Haberger | 24.04.2014 22:04 | FRST Teil II Code:
2014-03-30 23:10 - 2013-09-25 04:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-03-30 23:10 - 2013-09-25 03:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-03-30 23:10 - 2013-09-25 03:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-03-30 23:10 - 2013-09-25 03:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-03-30 23:10 - 2013-09-25 03:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-03-30 23:10 - 2013-09-25 03:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-03-30 23:10 - 2013-07-04 14:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-03-30 23:09 - 2013-10-05 22:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-03-30 23:09 - 2013-10-05 21:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-03-30 23:08 - 2013-09-28 03:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-03-30 23:07 - 2014-03-30 23:07 - 00000000 ____D () C:\Users\root\AppData\Local\Microsoft Games
2014-03-30 23:07 - 2013-10-03 04:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-03-30 23:07 - 2013-10-03 04:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-03-30 23:07 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-03-30 23:07 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-03-30 23:06 - 2014-03-30 23:06 - 00000000 ____D () C:\Program Files\Microsoft Games
2014-03-30 23:03 - 2014-03-30 23:03 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-03-30 22:51 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-03-30 22:51 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-03-30 22:49 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-03-30 22:49 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-03-30 22:49 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-03-30 22:48 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2014-03-30 22:47 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-03-30 22:47 - 2012-11-29 00:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-03-30 22:47 - 2012-11-29 00:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-03-30 22:47 - 2012-11-29 00:56 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-03-30 22:46 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-03-30 22:46 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2014-03-30 22:44 - 2014-04-04 12:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AbiWord Word Processor
2014-03-30 22:44 - 2014-03-30 22:44 - 00000000 ____D () C:\Users\root\AbiSuite
2014-03-30 22:44 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-03-30 22:44 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-03-30 22:44 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-03-30 22:44 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-03-30 22:44 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2014-03-30 22:44 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-03-30 22:44 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2014-03-30 22:44 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-03-30 22:44 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-03-30 22:44 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-03-30 22:39 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-03-30 22:39 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-03-30 22:39 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-03-30 22:39 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-03-30 22:39 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-03-30 22:36 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-03-30 22:36 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-03-30 22:36 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-03-30 22:36 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-03-30 22:36 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-03-30 22:36 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-03-30 22:35 - 2014-03-30 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-03-30 22:35 - 2014-03-30 22:35 - 00000000 ____D () C:\Program Files\7-Zip
2014-03-30 22:35 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-03-30 22:34 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-03-30 22:34 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-03-30 22:33 - 2013-10-07 20:06 - 00448512 _____ (OldTimer Tools) C:\Users\bash\Desktop\TFC.exe
2014-03-30 22:32 - 2013-01-03 08:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-03-30 22:32 - 2012-08-22 20:12 - 00376688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-03-30 22:31 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-03-30 22:31 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-03-30 22:29 - 2014-03-30 22:29 - 00000000 ____D () C:\Users\root\AppData\Roaming\Ashampoo
2014-03-30 22:29 - 2014-03-30 22:29 - 00000000 ____D () C:\Users\root\AppData\Local\ashampoo
2014-03-30 22:29 - 2014-03-30 22:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2014-03-30 22:29 - 2014-03-30 22:29 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-03-30 22:29 - 2014-03-30 22:29 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-03-30 22:22 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-03-30 22:22 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-03-30 22:22 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2014-03-30 22:22 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2014-03-30 22:21 - 2014-03-30 22:21 - 00000000 ____D () C:\Users\root\AppData\Local\Mozilla
2014-03-30 22:21 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-03-30 22:21 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-03-30 22:18 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-03-30 22:17 - 2014-03-30 22:17 - 00002102 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-03-30 22:17 - 2014-03-30 22:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-30 22:17 - 2013-02-15 08:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-03-30 22:17 - 2013-02-15 08:06 - 03717632 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-03-30 22:17 - 2013-02-15 08:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-03-30 22:17 - 2013-02-15 06:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-03-30 22:17 - 2013-02-15 06:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-03-30 22:17 - 2013-02-15 05:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-03-30 22:16 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-03-30 22:14 - 2014-04-22 13:01 - 00000000 ____D () C:\Windows\Panther
2014-03-30 22:14 - 2014-03-30 22:14 - 00000000 ____D () C:\Users\bash\AppData\Roaming\Mozilla
2014-03-30 22:14 - 2014-03-30 22:14 - 00000000 ____D () C:\Users\bash\AppData\Local\Mozilla
2014-03-30 22:11 - 2014-04-05 11:15 - 00000000 ____D () C:\Users\bash\AppData\Local\VirtualStore
2014-03-30 22:11 - 2014-03-31 13:51 - 00000000 ___RD () C:\Users\bash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-30 22:11 - 2014-03-31 13:51 - 00000000 ___RD () C:\Users\bash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-30 22:11 - 2014-03-31 13:12 - 00001425 _____ () C:\Users\bash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-30 22:10 - 2014-04-22 12:32 - 00000000 ____D () C:\Users\bash
2014-03-30 22:10 - 2014-03-30 22:10 - 00000020 ___SH () C:\Users\bash\ntuser.ini
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Vorlagen
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Startmenü
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Netzwerkumgebung
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Lokale Einstellungen
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Eigene Dateien
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Druckumgebung
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Documents\Eigene Musik
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Documents\Eigene Bilder
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\AppData\Local\Verlauf
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\AppData\Local\Anwendungsdaten
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Anwendungsdaten
2014-03-30 22:10 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\bash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-03-30 22:10 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\bash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-03-30 22:04 - 2012-11-02 07:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-03-30 22:04 - 2012-11-02 07:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-03-30 22:04 - 2012-11-01 07:43 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-03-30 22:04 - 2012-11-01 06:47 - 01389568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-03-30 22:00 - 2012-09-26 00:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-03-30 22:00 - 2012-09-26 00:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-03-30 21:59 - 2012-08-11 02:56 - 00715776 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-03-30 21:59 - 2012-08-11 01:56 - 00542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-03-30 21:58 - 2012-07-05 00:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-03-30 21:58 - 2012-07-05 00:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-03-30 21:58 - 2012-07-05 00:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-03-30 21:58 - 2012-07-04 23:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-03-30 21:58 - 2012-07-04 23:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-03-30 21:56 - 2012-05-14 07:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-03-30 21:54 - 2012-06-06 08:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-03-30 21:54 - 2012-06-06 07:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2014-03-30 21:53 - 2012-04-28 05:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-03-30 21:53 - 2012-04-26 07:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-03-30 21:53 - 2012-04-26 07:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-03-30 21:53 - 2012-04-26 07:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-03-30 21:52 - 2012-03-17 09:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-03-30 21:49 - 2012-03-01 08:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-03-30 21:49 - 2012-03-01 08:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-03-30 21:49 - 2012-03-01 07:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2014-03-30 21:49 - 2012-02-17 08:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-03-30 21:49 - 2012-02-17 07:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-03-30 21:49 - 2012-02-17 06:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-03-30 21:48 - 2011-12-16 10:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-03-30 21:48 - 2011-12-16 09:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2014-03-30 21:47 - 2011-11-17 08:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-03-30 21:47 - 2011-11-17 07:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2014-03-30 21:46 - 2011-11-19 16:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-03-30 21:46 - 2011-11-19 16:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-03-30 21:45 - 2011-10-26 07:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-03-30 21:45 - 2011-10-26 07:25 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-03-30 21:45 - 2011-10-26 06:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-03-30 21:45 - 2011-10-26 06:32 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-03-30 21:45 - 2011-10-15 08:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-03-30 21:45 - 2011-10-15 07:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2014-03-30 21:43 - 2011-08-27 07:37 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-03-30 21:43 - 2011-08-27 07:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-03-30 21:43 - 2011-08-27 06:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-03-30 21:43 - 2011-08-27 06:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2014-03-30 21:43 - 2011-08-17 07:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-03-30 21:43 - 2011-08-17 07:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-03-30 21:43 - 2011-08-17 06:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2014-03-30 21:43 - 2011-08-17 06:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2014-03-30 21:41 - 2011-06-15 12:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-03-30 21:41 - 2011-06-15 12:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-03-30 21:41 - 2011-06-15 12:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-03-30 21:41 - 2011-06-15 12:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-03-30 21:41 - 2011-06-15 10:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2014-03-30 21:41 - 2011-06-15 10:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2014-03-30 21:41 - 2011-06-15 10:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2014-03-30 21:41 - 2011-06-15 10:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2014-03-30 21:41 - 2011-06-15 10:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2014-03-30 21:40 - 2011-05-24 13:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-03-30 21:40 - 2011-05-24 12:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2014-03-30 21:40 - 2011-05-24 12:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2014-03-30 21:40 - 2011-05-24 12:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2014-03-30 21:40 - 2011-05-24 12:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-03-30 21:39 - 2011-04-29 05:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-03-30 21:39 - 2011-04-29 05:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-03-30 21:39 - 2011-04-29 05:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-03-30 21:38 - 2011-07-09 04:46 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-03-30 21:38 - 2011-04-27 04:40 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-03-30 21:38 - 2011-04-27 04:39 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-03-30 21:37 - 2011-05-03 07:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-03-30 21:37 - 2011-05-03 06:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-03-30 21:36 - 2011-03-03 08:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-03-30 21:36 - 2011-03-03 08:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-03-30 21:36 - 2011-03-03 08:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-03-30 21:36 - 2011-03-03 07:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-03-30 21:36 - 2011-03-03 07:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2014-03-30 21:35 - 2011-03-11 08:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-03-30 21:35 - 2011-03-11 08:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-03-30 21:35 - 2011-03-11 07:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2014-03-30 21:35 - 2011-03-11 07:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2014-03-30 21:35 - 2011-02-12 13:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-03-30 21:34 - 2011-02-23 06:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-03-30 21:33 - 2010-12-23 12:42 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-03-30 21:33 - 2010-12-23 12:42 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-03-30 21:33 - 2010-12-23 12:36 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-03-30 21:33 - 2010-12-23 07:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2014-03-30 21:33 - 2010-12-23 07:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2014-03-30 21:33 - 2010-12-23 07:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2014-03-30 21:23 - 2014-04-22 12:32 - 00000000 ____D () C:\Users\root
2014-03-30 21:23 - 2014-04-02 11:53 - 00001425 _____ () C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-30 21:23 - 2014-04-02 11:53 - 00000000 ___RD () C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-30 21:23 - 2014-04-02 11:53 - 00000000 ___RD () C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-30 21:23 - 2014-03-30 21:23 - 00000020 ___SH () C:\Users\root\ntuser.ini
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Vorlagen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Startmenü
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Netzwerkumgebung
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Lokale Einstellungen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Eigene Dateien
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Druckumgebung
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Documents\Eigene Musik
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Documents\Eigene Bilder
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\AppData\Local\Verlauf
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\AppData\Local\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Programme
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Favoriten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 ____D () C:\Users\root\AppData\Local\VirtualStore
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 ____D () C:\Recovery
2014-03-30 21:23 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-03-30 21:23 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-03-30 21:19 - 2014-03-30 21:19 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2014-03-30 21:19 - 2014-03-30 21:19 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2014-03-30 21:18 - 2014-04-24 22:46 - 01966317 _____ () C:\Windows\WindowsUpdate.log
==================== One Month Modified Files and Folders =======
2014-04-24 22:47 - 2014-04-24 22:47 - 00007657 _____ () C:\Users\bash\Desktop\FRST.txt
2014-04-24 22:47 - 2014-04-24 22:47 - 00000000 ____D () C:\FRST
2014-04-24 22:46 - 2014-04-24 22:41 - 02061824 _____ (Farbar) C:\Users\bash\Desktop\FRST64.exe
2014-04-24 22:46 - 2014-03-30 21:18 - 01966317 _____ () C:\Windows\WindowsUpdate.log
2014-04-24 20:07 - 2014-04-24 20:07 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-24 20:06 - 2014-04-24 20:06 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-24 20:06 - 2014-04-24 20:06 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-24 20:06 - 2014-04-24 20:06 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-24 20:06 - 2014-04-24 20:06 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-24 20:06 - 2014-04-24 20:06 - 00000000 ____D () C:\ProgramData\Sun
2014-04-24 20:05 - 2014-04-24 20:05 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-24 19:04 - 2014-04-24 19:00 - 00921512 _____ (Oracle Corporation) C:\Users\bash\Downloads\jxpiinstall.exe
2014-04-24 18:18 - 2009-07-14 06:45 - 00031280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-24 18:18 - 2009-07-14 06:45 - 00031280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-24 18:12 - 2014-04-24 18:12 - 00000000 ____D () C:\Users\root\AppData\Local\WindowsUpdate
2014-04-24 18:01 - 2014-04-24 18:01 - 00000000 __SHD () C:\Users\root\AppData\Local\EmieUserList
2014-04-24 18:01 - 2014-04-24 18:01 - 00000000 __SHD () C:\Users\root\AppData\Local\EmieSiteList
2014-04-24 16:45 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-24 16:44 - 2014-04-23 08:28 - 00000280 _____ () C:\Windows\setupact.log
2014-04-24 16:31 - 2014-04-24 16:27 - 00000429 _____ () C:\Users\bash\Documents\Track List Bonanza Trip 2014 Vol. I (138 bpm).txt
2014-04-24 15:57 - 2014-04-15 13:12 - 00000000 ____D () C:\Users\bash\Documents\Calibre-Bibliothek
2014-04-23 12:47 - 2014-04-23 12:47 - 00000102 _____ () C:\Users\bash\Documents\lektuere.txt
2014-04-23 08:34 - 2014-03-31 13:28 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-04-23 08:28 - 2014-04-23 08:28 - 00274464 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-23 08:28 - 2014-04-23 08:28 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-22 17:20 - 2014-03-31 15:54 - 00000000 ____D () C:\Users\bash\AbiSuite
2014-04-22 14:00 - 2014-03-31 15:13 - 00000000 ____D () C:\Users\bash\AppData\Roaming\vlc
2014-04-22 13:59 - 2014-04-09 20:17 - 00000000 ____D () C:\Users\root\AppData\Roaming\vlc
2014-04-22 13:01 - 2014-04-02 11:44 - 00000000 ____D () C:\Windows\Minidump
2014-04-22 13:01 - 2014-03-30 22:14 - 00000000 ____D () C:\Windows\Panther
2014-04-22 12:32 - 2014-03-30 22:10 - 00000000 ____D () C:\Users\bash
2014-04-22 12:32 - 2014-03-30 21:23 - 00000000 ____D () C:\Users\root
2014-04-22 11:56 - 2014-04-05 17:12 - 00000000 ____D () C:\Users\bash\AppData\Local\Microsoft Games
2014-04-22 11:45 - 2014-04-03 11:19 - 00000000 ____D () C:\Users\bash\Downloads\Tools
2014-04-22 01:08 - 2014-04-15 15:36 - 00000566 _____ () C:\Users\bash\Documents\zitate.txt
2014-04-21 16:46 - 2014-04-21 16:46 - 00001992 _____ () C:\Users\bash\Desktop\Terrorist Takedown 3.lnk
2014-04-21 16:46 - 2014-04-21 16:46 - 00000000 ____D () C:\Users\Public\Documents\City Interactive
2014-04-21 16:41 - 2014-04-21 16:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\City Interactive
2014-04-21 16:37 - 2014-04-21 16:37 - 00000000 ____D () C:\Program Files (x86)\City Interactive
2014-04-21 15:59 - 2014-04-07 12:21 - 00000000 ____D () C:\Users\root\AppData\Roaming\Skype
2014-04-21 15:59 - 2014-04-07 12:20 - 00000000 ____D () C:\ProgramData\Skype
2014-04-21 15:52 - 2014-04-07 12:23 - 00000000 ____D () C:\Users\bash\AppData\Roaming\Skype
2014-04-18 18:52 - 2014-04-05 12:58 - 00000000 ____D () C:\Users\bash\dwhelper
2014-04-17 16:18 - 2014-04-17 15:58 - 00000000 ____D () C:\Users\bash\Documents\unsortiert
2014-04-16 14:50 - 2014-04-12 10:38 - 00000000 ____D () C:\Users\bash\.gimp-2.8
2014-04-15 15:35 - 2014-04-04 13:45 - 00000000 ____D () C:\Users\bash\AppData\Roaming\calibre
2014-04-15 13:36 - 2014-04-15 13:35 - 00000000 ____D () C:\Users\bash\Documents\Spiegel Hardcover Sachbuch 16-2014
2014-04-15 13:35 - 2014-04-15 13:35 - 00000000 ____D () C:\Users\bash\Documents\Spiegel Hardcover Belletristik 16-2014
2014-04-15 09:33 - 2014-04-15 09:33 - 00019511 _____ () C:\Users\bash\Documents\Ostmitteleuropa 1944 bis 1951.abw
2014-04-14 20:23 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-14 13:22 - 2014-04-03 13:50 - 00000000 ____D () C:\Users\bash\Documents\Akif Pirincci
2014-04-14 12:49 - 2014-04-14 12:49 - 00000000 __SHD () C:\Users\bash\AppData\Local\EmieUserList
2014-04-14 12:49 - 2014-04-14 12:49 - 00000000 __SHD () C:\Users\bash\AppData\Local\EmieSiteList
2014-04-14 12:30 - 2011-04-12 09:43 - 00698688 _____ () C:\Windows\system32\perfh007.dat
2014-04-14 12:30 - 2011-04-12 09:43 - 00148828 _____ () C:\Windows\system32\perfc007.dat
2014-04-14 12:30 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-12 10:48 - 2014-04-12 10:48 - 00000000 ____D () C:\Users\bash\Documents\Any Video Converter
2014-04-12 10:48 - 2014-04-01 18:43 - 00000000 ____D () C:\Users\bash\AppData\Roaming\AnvSoft
2014-04-12 10:39 - 2014-04-12 10:39 - 00000861 _____ () C:\Users\bash\AppData\Local\recently-used.xbel
2014-04-12 10:38 - 2014-04-12 10:38 - 00000000 ____D () C:\Users\bash\AppData\Local\gegl-0.2
2014-04-09 20:06 - 2014-04-09 20:06 - 00000000 ____D () C:\Users\root\Documents\Any Video Converter
2014-04-09 20:06 - 2014-04-09 20:06 - 00000000 ____D () C:\Users\root\AppData\Roaming\AnvSoft
2014-04-09 20:06 - 2014-04-01 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnvSoft
2014-04-09 20:06 - 2014-04-01 18:42 - 00000000 ____D () C:\Program Files (x86)\AnvSoft
2014-04-09 14:42 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-09 10:48 - 2014-03-31 00:32 - 00000000 ____D () C:\Users\root\AppData\Local\Adobe
2014-04-09 10:47 - 2014-03-31 14:02 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-09 10:47 - 2014-03-31 14:02 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-09 09:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-09 09:00 - 2014-03-31 13:35 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-09 08:58 - 2014-03-31 13:35 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-07 13:07 - 2014-04-07 13:07 - 00003082 _____ () C:\Windows\System32\Tasks\{BBDCDA6A-B825-4275-9A26-49EC2507DE5A}
2014-04-07 13:07 - 2014-03-31 00:22 - 00000000 _____ () C:\ProgramData\LauncherAccess.dt
2014-04-07 13:01 - 2014-04-07 13:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows8FirewallControl
2014-04-07 13:01 - 2014-04-07 13:01 - 00000000 ____D () C:\Program Files\Windows8FirewallControl
2014-04-05 11:15 - 2014-03-30 22:11 - 00000000 ____D () C:\Users\bash\AppData\Local\VirtualStore
2014-04-05 10:59 - 2014-04-05 10:59 - 00087704 _____ () C:\Windows\cadkasdeinst01.exe
2014-04-05 10:59 - 2014-04-05 10:59 - 00001129 _____ () C:\Users\UpdatusUser\Desktop\Scanned Text Editor 1.0.lnk
2014-04-05 10:44 - 2014-04-05 10:44 - 00003120 _____ () C:\Windows\SysWOW64\2ACINSPO.ocx
2014-04-05 10:43 - 2014-04-05 10:43 - 00000000 ____D () C:\Users\root\Normica
2014-04-04 13:47 - 2014-04-04 13:46 - 00000000 ____D () C:\Users\bash\AppData\Local\calibre-cache
2014-04-04 12:22 - 2014-04-04 12:22 - 00000000 ____D () C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AbiWord Word Processor
2014-04-04 12:22 - 2014-04-04 12:21 - 00000000 ____D () C:\Program Files (x86)\AbiWord
2014-04-04 12:22 - 2014-03-30 22:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AbiWord Word Processor
2014-04-04 12:16 - 2014-04-02 15:17 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-02 17:14 - 2014-04-02 16:18 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-04-02 16:57 - 2014-04-02 15:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-02 16:54 - 2014-04-02 16:52 - 00000000 ____D () C:\Users\root\AppData\Roaming\Mozilla
2014-04-02 16:05 - 2014-04-02 16:05 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-02 15:30 - 2014-04-02 15:30 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-04-02 15:30 - 2014-04-02 15:30 - 00000000 ____D () C:\ProgramData\Mozilla
2014-04-02 15:30 - 2014-04-02 15:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-02 15:25 - 2014-04-02 15:25 - 00000000 ____D () C:\Users\root\AppData\Roaming\AVAST Software
2014-04-02 12:23 - 2014-04-02 12:23 - 00000000 ____D () C:\Users\bash\AppData\Roaming\Adobe
2014-04-02 11:53 - 2014-03-30 21:23 - 00001425 _____ () C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-02 11:53 - 2014-03-30 21:23 - 00000000 ___RD () C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-02 11:53 - 2014-03-30 21:23 - 00000000 ___RD () C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-02 11:53 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-04-02 11:52 - 2014-04-02 11:35 - 00000000 ____D () C:\Windows\erdnt
2014-04-01 18:48 - 2014-04-01 18:48 - 00000000 ____D () C:\Users\root\AppData\Roaming\Macromedia
2014-04-01 18:48 - 2014-04-01 18:48 - 00000000 ____D () C:\Users\root\AppData\Roaming\Adobe
2014-04-01 18:48 - 2014-04-01 18:48 - 00000000 ____D () C:\Users\root\AppData\Local\Macromedia
2014-04-01 18:43 - 2014-04-01 18:43 - 00000000 ____D () C:\Users\bash\Documents\Any Audio Converter
2014-03-31 16:13 - 2014-03-31 16:13 - 00000000 ____D () C:\Users\bash\AppData\Roaming\NVIDIA
2014-03-31 15:57 - 2014-03-31 15:57 - 00000000 ____D () C:\Users\bash\AppData\Roaming\Malwarebytes
2014-03-31 15:38 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-03-31 14:17 - 2014-03-31 14:17 - 00000000 ____D () C:\Users\bash\AppData\Roaming\Macromedia
2014-03-31 14:17 - 2014-03-31 14:17 - 00000000 ____D () C:\Users\bash\AppData\Local\Macromedia
2014-03-31 14:03 - 2014-03-31 14:03 - 00000000 ____D () C:\Users\bash\AppData\Roaming\Ashampoo
2014-03-31 14:02 - 2014-03-31 14:02 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-03-31 14:01 - 2014-03-31 14:01 - 00000000 ____D () C:\Windows\system32\Macromed
2014-03-31 13:55 - 2014-03-31 13:55 - 00000000 ____D () C:\Users\root\AppData\Roaming\Malwarebytes
2014-03-31 13:51 - 2014-03-31 13:51 - 00000000 ____D () C:\Users\bash\AppData\Roaming\AVAST Software
2014-03-31 13:51 - 2014-03-30 22:11 - 00000000 ___RD () C:\Users\bash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-31 13:51 - 2014-03-30 22:11 - 00000000 ___RD () C:\Users\bash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-31 13:50 - 2014-03-31 00:24 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-03-31 13:44 - 2014-03-31 00:25 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-03-31 13:43 - 2014-03-31 13:43 - 00000000 ____D () C:\Users\bash\AppData\Roaming\Thunderbird
2014-03-31 13:43 - 2014-03-31 13:43 - 00000000 ____D () C:\Users\bash\AppData\Local\Thunderbird
2014-03-31 13:40 - 2014-03-31 00:36 - 01591896 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-31 13:36 - 2014-03-31 13:36 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-03-31 13:36 - 2014-03-31 13:36 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-03-31 13:36 - 2014-03-31 01:25 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-03-31 13:36 - 2014-03-31 01:25 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-03-31 13:36 - 2014-03-31 01:25 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-03-31 13:36 - 2014-03-31 01:25 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-03-31 13:36 - 2014-03-31 01:25 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-03-31 13:36 - 2014-03-31 01:25 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-03-31 13:36 - 2014-03-31 01:25 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-03-31 13:30 - 2014-03-31 01:23 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-03-31 13:28 - 2014-03-31 01:25 - 00000000 _____ () C:\Windows\SysWOW64\config.nt
2014-03-31 13:12 - 2014-03-30 22:11 - 00001425 _____ () C:\Users\bash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-31 12:01 - 2014-03-31 12:01 - 00001101 _____ () C:\Users\root\Desktop\Mobile Partner.lnk
2014-03-31 11:59 - 2014-03-31 11:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-03-31 11:59 - 2014-03-31 11:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-03-31 11:59 - 2014-03-31 11:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-03-31 11:59 - 2014-03-31 11:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-03-31 11:59 - 2014-03-31 11:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-03-31 11:59 - 2014-03-31 11:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-03-31 11:59 - 2014-03-31 11:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-03-31 11:59 - 2014-03-31 11:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-03-31 11:59 - 2014-03-31 11:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-03-31 11:59 - 2014-03-31 11:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-03-31 11:59 - 2014-03-31 11:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-03-31 11:59 - 2014-03-31 11:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-03-31 11:59 - 2014-03-31 11:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-03-31 11:59 - 2014-03-31 11:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-03-31 11:59 - 2014-03-31 11:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-03-31 11:59 - 2014-03-31 11:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-03-31 11:59 - 2014-03-31 11:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-03-31 11:59 - 2014-03-31 11:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-03-31 11:59 - 2014-03-31 11:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-03-31 11:58 - 2014-03-31 11:58 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-03-31 11:58 - 2014-03-31 11:58 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-03-31 11:58 - 2014-03-31 11:58 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-03-31 11:58 - 2014-03-31 11:58 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-03-31 11:58 - 2014-03-31 11:58 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-03-31 11:58 - 2014-03-31 11:58 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-03-31 11:58 - 2014-03-31 11:58 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-03-31 11:58 - 2014-03-31 11:58 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-03-31 11:58 - 2014-03-31 11:58 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-03-31 11:57 - 2014-03-31 11:57 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-03-31 11:57 - 2014-03-31 11:57 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-03-31 11:57 - 2014-03-31 11:57 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-03-31 01:23 - 2014-03-31 01:23 - 00000000 ____D () C:\Program Files\AVAST Software
2014-03-31 00:46 - 2014-03-31 00:45 - 00000000 ____D () C:\Program Files (x86)\Mobile Partner
2014-03-31 00:45 - 2014-03-31 00:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mobile Partner
2014-03-31 00:40 - 2014-03-31 00:40 - 00001073 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
2014-03-31 00:40 - 2014-03-31 00:40 - 00000000 ____D () C:\Users\root\AppData\Local\Secunia PSI
2014-03-31 00:40 - 2014-03-31 00:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer
2014-03-31 00:40 - 2014-03-31 00:40 - 00000000 ____D () C:\Program Files\Tracker Software
2014-03-31 00:40 - 2014-03-31 00:40 - 00000000 ____D () C:\Program Files (x86)\Secunia
2014-03-31 00:40 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-31 00:39 - 2014-03-31 00:39 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-31 00:39 - 2014-03-31 00:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-03-31 00:39 - 2014-03-31 00:39 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-31 00:31 - 2014-03-31 00:31 - 00000892 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2014-03-31 00:31 - 2014-03-31 00:31 - 00000000 ____D () C:\Program Files\GIMP 2
2014-03-31 00:28 - 2014-03-31 00:28 - 00000020 ___SH () C:\Users\UpdatusUser\ntuser.ini
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\Vorlagen
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\Startmenü
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\Netzwerkumgebung
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\Lokale Einstellungen
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\Eigene Dateien
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\Druckumgebung
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Musik
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Bilder
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Verlauf
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten
2014-03-31 00:28 - 2014-03-31 00:28 - 00000000 _SHDL () C:\Users\UpdatusUser\Anwendungsdaten
2014-03-31 00:28 - 2014-03-31 00:24 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-03-31 00:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help
2014-03-31 00:26 - 2014-03-31 00:26 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-03-31 00:25 - 2014-03-31 00:25 - 00000000 ____D () C:\Windows\nvmup
2014-03-31 00:23 - 2014-03-31 00:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-03-31 00:23 - 2014-03-31 00:23 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-03-31 00:22 - 2014-03-31 00:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung PC Studio 3
2014-03-31 00:17 - 2014-03-31 00:17 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-31 00:17 - 2014-03-31 00:17 - 00000000 ____D () C:\Program Files (x86)\Samsung
2014-03-31 00:16 - 2014-03-31 00:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management
2014-03-31 00:16 - 2014-03-31 00:16 - 00000000 ____D () C:\Program Files\Calibre2
2014-03-31 00:15 - 2014-03-31 00:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-03-31 00:15 - 2014-03-31 00:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mixxx
2014-03-31 00:15 - 2014-03-31 00:15 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-03-31 00:14 - 2014-03-31 00:14 - 00000000 ____D () C:\Program Files\Mixxx
2014-03-31 00:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-03-31 00:13 - 2014-03-31 00:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
2014-03-31 00:13 - 2014-03-31 00:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-31 00:13 - 2014-03-31 00:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-31 00:12 - 2014-03-31 00:12 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-03-31 00:12 - 2014-03-31 00:12 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-03-31 00:12 - 2014-03-31 00:12 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-03-31 00:12 - 2014-03-31 00:12 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-03-31 00:12 - 2014-03-31 00:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-03-31 00:12 - 2014-03-31 00:12 - 00000000 ____D () C:\Program Files\Java
2014-03-30 23:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2014-03-30 23:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2014-03-30 23:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-03-30 23:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-03-30 23:07 - 2014-03-30 23:07 - 00000000 ____D () C:\Users\root\AppData\Local\Microsoft Games
2014-03-30 23:06 - 2014-03-30 23:06 - 00000000 ____D () C:\Program Files\Microsoft Games
2014-03-30 23:06 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-03-30 23:03 - 2014-03-30 23:03 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-03-30 22:55 - 2011-04-12 09:55 - 00000000 ____D () C:\Program Files\Windows Journal
2014-03-30 22:55 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-03-30 22:55 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-03-30 22:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-03-30 22:44 - 2014-03-30 22:44 - 00000000 ____D () C:\Users\root\AbiSuite
2014-03-30 22:35 - 2014-03-30 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-03-30 22:35 - 2014-03-30 22:35 - 00000000 ____D () C:\Program Files\7-Zip
2014-03-30 22:29 - 2014-03-30 22:29 - 00000000 ____D () C:\Users\root\AppData\Roaming\Ashampoo
2014-03-30 22:29 - 2014-03-30 22:29 - 00000000 ____D () C:\Users\root\AppData\Local\ashampoo
2014-03-30 22:29 - 2014-03-30 22:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2014-03-30 22:29 - 2014-03-30 22:29 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-03-30 22:29 - 2014-03-30 22:29 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-03-30 22:21 - 2014-03-30 22:21 - 00000000 ____D () C:\Users\root\AppData\Local\Mozilla
2014-03-30 22:17 - 2014-03-30 22:17 - 00002102 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-03-30 22:17 - 2014-03-30 22:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-30 22:14 - 2014-03-30 22:14 - 00000000 ____D () C:\Users\bash\AppData\Roaming\Mozilla
2014-03-30 22:14 - 2014-03-30 22:14 - 00000000 ____D () C:\Users\bash\AppData\Local\Mozilla
2014-03-30 22:14 - 2009-07-14 07:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2014-03-30 22:14 - 2009-07-14 07:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2014-03-30 22:10 - 2014-03-30 22:10 - 00000020 ___SH () C:\Users\bash\ntuser.ini
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Vorlagen
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Startmenü
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Netzwerkumgebung
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Lokale Einstellungen
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Eigene Dateien
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Druckumgebung
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Documents\Eigene Musik
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Documents\Eigene Bilder
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\AppData\Local\Verlauf
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\AppData\Local\Anwendungsdaten
2014-03-30 22:10 - 2014-03-30 22:10 - 00000000 _SHDL () C:\Users\bash\Anwendungsdaten
2014-03-30 21:32 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\restore
2014-03-30 21:23 - 2014-03-30 21:23 - 00000020 ___SH () C:\Users\root\ntuser.ini
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Vorlagen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Startmenü
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Netzwerkumgebung
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Lokale Einstellungen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Eigene Dateien
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Druckumgebung
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Documents\Eigene Musik
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Documents\Eigene Bilder
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\AppData\Local\Verlauf
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\AppData\Local\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\root\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Programme
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Favoriten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 ____D () C:\Users\root\AppData\Local\VirtualStore
2014-03-30 21:23 - 2014-03-30 21:23 - 00000000 ____D () C:\Recovery
2014-03-30 21:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Windows NT
2014-03-30 21:19 - 2014-03-30 21:19 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2014-03-30 21:19 - 2014-03-30 21:19 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2014-03-30 21:19 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-30 21:19 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-03-30 21:18 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sysprep
2014-03-30 21:16 - 2011-04-12 09:55 - 00000000 ____D () C:\Windows\CSC
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-19 00:48
==================== End Of Log ============================ Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-04-2014
Ran by root at 2014-04-24 22:48:08
Running from C:\Users\bash\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
AbiWord 2.8.6 (HKLM-x32\...\AbiWord2) (Version: 2.8.6 - AbiSource Developers)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.182 - Adobe Systems Incorporated)
Any Audio Converter 4.0.1 (HKLM-x32\...\Any Audio Converter_is1) (Version: - Any-Audio-Converter.com)
Any Video Converter 5.5.8 (HKLM-x32\...\Any Video Converter_is1) (Version: - Any-Video-Converter.com)
Ashampoo Burning Studio 2013 v.11.0.6 (HKLM-x32\...\{91B33C97-0FBA-74AE-E802-D782F5C8AA89}_is1) (Version: 11.0.6 - Ashampoo GmbH & Co. KG)
avast! Free Antivirus (HKLM-x32\...\avast) (Version: 9.0.2016 - Avast Software)
calibre 64bit (HKLM\...\{1266D026-FDCA-458F-8849-BF23EF0766D8}) (Version: 1.28.0 - Kovid Goyal)
CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform)
GIMP 2.8.6 (HKLM\...\GIMP-2_is1) (Version: 2.8.6 - The GIMP Team)
Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.550 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Mixxx 1.11.0 (64-bit) (HKLM-x32\...\Mixxx (1.11.0)) (Version: 1.11.0 - The Mixxx Development Team)
Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 11.302.06.07.40 - Huawei Technologies Co.,Ltd)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
NVIDIA Grafiktreiber 307.83 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 307.83 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.109.706 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 307.83 (Version: 307.83 - NVIDIA Corporation) Hidden
NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.10.8 - NVIDIA Corporation) Hidden
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.212.0 - Tracker Software Products Ltd)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SAMSUNG Mobile Composite Device Software (HKLM\...\SAMSUNG Mobile Composite Device) (Version: - )
SAMSUNG Mobile Modem Driver Set (HKLM\...\SAMSUNG Mobile Modem) (Version: - )
Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version: - )
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version: - )
SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version: - )
Samsung PC Studio 3 (HKLM-x32\...\{C4A4722E-79F9-417C-BD72-8D359A090C97}) (Version: 3.2.2.80601 - Samsung Electronics Co., Ltd.)
Samsung PC Studio 3 (x32 Version: 3.0.0.80601 - Samsung Electronics Co., Ltd.) Hidden
Secunia PSI (3.0.0.7011) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.7011 - Secunia)
Terrorist Takedown 3 (HKLM-x32\...\Terrorist Takedown 3/DE-German_is1) (Version: - City Interactive)
Tweaking.com - Windows Repair (All in One) (HKLM-x32\...\Tweaking.com - Windows Repair (All in One)) (Version: 2.1.0 - Tweaking.com)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Windows8FirewallControl (x64) 6.1.9.53 (HKLM\...\Windows8FirewallControl_is1) (Version: 6.1.9.53 - Sphinx Software)
==================== Restore Points =========================
23-04-2014 14:37:33 Geplanter Prüfpunkt
24-04-2014 18:05:39 Installed Java 7 Update 55
24-04-2014 18:15:03 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2014-04-06 08:52 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {43592662-6CC6-42BC-B929-742C296E5A9E} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {997E5E88-C06E-449E-94BF-F181043400C1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd)
Task: {A31A2E38-F329-4C58-9A32-C0793E5EFD0F} - System32\Tasks\{BBDCDA6A-B825-4275-9A26-49EC2507DE5A} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.14.0.104/en/abandoninstall?page=tsProgressBar
Task: {D7E34064-365D-4B23-BC71-944BFC9BE577} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-03-31] (AVAST Software)
==================== Loaded Modules (whitelisted) =============
2014-03-31 00:28 - 2013-01-31 11:25 - 00087328 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-04-24 10:23 - 2014-04-24 10:23 - 02215936 _____ () C:\Program Files\AVAST Software\Avast\defs\14042400\algo.dll
2014-03-31 13:36 - 2014-03-31 13:36 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/24/2014 04:46:32 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/24/2014 04:43:08 PM) (Source: Wininit) (User: )
Description: Ein kritischer Systemprozess C:\Windows\system32\lsm.exe ist fehlgeschlagen mit den Statuscode 255. Der Computer muss neu gestartet werden.
Error: (04/24/2014 04:43:07 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: lsm.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7abf0
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000020a7a
ID des fehlerhaften Prozesses: 0x258
Startzeit der fehlerhaften Anwendung: 0xlsm.exe0
Pfad der fehlerhaften Anwendung: lsm.exe1
Pfad des fehlerhaften Moduls: lsm.exe2
Berichtskennung: lsm.exe3
Error: (04/24/2014 10:19:43 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/24/2014 08:18:25 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/23/2014 00:53:59 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/23/2014 00:50:30 PM) (Source: Wininit) (User: )
Description: Ein kritischer Systemprozess C:\Windows\system32\lsass.exe ist fehlgeschlagen mit den Statuscode 255. Der Computer muss neu gestartet werden.
Error: (04/23/2014 00:50:27 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: lsass.exe, Version: 6.1.7601.18270, Zeitstempel: 0x5242365b
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000020a7a
ID des fehlerhaften Prozesses: 0x254
Startzeit der fehlerhaften Anwendung: 0xlsass.exe0
Pfad der fehlerhaften Anwendung: lsass.exe1
Pfad des fehlerhaften Moduls: lsass.exe2
Berichtskennung: lsass.exe3
Error: (04/23/2014 08:31:11 AM) (Source: Windows Search Service) (User: )
Description: Der Index kann nicht initialisiert werden.
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (04/23/2014 08:31:11 AM) (Source: Windows Search Service) (User: )
Description: Die Anwendung kann nicht initialisiert werden.
Kontext: Windows Anwendung
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
System errors:
=============
Error: (04/24/2014 04:45:25 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
StarOpen
Error: (04/24/2014 04:44:52 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 24.04.2014 um 16:43:57 unerwartet heruntergefahren.
Error: (04/24/2014 04:44:48 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.
Error: (04/24/2014 04:44:46 PM) (Source: Application Popup) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.
Error: (04/24/2014 10:18:44 AM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
StarOpen
Error: (04/24/2014 10:17:57 AM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.
Error: (04/24/2014 10:17:56 AM) (Source: Application Popup) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.
Error: (04/24/2014 08:17:28 AM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
StarOpen
Error: (04/24/2014 08:16:31 AM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.
Error: (04/24/2014 08:16:31 AM) (Source: Application Popup) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\StarOpen.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.
Microsoft Office Sessions:
=========================
Error: (04/24/2014 04:46:32 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/24/2014 04:43:08 PM) (Source: Wininit)(User: )
Description: C:\Windows\system32\lsm.exe255
Error: (04/24/2014 04:43:07 PM) (Source: Application Error)(User: )
Description: lsm.exe6.1.7601.175144ce7abf0ntdll.dll6.1.7601.18247521eaf24c00000050000000000020a7a25801cf5f95b5c7b084C:\Windows\system32\lsm.exeC:\Windows\SYSTEM32\ntdll.dllbf564eeb-cbbe-11e3-8945-001e101fb45e
Error: (04/24/2014 10:19:43 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/24/2014 08:18:25 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/23/2014 00:53:59 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/23/2014 00:50:30 PM) (Source: Wininit)(User: )
Description: C:\Windows\system32\lsass.exe255
Error: (04/23/2014 00:50:27 PM) (Source: Application Error)(User: )
Description: lsass.exe6.1.7601.182705242365bntdll.dll6.1.7601.18247521eaf24c00000050000000000020a7a25401cf5ebd3edde796C:\Windows\system32\lsass.exeC:\Windows\SYSTEM32\ntdll.dll14514feb-cad5-11e3-81c0-001e101f4e71
Error: (04/23/2014 08:31:11 AM) (Source: Windows Search Service)(User: )
Description:
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (04/23/2014 08:31:11 AM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
CodeIntegrity Errors:
===================================
Date: 2014-04-06 08:51:37.386
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-04-06 08:51:37.339
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-04-02 11:51:22.067
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-04-02 11:51:22.020
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 36%
Total physical RAM: 4991.3 MB
Available physical RAM: 3188.62 MB
Total Pagefile: 9980.79 MB
Available Pagefile: 8215.77 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:74.43 GB) (Free:11.24 GB) NTFS
Drive e: (Mobile Partner) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 75 GB) (Disk ID: 00086CC3)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=74 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Vollscans mit Avast & Malwarebytes - Keine Befunde. Falls gewünscht, reiche ich die Logs nach! |