (Microsoft Corporation) C:\windows\system32\dpapisrv.dll
2014-03-28 20:38 - 2013-09-21 07:37 - 00101376 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2014-03-28 20:38 - 2013-09-21 07:02 - 00158208 _____ (Microsoft Corporation) C:\windows\system32\thumbcache.dll
2014-03-28 20:38 - 2013-09-21 06:54 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\thumbcache.dll
2014-03-28 20:38 - 2013-09-21 06:38 - 01057792 _____ (Microsoft Corporation) C:\windows\SysWOW64\printui.dll
2014-03-28 20:38 - 2013-09-21 06:38 - 00102400 _____ (Microsoft Corporation) C:\windows\SysWOW64\efswrt.dll
2014-03-28 20:38 - 2013-09-21 06:37 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\efswrt.dll
2014-03-28 20:38 - 2013-09-21 06:36 - 01185280 _____ (Microsoft Corporation) C:\windows\system32\printui.dll
2014-03-28 20:38 - 2013-09-19 08:39 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\pcaui.dll
2014-03-28 20:38 - 2013-09-19 08:17 - 00456192 _____ (Microsoft Corporation) C:\windows\system32\sysmon.ocx
2014-03-28 20:38 - 2013-09-19 07:47 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\pcaui.dll
2014-03-28 20:38 - 2013-09-19 07:29 - 00393728 _____ (Microsoft Corporation) C:\windows\SysWOW64\sysmon.ocx
2014-03-28 20:38 - 2013-09-19 06:25 - 00471552 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2014-03-28 20:38 - 2013-09-19 05:34 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSync.dll
2014-03-28 20:38 - 2013-09-17 11:18 - 00467800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
2014-03-28 20:38 - 2013-09-17 08:58 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2014-03-28 20:38 - 2013-09-17 07:26 - 00079360 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2014-03-28 20:38 - 2013-09-17 07:15 - 01225728 _____ (Microsoft Corporation) C:\windows\system32\usercpl.dll
2014-03-28 20:38 - 2013-09-17 06:09 - 01160704 _____ (Microsoft Corporation) C:\windows\SysWOW64\usercpl.dll
2014-03-28 20:38 - 2013-09-17 06:08 - 00738304 _____ (Microsoft Corporation) C:\windows\system32\msctfuimanager.dll
2014-03-28 20:38 - 2013-09-17 05:28 - 00695808 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctfuimanager.dll
2014-03-28 20:38 - 2013-09-14 16:06 - 00175960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\VerifierExt.sys
2014-03-28 20:38 - 2013-09-14 16:06 - 00066904 _____ (Microsoft Corporation) C:\windows\system32\PSHED.DLL
2014-03-28 20:38 - 2013-09-14 13:39 - 00083456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2014-03-28 20:38 - 2013-09-13 11:52 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\SensorsClassExtension.dll
2014-03-28 20:38 - 2013-09-13 10:54 - 00426496 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Usb.dll
2014-03-28 20:38 - 2013-09-13 10:10 - 00288256 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Usb.dll
2014-03-28 20:38 - 2013-09-13 09:55 - 00233984 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.HumanInterfaceDevice.dll
2014-03-28 20:38 - 2013-09-13 09:30 - 00155136 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2014-03-28 20:38 - 2013-09-11 11:31 - 00442368 _____ (Microsoft Corporation) C:\windows\system32\Drivers\nwifi.sys
2014-03-28 20:38 - 2013-09-11 11:31 - 00244224 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2014-03-28 20:38 - 2013-09-11 09:41 - 00353792 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore.dll
2014-03-28 20:38 - 2013-09-11 09:09 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcore.dll
2014-03-28 20:38 - 2013-09-07 14:44 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\fdprint.dll
2014-03-28 20:38 - 2013-09-07 14:29 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\DeviceCenter.dll
2014-03-28 20:38 - 2013-09-07 14:00 - 00256000 _____ (Microsoft Corporation) C:\windows\SysWOW64\fdprint.dll
2014-03-28 20:38 - 2013-09-07 13:50 - 00482816 _____ (Microsoft Corporation) C:\windows\SysWOW64\DeviceCenter.dll
2014-03-28 20:38 - 2013-09-07 13:45 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\CryptoWinRT.dll
2014-03-28 20:38 - 2013-09-07 13:30 - 00244736 _____ (Microsoft Corporation) C:\windows\system32\Windows.Networking.Vpn.dll
2014-03-28 20:38 - 2013-09-07 13:22 - 00153600 _____ (Microsoft Corporation) C:\windows\SysWOW64\CryptoWinRT.dll
2014-03-28 20:38 - 2013-09-07 13:13 - 00248320 _____ (Microsoft Corporation) C:\windows\system32\rascustom.dll
2014-03-28 20:38 - 2013-09-07 13:07 - 00273408 _____ (Microsoft Corporation) C:\windows\system32\TetheringMgr.dll
2014-03-28 20:38 - 2013-09-05 09:39 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ks.sys
2014-03-28 20:38 - 2013-09-05 08:42 - 00081920 _____ (Microsoft Corporation) C:\windows\system32\Utilman.exe
2014-03-28 20:38 - 2013-09-05 07:40 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\Utilman.exe
2014-03-28 20:38 - 2013-09-04 09:01 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\WorkFoldersGPExt.dll
2014-03-28 20:38 - 2013-09-04 08:16 - 00358912 _____ (Microsoft Corporation) C:\windows\system32\vmrdvcore.dll
2014-03-28 20:38 - 2013-09-04 07:12 - 00198656 _____ (Microsoft Corporation) C:\windows\system32\DscCoreConfProv.dll
2014-03-28 20:38 - 2013-09-04 06:57 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\DscCore.dll
2014-03-28 20:38 - 2013-09-04 06:48 - 00326656 _____ (Microsoft Corporation) C:\windows\system32\SessEnv.dll
2014-03-28 20:38 - 2013-09-04 06:35 - 00280576 _____ (Microsoft Corporation) C:\windows\SysWOW64\SessEnv.dll
2014-03-28 20:38 - 2013-08-31 16:18 - 00205024 _____ (Microsoft Corporation) C:\windows\system32\mftranscode.dll
2014-03-28 20:38 - 2013-08-31 14:15 - 00180232 _____ (Microsoft Corporation) C:\windows\SysWOW64\mftranscode.dll
2014-03-28 20:38 - 2013-08-31 14:04 - 00638464 _____ (Microsoft Corporation) C:\windows\system32\riched20.dll
2014-03-28 20:38 - 2013-08-31 12:46 - 00513536 _____ (Microsoft Corporation) C:\windows\SysWOW64\riched20.dll
2014-03-28 20:38 - 2013-08-31 12:00 - 00491520 _____ (Microsoft Corporation) C:\windows\system32\GeofenceMonitorService.dll
2014-03-28 20:38 - 2013-08-31 11:25 - 00357376 _____ (Microsoft Corporation) C:\windows\SysWOW64\GeofenceMonitorService.dll
2014-03-28 20:38 - 2013-08-30 09:31 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\AxInstSv.dll
2014-03-28 20:38 - 2013-08-28 09:55 - 00334336 _____ (Microsoft Corporation) C:\windows\system32\MDEServer.exe
2014-03-28 20:38 - 2013-08-28 09:49 - 00597504 _____ (Microsoft Corporation) C:\windows\system32\msra.exe
2014-03-28 20:38 - 2013-08-28 09:09 - 00054272 _____ (Microsoft Corporation) C:\windows\system32\rdsdwmdr.dll
2014-03-28 20:38 - 2013-08-27 08:09 - 00970752 _____ (Microsoft Corporation) C:\windows\system32\WebcamUi.dll
2014-03-28 20:38 - 2013-08-27 07:24 - 00813568 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebcamUi.dll
2014-03-28 20:23 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-28 20:23 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-03-28 20:23 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-03-28 20:23 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-03-28 20:23 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-03-28 20:23 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-03-28 20:23 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-03-28 20:23 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-03-28 20:23 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-03-28 20:23 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-03-28 20:23 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-03-28 20:23 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-03-28 20:23 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-03-28 20:23 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-03-28 20:23 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-03-28 20:23 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-03-28 20:23 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-03-28 20:23 - 2014-02-06 13:30 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-28 20:23 - 2014-02-06 13:30 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-03-28 20:23 - 2014-02-06 13:07 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-03-28 20:23 - 2014-02-06 13:06 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-03-28 20:23 - 2014-02-06 12:57 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-03-28 20:23 - 2014-02-06 12:56 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-03-28 20:23 - 2014-02-06 12:49 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-03-28 20:23 - 2014-02-06 12:48 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-03-28 20:23 - 2014-02-06 12:48 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-03-28 20:23 - 2014-02-06 12:20 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-03-28 20:23 - 2014-02-06 12:17 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-03-28 20:23 - 2014-02-06 12:01 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-03-28 20:23 - 2014-02-06 12:00 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-03-28 20:23 - 2014-02-06 11:52 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-03-28 20:23 - 2014-02-06 11:52 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-03-28 20:23 - 2014-02-06 11:50 - 02041856 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-03-28 20:23 - 2014-02-06 11:47 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-03-28 20:23 - 2014-02-06 11:46 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-03-28 20:23 - 2014-02-06 11:25 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-03-28 20:23 - 2014-02-06 11:09 - 01964032 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-03-28 20:23 - 2013-12-20 12:18 - 01643584 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2014-03-28 20:23 - 2013-12-20 12:18 - 01507704 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2014-03-28 20:23 - 2013-12-09 02:27 - 02152448 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-03-28 20:23 - 2013-12-09 02:19 - 00570880 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll
2014-03-28 20:23 - 2013-12-09 01:55 - 00444928 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdrm.dll
2014-03-28 20:23 - 2013-12-09 01:54 - 01317376 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2014-03-28 20:23 - 2013-10-31 02:33 - 01476184 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2014-03-28 20:23 - 2013-10-31 02:33 - 01345536 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2014-03-28 20:23 - 2013-10-19 10:53 - 00075360 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2014-03-28 20:23 - 2013-10-19 09:14 - 00070680 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2014-03-28 20:23 - 2013-10-03 11:16 - 00294400 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Sensors.dll
2014-03-28 20:23 - 2013-10-03 11:02 - 00225792 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Sensors.dll
2014-03-28 20:23 - 2013-10-02 13:00 - 01286552 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2014-03-28 20:23 - 2013-10-02 11:47 - 01018960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2014-03-28 20:23 - 2013-10-01 05:42 - 01217024 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.Streaming.dll
2014-03-28 20:23 - 2013-10-01 05:36 - 00977408 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.Streaming.dll
2014-03-28 20:22 - 2014-02-11 05:04 - 04189184 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-03-28 20:22 - 2014-02-11 04:43 - 00488448 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2014-03-28 20:22 - 2014-02-11 04:04 - 00586240 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-03-28 20:22 - 2014-01-31 18:15 - 00311640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\volsnap.sys
2014-03-28 20:22 - 2014-01-31 18:07 - 00233920 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2014-03-28 20:22 - 2014-01-31 18:06 - 02133208 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll
2014-03-28 20:22 - 2014-01-31 15:47 - 02143960 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll
2014-03-28 20:22 - 2014-01-31 11:06 - 00716288 _____ (Microsoft Corporation) C:\windows\system32\swprv.dll
2014-03-28 20:22 - 2014-01-29 11:55 - 01287064 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2014-03-28 20:22 - 2014-01-29 10:53 - 00458616 _____ (Microsoft Corporation) C:\windows\system32\WerFault.exe
2014-03-28 20:22 - 2014-01-29 10:53 - 00407024 _____ (Microsoft Corporation) C:\windows\system32\Faultrep.dll
2014-03-28 20:22 - 2014-01-29 10:49 - 01928144 _____ (Microsoft Corporation) C:\windows\system32\combase.dll
2014-03-28 20:22 - 2014-01-29 10:47 - 02543960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-03-28 20:22 - 2014-01-29 09:44 - 01371824 _____ (Microsoft Corporation) C:\windows\SysWOW64\combase.dll
2014-03-28 20:22 - 2014-01-29 09:44 - 00408480 _____ (Microsoft Corporation) C:\windows\SysWOW64\WerFault.exe
2014-03-28 20:22 - 2014-01-29 09:44 - 00369280 _____ (Microsoft Corporation) C:\windows\SysWOW64\Faultrep.dll
2014-03-28 20:22 - 2014-01-29 08:41 - 00208896 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpencom.dll
2014-03-28 20:22 - 2014-01-29 02:36 - 00249856 _____ (Microsoft Corporation) C:\windows\system32\rdpencom.dll
2014-03-28 20:22 - 2014-01-27 21:07 - 04175360 _____ (Microsoft Corporation) C:\windows\system32\dbgeng.dll
2014-03-28 20:22 - 2014-01-27 21:06 - 00064512 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2014-03-28 20:22 - 2014-01-27 21:04 - 00160256 _____ (Microsoft Corporation) C:\windows\system32\DWWIN.EXE
2014-03-28 20:22 - 2014-01-27 20:52 - 01036288 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2014-03-28 20:22 - 2014-01-27 20:23 - 02873344 _____ (Microsoft Corporation) C:\windows\SysWOW64\dbgeng.dll
2014-03-28 20:22 - 2014-01-27 20:21 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2014-03-28 20:22 - 2014-01-27 20:20 - 00138752 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWWIN.EXE
2014-03-28 20:22 - 2014-01-27 20:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2014-03-28 20:22 - 2014-01-27 19:43 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2014-03-28 20:22 - 2014-01-27 19:18 - 01486848 _____ (Microsoft Corporation) C:\windows\system32\dbghelp.dll
2014-03-28 20:22 - 2014-01-27 19:00 - 01238016 _____ (Microsoft Corporation) C:\windows\SysWOW64\dbghelp.dll
2014-03-28 20:22 - 2014-01-27 17:58 - 05770752 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-03-28 20:22 - 2014-01-27 17:50 - 06640640 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-03-28 20:22 - 2014-01-27 13:45 - 00386722 _____ () C:\windows\system32\ApnDatabase.xml
2014-03-28 20:22 - 2014-01-18 01:04 - 00764864 _____ (Microsoft Corporation) C:\windows\system32\mfmpeg2srcsnk.dll
2014-03-28 20:22 - 2014-01-17 23:54 - 00669352 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmpeg2srcsnk.dll
2014-03-28 20:22 - 2014-01-07 09:03 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\pcaui.exe
2014-03-28 20:22 - 2014-01-07 07:59 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\pcaui.exe
2014-03-28 20:22 - 2014-01-07 07:00 - 02397184 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2014-03-28 20:22 - 2014-01-07 06:30 - 02071552 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
2014-03-28 20:22 - 2014-01-04 22:50 - 01462216 _____ (Microsoft Corporation) C:\windows\system32\propsys.dll
2014-03-28 20:22 - 2014-01-04 21:22 - 01202888 _____ (Microsoft Corporation) C:\windows\SysWOW64\propsys.dll
2014-03-28 20:22 - 2014-01-04 16:30 - 13209088 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
2014-03-28 20:22 - 2014-01-04 16:23 - 11702272 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
2014-03-28 20:22 - 2014-01-04 15:42 - 01105408 _____ (Microsoft Corporation) C:\windows\system32\SearchFolder.dll
2014-03-28 20:22 - 2014-01-04 15:40 - 07416832 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Search.dll
2014-03-28 20:22 - 2014-01-04 15:36 - 00830976 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFolder.dll
2014-03-28 20:22 - 2014-01-04 15:28 - 04961792 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Search.dll
2014-03-28 20:22 - 2013-12-21 16:51 - 06353960 _____ (Microsoft Corporation) C:\windows\system32\sppsvc.exe
2014-03-28 20:22 - 2013-12-21 10:54 - 00447488 _____ (Microsoft Corporation) C:\windows\system32\sppcomapi.dll
2014-03-28 20:22 - 2013-12-21 04:10 - 00009701 _____ () C:\windows\SysWOW64\connectedsearch-results.searchconnector-ms
2014-03-28 20:22 - 2013-12-21 04:10 - 00009701 _____ () C:\windows\system32\connectedsearch-results.searchconnector-ms
2014-03-28 20:22 - 2013-12-20 12:10 - 01113040 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2014-03-28 20:22 - 2013-12-20 08:13 - 00835584 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2014-03-28 20:22 - 2013-12-09 04:57 - 00548864 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-03-28 20:22 - 2013-12-09 03:51 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-03-28 20:22 - 2013-11-27 17:36 - 03395920 _____ (Microsoft Corporation) C:\windows\system32\WSService.dll
2014-03-28 20:22 - 2013-11-27 13:41 - 00084480 _____ (Microsoft Corporation) C:\windows\system32\WSCollect.exe
2014-03-28 20:22 - 2013-11-27 10:48 - 00249856 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-03-28 20:22 - 2013-11-27 10:40 - 00189952 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-03-28 20:22 - 2013-11-27 10:17 - 00695808 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2014-03-28 20:22 - 2013-11-27 10:12 - 00848384 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2014-03-28 20:22 - 2013-11-23 06:34 - 00393216 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2014-03-28 20:22 - 2013-11-23 06:13 - 00348160 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2014-03-28 20:22 - 2013-11-21 08:42 - 04604416 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2014-03-28 20:22 - 2013-11-21 07:44 - 03936256 _____ (Microsoft Corporation) C:\windows\SysWOW64\d2d1.dll
2014-03-28 20:22 - 2013-10-31 02:29 - 00236888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdFilter.sys
2014-03-28 20:22 - 2013-10-31 02:29 - 00124760 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdNisDrv.sys
2014-03-28 20:22 - 2013-10-31 02:28 - 00035856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdBoot.sys
2014-03-28 20:22 - 2013-10-23 13:01 - 00872840 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2014-03-28 20:22 - 2013-10-23 10:59 - 00698232 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2014-03-28 20:22 - 2013-10-15 10:54 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2014-03-28 20:22 - 2013-10-15 10:03 - 00156672 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2014-03-28 20:22 - 2013-10-13 04:48 - 00136536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wfplwfs.sys
2014-03-28 20:22 - 2013-10-12 23:48 - 00828416 _____ (Microsoft Corporation) C:\windows\system32\BFE.DLL
2014-03-28 20:22 - 2013-10-12 23:34 - 01104384 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2014-03-28 20:22 - 2013-10-05 16:21 - 01341288 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2014-03-28 20:22 - 2013-10-05 10:39 - 01067008 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2014-03-28 20:22 - 2013-09-21 12:53 - 00996320 _____ (Microsoft Corporation) C:\windows\system32\WinTypes.dll
2014-03-28 20:21 - 2013-12-09 02:15 - 00787968 _____ (Microsoft Corporation) C:\windows\system32\uDWM.dll
2014-03-28 20:21 - 2013-11-09 08:34 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\MDMAgent.exe
2014-03-28 20:21 - 2013-11-09 08:34 - 00287744 _____ (Microsoft Corporation) C:\windows\system32\mdmregistration.dll
2014-03-28 20:21 - 2013-11-09 07:52 - 00240128 _____ (Microsoft Corporation) C:\windows\SysWOW64\mdmregistration.dll
2014-03-28 20:20 - 2014-01-09 10:25 - 02804224 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll
2014-03-28 20:20 - 2014-01-09 09:59 - 01020928 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll
2014-03-28 20:20 - 2014-01-09 09:59 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\winbici.dll
2014-03-28 20:20 - 2014-01-09 09:49 - 00919040 _____ (Microsoft Corporation) C:\windows\system32\MrmCoreR.dll
2014-03-28 20:20 - 2014-01-09 09:44 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveTelemetry.dll
2014-03-28 20:20 - 2014-01-09 09:43 - 00121344 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveShell.dll
2014-03-28 20:20 - 2014-01-09 09:29 - 00105984 _____ (Microsoft Corporation) C:\windows\SysWOW64\SkyDriveShell.dll
2014-03-28 20:20 - 2014-01-09 09:28 - 04217344 _____ (Microsoft Corporation) C:\windows\system32\SyncEngine.dll
2014-03-28 20:20 - 2014-01-09 09:28 - 00628736 _____ (Microsoft Corporation) C:\windows\SysWOW64\MrmCoreR.dll
2014-03-28 20:20 - 2014-01-09 09:18 - 00870912 _____ (Microsoft Corporation) C:\windows\system32\SkyDrive.exe
2014-03-28 20:20 - 2013-10-16 17:58 - 01943536 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2014-03-28 20:20 - 2013-10-16 15:54 - 01581968 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2014-03-28 16:23 - 2014-03-29 18:28 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-03-28 16:23 - 2014-03-28 16:23 - 00000000 ____D () C:\Users\dkoen_000\Documents\PDF Architect Files
2014-03-28 16:23 - 2014-03-28 16:23 - 00000000 ____D () C:\Program Files (x86)\PDF Architect
2014-03-28 16:23 - 2013-04-09 15:13 - 00110264 _____ (pdfforge GmbH) C:\windows\system32\pdfcmon.dll
2014-03-28 16:23 - 2012-05-05 11:54 - 00662288 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSCOMCT2.OCX
2014-03-28 16:23 - 2012-05-05 11:54 - 00137000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSMAPI32.OCX
2014-03-28 16:23 - 2012-05-05 11:54 - 00023552 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSMPIDE.DLL
2014-03-28 16:23 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\windows\SysWOW64\VB6DE.DLL
2014-03-28 16:23 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSCMCDE.DLL
2014-03-28 16:23 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSCC2DE.DLL
2014-03-28 15:36 - 2014-03-28 16:25 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-28 15:36 - 2014-03-28 15:36 - 00002046 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-03-28 15:36 - 2014-03-28 15:36 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-03-28 15:13 - 2014-03-28 15:13 - 00000000 ____D () C:\Program Files (x86)\Microsoft Sync Framework
2014-03-28 15:06 - 2014-03-28 15:06 - 00000000 ____D () C:\Users\dkoen_000\Documents\mobackups
2014-03-28 14:56 - 2014-03-30 12:17 - 00000000 ____D () C:\windows\Minidump
2014-03-28 01:13 - 2014-03-28 01:13 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Heiko Schröder Software
2014-03-28 01:13 - 2014-03-28 01:13 - 00000000 ____D () C:\Program Files (x86)\MOBackup
2014-03-28 01:03 - 2014-03-28 01:03 - 00000000 ____D () C:\windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-03-28 01:03 - 2014-03-28 01:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services
2014-03-28 01:01 - 2014-03-28 01:01 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-03-28 01:00 - 2014-03-29 15:29 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-28 01:00 - 2014-03-28 15:12 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-03-28 01:00 - 2014-03-28 01:00 - 00000000 __RHD () C:\MSOCache
2014-03-28 01:00 - 2014-03-28 01:00 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Microsoft Help
2014-03-28 01:00 - 2014-03-28 01:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services
2014-03-28 00:55 - 2012-08-16 21:06 - 1096292976 _____ (Microsoft Corporation) C:\Users\dkoen_000\Downloads\X17-75245.exe
2014-03-28 00:02 - 2014-03-28 00:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Hewlett-Packard
2014-03-27 23:59 - 2014-03-27 23:59 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\ATI
2014-03-27 23:59 - 2014-03-27 23:59 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Power2Go8
2014-03-27 23:59 - 2014-03-27 23:59 - 00000000 ____D () C:\Users\Administrator\AppData\Local\ATI
2014-03-27 23:58 - 2014-03-27 23:59 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Packages
2014-03-27 23:58 - 2014-03-27 23:58 - 00001453 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-27 23:58 - 2014-03-27 23:58 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Startmenü
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 ____D () C:\Users\Administrator
2014-03-27 23:58 - 2014-02-23 05:26 - 00000000 ___HD () C:\Users\Administrator\Documents\hp.system.package.metadata
2014-03-27 23:58 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-03-27 23:58 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-03-27 23:58 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-03-27 23:58 - 2013-08-22 17:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-03-27 22:26 - 2014-03-27 22:26 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Thunderbird
2014-03-27 22:26 - 2014-03-27 22:26 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Thunderbird
2014-03-27 21:43 - 2014-03-27 21:43 - 00115992 _____ () C:\Users\dkoen_000\Documents\cc_20140327_204304.reg
2014-03-27 21:43 - 2014-03-27 21:43 - 00004250 _____ () C:\Users\dkoen_000\Documents\cc_20140327_204320.reg
2014-03-27 21:40 - 2014-03-27 19:42 - 00000426 _____ () C:\AVScanner.ini
2014-03-27 21:39 - 2014-03-27 21:39 - 00000000 ____D () C:\Program Files (x86)\Foxit Software
2014-03-27 21:38 - 2014-03-28 15:51 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0
2014-03-27 21:38 - 2014-03-27 21:39 - 00002190 _____ () C:\Users\Public\Desktop\StarMoney 9.0.lnk
2014-03-27 21:38 - 2014-03-27 21:38 - 00000000 ____D () C:\ProgramData\StarMoney 9.0
2014-03-27 21:38 - 2014-03-27 21:38 - 00000000 ____D () C:\Program Files (x86)\Business Objects
2014-03-27 21:24 - 2014-03-27 23:39 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Apple Computer
2014-03-27 21:24 - 2014-03-27 21:24 - 00001802 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Apple Computer
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Apple
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Program Files\iTunes
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Program Files\iPod
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-03-27 21:24 - 2012-08-21 14:01 - 00033240 _____ (GEAR Software Inc.) C:\windows\system32\Drivers\GEARAspiWDM.sys
2014-03-27 20:44 - 2014-03-27 20:44 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2014-03-27 18:14 - 2014-03-27 18:14 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Macromedia
2014-03-27 18:13 - 2014-03-30 05:13 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-03-27 18:13 - 2014-03-28 16:23 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Adobe
2014-03-27 18:13 - 2014-03-27 18:13 - 00003772 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-03-27 17:58 - 2014-03-27 17:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-27 17:55 - 2014-03-29 17:33 - 00000000 ____D () C:\Program Files (x86)\MozBackup
2014-03-27 17:47 - 2014-03-30 12:20 - 00000000 ___RD () C:\Users\dkoen_000\Dropbox
2014-03-27 17:47 - 2014-03-27 17:47 - 00001095 _____ () C:\Users\dkoen_000\Desktop\Dropbox.lnk
2014-03-27 17:47 - 2014-03-27 17:47 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\DropboxMaster
2014-03-27 17:46 - 2014-03-30 12:20 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Dropbox
2014-03-27 17:46 - 2014-03-27 17:46 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-03-27 15:48 - 2014-03-27 23:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-27 15:48 - 2014-03-27 15:48 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Mozilla
2014-03-27 15:48 - 2014-03-27 15:48 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Mozilla
2014-03-27 15:48 - 2014-03-27 15:48 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-27 15:48 - 2014-03-27 15:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 15:39 - 2014-03-29 19:30 - 00000000 ____D () C:\AdwCleaner
2014-03-27 15:39 - 2014-03-27 15:39 - 01950720 _____ () C:\Users\dkoen_000\Downloads\adwcleaner_3.022.exe
2014-03-27 15:35 - 2014-03-27 15:35 - 00002780 _____ () C:\windows\System32\Tasks\CCleanerSkipUAC
2014-03-27 15:35 - 2014-03-27 15:35 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-27 14:54 - 2014-03-27 14:54 - 00004020 _____ () C:\windows\System32\Tasks\HPGenoobeReminder
2014-03-27 14:49 - 2014-03-27 14:49 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Avira
2014-03-27 14:43 - 2014-02-25 12:41 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2014-03-27 14:43 - 2014-02-25 12:41 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2014-03-27 14:43 - 2014-02-25 12:41 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2014-03-27 14:40 - 2014-03-27 14:42 - 00000000 ____D () C:\ProgramData\Avira
2014-03-27 14:40 - 2014-03-27 14:42 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-03-27 14:40 - 2014-03-27 14:40 - 00001160 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-03-27 14:38 - 2014-03-27 14:38 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Macromedia
2014-03-27 14:30 - 2014-03-30 01:40 - 00003596 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-780775887-1489837654-630077470-1001
2014-03-27 14:30 - 2014-03-27 14:30 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Hewlett-Packard
2014-03-27 14:29 - 2014-03-27 14:29 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Hewlett-Packard
2014-03-27 14:26 - 2014-03-29 21:58 - 00000000 __RDO () C:\Users\dkoen_000\SkyDrive
2014-03-27 14:26 - 2014-03-27 14:26 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\ATI
2014-03-27 14:26 - 2014-03-27 14:26 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\ATI
2014-03-27 14:26 - 2014-03-27 14:26 - 00000000 ____D () C:\ProgramData\ATI
2014-03-27 14:25 - 2014-03-29 20:30 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\VirtualStore
2014-03-27 14:25 - 2014-03-29 17:47 - 00000000 ___RD () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-27 14:25 - 2014-03-29 17:47 - 00000000 ___RD () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-27 14:25 - 2014-03-29 17:47 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Packages
2014-03-27 14:25 - 2014-03-28 16:23 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Adobe
2014-03-27 14:25 - 2014-03-27 14:25 - 00001457 _____ () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-27 14:25 - 2014-03-27 14:25 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Power2Go8
2014-03-27 14:24 - 2014-03-29 21:16 - 00000000 ____D () C:\Users\dkoen_000
2014-03-27 14:24 - 2014-03-27 14:24 - 00000020 ___SH () C:\Users\dkoen_000\ntuser.ini
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Vorlagen
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Startmenü
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Netzwerkumgebung
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Lokale Einstellungen
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Eigene Dateien
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Druckumgebung
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\AppData\Local\Verlauf
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\AppData\Local\Anwendungsdaten
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Anwendungsdaten
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 __RDL () C:\Users\dkoen_000\Documents\Eigene Musik
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 __RDL () C:\Users\dkoen_000\Documents\Eigene Bilder
2014-03-27 14:24 - 2014-02-23 05:26 - 00000000 ___HD () C:\Users\dkoen_000\Documents\hp.system.package.metadata
2014-03-27 14:24 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-03-27 14:24 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-03-27 14:24 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-03-27 14:24 - 2013-08-22 17:36 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Programme
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Dokumente und Einstellungen
==================== One Month Modified Files and Folders =======
2014-03-30 12:25 - 2014-03-30 00:36 - 00016679 _____ () C:\Users\dkoen_000\Downloads\FRST.txt
2014-03-30 12:24 - 2014-03-29 20:51 - 00000000 ____D () C:\FRST
2014-03-30 12:22 - 2014-02-23 06:14 - 00757756 _____ () C:\windows\system32\perfh007.dat
2014-03-30 12:22 - 2014-02-23 06:14 - 00173028 _____ () C:\windows\system32\perfc007.dat
2014-03-30 12:22 - 2013-08-24 23:38 - 01783968 _____ () C:\windows\system32\PerfStringBackup.INI
2014-03-30 12:21 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\rescache
2014-03-30 12:20 - 2014-03-27 17:47 - 00000000 ___RD () C:\Users\dkoen_000\Dropbox
2014-03-30 12:20 - 2014-03-27 17:46 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Dropbox
2014-03-30 12:17 - 2014-03-30 12:17 - 00837112 _____ () C:\windows\Minidump\033014-33234-01.dmp
2014-03-30 12:17 - 2014-03-28 14:56 - 00000000 ____D () C:\windows\Minidump
2014-03-30 12:17 - 2013-08-22 16:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-03-30 12:16 - 2014-03-30 12:16 - 1439110558 _____ () C:\windows\MEMORY.DMP
2014-03-30 12:16 - 2013-08-28 06:33 - 00000000 ____D () C:\windows\en-GB
2014-03-30 12:16 - 2013-08-22 21:12 - 00000000 ____D () C:\Program Files\Windows Journal
2014-03-30 12:16 - 2013-08-22 21:10 - 00000000 ____D () C:\windows\SysWOW64\winrm
2014-03-30 12:16 - 2013-08-22 21:10 - 00000000 ____D () C:\windows\SysWOW64\WCN
2014-03-30 12:16 - 2013-08-22 21:10 - 00000000 ____D () C:\windows\SysWOW64\slmgr
2014-03-30 12:16 - 2013-08-22 21:10 - 00000000 ____D () C:\windows\SysWOW64\Printing_Admin_Scripts
2014-03-30 12:16 - 2013-08-22 21:10 - 00000000 ____D () C:\windows\system32\winrm
2014-03-30 12:16 - 2013-08-22 21:10 - 00000000 ____D () C:\windows\system32\WCN
2014-03-30 12:16 - 2013-08-22 21:10 - 00000000 ____D () C:\windows\system32\slmgr
2014-03-30 12:16 - 2013-08-22 21:10 - 00000000 ____D () C:\windows\system32\Printing_Admin_Scripts
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ___SD () C:\windows\system32\dsc
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ImmersiveControlPanel
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\WinStore
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\SysWOW64\en-GB
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\SystemResetPlatform
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\migwiz
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\en-GB
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\Help
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\System
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2014-03-30 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-03-30 12:16 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\SysWOW64\oobe
2014-03-30 12:16 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\system32\oobe
2014-03-30 12:16 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\servicing
2014-03-30 05:13 - 2014-03-27 18:13 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-03-30 05:00 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\sru
2014-03-30 04:50 - 2014-03-29 21:38 - 00097265 _____ () C:\windows\WindowsUpdate.log
2014-03-30 02:06 - 2014-03-30 02:06 - 02347384 _____ (ESET) C:\Users\dkoen_000\Downloads\esetsmartinstaller_enu.exe
2014-03-30 01:57 - 2014-03-30 01:57 - 00001139 _____ () C:\Users\dkoen_000\Downloads\MBAM.txt
2014-03-30 01:47 - 2014-03-29 18:42 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-30 01:40 - 2014-03-27 14:30 - 00003596 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-780775887-1489837654-630077470-1001
2014-03-30 01:27 - 2014-03-30 01:27 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-03-30 01:26 - 2014-03-30 01:26 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\dkoen_000\Downloads\revosetup95.exe
2014-03-30 00:58 - 2014-03-30 00:58 - 00043283 _____ () C:\Users\dkoen_000\Downloads\Addition.txt
2014-03-30 00:35 - 2014-03-30 00:35 - 02157056 _____ (Farbar) C:\Users\dkoen_000\Downloads\FRST64.exe
2014-03-29 23:57 - 2014-03-29 23:57 - 00000000 ___SH () C:\DkHyperbootSync
2014-03-29 21:58 - 2014-03-27 14:26 - 00000000 __RDO () C:\Users\dkoen_000\SkyDrive
2014-03-29 21:56 - 2014-03-29 21:56 - 00004766 _____ () C:\Users\dkoen_000\Documents\cc_20140329_205634.reg
2014-03-29 21:55 - 2014-03-29 21:39 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
2014-03-29 21:40 - 2013-08-22 15:25 - 00262144 ___SH () C:\windows\system32\config\ELAM
2014-03-29 21:32 - 2014-03-29 21:32 - 00009192 _____ () C:\Users\dkoen_000\Documents\install.txt
2014-03-29 21:31 - 2014-03-29 21:31 - 00003928 _____ () C:\Users\dkoen_000\Documents\cc_20140329_203150.reg
2014-03-29 21:25 - 2014-03-29 21:12 - 00127268 _____ () C:\zoek-results.log
2014-03-29 21:24 - 2013-08-22 15:25 - 00262144 ___SH () C:\windows\system32\config\BBI
2014-03-29 21:16 - 2014-03-29 21:11 - 00000000 ____D () C:\zoek_backup
2014-03-29 21:16 - 2014-03-27 14:24 - 00000000 ____D () C:\Users\dkoen_000
2014-03-29 21:11 - 2014-03-29 21:21 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-03-29 20:30 - 2014-03-27 14:25 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\VirtualStore
2014-03-29 19:30 - 2014-03-27 15:39 - 00000000 ____D () C:\AdwCleaner
2014-03-29 19:29 - 2014-03-29 19:29 - 00004644 _____ () C:\Users\dkoen_000\Documents\cc_20140329_182942.reg
2014-03-29 18:42 - 2014-03-29 18:42 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-29 18:42 - 2014-03-29 18:42 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-03-29 18:36 - 2014-03-29 18:17 - 00000000 ____D () C:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-03-29 18:28 - 2014-03-28 16:23 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-03-29 18:27 - 2014-03-29 18:27 - 00020850 _____ () C:\Users\dkoen_000\Documents\cc_20140329_172727.reg
2014-03-29 18:27 - 2014-03-29 18:27 - 00000342 _____ () C:\Users\dkoen_000\Documents\cc_20140329_172740.reg
2014-03-29 18:18 - 2014-03-29 18:18 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-03-29 18:18 - 2014-03-29 18:18 - 00000000 _____ () C:\autoexec.bat
2014-03-29 17:52 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\AppReadiness
2014-03-29 17:49 - 2014-03-29 17:49 - 00000000 ____D () C:\windows\ERUNT
2014-03-29 17:47 - 2014-03-29 17:41 - 00000000 ___RD () C:\windows\BrowserChoice
2014-03-29 17:47 - 2014-03-27 14:25 - 00000000 ___RD () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-29 17:47 - 2014-03-27 14:25 - 00000000 ___RD () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-29 17:47 - 2014-03-27 14:25 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Packages
2014-03-29 17:42 - 2013-08-22 16:44 - 00422224 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-29 17:41 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ToastData
2014-03-29 17:41 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-03-29 17:41 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-03-29 17:41 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\MediaViewer
2014-03-29 17:41 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\FileManager
2014-03-29 17:41 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\Camera
2014-03-29 17:41 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\SysWOW64\Dism
2014-03-29 17:41 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\system32\Dism
2014-03-29 17:36 - 2014-03-29 17:36 - 01038974 _____ (Thisisu) C:\Users\dkoen_000\Downloads\JRT.exe
2014-03-29 17:33 - 2014-03-27 17:55 - 00000000 ____D () C:\Program Files (x86)\MozBackup
2014-03-29 17:30 - 2014-03-29 17:30 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Foxit Software
2014-03-29 17:27 - 2014-03-28 21:39 - 00013389 _____ () C:\Users\dkoen_000\Documents\Umzugsservice.xlsx
2014-03-29 16:05 - 2014-03-29 16:05 - 00104680 _____ () C:\Users\dkoen_000\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-29 16:05 - 2014-03-29 16:05 - 00000000 ____D () C:\Users\dkoen_000\Documents\Neuer Ordner
2014-03-29 16:05 - 2014-03-29 16:05 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\PDF Architect
2014-03-29 16:05 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Geld
2014-03-29 15:29 - 2014-03-28 01:00 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-29 15:18 - 2013-08-22 15:25 - 00000199 _____ () C:\windows\win.ini
2014-03-29 15:13 - 2014-03-29 15:13 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-03-29 15:13 - 2014-03-29 15:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-03-29 15:09 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-03-29 15:07 - 2014-03-29 15:07 - 00000000 ____D () C:\windows\system32\MRT
2014-03-28 23:58 - 2014-03-28 23:50 - 00000000 ____D () C:\ProgramData\Acronis
2014-03-28 23:57 - 2014-03-28 23:57 - 00367200 _____ (Acronis) C:\windows\system32\Drivers\afcdp.sys
2014-03-28 23:57 - 2014-03-28 23:57 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\F6C2F7B5-D690-4C9B-92B9-12944FA97007
2014-03-28 23:57 - 2014-03-28 23:50 - 01464096 _____ (Acronis International GmbH) C:\windows\system32\Drivers\tdrpman.sys
2014-03-28 23:52 - 2014-03-28 23:52 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Acronis
2014-03-28 23:50 - 2014-03-28 23:50 - 01120032 _____ (Acronis International GmbH) C:\windows\system32\Drivers\tib.sys
2014-03-28 23:50 - 2014-03-28 23:50 - 00269600 _____ (Acronis International GmbH) C:\windows\system32\Drivers\snapman.sys
2014-03-28 23:50 - 2014-03-28 23:50 - 00198432 _____ (Acronis International GmbH) C:\windows\system32\Drivers\tib_mounter.sys
2014-03-28 23:50 - 2014-03-28 23:50 - 00116000 _____ (Acronis International GmbH) C:\windows\system32\Drivers\fltsrv.sys
2014-03-28 23:50 - 2014-03-28 23:50 - 00000000 ____D () C:\Program Files (x86)\Acronis
2014-03-28 23:05 - 2014-03-28 23:05 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\IDT
2014-03-28 22:05 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Persönlich
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\webkit
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Versicherungen
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Unfall 14.11.2011
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\TT259_Lead_Vocals_EZmix_Pack
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\TT205_EZX_Pop_Update
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\TT205_EZX_Pop_MIDI
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Toontrack
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Telefon
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Teisco
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Strom
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Stock
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Soltau
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Shopping
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Santorin 2005
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\samsung
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Planet Crown
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\PDF-Dateien
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Outlook-Dateien
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\OneNote-Notizbücher
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Nokia Suite
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\NeroVision
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Native Instruments
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Muttern
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\Job
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\iZotope Ozone Presets
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\Documents\IK Multimedia
2014-03-28 21:39 - 2014-03-28 21:39 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\mobackups
2014-03-28 21:39 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Homepage
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Haus
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Hagstrom
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Gesundheit
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\FFOutput
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Falk
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\EZmix_WIN
2014-03-28 21:38 - 2014-03-28 21:38 - 00000000 ____D () C:\Users\dkoen_000\Documents\Excel
2014-03-28 21:36 - 2014-03-28 21:36 - 00000000 ____D () C:\Users\dkoen_000\Documents\Eigene eBooks
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\eBay
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\DSSPlayer
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\DSL
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Comedy
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Coaching
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Checklisten
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Best Service
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Auto
2014-03-28 21:31 - 2014-03-28 21:31 - 00000000 ____D () C:\Users\dkoen_000\Documents\Anti-Stress
2014-03-28 16:25 - 2014-03-28 15:36 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-28 16:23 - 2014-03-28 16:23 - 00000000 ____D () C:\Users\dkoen_000\Documents\PDF Architect Files
2014-03-28 16:23 - 2014-03-28 16:23 - 00000000 ____D () C:\Program Files (x86)\PDF Architect
2014-03-28 16:23 - 2014-03-27 18:13 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Adobe
2014-03-28 16:23 - 2014-03-27 14:25 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Adobe
2014-03-28 15:51 - 2014-03-27 21:38 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0
2014-03-28 15:36 - 2014-03-28 15:36 - 00002046 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-03-28 15:36 - 2014-03-28 15:36 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-03-28 15:13 - 2014-03-28 15:13 - 00000000 ____D () C:\Program Files (x86)\Microsoft Sync Framework
2014-03-28 15:12 - 2014-03-28 01:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-03-28 15:06 - 2014-03-28 15:06 - 00000000 ____D () C:\Users\dkoen_000\Documents\mobackups
2014-03-28 13:06 - 2014-03-28 21:31 - 00014722 _____ () C:\Users\dkoen_000\Documents\cc_20140328_120603.reg
2014-03-28 01:13 - 2014-03-28 01:13 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Heiko Schröder Software
2014-03-28 01:13 - 2014-03-28 01:13 - 00000000 ____D () C:\Program Files (x86)\MOBackup
2014-03-28 01:03 - 2014-03-28 01:03 - 00000000 ____D () C:\windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-03-28 01:03 - 2014-03-28 01:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services
2014-03-28 01:03 - 2014-02-23 05:37 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-03-28 01:01 - 2014-03-28 01:01 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-03-28 01:00 - 2014-03-28 01:00 - 00000000 __RHD () C:\MSOCache
2014-03-28 01:00 - 2014-03-28 01:00 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Microsoft Help
2014-03-28 01:00 - 2014-03-28 01:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services
2014-03-28 01:00 - 2013-08-22 21:12 - 00000000 ____D () C:\windows\ShellNew
2014-03-28 00:04 - 2014-02-22 21:07 - 00003592 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-780775887-1489837654-630077470-500
2014-03-28 00:02 - 2014-03-28 00:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Hewlett-Packard
2014-03-27 23:59 - 2014-03-27 23:59 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\ATI
2014-03-27 23:59 - 2014-03-27 23:59 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Power2Go8
2014-03-27 23:59 - 2014-03-27 23:59 - 00000000 ____D () C:\Users\Administrator\AppData\Local\ATI
2014-03-27 23:59 - 2014-03-27 23:58 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Packages
2014-03-27 23:58 - 2014-03-27 23:58 - 00001453 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-27 23:58 - 2014-03-27 23:58 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Startmenü
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-03-27 23:58 - 2014-03-27 23:58 - 00000000 ____D () C:\Users\Administrator
2014-03-27 23:58 - 2014-03-27 15:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-27 23:39 - 2014-03-27 21:24 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Apple Computer
2014-03-27 22:26 - 2014-03-27 22:26 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Thunderbird
2014-03-27 22:26 - 2014-03-27 22:26 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Thunderbird
2014-03-27 21:43 - 2014-03-27 21:43 - 00115992 _____ () C:\Users\dkoen_000\Documents\cc_20140327_204304.reg
2014-03-27 21:43 - 2014-03-27 21:43 - 00004250 _____ () C:\Users\dkoen_000\Documents\cc_20140327_204320.reg
2014-03-27 21:39 - 2014-03-27 21:39 - 00000000 ____D () C:\Program Files (x86)\Foxit Software
2014-03-27 21:39 - 2014-03-27 21:38 - 00002190 _____ () C:\Users\Public\Desktop\StarMoney 9.0.lnk
2014-03-27 21:38 - 2014-03-27 21:38 - 00000000 ____D () C:\ProgramData\StarMoney 9.0
2014-03-27 21:38 - 2014-03-27 21:38 - 00000000 ____D () C:\Program Files (x86)\Business Objects
2014-03-27 21:38 - 2014-02-23 05:26 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-27 21:38 - 2013-08-22 15:25 - 00017486 _____ () C:\windows\system32\Drivers\etc\services
2014-03-27 21:24 - 2014-03-27 21:24 - 00001802 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Apple Computer
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Apple
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Program Files\iTunes
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Program Files\iPod
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-03-27 21:24 - 2014-03-27 21:24 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-03-27 21:24 - 2014-02-23 05:34 - 00000000 ____D () C:\ProgramData\Apple
2014-03-27 20:44 - 2014-03-27 20:44 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2014-03-27 19:42 - 2014-03-27 21:40 - 00000426 _____ () C:\AVScanner.ini
2014-03-27 18:14 - 2014-03-27 18:14 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Macromedia
2014-03-27 18:13 - 2014-03-27 18:13 - 00003772 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-03-27 18:13 - 2014-02-23 05:37 - 00000000 ____D () C:\ProgramData\McAfee
2014-03-27 18:03 - 2014-03-28 21:39 - 600147313 _____ () C:\Users\dkoen_000\Documents\Thunderbird 3.1.4 (de) - 2014-03-27.pcv
2014-03-27 17:58 - 2014-03-27 17:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-27 17:47 - 2014-03-27 17:47 - 00001095 _____ () C:\Users\dkoen_000\Desktop\Dropbox.lnk
2014-03-27 17:47 - 2014-03-27 17:47 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\DropboxMaster
2014-03-27 17:46 - 2014-03-27 17:46 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-03-27 15:51 - 2014-02-23 05:33 - 00000000 ____D () C:\ProgramData\CyberLink
2014-03-27 15:48 - 2014-03-27 15:48 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Mozilla
2014-03-27 15:48 - 2014-03-27 15:48 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Mozilla
2014-03-27 15:48 - 2014-03-27 15:48 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-27 15:48 - 2014-03-27 15:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 15:39 - 2014-03-27 15:39 - 01950720 _____ () C:\Users\dkoen_000\Downloads\adwcleaner_3.022.exe
2014-03-27 15:35 - 2014-03-27 15:35 - 00002780 _____ () C:\windows\System32\Tasks\CCleanerSkipUAC
2014-03-27 15:35 - 2014-03-27 15:35 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-27 15:35 - 2013-08-25 00:31 - 00000000 ____D () C:\windows\Panther
2014-03-27 14:59 - 2014-02-23 05:37 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-03-27 14:58 - 2014-02-23 05:38 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-03-27 14:58 - 2014-02-23 05:37 - 00000000 ____D () C:\Program Files\mcafee
2014-03-27 14:54 - 2014-03-27 14:54 - 00004020 _____ () C:\windows\System32\Tasks\HPGenoobeReminder
2014-03-27 14:51 - 2013-08-22 17:36 - 00000000 ___HD () C:\windows\ELAMBKUP
2014-03-27 14:49 - 2014-03-27 14:49 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Avira
2014-03-27 14:42 - 2014-03-27 14:40 - 00000000 ____D () C:\ProgramData\Avira
2014-03-27 14:42 - 2014-03-27 14:40 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-03-27 14:40 - 2014-03-27 14:40 - 00001160 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-03-27 14:38 - 2014-03-27 14:38 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Macromedia
2014-03-27 14:31 - 2014-02-23 05:26 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2014-03-27 14:30 - 2014-03-27 14:30 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Hewlett-Packard
2014-03-27 14:29 - 2014-03-27 14:29 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\Hewlett-Packard
2014-03-27 14:26 - 2014-03-27 14:26 - 00000000 ____D () C:\Users\dkoen_000\AppData\Roaming\ATI
2014-03-27 14:26 - 2014-03-27 14:26 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\ATI
2014-03-27 14:26 - 2014-03-27 14:26 - 00000000 ____D () C:\ProgramData\ATI
2014-03-27 14:25 - 2014-03-27 14:25 - 00001457 _____ () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-27 14:25 - 2014-03-27 14:25 - 00000000 ____D () C:\Users\dkoen_000\AppData\Local\Power2Go8
2014-03-27 14:25 - 2014-02-23 05:35 - 00000000 ___RD () C:\Program Files\Online Services
2014-03-27 14:25 - 2014-02-23 05:30 - 00000000 ___RD () C:\Program Files (x86)\Online Services
2014-03-27 14:25 - 2013-09-03 06:57 - 00000000 _RSHD () C:\SYSTEM.SAV
2014-03-27 14:24 - 2014-03-27 14:24 - 00000020 ___SH () C:\Users\dkoen_000\ntuser.ini
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Vorlagen
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Startmenü
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Netzwerkumgebung
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Lokale Einstellungen
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Eigene Dateien
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Druckumgebung
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\AppData\Local\Verlauf
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\AppData\Local\Anwendungsdaten
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 _SHDL () C:\Users\dkoen_000\Anwendungsdaten
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 __RDL () C:\Users\dkoen_000\Documents\Eigene Musik
2014-03-27 14:24 - 2014-03-27 14:24 - 00000000 __RDL () C:\Users\dkoen_000\Documents\Eigene Bilder
2014-03-27 14:13 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\restore
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Programme
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2014-03-27 14:04 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows NT
2014-03-27 14:04 - 2013-08-22 15:36 - 00000000 __RHD () C:\Users\Default
2014-03-05 14:31 - 2014-03-28 21:31 - 00241136 _____ () C:\Users\dkoen_000\Documents\cc_20140305_133057.reg
2014-03-05 10:26 - 2014-03-29 18:42 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-03-05 10:26 - 2014-03-29 18:42 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-03-05 10:26 - 2014-03-29 18:42 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-03-05 00:53 - 2013-08-22 17:38 - 00693240 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-03-05 00:53 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-01 08:05 - 2014-03-28 20:23 - 23133696 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-01 06:58 - 2014-03-28 20:23 - 02765824 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-03-01 06:30 - 2014-03-28 20:23 - 17074688 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-03-01 06:17 - 2014-03-28 20:23 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-03-01 05:54 - 2014-03-28 20:23 - 05768704 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-03-01 05:47 - 2014-03-28 20:23 - 02168320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-03-01 05:42 - 2014-03-28 20:23 - 00627200 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-03-01 05:18 - 2014-03-28 20:23 - 13051904 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-03-01 05:14 - 2014-03-28 20:23 - 04244480 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-03-01 05:10 - 2014-03-28 20:23 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-03-01 05:03 - 2014-03-28 20:23 - 00524288 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-03-01 04:57 - 2014-03-28 20:23 - 11266048 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-03-01 04:38 - 2014-03-28 20:23 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-03-01 04:32 - 2014-03-28 20:23 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-03-01 04:27 - 2014-03-28 20:23 - 01156096 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-03-01 04:25 - 2014-03-28 20:23 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-03-01 04:25 - 2014-03-28 20:23 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-02-28 20:44 - 2014-03-28 21:39 - 00019575 _____ () C:\Users\dkoen_000\Documents\Zählerstand.xlsx
Some content of TEMP:
====================
C:\Users\dkoen_000\AppData\Local\Temp\avgnt.exe
C:\Users\dkoen_000\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp0mod95.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2014-03-28 20:22] - [2014-01-31 18:15] - 0311640 ____A (Microsoft Corporation) C85C075DE5B6D0FE116043054DE8EE02
LastRegBack: 2013-08-24 23:32
==================== End Of Log ============================