ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=519abdd0a5f7a543806f7eb2e35873d4
# engine=14629
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-08-03 01:01:54
# local_time=2013-08-03 03:01:54 (+0100, Westeuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1797 16775165 100 93 388031 112028535 0 0
# scanned=66952
# found=7
# cleaned=0
# scan_time=10758
sh=CE459E2B703045F9C4A1DA2A1F8413BF31BBF8D9 ft=0 fh=0000000000000000 vn="HTML/Iframe.B.Gen virus" ac=I fn="C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temporary Internet Files\Content.IE5\XFHTYAD1\index[1].htm"
sh=B192E934A028A7005AF0EC2ABC4163B7CB950A89 ft=0 fh=0000000000000000 vn="Win32/Reveton.M trojan" ac=I fn="C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Autostart\regmonstd.lnk"
sh=856613B8F17DA77B4B2C72E0B46649BE84BDDE5A ft=0 fh=0000000000000000 vn="Win32/Reveton.R trojan" ac=I fn="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\rolhj.js"
sh=0F86D6E620BC11634F51FA107FC914508E90C0E6 ft=0 fh=0000000000000000 vn="Win32/Reveton.R trojan" ac=I fn="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\tr2v.js"
sh=F5DF9118614E4762A87CD6FFC59C913C475AB07D ft=1 fh=8609b39d4bef4d50 vn="a variant of Win32/Kryptik.BCHP trojan" ac=I fn="C:\System Volume Information\_restore{481B3143-4F14-4E65-AFC3-95B8F28AFFC7}\RP506\A0138529.exe"
sh=54C8AE680659F97C0D89FB357C903EEA6CC6FB77 ft=1 fh=c71c0011c7e26e7a vn="a variant of Win32/Kryptik.AZNU trojan" ac=I fn="C:\Temp\hlywmtu"
sh=C6124E69FEA7AE7503637EBE34695291E7962894 ft=0 fh=0000000000000000 vn="Win32/LockScreen.AXJ trojan" ac=I fn="C:\Temp\index.html"
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=519abdd0a5f7a543806f7eb2e35873d4
# engine=14629
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-08-03 04:32:21
# local_time=2013-08-03 06:32:21 (+0100, Westeuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1797 16775165 100 93 400658 112041162 120573 0
# scanned=66828
# found=7
# cleaned=0
# scan_time=9737
sh=CE459E2B703045F9C4A1DA2A1F8413BF31BBF8D9 ft=0 fh=0000000000000000 vn="HTML/Iframe.B.Gen virus" ac=I fn="C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temporary Internet Files\Content.IE5\XFHTYAD1\index[1].htm"
sh=B192E934A028A7005AF0EC2ABC4163B7CB950A89 ft=0 fh=0000000000000000 vn="Win32/Reveton.M trojan" ac=I fn="C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Autostart\regmonstd.lnk"
sh=856613B8F17DA77B4B2C72E0B46649BE84BDDE5A ft=0 fh=0000000000000000 vn="Win32/Reveton.R trojan" ac=I fn="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\rolhj.js"
sh=0F86D6E620BC11634F51FA107FC914508E90C0E6 ft=0 fh=0000000000000000 vn="Win32/Reveton.R trojan" ac=I fn="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\tr2v.js"
sh=F5DF9118614E4762A87CD6FFC59C913C475AB07D ft=1 fh=8609b39d4bef4d50 vn="a variant of Win32/Kryptik.BCHP trojan" ac=I fn="C:\System Volume Information\_restore{481B3143-4F14-4E65-AFC3-95B8F28AFFC7}\RP506\A0138529.exe"
sh=54C8AE680659F97C0D89FB357C903EEA6CC6FB77 ft=1 fh=c71c0011c7e26e7a vn="a variant of Win32/Kryptik.AZNU trojan" ac=I fn="C:\Temp\hlywmtu"
sh=C6124E69FEA7AE7503637EBE34695291E7962894 ft=0 fh=0000000000000000 vn="Win32/LockScreen.AXJ trojan" ac=I fn="C:\Temp\index.html"
Results of screen317's Security Check version 0.99.71
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:`````````````` Windows Security Center service is not running! This report may not be accurate! WMI entry may not exist for antivirus; attempting automatic update.
Avira successfully updated!
`````````Anti-malware/Other Utilities Check:`````````
Java(TM) 6 Update 24
Java version out of Date!
Adobe Reader 10.1.7
Adobe Reader out of Date! ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check`````````````````
Total Fragmentation on Drive C::
````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-07-2013 04
Ran by Karo (administrator) on 03-08-2013 12:28:03
Running from C:\Dokumente und Einstellungen\Karo\Desktop
Microsoft Windows XP Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Could not list processes ===============
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [16062464 2006-12-19] (Realtek Semiconductor Corp.)
HKLM\...\Run: [SkyTel] - C:\Windows\SkyTel.EXE [2879488 2006-05-16] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] - C:\Windows\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [avgnt] - C:\Programme\Avira\AntiVir Desktop\avgnt.exe [281768 2010-12-13] (Avira GmbH)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [249064 2010-10-29] (Sun Microsystems, Inc.)
HKLM\...\Run: [AppleSyncNotifier] - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleSyncNotifier.exe [58656 2011-04-20] (Apple Inc.)
HKLM\...\Run: [LWS] - C:\Programme\Logitech\LWS\Webcam Software\LWS.exe [165208 2010-05-07] (Logitech Inc.)
HKLM\...\Run: [HP Software Update] - C:\Programme\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM\...\Run: [APSDaemon] - C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Programme\iTunes\iTunesHelper.exe [421736 2011-11-13] (Apple Inc.)
HKLM\...\Run: [KiesTrayAgent] - C:\Programme\Samsung\Kies\KiesTrayAgent.exe [309688 2012-12-03] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [Adobe ARM] - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-10] (Adobe Systems Incorporated)
HKLM\...\Winlogon: [Shell] Explorer.exe, C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\phxzbypky [x ] ()
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
HKLM\...\InprocServer32: [Default-cscui(XP)] C:\Temp\qljehgsaovfkesavc.dll <==== ATTENTION!
HKCU\...\Run: [] - [x]
HKCU\...\Run: [StartCCC] - C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [90112 2006-11-10] ()
HKCU\...\Run: [swg] - "C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKCU\...\Run: [Logitech Vid HD] - C:\Programme\Logitech\Vid\vid.exe [6061400 2010-05-11] (Logitech Inc.)
HKCU\...\Run: [MSMSGS] - C:\Programme\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKCU\...\Run: [NTRedirect] - C:\WINDOWS\system32\rundll32.exe [33792 2008-04-14] (Microsoft Corporation)
HKU\Administrator\...\Run: [] - [x]
HKU\Administrator\...\Run: [StartCCC] - C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [ 2006-11-10] ()
HKU\Administrator\...\Run: [swg] - "C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\Administrator\...\Run: [MSMSGS] - C:\Programme\Messenger\msmsgs.exe [ 2008-04-14] (Microsoft Corporation)
HKU\Administrator\...\Run: [ctfmon32.exe] - C:\DOKUME~1\ALLUSE~1\ANWEND~1\rundll32.exe C:\DOKUME~1\ALLUSE~1\ANWEND~1\jhlor.dat,XFG00 [x] <===== ATTENTION
HKU\Administrator\...\RunOnce: [FlashPlayerUpdate] - C:\WINDOWS\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe -update activex [x]
HKU\Default User\...\RunOnce: [nltide_3] - rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N [x]
HKU\Default User\...\RunOnce: [_nltide_3] - rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N [x]
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\REALTEK 11n USB Wireless LAN Utility.lnk
ShortcutTarget: REALTEK 11n USB Wireless LAN Utility.lnk -> C:\Programme\Realtek\11n USB Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Windows Search.lnk
ShortcutTarget: Windows Search.lnk -> C:\Programme\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
Startup: C:\Dokumente und Einstellungen\Karo\Startmenü\Programme\Autostart\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {65759893-8694-43BC-876A-6699814FD7C9} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=827316&p={searchTerms}
SearchScopes: HKCU - {C8AAC839-E6AB-418F-8444-2AFA890364E6} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=DVS2&o=1586&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=^AAA&apn_dtid=^YYYYYY^YY^DE&apn_uid=59755d13-de52-4e86-869b-39980b806c89&apn_sauid=7A519D86-4CC2-4414-A0B5-FA937669223B
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programme\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: LyricXeeker - {17E58097-6CA5-448B-830F-2A19678248FB} - C:\Programme\LyriXeeker\125.dll (LyriXeeker Tech)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Programme\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKCU -No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1296499764250
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Programme\Avira\AntiVir Desktop\sched.exe [136360 2011-05-08] (Avira GmbH)
R2 AntiVirService; C:\Programme\Avira\AntiVir Desktop\avguard.exe [269480 2011-06-28] (Avira GmbH)
R3 hpqcxs08; C:\Programme\HP\Digital Imaging\bin\hpqcxs08.dll [253568 2009-11-18] (Hewlett-Packard Co.)
R2 hpqddsvc; C:\Programme\HP\Digital Imaging\bin\hpqddsvc.dll [137344 2009-11-18] (Hewlett-Packard Co.)
R3 iPod Service; C:\Programme\iPod\bin\iPodService.exe [821608 2011-11-13] (Apple Inc.)
R2 LVPrcSrv; C:\Programme\Gemeinsame Dateien\Logishrd\LVMVFM\LVPrcSrv.exe [162648 2010-05-07] (Logitech Inc.)
R2 Skype C2C Service; C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.)
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [161384 2013-02-28] (Skype Technologies)
S3 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2009-02-04] (Microsoft Corporation)
S4 HidServ; %SystemRoot%\System32\hidserv.dll [x]
R2 JavaQuickStarterService; "C:\Programme\Java\jre6\bin\jqs.exe" -service -config "C:\Programme\Java\jre6\lib\deploy\jqs\jqs.conf" [x]
S2 winmgmt; C:\DOKUME~1\Erilk\5085948.dll [x]
==================== Drivers (Whitelisted) ====================
R2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [21361 2011-01-31] (Cisco Systems, Inc.)
R3 AR5416; C:\Windows\System32\DRIVERS\athw.sys [1606368 2011-01-31] (Atheros Communications, Inc.)
R1 avgio; C:\Programme\Avira\AntiVir Desktop\avgio.sys [11608 2010-06-17] (Avira GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [66616 2011-06-28] (Avira GmbH)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [138192 2011-06-28] (Avira GmbH)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 CompFilter; C:\Windows\System32\DRIVERS\lvbusflt.sys [20704 2010-05-14] (Logitech Inc.)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2008-10-29] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2008-10-29] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2008-10-29] (HP)
R3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2Mon.sys [25824 2010-05-07] ()
S3 NABTSFEC; C:\Windows\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-14] (Microsoft Corporation)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 rtl8139; C:\Windows\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
S3 SLIP; C:\Windows\System32\DRIVERS\SLIP.sys [11136 2008-04-14] (Microsoft Corporation)
S3 sscebus; C:\Windows\System32\DRIVERS\sscebus.sys [98560 2012-06-27] (MCCI Corporation)
S3 sscemdfl; C:\Windows\System32\DRIVERS\sscemdfl.sys [14848 2012-06-27] (MCCI Corporation)
S3 sscemdm; C:\Windows\System32\DRIVERS\sscemdm.sys [123648 2012-06-27] (MCCI Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2010-06-17] (Avira GmbH)
S3 streamip; C:\Windows\System32\DRIVERS\StreamIP.sys [15232 2008-04-14] (Microsoft Corporation)
S3 WSTCODEC; C:\Windows\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-14] (Microsoft Corporation)
S4 IntelIde; No ImagePath
S3 USBAAPL; System32\Drivers\usbaapl.sys [x]
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-03 12:29 - 2013-08-03 12:30 - 00012600 _____ C:\Temp\log3
2013-08-03 12:29 - 2013-08-03 12:30 - 00003869 _____ C:\Temp\log1
2013-08-03 12:29 - 2013-08-03 12:29 - 00000000 ____T C:\Temp\~DFD6F4.tmp
2013-08-03 12:28 - 2013-08-03 12:29 - 00011172 _____ C:\Temp\frstlog
2013-08-03 12:28 - 2013-08-03 12:28 - 00000303 _____ C:\Temp\users00
2013-08-03 12:28 - 2013-08-03 12:28 - 00000003 _____ C:\Temp\others
2013-08-03 12:18 - 2013-08-03 12:18 - 00000000 ____D C:\Temp\RarSFX0
2013-08-03 12:14 - 2013-08-03 12:15 - 00891098 _____ C:\Dokumente und Einstellungen\Karo\Desktop\SecurityCheck.exe
2013-08-03 03:48 - 2013-08-03 12:25 - 00032768 ____T C:\Temp\~DF2413.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00032768 _____ C:\Temp\~DFF3C0.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00032768 _____ C:\Temp\~DFF311.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00016384 ____T C:\Temp\~DF1895.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00016384 _____ C:\Temp\~DFF376.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00000512 ____T C:\Temp\~DFF3CE.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00000512 ____T C:\Temp\~DFF384.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00000512 ____T C:\Temp\~DFF325.tmp
2013-08-03 03:33 - 2013-08-03 03:33 - 00001313 ____T C:\Temp\MARA14.tmp
2013-08-03 03:33 - 2013-08-03 03:33 - 00001285 ____T C:\Temp\MARA15.tmp
2013-08-03 03:33 - 2013-08-03 03:33 - 00000000 ____D C:\Temp\svfdm.tmp
2013-08-03 03:32 - 2013-08-03 03:32 - 00000073 _____ C:\Temp\upe12.tmp
2013-08-03 03:31 - 2013-08-03 03:32 - 00000281 _____ C:\Temp\uprB.tmp
2013-08-03 03:31 - 2013-08-03 03:31 - 00000000 ____D C:\Temp\WPDNSE
2013-08-02 23:57 - 2013-08-02 23:57 - 03126311 _____ C:\Temp\NOD377B.tmp
2013-08-02 23:57 - 2013-08-02 23:57 - 00000333 _____ C:\Temp\NOD3B87.tmp
2013-08-02 23:34 - 2013-08-02 23:34 - 00000000 ____D C:\Dokumente und Einstellungen\Karo\Anwendungsdaten\ESET
2013-08-02 23:33 - 2013-08-02 23:33 - 00264880 _____ (ESET) C:\Temp\InstHelper.exe
2013-08-02 22:44 - 2013-08-02 22:44 - 00001313 ____T C:\Temp\MARA12.tmp
2013-08-02 22:44 - 2013-08-02 22:44 - 00001285 ____T C:\Temp\MARA13.tmp
2013-08-02 22:43 - 2013-08-02 22:43 - 00000281 _____ C:\Temp\uprA.tmp
2013-08-02 22:43 - 2013-08-02 22:43 - 00000073 _____ C:\Temp\upe11.tmp
2013-08-02 14:01 - 2013-08-02 14:01 - 00062770 _____ C:\Dokumente und Einstellungen\Karo\Desktop\FRST2.txt
2013-08-02 14:00 - 2013-08-02 14:00 - 00029310 _____ C:\Dokumente und Einstellungen\Karo\Desktop\Addition2.txt
2013-08-02 13:18 - 2013-08-02 13:18 - 00000073 _____ C:\Temp\upeA12.tmp
2013-08-02 13:16 - 2013-08-02 13:16 - 00001313 ____T C:\Temp\MARA10.tmp
2013-08-02 13:16 - 2013-08-02 13:16 - 00001285 ____T C:\Temp\MARA11.tmp
2013-08-02 13:16 - 2013-08-02 13:16 - 00000000 _____ C:\Temp\upeF.tmp
2013-08-02 13:15 - 2013-08-02 13:15 - 00000000 _____ C:\Temp\upr9.tmp
2013-08-02 13:15 - 2013-08-02 13:15 - 00000000 _____ C:\Temp\upeE.tmp
2013-08-02 13:12 - 2013-08-02 13:12 - 00017176 _____ C:\AdwCleaner[S1].txt
2013-08-02 13:10 - 2013-08-02 13:10 - 00666633 _____ C:\Dokumente und Einstellungen\Karo\Desktop\adwcleaner06.exe
2013-08-02 12:50 - 2013-08-02 12:50 - 00001313 ____T C:\Temp\MARA0E.tmp
2013-08-02 12:50 - 2013-08-02 12:50 - 00001285 ____T C:\Temp\MARA0F.tmp
2013-08-02 12:49 - 2013-08-02 12:49 - 00000073 _____ C:\Temp\upeD.tmp
2013-08-02 12:48 - 2013-08-02 12:49 - 00000281 _____ C:\Temp\upr8.tmp
2013-08-01 19:54 - 2013-08-01 19:54 - 00001313 ____T C:\Temp\MARA0C.tmp
2013-08-01 19:54 - 2013-08-01 19:54 - 00001285 ____T C:\Temp\MARA0D.tmp
2013-08-01 19:54 - 2013-08-01 19:54 - 00000073 _____ C:\Temp\upeC.tmp
2013-08-01 19:53 - 2013-08-01 19:53 - 00000281 _____ C:\Temp\upr7.tmp
2013-08-01 19:06 - 2013-08-01 19:08 - 00000213 _____ C:\Dokumente und Einstellungen\Karo\Eigene Dateien\Fixlist.txt
2013-08-01 19:01 - 2013-08-01 19:01 - 00001313 ____T C:\Temp\MARA0A.tmp
2013-08-01 19:01 - 2013-08-01 19:01 - 00001285 ____T C:\Temp\MARA0B.tmp
2013-08-01 19:00 - 2013-08-01 19:00 - 00000281 _____ C:\Temp\upr6.tmp
2013-08-01 19:00 - 2013-08-01 19:00 - 00000073 _____ C:\Temp\upe47.tmp
2013-07-31 15:28 - 2013-08-02 13:35 - 00029310 _____ C:\Dokumente und Einstellungen\Karo\Desktop\Addition.txt
2013-07-31 15:22 - 2013-07-31 15:22 - 00000073 _____ C:\Temp\upeB.tmp
2013-07-31 15:21 - 2013-07-31 15:22 - 00000281 _____ C:\Temp\upr5.tmp
2013-07-31 15:17 - 2013-07-31 15:17 - 01781589 _____ (Farbar) C:\Dokumente und Einstellungen\Karo\Desktop\FRST64.exe
2013-07-31 15:16 - 2013-07-31 15:16 - 01222064 _____ (Farbar) C:\Dokumente und Einstellungen\Karo\Desktop\FRST.exe
2013-07-31 15:16 - 2013-07-31 15:16 - 00000000 ____D C:\FRST
2013-07-31 15:00 - 2013-07-31 15:00 - 00000281 _____ C:\Temp\uprA13.tmp
2013-07-31 15:00 - 2013-07-31 15:00 - 00000073 _____ C:\Temp\upeA14.tmp
2013-07-31 14:50 - 2013-07-31 14:50 - 00001313 ____T C:\Temp\MARA08.tmp
2013-07-31 14:50 - 2013-07-31 14:50 - 00001285 ____T C:\Temp\MARA09.tmp
2013-07-31 14:49 - 2013-07-31 14:49 - 00000281 _____ C:\Temp\upr4.tmp
2013-07-31 14:49 - 2013-07-31 14:49 - 00000073 _____ C:\Temp\upeA.tmp
2013-07-31 14:32 - 2013-07-31 14:36 - 00000000 ____D C:\Temp\B5EC8CB8-BAB0-7891-93B8-0638EA6B0C45
2013-07-31 14:32 - 2013-07-31 14:32 - 00000281 _____ C:\Temp\uprF.tmp
2013-07-31 14:32 - 2013-07-31 14:32 - 00000073 _____ C:\Temp\upe10.tmp
2013-07-31 14:32 - 2013-07-31 14:32 - 00000000 ____D C:\Temp\tmp1985
2013-07-31 14:32 - 2013-07-31 14:32 - 00000000 ____D C:\Temp\ish135531
2013-07-31 14:32 - 2013-07-31 14:32 - 00000000 ____D C:\Programme\LyriXeeker
2013-07-31 14:31 - 2013-07-31 14:31 - 00000281 _____ C:\Temp\upr3.tmp
2013-07-31 14:31 - 2013-07-31 14:31 - 00000073 _____ C:\Temp\upe9.tmp
2013-07-31 13:56 - 2013-07-31 13:56 - 00000000 ____D C:\Dokumente und Einstellungen\Karo\Qtrax
2013-07-31 13:52 - 2013-07-31 13:59 - 00000000 ____D C:\Temp\CFC193DF-BAB0-7891-BDCD-EA1E26220A59
2013-07-31 13:52 - 2013-07-31 13:52 - 00000281 _____ C:\Temp\uprA12.tmp
2013-07-31 13:52 - 2013-07-31 13:52 - 00000073 _____ C:\Temp\upeA13.tmp
2013-07-31 13:52 - 2013-07-31 13:52 - 00000000 ____D C:\Temp\tmp6241
2013-07-31 13:52 - 2013-07-31 13:52 - 00000000 ____D C:\Temp\ish18754078
2013-07-31 08:45 - 2013-07-31 08:47 - 00004392 _____ C:\Temp\HPWUCl084.log
2013-07-31 08:42 - 2013-07-31 08:42 - 00001313 ____T C:\Temp\MARA06.tmp
2013-07-31 08:42 - 2013-07-31 08:42 - 00001285 ____T C:\Temp\MARA07.tmp
2013-07-31 08:41 - 2013-07-31 08:41 - 00000073 _____ C:\Temp\upe8.tmp
2013-07-31 08:40 - 2013-07-31 08:41 - 00000272 _____ C:\Temp\upr2.tmp
2013-07-30 19:00 - 2013-07-30 19:00 - 00001313 ____T C:\Temp\MARA04.tmp
2013-07-30 19:00 - 2013-07-30 19:00 - 00001285 ____T C:\Temp\MARA05.tmp
2013-07-30 18:59 - 2013-07-30 18:59 - 00000073 _____ C:\Temp\upe7.tmp
2013-07-30 18:58 - 2013-07-30 18:59 - 00000272 _____ C:\Temp\upr1.tmp
2013-07-30 15:10 - 2013-08-03 03:32 - 00000346 _____ C:\WINDOWS\Tasks\LyricXeeker Update.job
2013-07-30 15:10 - 2013-07-31 14:33 - 00000735 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Open It!.lnk
2013-07-30 15:10 - 2013-07-30 15:14 - 00000000 ____D C:\Temp\1EA55D3C-BAB0-7891-9DA9-F386E4DCBD17
2013-07-30 15:10 - 2013-07-30 15:10 - 00000272 _____ C:\Temp\uprA07.tmp
2013-07-30 15:10 - 2013-07-30 15:10 - 00000073 _____ C:\Temp\upeA08.tmp
2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ____D C:\Temp\tmp1978
2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ____D C:\Temp\{2F822836-52C6-427A-8690-91732CB6F143}
2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ____D C:\Programme\OpenIt
2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ____D C:\Dokumente und Einstellungen\Karo\Anwendungsdaten\DigitalSite
2013-07-30 15:09 - 2013-07-31 14:32 - 00000000 ____D C:\Temp\is357113909
2013-07-30 15:09 - 2013-07-30 15:09 - 00717160 _____ C:\Dokumente und Einstellungen\Karo\Eigene Dateien\ZipOpenerSetup.exe
2013-07-30 15:09 - 2013-07-30 15:09 - 00000000 ____D C:\Temp\ish6262156
2013-07-30 13:30 - 2013-07-30 13:30 - 00000000 ____D C:\Dokumente und Einstellungen\Karo\Anwendungsdaten\Windows Search
2013-07-30 13:27 - 2013-07-30 13:27 - 00001313 ____T C:\Temp\MARA02.tmp
2013-07-30 13:27 - 2013-07-30 13:27 - 00001285 ____T C:\Temp\MARA03.tmp
2013-07-30 11:59 - 2013-07-30 11:59 - 00001313 ____T C:\Temp\MAR9FE.tmp
2013-07-30 11:59 - 2013-07-30 11:59 - 00001285 ____T C:\Temp\MAR9FF.tmp
2013-07-30 11:55 - 2013-07-30 11:55 - 00001313 ____T C:\Temp\MARA00.tmp
2013-07-30 11:55 - 2013-07-30 11:55 - 00001285 ____T C:\Temp\MARA01.tmp
2013-07-30 11:22 - 2013-07-30 11:22 - 00001313 ____T C:\Temp\MAR9FC.tmp
2013-07-30 11:22 - 2013-07-30 11:22 - 00001285 ____T C:\Temp\MAR9FD.tmp
2013-07-29 19:07 - 2013-07-29 19:07 - 00001313 ____T C:\Temp\MAR9FA.tmp
2013-07-29 19:07 - 2013-07-29 19:07 - 00001285 ____T C:\Temp\MAR9FB.tmp
2013-07-29 19:06 - 2013-07-29 19:06 - 00000000 ____D C:\Temp\svkah.tmp
2013-07-29 19:05 - 2013-07-29 19:05 - 00049152 _____ C:\Temp\~DF3474.tmp
2013-07-29 15:17 - 2013-07-29 15:17 - 00001313 ____T C:\Temp\MAR9F8.tmp
2013-07-29 15:17 - 2013-07-29 15:17 - 00001285 ____T C:\Temp\MAR9F9.tmp
2013-07-29 15:15 - 2013-07-29 15:15 - 00049152 _____ C:\Temp\~DF3F36.tmp
2013-07-29 12:01 - 2013-07-29 12:01 - 00001313 ____T C:\Temp\MAR9F6.tmp
2013-07-29 12:01 - 2013-07-29 12:01 - 00001285 ____T C:\Temp\MAR9F7.tmp
2013-07-29 12:00 - 2013-07-29 12:00 - 00049152 _____ C:\Temp\~DFEE53.tmp
2013-07-27 08:55 - 2013-07-27 08:55 - 00001313 ____T C:\Temp\MAR9F3.tmp
2013-07-27 08:55 - 2013-07-27 08:55 - 00001285 ____T C:\Temp\MAR9F5.tmp
2013-07-27 08:53 - 2013-07-27 08:53 - 00049152 _____ C:\Temp\~DF27CC.tmp
2013-07-27 02:41 - 2013-07-27 02:41 - 00001313 ____T C:\Temp\MAR9F2.tmp
2013-07-27 02:41 - 2013-07-27 02:41 - 00001285 ____T C:\Temp\MAR9F4.tmp
2013-07-27 02:39 - 2013-07-27 02:39 - 00049152 _____ C:\Temp\~DFD3.tmp
2013-07-27 02:36 - 2013-07-27 02:36 - 00016384 ____T C:\Temp\~DF2345.tmp
2013-07-27 02:35 - 2013-07-27 02:35 - 00016384 ____T C:\Temp\~DF9B0D.tmp
2013-07-27 02:35 - 2013-07-27 02:35 - 00000000 ____D C:\Temp\WER104a.dir00
2013-07-27 02:35 - 2013-07-27 02:35 - 00000000 ____D C:\Temp\WER1022.dir00
2013-07-27 02:34 - 2013-07-27 02:34 - 00016384 ____T C:\Temp\~DF2B6.tmp
2013-07-27 02:33 - 2013-07-27 02:33 - 00016384 ____T C:\Temp\~DF652B.tmp
2013-07-27 02:33 - 2013-07-27 02:33 - 00016384 ____T C:\Temp\~DF24D8.tmp
2013-07-27 02:32 - 2013-07-27 02:32 - 00000000 ____T C:\Temp\~DF998F.tmp
2013-07-27 02:30 - 2013-07-27 02:30 - 00000000 ____T C:\Temp\~DF7A36.tmp
2013-07-27 02:29 - 2013-07-27 02:29 - 18655396 _____ C:\Temp\fla9F3.tmp
2013-07-27 02:29 - 2013-07-27 02:29 - 00000000 ____T C:\Temp\~DF1194.tmp
2013-07-27 02:03 - 2013-07-27 02:28 - 00016384 ____T C:\Temp\~DF237.tmp
2013-07-27 02:03 - 2013-07-27 02:03 - 00001313 ____T C:\Temp\MAR9F0.tmp
2013-07-27 02:03 - 2013-07-27 02:03 - 00001285 ____T C:\Temp\MAR9F1.tmp
2013-07-27 02:03 - 2013-07-27 02:03 - 00000000 ____T C:\Temp\~DFBE36.tmp
2013-07-27 02:02 - 2013-07-27 02:02 - 00049152 _____ C:\Temp\~DF2A07.tmp
2013-07-27 02:02 - 2013-07-27 02:02 - 00016384 ____T C:\Temp\Perflib_Perfdata_fe8.dat
2013-07-26 14:58 - 2013-07-26 14:58 - 00000000 ____T C:\Temp\~DFC07F.tmp
2013-07-26 14:58 - 2013-07-26 14:58 - 00000000 ____T C:\Temp\~DFB5B8.tmp
2013-07-26 14:48 - 2013-07-26 14:48 - 00001313 ____T C:\Temp\MAR9EE.tmp
2013-07-26 14:48 - 2013-07-26 14:48 - 00001285 ____T C:\Temp\MAR9EF.tmp
2013-07-26 14:47 - 2013-07-26 14:47 - 00016384 ____T C:\Temp\Perflib_Perfdata_7c0.dat
2013-07-26 14:46 - 2013-07-26 14:46 - 00049152 _____ C:\Temp\~DF209D.tmp
2013-07-25 21:06 - 2013-07-25 21:06 - 00001313 ____T C:\Temp\MAR9EC.tmp
2013-07-25 21:06 - 2013-07-25 21:06 - 00001285 ____T C:\Temp\MAR9ED.tmp
2013-07-25 21:04 - 2013-07-25 21:04 - 00049152 _____ C:\Temp\~DF22E4.tmp
2013-07-25 12:43 - 2013-07-25 12:43 - 00001714 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader X.lnk
2013-07-25 12:42 - 2013-07-25 12:42 - 00000000 ____D C:\Programme\Adobe
2013-07-25 12:35 - 2013-07-25 12:35 - 00001313 ____T C:\Temp\MAR9EA.tmp
2013-07-25 12:35 - 2013-07-25 12:35 - 00001285 ____T C:\Temp\MAR9EB.tmp
2013-07-25 12:33 - 2013-07-25 12:33 - 00049152 _____ C:\Temp\~DF7DC4.tmp
2013-07-25 00:26 - 2013-07-25 00:26 - 00001313 ____T C:\Temp\MAR9E7.tmp
2013-07-25 00:26 - 2013-07-25 00:26 - 00001285 ____T C:\Temp\MAR9E9.tmp
2013-07-25 00:24 - 2013-07-25 00:24 - 00049152 _____ C:\Temp\~DFD00C.tmp
2013-07-24 14:05 - 2013-07-24 14:05 - 00001313 ____T C:\Temp\MAR9E6.tmp
2013-07-24 14:05 - 2013-07-24 14:05 - 00001285 ____T C:\Temp\MAR9E8.tmp
2013-07-24 14:03 - 2013-07-24 14:03 - 00049152 _____ C:\Temp\~DFF7C6.tmp
2013-07-23 23:21 - 2013-07-23 23:23 - 00004392 _____ C:\Temp\HPWUCl083.log
2013-07-23 23:19 - 2013-07-23 23:19 - 00001313 ____T C:\Temp\MAR9E4.tmp
2013-07-23 23:19 - 2013-07-23 23:19 - 00001285 ____T C:\Temp\MAR9E5.tmp
2013-07-23 23:17 - 2013-07-23 23:17 - 00049152 _____ C:\Temp\~DF6ACC.tmp
2013-07-23 15:02 - 2013-07-23 15:02 - 00001313 ____T C:\Temp\MAR9E2.tmp
2013-07-23 15:02 - 2013-07-23 15:02 - 00001285 ____T C:\Temp\MAR9E3.tmp
2013-07-23 15:00 - 2013-07-23 15:00 - 00049152 _____ C:\Temp\~DFDDC5.tmp
2013-07-23 12:34 - 2013-07-23 12:34 - 00001313 ____T C:\Temp\MAR9E0.tmp
2013-07-23 12:34 - 2013-07-23 12:34 - 00001285 ____T C:\Temp\MAR9E1.tmp
2013-07-23 12:32 - 2013-07-23 12:32 - 00049152 _____ C:\Temp\~DFE25E.tmp
2013-07-23 00:49 - 2013-07-23 00:49 - 00001313 ____T C:\Temp\MAR9DE.tmp
2013-07-23 00:49 - 2013-07-23 00:49 - 00001285 ____T C:\Temp\MAR9DF.tmp
2013-07-23 00:47 - 2013-07-23 00:47 - 00049152 _____ C:\Temp\~DF1E6A.tmp
2013-07-22 14:31 - 2013-07-22 14:31 - 00001313 ____T C:\Temp\MAR9DC.tmp
2013-07-22 14:31 - 2013-07-22 14:31 - 00001285 ____T C:\Temp\MAR9DD.tmp
2013-07-22 14:29 - 2013-07-22 14:29 - 00049152 _____ C:\Temp\~DFE12A.tmp
2013-07-21 22:19 - 2013-07-21 22:39 - 00016384 ____T C:\Temp\~DFF32C.tmp
2013-07-21 22:19 - 2013-07-21 22:19 - 00000000 ____T C:\Temp\~DFEACA.tmp
2013-07-21 16:38 - 2013-07-21 16:38 - 00001313 ____T C:\Temp\MAR9DA.tmp
2013-07-21 16:38 - 2013-07-21 16:38 - 00001285 ____T C:\Temp\MAR9DB.tmp
2013-07-21 16:37 - 2013-07-21 16:37 - 00016384 ____T C:\Temp\Perflib_Perfdata_9cc.dat
2013-07-21 16:36 - 2013-07-21 16:36 - 00049152 _____ C:\Temp\~DF8E7.tmp
2013-07-21 16:29 - 2013-07-21 16:30 - 00016384 ____T C:\Temp\~DFF9F2.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00057344 ____T C:\Temp\~DF41EB.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00000000 ____T C:\Temp\~DFCB8A.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00000000 ____T C:\Temp\~DFBA2C.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00000000 ____T C:\Temp\~DF8322.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00000000 ____T C:\Temp\~DF521.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00000000 ____T C:\Temp\~DF2964.tmp
2013-07-21 16:28 - 2013-07-21 16:33 - 00016384 ____T C:\Temp\~DFFB26.tmp
2013-07-21 16:28 - 2013-07-21 16:32 - 00016384 ____T C:\Temp\~DFE8E2.tmp
2013-07-21 16:28 - 2013-07-21 16:30 - 00016384 ____T C:\Temp\~DF9676.tmp
2013-07-21 16:28 - 2013-07-21 16:29 - 00016384 ____T C:\Temp\~DF8474.tmp
2013-07-21 16:28 - 2013-07-21 16:28 - 00000000 ____T C:\Temp\~DF2D5C.tmp
2013-07-21 16:23 - 2013-07-21 16:27 - 00016384 ____T C:\Temp\~DFD4C7.tmp
2013-07-21 16:23 - 2013-07-21 16:23 - 00016384 ____T C:\Temp\~DFC7E7.tmp
2013-07-21 14:04 - 2013-07-21 14:04 - 00001313 ____T C:\Temp\MAR9D8.tmp
2013-07-21 14:04 - 2013-07-21 14:04 - 00001285 ____T C:\Temp\MAR9D9.tmp
2013-07-21 14:03 - 2013-07-21 14:03 - 00049152 _____ C:\Temp\~DFE92F.tmp
2013-07-20 16:09 - 2013-07-20 16:09 - 00001313 ____T C:\Temp\MAR9D6.tmp
2013-07-20 16:09 - 2013-07-20 16:09 - 00001285 ____T C:\Temp\MAR9D7.tmp
2013-07-20 16:08 - 2013-07-20 16:08 - 00049152 _____ C:\Temp\~DFEB37.tmp
2013-07-20 14:17 - 2013-07-20 14:17 - 00001313 ____T C:\Temp\MAR9D3.tmp
2013-07-20 14:17 - 2013-07-20 14:17 - 00001285 ____T C:\Temp\MAR9D5.tmp
2013-07-20 14:15 - 2013-07-20 14:15 - 00049152 _____ C:\Temp\~DF576E.tmp
2013-07-19 02:24 - 2013-07-19 02:24 - 00001313 ____T C:\Temp\MAR9D2.tmp
2013-07-19 02:24 - 2013-07-19 02:24 - 00001285 ____T C:\Temp\MAR9D4.tmp
2013-07-19 02:22 - 2013-07-19 02:22 - 00049152 _____ C:\Temp\~DFC222.tmp
2013-07-17 19:00 - 2013-07-17 19:00 - 00001313 ____T C:\Temp\MAR9D0.tmp
2013-07-17 19:00 - 2013-07-17 19:00 - 00001285 ____T C:\Temp\MAR9D1.tmp
2013-07-17 18:58 - 2013-07-17 18:58 - 00049152 _____ C:\Temp\~DFD784.tmp
2013-07-16 20:35 - 2013-07-16 20:35 - 00047416 ____T C:\Temp\DIOADD.tmp
2013-07-16 20:34 - 2013-07-16 20:34 - 00047416 ____T C:\Temp\DIOA20.tmp
2013-07-16 20:34 - 2013-07-16 20:34 - 00047416 ____T C:\Temp\DIO9EB.tmp
2013-07-16 19:00 - 2013-07-16 19:02 - 00004392 _____ C:\Temp\HPWUCl082.log
2013-07-16 18:57 - 2013-07-16 18:57 - 00001313 ____T C:\Temp\MAR9CE.tmp
2013-07-16 18:57 - 2013-07-16 18:57 - 00001285 ____T C:\Temp\MAR9CF.tmp
2013-07-16 18:55 - 2013-07-16 18:55 - 00049152 _____ C:\Temp\~DF9742.tmp
2013-07-15 18:15 - 2013-07-15 18:15 - 00001313 ____T C:\Temp\MAR9CC.tmp
2013-07-15 18:15 - 2013-07-15 18:15 - 00001285 ____T C:\Temp\MAR9CD.tmp
2013-07-15 18:13 - 2013-07-15 18:13 - 00049152 _____ C:\Temp\~DFF71D.tmp
2013-07-15 04:54 - 2013-07-15 04:54 - 00001313 ____T C:\Temp\MAR9CA.tmp
2013-07-15 04:54 - 2013-07-15 04:54 - 00001285 ____T C:\Temp\MAR9CB.tmp
2013-07-15 04:51 - 2013-07-15 04:51 - 00049152 _____ C:\Temp\~DFE7C.tmp
2013-07-14 15:28 - 2013-07-14 15:28 - 00001313 ____T C:\Temp\MAR9C8.tmp
2013-07-14 15:28 - 2013-07-14 15:28 - 00001285 ____T C:\Temp\MAR9C9.tmp
2013-07-14 15:26 - 2013-07-14 15:26 - 00049152 _____ C:\Temp\~DF3C5A.tmp
2013-07-14 07:45 - 2013-07-14 07:45 - 00001313 ____T C:\Temp\MAR9C6.tmp
2013-07-14 07:45 - 2013-07-14 07:45 - 00001285 ____T C:\Temp\MAR9C7.tmp
2013-07-14 07:43 - 2013-07-14 07:43 - 00049152 _____ C:\Temp\~DF2D8.tmp
2013-07-14 00:09 - 2013-07-14 00:09 - 00001313 ____T C:\Temp\MAR9C4.tmp
2013-07-14 00:09 - 2013-07-14 00:09 - 00001285 ____T C:\Temp\MAR9C5.tmp
2013-07-14 00:08 - 2013-07-14 00:08 - 00049152 _____ C:\Temp\~DF298.tmp
2013-07-13 15:12 - 2013-07-13 15:12 - 00001313 ____T C:\Temp\MAR9C2.tmp
2013-07-13 15:12 - 2013-07-13 15:12 - 00001285 ____T C:\Temp\MAR9C3.tmp
2013-07-13 15:11 - 2013-07-13 15:11 - 00049152 _____ C:\Temp\~DF30AC.tmp
2013-07-13 11:11 - 2013-07-13 11:11 - 00001313 ____T C:\Temp\MAR9C0.tmp
2013-07-13 11:11 - 2013-07-13 11:11 - 00001285 ____T C:\Temp\MAR9C1.tmp
2013-07-13 11:09 - 2013-07-13 11:09 - 00049152 _____ C:\Temp\~DF2A1C.tmp
2013-07-13 11:07 - 2013-07-13 11:07 - 00000000 ____T C:\Temp\~DF607C.tmp
2013-07-13 11:03 - 2013-07-13 11:05 - 00016384 ____T C:\Temp\~DFBC83.tmp
2013-07-13 11:03 - 2013-07-13 11:03 - 00000000 ____T C:\Temp\~DFB452.tmp
2013-07-13 11:01 - 2013-07-13 11:01 - 00001313 ____T C:\Temp\MAR9BE.tmp
2013-07-13 11:01 - 2013-07-13 11:01 - 00001285 ____T C:\Temp\MAR9BF.tmp
2013-07-13 11:00 - 2013-07-13 11:00 - 00016384 ____T C:\Temp\Perflib_Perfdata_98c.dat
2013-07-13 10:59 - 2013-07-13 10:59 - 00049152 _____ C:\Temp\~DFB9C4.tmp
2013-07-12 15:09 - 2013-07-12 15:09 - 00001313 ____T C:\Temp\MAR9BC.tmp
2013-07-12 15:09 - 2013-07-12 15:09 - 00001285 ____T C:\Temp\MAR9BD.tmp
2013-07-12 15:07 - 2013-07-12 15:07 - 00049152 _____ C:\Temp\~DFAA2F.tmp
2013-07-11 21:41 - 2013-07-11 21:41 - 00123763 _____ C:\WINDOWS\KB2834904.log
2013-07-11 21:41 - 2013-07-11 21:41 - 00123541 _____ C:\WINDOWS\KB2834886.log
2013-07-11 21:41 - 2013-07-11 21:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-11 21:41 - 2013-07-11 21:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-11 21:41 - 2013-07-11 21:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-11 21:40 - 2013-07-11 21:40 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-11 21:30 - 2013-07-11 21:31 - 00128951 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-11 19:03 - 2013-07-11 21:41 - 00128560 _____ C:\WINDOWS\KB2850851.log
2013-07-11 19:03 - 2013-07-11 21:40 - 00127298 _____ C:\WINDOWS\KB2845187.log
2013-07-11 18:58 - 2013-07-11 18:58 - 00001313 ____T C:\Temp\MAR9BA.tmp
2013-07-11 18:58 - 2013-07-11 18:58 - 00001285 ____T C:\Temp\MAR9BB.tmp
2013-07-11 18:56 - 2013-07-11 18:56 - 00049152 _____ C:\Temp\~DF3661.tmp
2013-07-10 19:56 - 2013-07-10 19:56 - 00001313 ____T C:\Temp\MAR9B8.tmp
2013-07-10 19:56 - 2013-07-10 19:56 - 00001285 ____T C:\Temp\MAR9B9.tmp
2013-07-10 19:54 - 2013-07-10 19:54 - 00049152 _____ C:\Temp\~DF9409.tmp
2013-07-10 18:23 - 2013-07-10 18:23 - 00001313 ____T C:\Temp\MAR9B6.tmp
2013-07-10 18:23 - 2013-07-10 18:23 - 00001285 ____T C:\Temp\MAR9B7.tmp
2013-07-10 18:21 - 2013-07-10 18:21 - 00049152 _____ C:\Temp\~DF13FD.tmp
2013-07-09 22:24 - 2013-07-09 22:24 - 00001313 ____T C:\Temp\MAR9B4.tmp
2013-07-09 22:24 - 2013-07-09 22:24 - 00001285 ____T C:\Temp\MAR9B5.tmp
2013-07-09 22:22 - 2013-07-09 22:22 - 00049152 _____ C:\Temp\~DF2052.tmp
2013-07-09 22:18 - 2013-07-09 22:18 - 04518624 _____ C:\Temp\fla9FA.tmp
2013-07-09 22:18 - 2013-07-09 22:18 - 01339208 _____ C:\Temp\fla9F8.tmp
2013-07-09 22:18 - 2013-07-09 22:18 - 01084901 _____ C:\Temp\fla9F9.tmp
2013-07-09 22:18 - 2013-07-09 22:18 - 00523260 _____ C:\Temp\fla9F7.tmp
2013-07-09 22:18 - 2013-07-09 22:18 - 00016384 ____T C:\Temp\~DFB514.tmp
2013-07-09 22:12 - 2013-07-09 22:12 - 00020480 ____T C:\Temp\~DF5F.tmp
2013-07-09 22:12 - 2013-07-09 22:12 - 00000000 ____T C:\Temp\~DFFF9A.tmp
2013-07-09 21:05 - 2013-07-09 22:11 - 00016384 ____T C:\Temp\~DF4AEB.tmp
2013-07-09 20:16 - 2013-07-09 20:16 - 00016384 ____T C:\Temp\~DF64D7.tmp
2013-07-09 19:38 - 2013-07-09 19:38 - 00001313 ____T C:\Temp\MAR9B2.tmp
2013-07-09 19:38 - 2013-07-09 19:38 - 00001285 ____T C:\Temp\MAR9B3.tmp
2013-07-09 19:36 - 2013-07-09 19:36 - 00049152 _____ C:\Temp\~DFBCB6.tmp
2013-07-09 19:36 - 2013-07-09 19:36 - 00016384 ____T C:\Temp\Perflib_Perfdata_1ac.dat
2013-07-08 21:22 - 2013-07-08 21:24 - 00002190 _____ C:\Temp\HPWUCl081.log
2013-07-08 21:19 - 2013-07-08 21:19 - 00001313 ____T C:\Temp\MAR9B0.tmp
2013-07-08 21:19 - 2013-07-08 21:19 - 00001285 ____T C:\Temp\MAR9B1.tmp
2013-07-08 21:17 - 2013-07-08 21:17 - 00049152 _____ C:\Temp\~DF4F03.tmp
2013-07-07 16:39 - 2013-07-07 16:39 - 00001313 ____T C:\Temp\MAR9AE.tmp
2013-07-07 16:39 - 2013-07-07 16:39 - 00001285 ____T C:\Temp\MAR9AF.tmp
2013-07-07 16:37 - 2013-07-07 16:37 - 00049152 _____ C:\Temp\~DFF32A.tmp
2013-07-06 05:58 - 2013-07-06 05:58 - 00001313 ____T C:\Temp\MAR9AC.tmp
2013-07-06 05:58 - 2013-07-06 05:58 - 00001285 ____T C:\Temp\MAR9AD.tmp
2013-07-06 05:57 - 2013-07-06 05:57 - 00049152 _____ C:\Temp\~DFE5E7.tmp
2013-07-05 21:36 - 2013-07-05 21:36 - 00001313 ____T C:\Temp\MAR9AA.tmp
2013-07-05 21:36 - 2013-07-05 21:36 - 00001285 ____T C:\Temp\MAR9AB.tmp
2013-07-05 21:34 - 2013-07-05 21:34 - 00049152 _____ C:\Temp\~DF108D.tmp
2013-07-04 23:38 - 2013-07-04 23:38 - 00000000 ____D C:\Temp\tmpbbe3f74b
2013-07-04 17:40 - 2013-07-04 17:40 - 00001313 ____T C:\Temp\MAR9A8.tmp
2013-07-04 17:40 - 2013-07-04 17:40 - 00001285 ____T C:\Temp\MAR9A9.tmp
2013-07-04 17:38 - 2013-07-04 17:38 - 00049152 _____ C:\Temp\~DF4772.tmp
2013-07-04 17:38 - 2013-07-04 17:38 - 00000000 ____D C:\Temp\tmpa24bfa7a
2013-07-04 00:15 - 2013-07-04 00:15 - 00001313 ____T C:\Temp\MAR9A6.tmp
2013-07-04 00:15 - 2013-07-04 00:15 - 00001285 ____T C:\Temp\MAR9A7.tmp
2013-07-04 00:12 - 2013-07-04 00:12 - 00049152 _____ C:\Temp\~DF43C1.tmp
2013-07-04 00:12 - 2013-07-04 00:12 - 00000000 ____D C:\Temp\tmpe6c914f3
==================== One Month Modified Files and Folders =======
2013-08-03 12:30 - 2013-08-03 12:29 - 00003869 _____ C:\Temp\log1
2013-08-03 12:29 - 2013-08-03 12:29 - 00000000 ____T C:\Temp\~DFD6F4.tmp
2013-08-03 12:29 - 2013-08-03 12:28 - 00011172 _____ C:\Temp\frstlog
2013-08-03 12:28 - 2013-08-03 12:28 - 00000303 _____ C:\Temp\users00
2013-08-03 12:28 - 2013-08-03 12:28 - 00000003 _____ C:\Temp\others
2013-08-03 12:27 - 2011-01-31 21:45 - 00000434 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{2F660A0B-21EB-4224-A64D-9FCAFC9DDFD5}.job
2013-08-03 12:25 - 2013-08-03 03:48 - 00032768 ____T C:\Temp\~DF2413.tmp
2013-08-03 12:18 - 2013-08-03 12:18 - 00000000 ____D C:\Temp\RarSFX0
2013-08-03 12:15 - 2013-08-03 12:14 - 00891098 _____ C:\Dokumente und Einstellungen\Karo\Desktop\SecurityCheck.exe
2013-08-03 12:12 - 2011-01-31 20:24 - 00000000 ____D C:\Programme
2013-08-03 12:11 - 2011-01-31 20:36 - 01566747 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-03 11:39 - 2012-10-16 21:22 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-08-03 10:42 - 2012-12-09 23:37 - 00001018 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-299502267-1682526488-1547161642-1003UA.job
2013-08-03 03:48 - 2013-08-03 03:48 - 00032768 _____ C:\Temp\~DFF3C0.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00032768 _____ C:\Temp\~DFF311.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00016384 ____T C:\Temp\~DF1895.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00016384 _____ C:\Temp\~DFF376.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00000512 ____T C:\Temp\~DFF3CE.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00000512 ____T C:\Temp\~DFF384.tmp
2013-08-03 03:48 - 2013-08-03 03:48 - 00000512 ____T C:\Temp\~DFF325.tmp
2013-08-03 03:36 - 2011-01-31 23:43 - 01471242 _____ C:\Temp\jusched.log
2013-08-03 03:33 - 2013-08-03 03:33 - 00001313 ____T C:\Temp\MARA14.tmp
2013-08-03 03:33 - 2013-08-03 03:33 - 00001285 ____T C:\Temp\MARA15.tmp
2013-08-03 03:33 - 2013-08-03 03:33 - 00000000 ____D C:\Temp\svfdm.tmp
2013-08-03 03:33 - 2011-04-30 12:06 - 00159355 _____ C:\Temp\lws.man.xml
2013-08-03 03:33 - 2011-04-30 12:06 - 00000128 _____ C:\Temp\lws.man.xml.sig
2013-08-03 03:33 - 2011-02-02 16:26 - 00399260 _____ C:\Temp\hpqddusr.log
2013-08-03 03:32 - 2013-08-03 03:32 - 00000073 _____ C:\Temp\upe12.tmp
2013-08-03 03:32 - 2013-08-03 03:31 - 00000281 _____ C:\Temp\uprB.tmp
2013-08-03 03:32 - 2013-07-30 15:10 - 00000346 _____ C:\WINDOWS\Tasks\LyricXeeker Update.job
2013-08-03 03:32 - 2011-02-01 20:50 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2013-08-03 03:32 - 2011-01-31 23:37 - 00000000 _____ C:\WINDOWS\RTacDbg.txt
2013-08-03 03:32 - 2004-08-04 13:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-03 03:31 - 2013-08-03 03:31 - 00000000 ____D C:\Temp\WPDNSE
2013-08-03 03:31 - 2011-04-29 20:01 - 00000000 ____D C:\WINDOWS\system32\logishrd
2013-08-03 03:31 - 2011-02-02 16:20 - 00751017 _____ C:\Temp\AdobeARM.log
2013-08-03 03:31 - 2011-02-02 15:48 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-08-03 03:31 - 2011-02-02 15:48 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-08-03 03:31 - 2011-01-31 20:43 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-03 03:28 - 2011-02-02 00:25 - 00000190 ___SH C:\Dokumente und Einstellungen\Karo\ntuser.ini
2013-08-03 03:28 - 2011-02-02 00:25 - 00000000 ____D C:\Dokumente und Einstellungen\Karo
2013-08-03 03:28 - 2011-01-31 20:43 - 00032504 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-02 23:57 - 2013-08-02 23:57 - 03126311 _____ C:\Temp\NOD377B.tmp
2013-08-02 23:57 - 2013-08-02 23:57 - 00000333 _____ C:\Temp\NOD3B87.tmp
2013-08-02 23:56 - 2011-02-02 15:08 - 00326440 _____ C:\WINDOWS\setupapi.log
2013-08-02 23:52 - 2011-03-02 22:16 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2013-08-02 23:52 - 2011-02-09 19:14 - 00887392 _____ C:\WINDOWS\iis6.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00822944 _____ C:\WINDOWS\FaxSetup.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00421396 _____ C:\WINDOWS\ocgen.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00376963 _____ C:\WINDOWS\tsoc.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00273411 _____ C:\WINDOWS\comsetup.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00250696 _____ C:\WINDOWS\msmqinst.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00165939 _____ C:\WINDOWS\ntdtcsetup.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00144548 _____ C:\WINDOWS\netfxocm.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00056819 _____ C:\WINDOWS\MedCtrOC.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00045613 _____ C:\WINDOWS\ocmsn.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00041363 _____ C:\WINDOWS\tabletoc.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00041267 _____ C:\WINDOWS\msgsocm.log
2013-08-02 23:52 - 2011-02-09 19:14 - 00001891 _____ C:\WINDOWS\imsins.log
2013-08-02 23:46 - 2011-02-02 15:09 - 00000000 ____D C:\Temp\MSNL
2013-08-02 23:34 - 2013-08-02 23:34 - 00000000 ____D C:\Dokumente und Einstellungen\Karo\Anwendungsdaten\ESET
2013-08-02 23:33 - 2013-08-02 23:33 - 00264880 _____ (ESET) C:\Temp\InstHelper.exe
2013-08-02 22:54 - 2011-02-06 21:17 - 00000000 ____D C:\Temp\hsperfdata_Karo
2013-08-02 22:54 - 2011-02-01 20:50 - 00047112 _____ C:\Temp\AUCHECK_CORE.txt
2013-08-02 22:54 - 2011-01-31 23:43 - 00012219 _____ C:\Temp\AUCHECK_PARSER.txt
2013-08-02 22:44 - 2013-08-02 22:44 - 00001313 ____T C:\Temp\MARA12.tmp
2013-08-02 22:44 - 2013-08-02 22:44 - 00001285 ____T C:\Temp\MARA13.tmp
2013-08-02 22:43 - 2013-08-02 22:43 - 00000281 _____ C:\Temp\uprA.tmp
2013-08-02 22:43 - 2013-08-02 22:43 - 00000073 _____ C:\Temp\upe11.tmp
2013-08-02 14:01 - 2013-08-02 14:01 - 00062770 _____ C:\Dokumente und Einstellungen\Karo\Desktop\FRST2.txt
2013-08-02 14:00 - 2013-08-02 14:00 - 00029310 _____ C:\Dokumente und Einstellungen\Karo\Desktop\Addition2.txt
2013-08-02 13:35 - 2013-07-31 15:28 - 00029310 _____ C:\Dokumente und Einstellungen\Karo\Desktop\Addition.txt
2013-08-02 13:18 - 2013-08-02 13:18 - 00000073 _____ C:\Temp\upeA12.tmp
2013-08-02 13:16 - 2013-08-02 13:16 - 00001313 ____T C:\Temp\MARA10.tmp
2013-08-02 13:16 - 2013-08-02 13:16 - 00001285 ____T C:\Temp\MARA11.tmp
2013-08-02 13:16 - 2013-08-02 13:16 - 00000000 _____ C:\Temp\upeF.tmp
2013-08-02 13:15 - 2013-08-02 13:15 - 00000000 _____ C:\Temp\upr9.tmp
2013-08-02 13:15 - 2013-08-02 13:15 - 00000000 _____ C:\Temp\upeE.tmp
2013-08-02 13:12 - 2013-08-02 13:12 - 00017176 _____ C:\AdwCleaner[S1].txt
2013-08-02 13:12 - 2012-12-19 21:32 - 00000000 ____D C:\Programme\Gemeinsame Dateien\DVDVideoSoft
2013-08-02 13:12 - 2011-02-02 00:25 - 00000000 ___RD C:\Dokumente und Einstellungen\Karo\Startmenü\Programme
2013-08-02 13:10 - 2013-08-02 13:10 - 00666633 _____ C:\Dokumente und Einstellungen\Karo\Desktop\adwcleaner06.exe
2013-08-02 12:50 - 2013-08-02 12:50 - 00001313 ____T C:\Temp\MARA0E.tmp
2013-08-02 12:50 - 2013-08-02 12:50 - 00001285 ____T C:\Temp\MARA0F.tmp
2013-08-02 12:49 - 2013-08-02 12:49 - 00000073 _____ C:\Temp\upeD.tmp
2013-08-02 12:49 - 2013-08-02 12:48 - 00000281 _____ C:\Temp\upr8.tmp
2013-08-01 19:54 - 2013-08-01 19:54 - 00001313 ____T C:\Temp\MARA0C.tmp
2013-08-01 19:54 - 2013-08-01 19:54 - 00001285 ____T C:\Temp\MARA0D.tmp
2013-08-01 19:54 - 2013-08-01 19:54 - 00000073 _____ C:\Temp\upeC.tmp
2013-08-01 19:53 - 2013-08-01 19:53 - 00000281 _____ C:\Temp\upr7.tmp
2013-08-01 19:08 - 2013-08-01 19:06 - 00000213 _____ C:\Dokumente und Einstellungen\Karo\Eigene Dateien\Fixlist.txt
2013-08-01 19:01 - 2013-08-01 19:01 - 00001313 ____T C:\Temp\MARA0A.tmp
2013-08-01 19:01 - 2013-08-01 19:01 - 00001285 ____T C:\Temp\MARA0B.tmp
2013-08-01 19:00 - 2013-08-01 19:00 - 00000281 _____ C:\Temp\upr6.tmp
2013-08-01 19:00 - 2013-08-01 19:00 - 00000073 _____ C:\Temp\upe47.tmp
2013-07-31 15:22 - 2013-07-31 15:22 - 00000073 _____ C:\Temp\upeB.tmp
2013-07-31 15:22 - 2013-07-31 15:21 - 00000281 _____ C:\Temp\upr5.tmp
2013-07-31 15:17 - 2013-07-31 15:17 - 01781589 _____ (Farbar) C:\Dokumente und Einstellungen\Karo\Desktop\FRST64.exe
2013-07-31 15:16 - 2013-07-31 15:16 - 01222064 _____ (Farbar) C:\Dokumente und Einstellungen\Karo\Desktop\FRST.exe
2013-07-31 15:16 - 2013-07-31 15:16 - 00000000 ____D C:\FRST
2013-07-31 15:00 - 2013-07-31 15:00 - 00000281 _____ C:\Temp\uprA13.tmp
2013-07-31 15:00 - 2013-07-31 15:00 - 00000073 _____ C:\Temp\upeA14.tmp
2013-07-31 14:50 - 2013-07-31 14:50 - 00001313 ____T C:\Temp\MARA08.tmp
2013-07-31 14:50 - 2013-07-31 14:50 - 00001285 ____T C:\Temp\MARA09.tmp
2013-07-31 14:49 - 2013-07-31 14:49 - 00000281 _____ C:\Temp\upr4.tmp
2013-07-31 14:49 - 2013-07-31 14:49 - 00000073 _____ C:\Temp\upeA.tmp
2013-07-31 14:37 - 2011-02-02 00:25 - 00000000 ___RD C:\Dokumente und Einstellungen\Karo\Eigene Dateien\Eigene Musik
2013-07-31 14:36 - 2013-07-31 14:32 - 00000000 ____D C:\Temp\B5EC8CB8-BAB0-7891-93B8-0638EA6B0C45
2013-07-31 14:33 - 2013-07-30 15:10 - 00000735 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Open It!.lnk
2013-07-31 14:32 - 2013-07-31 14:32 - 00000281 _____ C:\Temp\uprF.tmp
2013-07-31 14:32 - 2013-07-31 14:32 - 00000073 _____ C:\Temp\upe10.tmp
2013-07-31 14:32 - 2013-07-31 14:32 - 00000000 ____D C:\Temp\tmp1985
2013-07-31 14:32 - 2013-07-31 14:32 - 00000000 ____D C:\Temp\ish135531
2013-07-31 14:32 - 2013-07-31 14:32 - 00000000 ____D C:\Programme\LyriXeeker
2013-07-31 14:32 - 2013-07-30 15:09 - 00000000 ____D C:\Temp\is357113909
2013-07-31 14:31 - 2013-07-31 14:31 - 00000281 _____ C:\Temp\upr3.tmp
2013-07-31 14:31 - 2013-07-31 14:31 - 00000073 _____ C:\Temp\upe9.tmp
2013-07-31 13:59 - 2013-07-31 13:52 - 00000000 ____D C:\Temp\CFC193DF-BAB0-7891-BDCD-EA1E26220A59
2013-07-31 13:56 - 2013-07-31 13:56 - 00000000 ____D C:\Dokumente und Einstellungen\Karo\Qtrax
2013-07-31 13:52 - 2013-07-31 13:52 - 00000281 _____ C:\Temp\uprA12.tmp
2013-07-31 13:52 - 2013-07-31 13:52 - 00000073 _____ C:\Temp\upeA13.tmp
2013-07-31 13:52 - 2013-07-31 13:52 - 00000000 ____D C:\Temp\tmp6241
2013-07-31 13:52 - 2013-07-31 13:52 - 00000000 ____D C:\Temp\ish18754078
2013-07-31 08:47 - 2013-07-31 08:45 - 00004392 _____ C:\Temp\HPWUCl084.log
2013-07-31 08:42 - 2013-07-31 08:42 - 00001313 ____T C:\Temp\MARA06.tmp
2013-07-31 08:42 - 2013-07-31 08:42 - 00001285 ____T C:\Temp\MARA07.tmp
2013-07-31 08:41 - 2013-07-31 08:41 - 00000073 _____ C:\Temp\upe8.tmp
2013-07-31 08:41 - 2013-07-31 08:40 - 00000272 _____ C:\Temp\upr2.tmp
2013-07-30 19:00 - 2013-07-30 19:00 - 00001313 ____T C:\Temp\MARA04.tmp
2013-07-30 19:00 - 2013-07-30 19:00 - 00001285 ____T C:\Temp\MARA05.tmp
2013-07-30 18:59 - 2013-07-30 18:59 - 00000073 _____ C:\Temp\upe7.tmp
2013-07-30 18:59 - 2013-07-30 18:58 - 00000272 _____ C:\Temp\upr1.tmp
2013-07-30 15:14 - 2013-07-30 15:10 - 00000000 ____D C:\Temp\1EA55D3C-BAB0-7891-9DA9-F386E4DCBD17
2013-07-30 15:10 - 2013-07-30 15:10 - 00000272 _____ C:\Temp\uprA07.tmp
2013-07-30 15:10 - 2013-07-30 15:10 - 00000073 _____ C:\Temp\upeA08.tmp
2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ____D C:\Temp\tmp1978
2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ____D C:\Temp\{2F822836-52C6-427A-8690-91732CB6F143}
2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ____D C:\Programme\OpenIt
2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ____D C:\Dokumente und Einstellungen\Karo\Anwendungsdaten\DigitalSite
2013-07-30 15:09 - 2013-07-30 15:09 - 00717160 _____ C:\Dokumente und Einstellungen\Karo\Eigene Dateien\ZipOpenerSetup.exe
2013-07-30 15:09 - 2013-07-30 15:09 - 00000000 ____D C:\Temp\ish6262156
2013-07-30 13:41 - 2011-02-08 15:22 - 00000276 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2013-07-30 13:30 - 2013-07-30 13:30 - 00000000 ____D C:\Dokumente und Einstellungen\Karo\Anwendungsdaten\Windows Search
2013-07-30 13:27 - 2013-07-30 13:27 - 00001313 ____T C:\Temp\MARA02.tmp
2013-07-30 13:27 - 2013-07-30 13:27 - 00001285 ____T C:\Temp\MARA03.tmp
2013-07-30 12:35 - 2013-04-14 20:54 - 00000000 ____D C:\Temp\nsd92C.tmp
2013-07-30 12:12 - 2011-02-01 23:38 - 00000000 ____D C:\Dokumente und Einstellungen\Erilk
2013-07-30 12:11 - 2011-01-31 20:44 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator\ntuser.ini
2013-07-30 11:59 - 2013-07-30 11:59 - 00001313 ____T C:\Temp\MAR9FE.tmp
2013-07-30 11:59 - 2013-07-30 11:59 - 00001285 ____T C:\Temp\MAR9FF.tmp
2013-07-30 11:55 - 2013-07-30 11:55 - 00001313 ____T C:\Temp\MARA00.tmp
2013-07-30 11:55 - 2013-07-30 11:55 - 00001285 ____T C:\Temp\MARA01.tmp
2013-07-30 11:22 - 2013-07-30 11:22 - 00001313 ____T C:\Temp\MAR9FC.tmp
2013-07-30 11:22 - 2013-07-30 11:22 - 00001285 ____T C:\Temp\MAR9FD.tmp
2013-07-30 00:04 - 2011-02-02 13:10 - 00000000 ____D C:\Temp\hsperfdata_Erilk
2013-07-29 22:42 - 2012-12-09 23:37 - 00000996 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-299502267-1682526488-1547161642-1003Core.job
2013-07-29 19:07 - 2013-07-29 19:07 - 00001313 ____T C:\Temp\MAR9FA.tmp
2013-07-29 19:07 - 2013-07-29 19:07 - 00001285 ____T C:\Temp\MAR9FB.tmp
2013-07-29 19:06 - 2013-07-29 19:06 - 00000000 ____D C:\Temp\svkah.tmp
2013-07-29 19:05 - 2013-07-29 19:05 - 00049152 _____ C:\Temp\~DF3474.tmp
2013-07-29 15:17 - 2013-07-29 15:17 - 00001313 ____T C:\Temp\MAR9F8.tmp
2013-07-29 15:17 - 2013-07-29 15:17 - 00001285 ____T C:\Temp\MAR9F9.tmp
2013-07-29 15:15 - 2013-07-29 15:15 - 00049152 _____ C:\Temp\~DF3F36.tmp
2013-07-29 12:01 - 2013-07-29 12:01 - 00001313 ____T C:\Temp\MAR9F6.tmp
2013-07-29 12:01 - 2013-07-29 12:01 - 00001285 ____T C:\Temp\MAR9F7.tmp
2013-07-29 12:00 - 2013-07-29 12:00 - 00049152 _____ C:\Temp\~DFEE53.tmp
2013-07-27 08:55 - 2013-07-27 08:55 - 00001313 ____T C:\Temp\MAR9F3.tmp
2013-07-27 08:55 - 2013-07-27 08:55 - 00001285 ____T C:\Temp\MAR9F5.tmp
2013-07-27 08:53 - 2013-07-27 08:53 - 00049152 _____ C:\Temp\~DF27CC.tmp
2013-07-27 02:41 - 2013-07-27 02:41 - 00001313 ____T C:\Temp\MAR9F2.tmp
2013-07-27 02:41 - 2013-07-27 02:41 - 00001285 ____T C:\Temp\MAR9F4.tmp
2013-07-27 02:39 - 2013-07-27 02:39 - 00049152 _____ C:\Temp\~DFD3.tmp
2013-07-27 02:36 - 2013-07-27 02:36 - 00016384 ____T C:\Temp\~DF2345.tmp
2013-07-27 02:35 - 2013-07-27 02:35 - 00016384 ____T C:\Temp\~DF9B0D.tmp
2013-07-27 02:35 - 2013-07-27 02:35 - 00000000 ____D C:\Temp\WER104a.dir00
2013-07-27 02:35 - 2013-07-27 02:35 - 00000000 ____D C:\Temp\WER1022.dir00
2013-07-27 02:34 - 2013-07-27 02:34 - 00016384 ____T C:\Temp\~DF2B6.tmp
2013-07-27 02:33 - 2013-07-27 02:33 - 00016384 ____T C:\Temp\~DF652B.tmp
2013-07-27 02:33 - 2013-07-27 02:33 - 00016384 ____T C:\Temp\~DF24D8.tmp
2013-07-27 02:32 - 2013-07-27 02:32 - 00000000 ____T C:\Temp\~DF998F.tmp
2013-07-27 02:30 - 2013-07-27 02:30 - 00000000 ____T C:\Temp\~DF7A36.tmp
2013-07-27 02:29 - 2013-07-27 02:29 - 18655396 _____ C:\Temp\fla9F3.tmp
2013-07-27 02:29 - 2013-07-27 02:29 - 00000000 ____T C:\Temp\~DF1194.tmp
2013-07-27 02:28 - 2013-07-27 02:03 - 00016384 ____T C:\Temp\~DF237.tmp
2013-07-27 02:03 - 2013-07-27 02:03 - 00001313 ____T C:\Temp\MAR9F0.tmp
2013-07-27 02:03 - 2013-07-27 02:03 - 00001285 ____T C:\Temp\MAR9F1.tmp
2013-07-27 02:03 - 2013-07-27 02:03 - 00000000 ____T C:\Temp\~DFBE36.tmp
2013-07-27 02:02 - 2013-07-27 02:02 - 00049152 _____ C:\Temp\~DF2A07.tmp
2013-07-27 02:02 - 2013-07-27 02:02 - 00016384 ____T C:\Temp\Perflib_Perfdata_fe8.dat
2013-07-26 14:58 - 2013-07-26 14:58 - 00000000 ____T C:\Temp\~DFC07F.tmp
2013-07-26 14:58 - 2013-07-26 14:58 - 00000000 ____T C:\Temp\~DFB5B8.tmp
2013-07-26 14:48 - 2013-07-26 14:48 - 00001313 ____T C:\Temp\MAR9EE.tmp
2013-07-26 14:48 - 2013-07-26 14:48 - 00001285 ____T C:\Temp\MAR9EF.tmp
2013-07-26 14:47 - 2013-07-26 14:47 - 00016384 ____T C:\Temp\Perflib_Perfdata_7c0.dat
2013-07-26 14:46 - 2013-07-26 14:46 - 00049152 _____ C:\Temp\~DF209D.tmp
2013-07-25 21:06 - 2013-07-25 21:06 - 00001313 ____T C:\Temp\MAR9EC.tmp
2013-07-25 21:06 - 2013-07-25 21:06 - 00001285 ____T C:\Temp\MAR9ED.tmp
2013-07-25 21:04 - 2013-07-25 21:04 - 00049152 _____ C:\Temp\~DF22E4.tmp
2013-07-25 12:43 - 2013-07-25 12:43 - 00001714 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader X.lnk
2013-07-25 12:42 - 2013-07-25 12:42 - 00000000 ____D C:\Programme\Adobe
2013-07-25 12:42 - 2011-02-02 15:33 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Adobe
2013-07-25 12:35 - 2013-07-25 12:35 - 00001313 ____T C:\Temp\MAR9EA.tmp
2013-07-25 12:35 - 2013-07-25 12:35 - 00001285 ____T C:\Temp\MAR9EB.tmp
2013-07-25 12:33 - 2013-07-25 12:33 - 00049152 _____ C:\Temp\~DF7DC4.tmp
2013-07-25 00:26 - 2013-07-25 00:26 - 00001313 ____T C:\Temp\MAR9E7.tmp
2013-07-25 00:26 - 2013-07-25 00:26 - 00001285 ____T C:\Temp\MAR9E9.tmp
2013-07-25 00:24 - 2013-07-25 00:24 - 00049152 _____ C:\Temp\~DFD00C.tmp
2013-07-24 14:05 - 2013-07-24 14:05 - 00001313 ____T C:\Temp\MAR9E6.tmp
2013-07-24 14:05 - 2013-07-24 14:05 - 00001285 ____T C:\Temp\MAR9E8.tmp
2013-07-24 14:03 - 2013-07-24 14:03 - 00049152 _____ C:\Temp\~DFF7C6.tmp
2013-07-23 23:23 - 2013-07-23 23:21 - 00004392 _____ C:\Temp\HPWUCl083.log
2013-07-23 23:19 - 2013-07-23 23:19 - 00001313 ____T C:\Temp\MAR9E4.tmp
2013-07-23 23:19 - 2013-07-23 23:19 - 00001285 ____T C:\Temp\MAR9E5.tmp
2013-07-23 23:17 - 2013-07-23 23:17 - 00049152 _____ C:\Temp\~DF6ACC.tmp
2013-07-23 15:02 - 2013-07-23 15:02 - 00001313 ____T C:\Temp\MAR9E2.tmp
2013-07-23 15:02 - 2013-07-23 15:02 - 00001285 ____T C:\Temp\MAR9E3.tmp
2013-07-23 15:00 - 2013-07-23 15:00 - 00049152 _____ C:\Temp\~DFDDC5.tmp
2013-07-23 12:34 - 2013-07-23 12:34 - 00001313 ____T C:\Temp\MAR9E0.tmp
2013-07-23 12:34 - 2013-07-23 12:34 - 00001285 ____T C:\Temp\MAR9E1.tmp
2013-07-23 12:32 - 2013-07-23 12:32 - 00049152 _____ C:\Temp\~DFE25E.tmp
2013-07-23 00:49 - 2013-07-23 00:49 - 00001313 ____T C:\Temp\MAR9DE.tmp
2013-07-23 00:49 - 2013-07-23 00:49 - 00001285 ____T C:\Temp\MAR9DF.tmp
2013-07-23 00:47 - 2013-07-23 00:47 - 00049152 _____ C:\Temp\~DF1E6A.tmp
2013-07-22 14:31 - 2013-07-22 14:31 - 00001313 ____T C:\Temp\MAR9DC.tmp
2013-07-22 14:31 - 2013-07-22 14:31 - 00001285 ____T C:\Temp\MAR9DD.tmp
2013-07-22 14:29 - 2013-07-22 14:29 - 00049152 _____ C:\Temp\~DFE12A.tmp
2013-07-21 22:39 - 2013-07-21 22:19 - 00016384 ____T C:\Temp\~DFF32C.tmp
2013-07-21 22:19 - 2013-07-21 22:19 - 00000000 ____T C:\Temp\~DFEACA.tmp
2013-07-21 16:38 - 2013-07-21 16:38 - 00001313 ____T C:\Temp\MAR9DA.tmp
2013-07-21 16:38 - 2013-07-21 16:38 - 00001285 ____T C:\Temp\MAR9DB.tmp
2013-07-21 16:37 - 2013-07-21 16:37 - 00016384 ____T C:\Temp\Perflib_Perfdata_9cc.dat
2013-07-21 16:36 - 2013-07-21 16:36 - 00049152 _____ C:\Temp\~DF8E7.tmp
2013-07-21 16:33 - 2013-07-21 16:28 - 00016384 ____T C:\Temp\~DFFB26.tmp
2013-07-21 16:32 - 2013-07-21 16:28 - 00016384 ____T C:\Temp\~DFE8E2.tmp
2013-07-21 16:30 - 2013-07-21 16:29 - 00016384 ____T C:\Temp\~DFF9F2.tmp
2013-07-21 16:30 - 2013-07-21 16:28 - 00016384 ____T C:\Temp\~DF9676.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00057344 ____T C:\Temp\~DF41EB.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00000000 ____T C:\Temp\~DFCB8A.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00000000 ____T C:\Temp\~DFBA2C.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00000000 ____T C:\Temp\~DF8322.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00000000 ____T C:\Temp\~DF521.tmp
2013-07-21 16:29 - 2013-07-21 16:29 - 00000000 ____T C:\Temp\~DF2964.tmp
2013-07-21 16:29 - 2013-07-21 16:28 - 00016384 ____T C:\Temp\~DF8474.tmp
2013-07-21 16:28 - 2013-07-21 16:28 - 00000000 ____T C:\Temp\~DF2D5C.tmp
2013-07-21 16:27 - 2013-07-21 16:23 - 00016384 ____T C:\Temp\~DFD4C7.tmp
2013-07-21 16:23 - 2013-07-21 16:23 - 00016384 ____T C:\Temp\~DFC7E7.tmp
2013-07-21 14:04 - 2013-07-21 14:04 - 00001313 ____T C:\Temp\MAR9D8.tmp
2013-07-21 14:04 - 2013-07-21 14:04 - 00001285 ____T C:\Temp\MAR9D9.tmp
2013-07-21 14:03 - 2013-07-21 14:03 - 00049152 _____ C:\Temp\~DFE92F.tmp
2013-07-20 16:09 - 2013-07-20 16:09 - 00001313 ____T C:\Temp\MAR9D6.tmp
2013-07-20 16:09 - 2013-07-20 16:09 - 00001285 ____T C:\Temp\MAR9D7.tmp
2013-07-20 16:08 - 2013-07-20 16:08 - 00049152 _____ C:\Temp\~DFEB37.tmp
2013-07-20 14:17 - 2013-07-20 14:17 - 00001313 ____T C:\Temp\MAR9D3.tmp
2013-07-20 14:17 - 2013-07-20 14:17 - 00001285 ____T C:\Temp\MAR9D5.tmp
2013-07-20 14:15 - 2013-07-20 14:15 - 00049152 _____ C:\Temp\~DF576E.tmp
2013-07-19 02:24 - 2013-07-19 02:24 - 00001313 ____T C:\Temp\MAR9D2.tmp
2013-07-19 02:24 - 2013-07-19 02:24 - 00001285 ____T C:\Temp\MAR9D4.tmp
2013-07-19 02:22 - 2013-07-19 02:22 - 00049152 _____ C:\Temp\~DFC222.tmp
2013-07-17 19:00 - 2013-07-17 19:00 - 00001313 ____T C:\Temp\MAR9D0.tmp
2013-07-17 19:00 - 2013-07-17 19:00 - 00001285 ____T C:\Temp\MAR9D1.tmp
2013-07-17 18:58 - 2013-07-17 18:58 - 00049152 _____ C:\Temp\~DFD784.tmp
2013-07-16 20:47 - 2013-03-17 20:41 - 00000637 _____ C:\Temp\IOConnection.txt
2013-07-16 20:35 - 2013-07-16 20:35 - 00047416 ____T C:\Temp\DIOADD.tmp
2013-07-16 20:34 - 2013-07-16 20:34 - 00047416 ____T C:\Temp\DIOA20.tmp
2013-07-16 20:34 - 2013-07-16 20:34 - 00047416 ____T C:\Temp\DIO9EB.tmp
2013-07-16 19:02 - 2013-07-16 19:00 - 00004392 _____ C:\Temp\HPWUCl082.log
2013-07-16 18:57 - 2013-07-16 18:57 - 00001313 ____T C:\Temp\MAR9CE.tmp
2013-07-16 18:57 - 2013-07-16 18:57 - 00001285 ____T C:\Temp\MAR9CF.tmp
2013-07-16 18:55 - 2013-07-16 18:55 - 00049152 _____ C:\Temp\~DF9742.tmp
2013-07-15 18:15 - 2013-07-15 18:15 - 00001313 ____T C:\Temp\MAR9CC.tmp
2013-07-15 18:15 - 2013-07-15 18:15 - 00001285 ____T C:\Temp\MAR9CD.tmp
2013-07-15 18:13 - 2013-07-15 18:13 - 00049152 _____ C:\Temp\~DFF71D.tmp
2013-07-15 04:54 - 2013-07-15 04:54 - 00001313 ____T C:\Temp\MAR9CA.tmp
2013-07-15 04:54 - 2013-07-15 04:54 - 00001285 ____T C:\Temp\MAR9CB.tmp
2013-07-15 04:51 - 2013-07-15 04:51 - 00049152 _____ C:\Temp\~DFE7C.tmp
2013-07-14 15:28 - 2013-07-14 15:28 - 00001313 ____T C:\Temp\MAR9C8.tmp
2013-07-14 15:28 - 2013-07-14 15:28 - 00001285 ____T C:\Temp\MAR9C9.tmp
2013-07-14 15:26 - 2013-07-14 15:26 - 00049152 _____ C:\Temp\~DF3C5A.tmp
2013-07-14 07:45 - 2013-07-14 07:45 - 00001313 ____T C:\Temp\MAR9C6.tmp
2013-07-14 07:45 - 2013-07-14 07:45 - 00001285 ____T C:\Temp\MAR9C7.tmp
2013-07-14 07:43 - 2013-07-14 07:43 - 00049152 _____ C:\Temp\~DF2D8.tmp
2013-07-14 00:09 - 2013-07-14 00:09 - 00001313 ____T C:\Temp\MAR9C4.tmp
2013-07-14 00:09 - 2013-07-14 00:09 - 00001285 ____T C:\Temp\MAR9C5.tmp
2013-07-14 00:08 - 2013-07-14 00:08 - 00049152 _____ C:\Temp\~DF298.tmp
2013-07-13 15:12 - 2013-07-13 15:12 - 00001313 ____T C:\Temp\MAR9C2.tmp
2013-07-13 15:12 - 2013-07-13 15:12 - 00001285 ____T C:\Temp\MAR9C3.tmp
2013-07-13 15:11 - 2013-07-13 15:11 - 00049152 _____ C:\Temp\~DF30AC.tmp
2013-07-13 11:11 - 2013-07-13 11:11 - 00001313 ____T C:\Temp\MAR9C0.tmp
2013-07-13 11:11 - 2013-07-13 11:11 - 00001285 ____T C:\Temp\MAR9C1.tmp
2013-07-13 11:09 - 2013-07-13 11:09 - 00049152 _____ C:\Temp\~DF2A1C.tmp
2013-07-13 11:07 - 2013-07-13 11:07 - 00000000 ____T C:\Temp\~DF607C.tmp
2013-07-13 11:05 - 2013-07-13 11:03 - 00016384 ____T C:\Temp\~DFBC83.tmp
2013-07-13 11:03 - 2013-07-13 11:03 - 00000000 ____T C:\Temp\~DFB452.tmp
2013-07-13 11:01 - 2013-07-13 11:01 - 00001313 ____T C:\Temp\MAR9BE.tmp
2013-07-13 11:01 - 2013-07-13 11:01 - 00001285 ____T C:\Temp\MAR9BF.tmp
2013-07-13 11:00 - 2013-07-13 11:00 - 00016384 ____T C:\Temp\Perflib_Perfdata_98c.dat
2013-07-13 10:59 - 2013-07-13 10:59 - 00049152 _____ C:\Temp\~DFB9C4.tmp
2013-07-12 15:41 - 2011-01-31 21:24 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-07-12 15:16 - 2011-02-14 19:01 - 00000649 _____ C:\Temp\AdobeARM_NotLocked.log
2013-07-12 15:09 - 2013-07-12 15:09 - 00001313 ____T C:\Temp\MAR9BC.tmp
2013-07-12 15:09 - 2013-07-12 15:09 - 00001285 ____T C:\Temp\MAR9BD.tmp
2013-07-12 15:07 - 2013-07-12 15:07 - 00049152 _____ C:\Temp\~DFAA2F.tmp
2013-07-12 15:06 - 2012-09-26 20:13 - 00000000 ____D C:\Programme\Microsoft Silverlight
2013-07-12 15:06 - 2011-01-31 20:22 - 00121336 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-11 21:41 - 2013-07-11 21:41 - 00123763 _____ C:\WINDOWS\KB2834904.log
2013-07-11 21:41 - 2013-07-11 21:41 - 00123541 _____ C:\WINDOWS\KB2834886.log
2013-07-11 21:41 - 2013-07-11 21:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-11 21:41 - 2013-07-11 21:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-11 21:41 - 2013-07-11 21:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-11 21:41 - 2013-07-11 19:03 - 00128560 _____ C:\WINDOWS\KB2850851.log
2013-07-11 21:41 - 2011-02-09 19:14 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-07-11 21:40 - 2013-07-11 21:40 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-11 21:40 - 2013-07-11 19:03 - 00127298 _____ C:\WINDOWS\KB2845187.log
2013-07-11 21:40 - 2011-01-31 20:24 - 01034830 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-07-11 21:32 - 2011-01-31 21:33 - 75699896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-07-11 21:31 - 2013-07-11 21:30 - 00128951 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-11 21:31 - 2011-02-09 19:14 - 00067906 _____ C:\WINDOWS\updspapi.log
2013-07-11 21:31 - 2011-01-31 21:35 - 00000000 ____D C:\WINDOWS\ie8updates
2013-07-11 21:23 - 2011-01-31 21:25 - 00000000 ____D C:\WINDOWS\system32\XPSViewer
2013-07-11 18:58 - 2013-07-11 18:58 - 00001313 ____T C:\Temp\MAR9BA.tmp
2013-07-11 18:58 - 2013-07-11 18:58 - 00001285 ____T C:\Temp\MAR9BB.tmp
2013-07-11 18:56 - 2013-07-11 18:56 - 00049152 _____ C:\Temp\~DF3661.tmp
2013-07-10 19:56 - 2013-07-10 19:56 - 00001313 ____T C:\Temp\MAR9B8.tmp
2013-07-10 19:56 - 2013-07-10 19:56 - 00001285 ____T C:\Temp\MAR9B9.tmp
2013-07-10 19:54 - 2013-07-10 19:54 - 00049152 _____ C:\Temp\~DF9409.tmp
2013-07-10 18:23 - 2013-07-10 18:23 - 00001313 ____T C:\Temp\MAR9B6.tmp
2013-07-10 18:23 - 2013-07-10 18:23 - 00001285 ____T C:\Temp\MAR9B7.tmp
2013-07-10 18:21 - 2013-07-10 18:21 - 00049152 _____ C:\Temp\~DF13FD.tmp
2013-07-09 22:24 - 2013-07-09 22:24 - 00001313 ____T C:\Temp\MAR9B4.tmp
2013-07-09 22:24 - 2013-07-09 22:24 - 00001285 ____T C:\Temp\MAR9B5.tmp
2013-07-09 22:22 - 2013-07-09 22:22 - 00049152 _____ C:\Temp\~DF2052.tmp
2013-07-09 22:18 - 2013-07-09 22:18 - 04518624 _____ C:\Temp\fla9FA.tmp
2013-07-09 22:18 - 2013-07-09 22:18 - 01339208 _____ C:\Temp\fla9F8.tmp
2013-07-09 22:18 - 2013-07-09 22:18 - 01084901 _____ C:\Temp\fla9F9.tmp
2013-07-09 22:18 - 2013-07-09 22:18 - 00523260 _____ C:\Temp\fla9F7.tmp
2013-07-09 22:18 - 2013-07-09 22:18 - 00016384 ____T C:\Temp\~DFB514.tmp
2013-07-09 22:12 - 2013-07-09 22:12 - 00020480 ____T C:\Temp\~DF5F.tmp
2013-07-09 22:12 - 2013-07-09 22:12 - 00000000 ____T C:\Temp\~DFFF9A.tmp
2013-07-09 22:11 - 2013-07-09 21:05 - 00016384 ____T C:\Temp\~DF4AEB.tmp
2013-07-09 20:16 - 2013-07-09 20:16 - 00016384 ____T C:\Temp\~DF64D7.tmp
2013-07-09 19:38 - 2013-07-09 19:38 - 00001313 ____T C:\Temp\MAR9B2.tmp
2013-07-09 19:38 - 2013-07-09 19:38 - 00001285 ____T C:\Temp\MAR9B3.tmp
2013-07-09 19:36 - 2013-07-09 19:36 - 00049152 _____ C:\Temp\~DFBCB6.tmp
2013-07-09 19:36 - 2013-07-09 19:36 - 00016384 ____T C:\Temp\Perflib_Perfdata_1ac.dat
2013-07-08 21:24 - 2013-07-08 21:22 - 00002190 _____ C:\Temp\HPWUCl081.log
2013-07-08 21:19 - 2013-07-08 21:19 - 00001313 ____T C:\Temp\MAR9B0.tmp
2013-07-08 21:19 - 2013-07-08 21:19 - 00001285 ____T C:\Temp\MAR9B1.tmp
2013-07-08 21:17 - 2013-07-08 21:17 - 00049152 _____ C:\Temp\~DF4F03.tmp
2013-07-07 16:39 - 2013-07-07 16:39 - 00001313 ____T C:\Temp\MAR9AE.tmp
2013-07-07 16:39 - 2013-07-07 16:39 - 00001285 ____T C:\Temp\MAR9AF.tmp
2013-07-07 16:37 - 2013-07-07 16:37 - 00049152 _____ C:\Temp\~DFF32A.tmp
2013-07-06 05:58 - 2013-07-06 05:58 - 00001313 ____T C:\Temp\MAR9AC.tmp
2013-07-06 05:58 - 2013-07-06 05:58 - 00001285 ____T C:\Temp\MAR9AD.tmp
2013-07-06 05:57 - 2013-07-06 05:57 - 00049152 _____ C:\Temp\~DFE5E7.tmp
2013-07-05 21:36 - 2013-07-05 21:36 - 00001313 ____T C:\Temp\MAR9AA.tmp
2013-07-05 21:36 - 2013-07-05 21:36 - 00001285 ____T C:\Temp\MAR9AB.tmp
2013-07-05 21:34 - 2013-07-05 21:34 - 00049152 _____ C:\Temp\~DF108D.tmp
2013-07-04 23:38 - 2013-07-04 23:38 - 00000000 ____D C:\Temp\tmpbbe3f74b
2013-07-04 17:40 - 2013-07-04 17:40 - 00001313 ____T C:\Temp\MAR9A8.tmp
2013-07-04 17:40 - 2013-07-04 17:40 - 00001285 ____T C:\Temp\MAR9A9.tmp
2013-07-04 17:38 - 2013-07-04 17:38 - 00049152 _____ C:\Temp\~DF4772.tmp
2013-07-04 17:38 - 2013-07-04 17:38 - 00000000 ____D C:\Temp\tmpa24bfa7a
2013-07-04 00:15 - 2013-07-04 00:15 - 00001313 ____T C:\Temp\MAR9A6.tmp
2013-07-04 00:15 - 2013-07-04 00:15 - 00001285 ____T C:\Temp\MAR9A7.tmp
2013-07-04 00:12 - 2013-07-04 00:12 - 00049152 _____ C:\Temp\~DF43C1.tmp
2013-07-04 00:12 - 2013-07-04 00:12 - 00000000 ____D C:\Temp\tmpe6c914f3
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2008-04-14 06:52] - [2008-04-14 06:52] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2008-04-14 06:53] - [2008-04-14 06:53] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2008-04-14 06:53] - [2008-04-14 06:53] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2008-04-14 06:53] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2008-04-14 06:52] - [2008-04-14 06:52] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2008-04-14 06:53] - [2008-04-14 06:53] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2008-04-14 06:22] - [2008-04-14 06:22] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================
--- --- ---
--- --- ---