Los gehts. Kurz zur Info. Nach dem ersten Scan mit adwCleaner habe ich festgestellt, dass noch ein User angemeldet war. Daher zwei Scanns.
1. Scan:
AdwCleaner Logfile: Code:
# AdwCleaner v3.212 - Bericht erstellt am 12/06/2014 um 16:39:25
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername :
# Gestartet von : C:\Users\SYS***\Desktop\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Users\P*****gen\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\T***\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\*****\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\DesktopIconForAmazon
Datei Gelöscht : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\905sg94x.default\searchplugins\search.xml
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2736476
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_pdf-xchange-viewer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_pdf-xchange-viewer_RASMANCS
Schlüssel Gelöscht : HKLM\Software\Conduit
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v
[ Datei : C:\Users\A***s\AppData\Roaming\Mozilla\Firefox\Profiles\ht6c804m.default\prefs.js ]
[ Datei : C:\Users\*****l\AppData\Roaming\Mozilla\Firefox\Profiles\6e2nzqq7.default\prefs.js ]
[ Datei : C:\Users\A****z\AppData\Roaming\Mozilla\Firefox\Profiles\tw9nubus.default\prefs.js ]
[ Datei : C:\Users\N*******i\AppData\Roaming\Mozilla\Firefox\Profiles\gh0o3b19.default\prefs.js ]
[ Datei : C:\Users\*******4\AppData\Roaming\Mozilla\Firefox\Profiles\3jpy6waq.default\prefs.js ]
[ Datei : C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\40h3xepj.default\prefs.js ]
[ Datei : C:\Users\T***\AppData\Roaming\Mozilla\Firefox\Profiles\905sg94x.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [2764 octets] - [12/06/2014 16:37:47]
AdwCleaner[S0].txt - [2685 octets] - [12/06/2014 16:39:25]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2745 octets] ########## --- --- ---
2. Scann:
AdwCleaner Logfile: Code:
# AdwCleaner v3.212 - Bericht erstellt am 12/06/2014 um 17:26:55
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : ***ADMIN - *****P10****
# Gestartet von : C:\Users\***ADMIN\Desktop\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v
[ Datei : C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\ht6c804m.default\prefs.js ]
[ Datei : C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\6e2nzqq7.default\prefs.js ]
[ Datei : C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\tw9nubus.default\prefs.js ]
[ Datei : C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\gh0o3b19.default\prefs.js ]
[ Datei : C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\3jpy6waq.default\prefs.js ]
[ Datei : C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\40h3xepj.default\prefs.js ]
[ Datei : C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\905sg94x.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [2764 octets] - [12/06/2014 16:37:47]
AdwCleaner[R1].txt - [1560 octets] - [12/06/2014 17:25:37]
AdwCleaner[S0].txt - [2825 octets] - [12/06/2014 16:39:25]
AdwCleaner[S1].txt - [1481 octets] - [12/06/2014 17:26:55]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1541 octets] ########## --- --- ---
EIN DRITTER SCAN HAT ERGEBEN; DASS DIE DATEIEN MIT DER ENDUNG .JS NICHT GELÖSCHT WERDEN KONNTEN!
JRT:
JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Admin *** on 12.06.2014 at 17:36:16,63
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\GTaskMMC_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\GTaskMMC_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\GTaskMMC_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\GTaskMMC_RASMANCS
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12.06.2014 at 17:41:39,03
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
FRST Log:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-06-2014 01
Ran by ****** (administrator) on ****** on 12-06-2014 17:43:14
Running from C:\Users\******\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe
() C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe
(Gladinet, INC) C:\Program Files (x86)\Gladinet\Gladinet Cloud Desktop\GladFileMonSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Program Files (x86)\Gladinet\Gladinet Cloud Desktop\WOSVSSSvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVCM.EXE
(Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney Business 4.0\ouservice\StarMoneyOnlineUpdate.exe
(Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney Business 5.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSMLBIZ\MSSQL\Binn\sqlservr.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\AutoDetector\Monitor.exe
() C:\Program Files (x86)\SplitView 2014\SplitScr.exe
() C:\Program Files (x86)\SplitView 2014\SplitScrX64.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\AlarmClock.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395344 2011-06-28] (Acronis)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1797064 2014-03-20] (NVIDIA Corporation)
HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5587672 2011-06-28] (Acronis)
HKLM-x32\...\Run: [MSCRM] => C:\Program Files (x86)\Microsoft Dynamics CRM\Client\ConfigWizard\CrmForOutlookInstaller.exe [35432 2012-04-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.)
HKLM-x32\...\Run: [Ulead AutoDetector v2] => C:\Program Files (x86)\Common Files\Ulead Systems\AutoDetector\monitor.exe [90112 2004-11-26] (Ulead Systems, Inc.)
HKLM-x32\...\Run: [SplitView] => C:\Program Files (x86)\SplitView 2014\SplitScr.exe [311888 2014-02-21] ()
HKLM-x32\...\RunOnce: [DES2] - C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2.exe state [354856 2010-03-01] ()
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2715938741-4103475793-2943915029-1052\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-07-03] (Google Inc.)
HKU\S-1-5-21-2715938741-4103475793-2943915029-1052\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2715938741-4103475793-2943915029-1052\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Im Verlag.lnk
ShortcutTarget: Im Verlag.lnk -> C:\Users\******\AppData\Roaming\Realtime Soft\UltraMon\3.1.0\Profiles\Im Verlag.umprofile ()
Startup: C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
ShortcutTarget: MagicDisc.lnk -> C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
Startup: C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk
ShortcutTarget: UltraMon.lnk -> C:\Windows\Installer\{537056B7-32A4-4408-9B54-0341963C7C9C}\IcoUltraMon.ico ()
GroupPolicyUsers\S-1-5-21-2715938741-4103475793-2943915029-1040\User: Group Policy restriction detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3E803ABB6D85CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Keeeb BHO - {1926B88C-7FAE-4121-A973-7D51FDD394D5} - C:\Program Files (x86)\Keeeb\1.2.17\KangoBHO64.dll (Kango)
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Keeeb BHO - {1926B88C-7FAE-4121-A973-7D51FDD394D5} - C:\Program Files (x86)\Keeeb\1.2.17\KangoBHO.dll (Kango)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM - Keeeb - {8B9DB820-C156-4FAA-AEBA-60F10E5D4C0A} - C:\Program Files (x86)\Keeeb\1.2.17\KangoBHO64.dll (Kango)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - Keeeb - {8B9DB820-C156-4FAA-AEBA-60F10E5D4C0A} - C:\Program Files (x86)\Keeeb\1.2.17\KangoBHO.dll (Kango)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - Keeeb - {8B9DB820-C156-4FAA-AEBA-60F10E5D4C0A} - C:\Program Files (x86)\Keeeb\1.2.17\KangoBHO64.dll (Kango)
DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.2.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - No File
Tcpip\..\Interfaces\{892F2CA6-0CB6-4CE5-A993-3B175126C846}: [NameServer]192.168.200.1,8.8.8.8
FireFox:
========
FF ProfilePath: C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\40h3xepj.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
==================== Services (Whitelisted) =================
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation)
R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [498096 2010-05-02] (REINER SCT)
R2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [68136 2009-06-17] ()
R2 GladFileMonSvc; C:\Program Files (x86)\Gladinet\Gladinet Cloud Desktop\GladFileMonSvc.exe [30032 2013-03-24] (Gladinet, INC)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2013-01-12] () [File not signed]
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [398184 2012-12-14] (Malwarebytes Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [682344 2012-12-14] (Malwarebytes Corporation) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R2 msoidsvc; C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE [2078112 2011-09-28] (Microsoft Corp.)
R3 MSSQL$MSSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSMLBIZ\MSSQL\Binn\sqlservr.exe [62111072 2011-06-17] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [123664 2012-08-25] (SANDBOXIE L.T.D)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1326176 2012-07-25] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [681056 2012-07-25] (Secunia)
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.) [File not signed]
S4 SQLAgent$MSSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSMLBIZ\MSSQL\Binn\SQLAGENT.EXE [431456 2011-06-17] (Microsoft Corporation)
R2 StarMoney Business 4.0 OnlineUpdate; C:\Program Files (x86)\StarMoney Business 4.0\ouservice\StarMoneyOnlineUpdate.exe [554160 2011-11-08] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
R2 StarMoney Business 5.0 OnlineUpdate; C:\Program Files (x86)\StarMoney Business 5.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
R3 TermService; C:\Windows\System32\termsrv.dll [680960 2011-03-07] (Microsoft Corporation) [File not signed]
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-05-29] (TuneUp Software)
R2 VMAuthdService; C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe [79872 2011-11-13] (VMware, Inc.) [File not signed]
S3 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [11839488 2011-11-13] () [File not signed]
S2 StarMoney 8.0 OnlineUpdate; "C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe" [X]
==================== Drivers (Whitelisted) ====================
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21544 2010-04-27] ()
S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [29184 2010-02-08] (REINER SCT)
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2011-06-30] ()
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [37392 2010-05-20] (Paragon Software Group)
R3 isdnusb; C:\Windows\System32\DRIVERS\isdnusb.sys [263224 2010-09-22] (Siemens Enterprise Communications GmbH & Co. KG) [File not signed]
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [24176 2012-12-14] (Malwarebytes Corporation) [File not signed]
R0 MDPMGRNT; C:\Windows\System32\DRIVERS\MDPMGRNT.SYS [32424 2010-10-21] (Mediafour Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202632 2012-08-25] (SANDBOXIE L.T.D)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-09-22] (TuneUp Software)
R3 usbcdc; C:\Windows\System32\DRIVERS\usbcdc.sys [154680 2010-09-22] (Siemens Enterprise Communications GmbH & Co. KG)
R1 vcdc; C:\Windows\System32\DRIVERS\vcdc.sys [153912 2010-09-22] (Siemens Enterprise Communications GmbH & Co. KG)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-12 17:41 - 2014-06-12 17:41 - 00001062 _____ () C:\Users\******\Desktop\JRT.txt
2014-06-12 17:36 - 2014-06-12 17:36 - 00000000 ____D () C:\Windows\ERUNT
2014-06-12 17:35 - 2014-06-12 17:35 - 01016261 _____ (Thisisu) C:\Users\******\Desktop\JRT.exe
2014-06-12 17:32 - 2014-06-12 17:32 - 00001593 _____ () C:\Users\******\Desktop\AdwCleaner[S0]-2.txt
2014-06-12 17:24 - 2014-06-12 17:24 - 00002787 _____ () C:\Users\******\Desktop\AdwCleaner[S0].txt
2014-06-12 16:37 - 2014-06-12 17:33 - 00000000 ____D () C:\AdwCleaner
2014-06-12 16:37 - 2014-06-12 16:37 - 01333465 _____ () C:\Users\******\Desktop\adwcleaner_3.212.exe
2014-06-12 14:26 - 2014-06-12 14:26 - 00000000 ____D () C:\Users\******\AppData\Roaming\Tracker Software
2014-06-12 14:24 - 2014-06-12 14:24 - 00001042 _____ () C:\Users\Public\Desktop\PDF-XChange Editor.lnk
2014-06-12 14:24 - 2014-06-12 14:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange
2014-06-12 14:24 - 2014-06-12 14:24 - 00000000 ____D () C:\Program Files\Tracker Software
2014-06-12 14:22 - 2014-06-12 14:22 - 00000000 ____D () C:\ProgramData\Package Cache
2014-06-12 14:21 - 2014-06-12 14:21 - 00000000 ____D () C:\Users\******\Downloads\PDFXVE5
2014-06-12 14:13 - 2014-06-12 14:15 - 54047280 _____ () C:\Users\******\Downloads\PDFXVE5.zip
2014-06-12 13:48 - 2014-06-12 13:48 - 00000000 ____D () C:\Users\******\AppData\Roaming\WinRAR
2014-06-12 11:01 - 2014-06-12 11:02 - 00000000 ____D () C:\Users\******\AppData\Roaming\DropboxMaster
2014-06-12 10:40 - 2014-06-12 10:40 - 00039997 _____ () C:\Users\******\AppData\Local\recently-used.xbel
2014-06-12 09:57 - 2014-06-12 17:00 - 00000000 ____D () C:\Users\***\Documents\Anika
2014-06-12 08:39 - 2014-06-12 08:39 - 00003408 ____N () C:\bootsqm.dat
2014-06-12 08:29 - 2014-06-12 08:29 - 00000000 __SHD () C:\found.001
2014-06-11 23:03 - 2014-06-12 17:17 - 00000000 ____D () C:\Users\******\AppData\Local\temp
2014-06-11 23:03 - 2014-06-12 17:05 - 00000000 ____D () C:\Users\******\AppData\Local\temp
2014-06-11 23:03 - 2014-06-12 17:01 - 00000000 ____D () C:\Users\***\AppData\Local\temp
2014-06-11 23:03 - 2014-06-12 16:59 - 00000000 ____D () C:\Users\******\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00035484 _____ () C:\ComboFix.txt
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Steffen Woywode\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Redaktion_4\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Praktikant 1\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\******\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Lars\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Assistenz\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\temp
2014-06-11 22:32 - 2014-06-11 23:03 - 00000000 ____D () C:\Qoobox
2014-06-11 22:32 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-11 22:32 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-11 22:32 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-11 22:32 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-11 22:32 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-11 22:32 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-11 22:32 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-11 22:32 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-11 22:31 - 2014-06-11 23:01 - 00000000 ____D () C:\Windows\erdnt
2014-06-11 22:30 - 2014-06-11 22:30 - 05205915 ____R (Swearware) C:\Users\******\Desktop\ComboFix.exe
2014-06-11 21:08 - 2014-06-12 17:43 - 00021949 _____ () C:\Users\******\Desktop\FRST.txt
2014-06-11 20:12 - 2014-06-12 17:43 - 00000000 ____D () C:\FRST
2014-06-11 20:12 - 2014-06-11 20:12 - 02081792 _____ (Farbar) C:\Users\******\Desktop\FRST64.exe
2014-06-11 20:05 - 2014-06-11 20:05 - 00000000 ____D () C:\Program Files (x86)\Neuer Ordner
2014-06-11 19:22 - 2014-06-11 19:23 - 00000000 ____D () C:\Users\******\Desktop\CALA 2
2014-06-11 18:34 - 2014-06-11 18:58 - 00000000 ____D () C:\Users\******\AppData\Local\Mozilla
2014-06-11 18:34 - 2014-06-11 18:34 - 00000000 ____D () C:\Users\******\AppData\Roaming\Mozilla
2014-06-11 16:45 - 2014-06-11 16:45 - 00000000 ____D () C:\Users\******\Documents\O&O
2014-06-11 16:45 - 2014-06-11 16:45 - 00000000 ____D () C:\Users\******\AppData\Local\O&O
2014-06-11 16:39 - 2014-06-11 21:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-11 15:35 - 2014-06-11 21:09 - 00000000 ____D () C:\Users\******\AppData\Local\Mozilla
2014-06-11 15:35 - 2014-06-11 15:35 - 00000000 ____D () C:\Users\******\AppData\Roaming\Mozilla
2014-06-11 14:08 - 2014-06-11 14:08 - 00000000 __SHD () C:\Users\******\AppData\Local\EmieUserList
2014-06-11 14:08 - 2014-06-11 14:08 - 00000000 __SHD () C:\Users\******\AppData\Local\EmieSiteList
2014-06-11 13:59 - 2014-06-11 13:59 - 00000000 ____D () C:\Users\******\AppData\Roaming\Malwarebytes
2014-06-11 13:59 - 2014-06-11 13:59 - 00000000 ____D () C:\Users\******\AppData\Local\NVIDIA
2014-06-11 13:37 - 2014-06-11 13:37 - 00000000 ____D () C:\Users\******\AppData\Roaming\Malwarebytes
2014-06-11 06:50 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 06:50 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 06:50 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-11 06:50 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 06:50 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 06:50 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-11 06:50 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-11 06:50 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 06:50 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-11 06:50 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 06:50 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 06:50 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-11 06:50 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-11 06:50 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-11 06:50 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-11 06:50 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 06:50 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 06:50 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-11 06:50 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-11 06:50 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-11 06:50 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 06:50 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-11 06:50 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 06:50 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-11 06:50 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-11 06:50 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-11 06:50 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-11 06:50 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-11 06:50 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-11 06:50 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-11 06:50 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 06:50 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-11 06:50 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-11 06:50 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-11 06:50 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 06:50 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-11 06:50 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-11 06:50 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-11 06:50 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-11 06:50 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-11 06:50 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-11 06:50 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 06:50 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-11 06:50 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-11 06:50 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-11 06:50 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 06:50 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-11 06:50 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 06:50 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-11 06:50 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-11 06:50 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-11 06:50 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-11 06:38 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-11 06:38 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-06-11 06:38 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 06:38 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-11 06:38 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 06:38 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-11 06:38 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 06:38 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 06:38 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-11 06:38 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-11 06:38 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-11 06:38 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-11 06:38 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-11 06:38 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-11 06:32 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-11 06:32 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-10 13:40 - 2014-06-10 13:40 - 00000000 ____D () C:\Users\******\AppData\Roaming\WinRAR
2014-06-04 11:27 - 2014-06-04 11:27 - 00002973 _____ () C:\Users\******\Desktop\14-06-029-027.txt
2014-06-03 15:55 - 2014-06-03 15:55 - 00000000 ____D () C:\Users\******\AppData\OICE_15_974FA576_32C1D314_1F16
2014-05-30 14:58 - 2014-05-30 14:58 - 00000054 _____ () C:\Users\******\Desktop\kindertausch.txt
2014-05-30 14:14 - 2014-06-02 09:48 - 00010255 _____ () C:\Users\******\Desktop\HotelsHannover.xlsx
2014-05-29 13:19 - 2014-05-29 13:24 - 00010216 _____ () C:\Users\******\Desktop\TerminanfrageBerlin1.xlsx
2014-05-28 17:00 - 2014-05-28 17:00 - 00001215 _____ () C:\Users\******\Desktop\HotelsHannover.txt
2014-05-28 11:34 - 2014-05-28 11:34 - 00000000 ____D () C:\Users\******\AppData\OICE_15_974FA576_32C1D314_33CE
2014-05-27 15:42 - 2014-05-27 15:42 - 00043008 _____ () C:\Users\******\Desktop\neue Liste.xls
2014-05-26 13:20 - 2014-05-26 10:00 - 373190979 _____ () C:\Users\******\Desktop\ISYbe_Erklaerfilm.mp4
2014-05-26 13:19 - 2014-05-26 10:00 - 175801613 _____ () C:\Users\******\Desktop\ISYbe_Erklaerfilm.mov
2014-05-26 13:08 - 2014-05-26 13:13 - 00000000 ____D () C:\Users\******\Desktop\anhang2
2014-05-22 15:02 - 2014-05-22 15:02 - 00074472 _____ () C:\Users\******\Desktop\anhang2.zip
2014-05-21 15:47 - 2014-05-21 15:47 - 00000000 ____D () C:\Users\******\AppData\Local\NVIDIA
2014-05-20 17:37 - 2014-05-20 17:37 - 00067046 _____ () C:\Users\******\Desktop\Präsentation Auswertung 2014_BadSaarow.pptx
2014-05-19 23:14 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-05-19 23:14 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-05-19 13:48 - 2014-05-19 13:48 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-19 13:39 - 2014-05-19 13:39 - 00088576 _____ () C:\Users\******\Desktop\Kinderläden_1.xls
2014-05-19 13:31 - 2014-05-19 13:31 - 00037376 _____ () C:\Users\******\Desktop\Kopie von Dresden.xls
2014-05-19 13:17 - 2014-05-19 13:17 - 00000000 ____D () C:\Users\******\AppData\Local\NVIDIA
2014-05-19 13:14 - 2014-05-19 13:14 - 00000000 ____D () C:\Users\******\AppData\Local\NVIDIA
2014-05-19 13:08 - 2014-05-19 13:08 - 00000000 ____D () C:\Users\******\AppData\Local\NVIDIA
2014-05-19 11:38 - 2014-05-19 11:38 - 00000000 ____D () C:\Users\***\AppData\Local\NVIDIA
2014-05-19 11:38 - 2014-05-19 11:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-05-19 10:25 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-05-19 10:25 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-19 10:25 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-19 10:25 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-05-19 10:25 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-05-19 10:25 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-05-19 10:25 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-05-19 10:25 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-05-19 10:25 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-05-19 10:25 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-05-19 10:25 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-05-19 10:25 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-05-19 10:25 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-05-19 10:25 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-05-19 10:25 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-05-19 10:25 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-05-19 10:24 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-05-19 10:21 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-05-19 10:21 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-05-16 13:53 - 2014-06-11 16:15 - 00000000 ___SD () C:\Users\******\Documents\Meine Datenquellen
2014-05-15 14:41 - 2014-05-15 14:41 - 00028672 _____ () C:\Users\******\Desktop\Teilnehmerliste.xls
2014-05-15 12:44 - 2014-05-15 12:44 - 00000000 ____D () C:\Users\******\AppData\Roaming\Realtime Soft
2014-05-15 12:07 - 2014-05-15 12:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SplitView
2014-05-15 12:07 - 2014-05-15 12:07 - 00000000 ____D () C:\Program Files (x86)\SplitView 2014
2014-05-15 12:02 - 2014-05-15 12:02 - 01190912 _____ () C:\Users\******\Downloads\SplitView.msi
2014-05-15 08:05 - 2014-05-15 08:05 - 00000000 ___RD () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 08:05 - 2014-05-15 08:05 - 00000000 ___RD () C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-14 16:41 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 16:41 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 16:41 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 16:41 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 16:41 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 16:41 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 16:41 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-14 16:41 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-14 16:41 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 16:41 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 16:41 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 16:41 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 16:41 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 16:41 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 16:41 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 16:41 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 16:41 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 16:41 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 16:41 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 16:41 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-14 16:41 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 16:41 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-14 16:41 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-14 16:41 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-14 16:41 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-14 16:41 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 16:41 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 16:41 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-14 16:41 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-14 16:41 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-14 16:41 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 16:41 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-13 11:11 - 2014-05-13 11:53 - 00011492 _____ () C:\Users\******\Desktop\Immobilien Berlin.xlsx
==================== One Month Modified Files and Folders =======
2014-06-12 17:43 - 2014-06-11 21:08 - 00021949 _____ () C:\Users\******\Desktop\FRST.txt
2014-06-12 17:43 - 2014-06-11 20:12 - 00000000 ____D () C:\FRST
2014-06-12 17:43 - 2013-10-11 13:57 - 00000000 ____D () C:\Users\******\AppData\Local\Temp
2014-06-12 17:41 - 2014-06-12 17:41 - 00001062 _____ () C:\Users\******\Desktop\JRT.txt
2014-06-12 17:41 - 2011-02-10 19:53 - 01169510 _____ () C:\Windows\WindowsUpdate.log
2014-06-12 17:37 - 2009-07-14 06:45 - 00026000 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-12 17:37 - 2009-07-14 06:45 - 00026000 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-12 17:36 - 2014-06-12 17:36 - 00000000 ____D () C:\Windows\ERUNT
2014-06-12 17:35 - 2014-06-12 17:35 - 01016261 _____ (Thisisu) C:\Users\******\Desktop\JRT.exe
2014-06-12 17:33 - 2014-06-12 16:37 - 00000000 ____D () C:\AdwCleaner
2014-06-12 17:32 - 2014-06-12 17:32 - 00001593 _____ () C:\Users\******\Desktop\AdwCleaner[S0]-2.txt
2014-06-12 17:30 - 2011-03-23 13:37 - 00000000 ____D () C:\ProgramData\VMware
2014-06-12 17:30 - 2011-03-17 13:58 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-12 17:30 - 2011-02-13 13:16 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2014-06-12 17:29 - 2011-08-07 09:49 - 00024174 _____ () C:\Windows\setupact.log
2014-06-12 17:29 - 2011-02-14 13:47 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-12 17:29 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-12 17:28 - 2011-09-01 09:26 - 00662776 _____ () C:\Windows\PFRO.log
2014-06-12 17:24 - 2014-06-12 17:24 - 00002787 _____ () C:\Users\******\Desktop\AdwCleaner[S0].txt
2014-06-12 17:22 - 2013-10-11 17:22 - 00129472 _____ () C:\Users\******\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-12 17:20 - 2009-07-14 06:45 - 00483672 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-12 17:17 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\******\AppData\Local\temp
2014-06-12 17:14 - 2011-02-10 21:12 - 00000000 ____D () C:\Users\******\Documents\Outlook-Dateien
2014-06-12 17:05 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\******\AppData\Local\temp
2014-06-12 17:05 - 2012-11-14 11:24 - 00000000 ___RD () C:\Users\******\Dropbox
2014-06-12 17:02 - 2013-11-07 17:30 - 00000000 ____D () C:\Users\***\Documents\Outlook-Dateien
2014-06-12 17:01 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\***\AppData\Local\temp
2014-06-12 17:00 - 2014-06-12 09:57 - 00000000 ____D () C:\Users\***\Documents\Anika
2014-06-12 16:59 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\******\AppData\Local\temp
2014-06-12 16:59 - 2011-12-05 11:42 - 00000000 ____D () C:\Users\******\Documents\Outlook-Dateien
2014-06-12 16:58 - 2012-06-27 17:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-12 16:48 - 2011-03-17 13:58 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-12 16:37 - 2014-06-12 16:37 - 01333465 _____ () C:\Users\******\Desktop\adwcleaner_3.212.exe
2014-06-12 16:03 - 2012-10-12 08:08 - 00000000 ____D () C:\Users\******\Desktop\Vorlagen
2014-06-12 14:35 - 2012-07-03 14:15 - 00129472 _____ () C:\Users\******\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-12 14:28 - 2013-11-07 17:15 - 00129472 _____ () C:\Users\***\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-12 14:28 - 2011-12-05 11:36 - 00129472 _____ () C:\Users\******\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-12 14:26 - 2014-06-12 14:26 - 00000000 ____D () C:\Users\******\AppData\Roaming\Tracker Software
2014-06-12 14:25 - 2011-02-10 20:11 - 00129472 _____ () C:\Users\******\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-12 14:24 - 2014-06-12 14:24 - 00001042 _____ () C:\Users\Public\Desktop\PDF-XChange Editor.lnk
2014-06-12 14:24 - 2014-06-12 14:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange
2014-06-12 14:24 - 2014-06-12 14:24 - 00000000 ____D () C:\Program Files\Tracker Software
2014-06-12 14:22 - 2014-06-12 14:22 - 00000000 ____D () C:\ProgramData\Package Cache
2014-06-12 14:21 - 2014-06-12 14:21 - 00000000 ____D () C:\Users\******\Downloads\PDFXVE5
2014-06-12 14:15 - 2014-06-12 14:13 - 54047280 _____ () C:\Users\******\Downloads\PDFXVE5.zip
2014-06-12 14:10 - 2011-02-13 15:59 - 00000000 ____D () C:\ProgramData\Adobe
2014-06-12 14:08 - 2012-11-19 11:13 - 00000000 ____D () C:\Users\******\Desktop\BERLIN
2014-06-12 13:48 - 2014-06-12 13:48 - 00000000 ____D () C:\Users\******\AppData\Roaming\WinRAR
2014-06-12 12:03 - 2013-01-25 15:21 - 00000000 ____D () C:\Users\******\Desktop\einnahmen_online
2014-06-12 11:29 - 2012-11-08 15:50 - 00000000 ____D () C:\Users\******\AppData\Roaming\Dropbox
2014-06-12 11:02 - 2014-06-12 11:01 - 00000000 ____D () C:\Users\******\AppData\Roaming\DropboxMaster
2014-06-12 11:01 - 2012-11-14 11:59 - 00001046 _____ () C:\Users\******\Desktop\Dropbox.lnk
2014-06-12 11:01 - 2012-11-14 11:55 - 00000000 ____D () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-06-12 10:40 - 2014-06-12 10:40 - 00039997 _____ () C:\Users\******\AppData\Local\recently-used.xbel
2014-06-12 10:40 - 2012-11-14 12:30 - 00000000 ____D () C:\Users\******\.gimp-2.8
2014-06-12 10:11 - 2012-01-05 20:52 - 00018432 _____ () C:\Users\******\Documents\Passwörter.xlsx
2014-06-12 09:26 - 2013-05-22 09:01 - 00005142 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for ******-****** ******
2014-06-12 09:17 - 2014-02-10 17:30 - 00005174 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for ******-****** ******
2014-06-12 09:05 - 2012-01-03 09:25 - 00000680 __RSH () C:\Users\******\ntuser.pol
2014-06-12 09:05 - 2011-02-10 20:03 - 00000000 ____D () C:\Users\******
2014-06-12 08:45 - 2013-11-07 17:13 - 00000680 __RSH () C:\Users\***\ntuser.pol
2014-06-12 08:45 - 2013-11-07 17:13 - 00000000 ____D () C:\Users\***
2014-06-12 08:42 - 2012-01-03 09:37 - 00004700 __RSH () C:\Users\******\ntuser.pol
2014-06-12 08:42 - 2011-12-05 11:35 - 00000000 ____D () C:\Users\******
2014-06-12 08:39 - 2014-06-12 08:39 - 00003408 ____N () C:\bootsqm.dat
2014-06-12 08:29 - 2014-06-12 08:29 - 00000000 __SHD () C:\found.001
2014-06-12 00:00 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-06-11 23:25 - 2014-02-13 06:02 - 00000000 ____D () C:\Windows\rescache
2014-06-11 23:15 - 2013-10-25 14:12 - 00000000 ____D () C:\Users\******\AppData\Local\Temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00035484 _____ () C:\ComboFix.txt
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Steffen Woywode\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Redaktion_4\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Praktikant 1\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\******\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Lars\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Assistenz\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 23:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\temp
2014-06-11 23:03 - 2014-06-11 22:32 - 00000000 ____D () C:\Qoobox
2014-06-11 23:03 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-06-11 23:01 - 2014-06-11 22:31 - 00000000 ____D () C:\Windows\erdnt
2014-06-11 23:01 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-06-11 22:56 - 2013-10-11 17:22 - 00000000 ____D () C:\Users\******\AppData\Local\Adobe
2014-06-11 22:30 - 2014-06-11 22:30 - 05205915 ____R (Swearware) C:\Users\******\Desktop\ComboFix.exe
2014-06-11 21:59 - 2013-10-25 14:12 - 00000680 __RSH () C:\Users\******\ntuser.pol
2014-06-11 21:59 - 2013-10-25 14:12 - 00000000 ____D () C:\Users\******
2014-06-11 21:09 - 2014-06-11 16:39 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-11 21:09 - 2014-06-11 15:35 - 00000000 ____D () C:\Users\******\AppData\Local\Mozilla
2014-06-11 21:05 - 2013-11-06 15:40 - 00007601 _____ () C:\Users\******\AppData\Local\Resmon.ResmonCfg
2014-06-11 20:12 - 2014-06-11 20:12 - 02081792 _____ (Farbar) C:\Users\******\Desktop\FRST64.exe
2014-06-11 20:05 - 2014-06-11 20:05 - 00000000 ____D () C:\Program Files (x86)\Neuer Ordner
2014-06-11 19:36 - 2013-09-06 09:13 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-11 19:34 - 2011-02-21 12:26 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-11 19:33 - 2013-12-12 04:01 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-06-11 19:33 - 2011-02-10 20:21 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-11 19:29 - 2014-04-30 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-11 19:23 - 2014-06-11 19:22 - 00000000 ____D () C:\Users\******\Desktop\CALA 2
2014-06-11 18:58 - 2014-06-11 18:34 - 00000000 ____D () C:\Users\******\AppData\Local\Mozilla
2014-06-11 18:34 - 2014-06-11 18:34 - 00000000 ____D () C:\Users\******\AppData\Roaming\Mozilla
2014-06-11 18:04 - 2012-09-13 17:33 - 00000000 ___RD () C:\Sandbox
2014-06-11 17:21 - 2011-02-14 14:12 - 03236864 _____ () C:\Users\******\Documents\****** Otto.QBW
2014-06-11 17:19 - 2011-02-14 14:12 - 00000000 ____D () C:\Users\******\Documents\Buchhaltung und Rechnungswesen
2014-06-11 16:55 - 2013-10-22 18:10 - 00000000 ____D () C:\Users\******\AppData\Local\Google
2014-06-11 16:55 - 2011-02-13 18:09 - 00000000 ____D () C:\Program Files (x86)\Google
2014-06-11 16:49 - 2011-02-13 18:09 - 00000000 ____D () C:\Users\******\AppData\Local\Google
2014-06-11 16:45 - 2014-06-11 16:45 - 00000000 ____D () C:\Users\******\Documents\O&O
2014-06-11 16:45 - 2014-06-11 16:45 - 00000000 ____D () C:\Users\******\AppData\Local\O&O
2014-06-11 16:41 - 2013-10-25 14:25 - 00000000 ____D () C:\Users\******\AppData\Local\Google
2014-06-11 16:32 - 2012-07-30 13:17 - 00000000 ____D () C:\Users\******\AppData\Local\Google
2014-06-11 16:15 - 2014-05-16 13:53 - 00000000 ___SD () C:\Users\******\Documents\Meine Datenquellen
2014-06-11 16:15 - 2014-02-06 10:09 - 00000000 ____D () C:\Users\******\AppData\Local\gladinet
2014-06-11 16:15 - 2013-10-25 14:14 - 00000000 ____D () C:\Users\******\AppData\Roaming\Apple Computer
2014-06-11 16:15 - 2013-10-25 14:12 - 00000000 ____D () C:\Users\******\AppData\Roaming\Adobe
2014-06-11 16:15 - 2013-01-29 17:22 - 00000000 ____D () C:\ProgramData\StarMoney Business 5.0
2014-06-11 16:15 - 2013-01-29 16:36 - 00000000 ____D () C:\ProgramData\StarMoney 8.0
2014-06-11 16:15 - 2011-06-10 11:58 - 00000000 ____D () C:\ProgramData\Skype Extras
2014-06-11 16:15 - 2011-03-07 14:56 - 00000000 ____D () C:\ProgramData\StarMoney Business 4.0
2014-06-11 16:15 - 2011-02-25 14:24 - 00000000 ____D () C:\ProgramData\Skype
2014-06-11 16:15 - 2011-02-22 19:17 - 00000000 ____D () C:\Users\Public\Documents\Lexware
2014-06-11 16:15 - 2011-02-13 14:07 - 00000000 ____D () C:\ProgramData\TAPICall
2014-06-11 15:35 - 2014-06-11 15:35 - 00000000 ____D () C:\Users\******\AppData\Roaming\Mozilla
2014-06-11 14:14 - 2012-06-27 17:42 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-11 14:14 - 2012-06-27 17:42 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-11 14:14 - 2011-06-22 13:35 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-11 14:08 - 2014-06-11 14:08 - 00000000 __SHD () C:\Users\******\AppData\Local\EmieUserList
2014-06-11 14:08 - 2014-06-11 14:08 - 00000000 __SHD () C:\Users\******\AppData\Local\EmieSiteList
2014-06-11 13:59 - 2014-06-11 13:59 - 00000000 ____D () C:\Users\******\AppData\Roaming\Malwarebytes
2014-06-11 13:59 - 2014-06-11 13:59 - 00000000 ____D () C:\Users\******\AppData\Local\NVIDIA
2014-06-11 13:57 - 2013-10-25 14:13 - 00000000 ___RD () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-11 13:37 - 2014-06-11 13:37 - 00000000 ____D () C:\Users\******\AppData\Roaming\Malwarebytes
2014-06-11 11:52 - 2013-11-29 09:47 - 00239104 _____ () C:\Users\***\Desktop\adressen_berlin.xls
2014-06-10 13:42 - 2013-12-20 10:05 - 00000280 ____H () C:\Users\Public\Documents\~$Vertrags und Umsatzübersicht 2013.xlsx
2014-06-10 13:40 - 2014-06-10 13:40 - 00000000 ____D () C:\Users\******\AppData\Roaming\WinRAR
2014-06-10 08:14 - 2012-09-13 17:32 - 00002362 _____ () C:\Windows\Sandboxie.ini
2014-06-08 11:13 - 2014-06-11 06:32 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-11 06:32 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-04 14:05 - 2014-02-21 15:21 - 00000000 ____D () C:\Users\***\Desktop\GbR Aufträge
2014-06-04 11:27 - 2014-06-04 11:27 - 00002973 _____ () C:\Users\******\Desktop\14-06-029-027.txt
2014-06-03 15:55 - 2014-06-03 15:55 - 00000000 ____D () C:\Users\******\AppData\OICE_15_974FA576_32C1D314_1F16
2014-06-03 12:05 - 2011-02-13 15:56 - 00000000 ___RD () C:\Users\******\Desktop\Kribbelbunt
2014-06-03 09:04 - 2013-11-18 15:01 - 00968704 _____ () C:\Users\***\Desktop\Archiv_60plusminus_Stand_April_2013.xls
2014-06-02 16:25 - 2013-12-02 10:42 - 00000000 ____D () C:\Users\******\Desktop\angebotsbanner
2014-06-02 09:48 - 2014-05-30 14:14 - 00010255 _____ () C:\Users\******\Desktop\HotelsHannover.xlsx
2014-05-30 14:58 - 2014-05-30 14:58 - 00000054 _____ () C:\Users\******\Desktop\kindertausch.txt
2014-05-30 12:21 - 2014-06-11 06:50 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-11 06:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-11 06:50 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-11 06:50 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-11 06:50 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-11 06:50 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-11 06:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-11 06:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-11 06:50 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-11 06:50 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-11 06:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-11 06:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-11 06:50 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-11 06:50 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-11 06:50 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-11 06:50 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-11 06:50 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-11 06:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-11 06:50 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-11 06:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-11 06:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-11 06:50 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-11 06:50 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-11 06:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-11 06:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-11 06:50 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-11 06:50 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-11 06:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-11 06:50 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-11 06:50 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-11 06:50 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-11 06:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-11 06:50 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-11 06:50 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-11 06:50 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-11 06:50 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-11 06:50 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:07 - 2013-03-26 12:09 - 00038062 _____ () C:\Users\******\Desktop\internetagenturen.xlsx
2014-05-30 10:06 - 2014-06-11 06:50 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-11 06:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-11 06:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-11 06:50 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-11 06:50 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-11 06:50 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-11 06:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-11 06:50 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-11 06:50 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-11 06:50 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-11 06:50 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-11 06:50 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-11 06:50 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-11 06:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-11 06:50 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-30 08:12 - 2013-12-09 10:31 - 00000000 ____D () C:\Users\******\steffen
2014-05-29 14:19 - 2013-09-05 09:27 - 00000000 ____D () C:\Users\******\Desktop\Potential
2014-05-29 14:18 - 2014-02-10 10:17 - 00000000 ____D () C:\Users\******\Desktop\Excel
2014-05-29 13:24 - 2014-05-29 13:19 - 00010216 _____ () C:\Users\******\Desktop\TerminanfrageBerlin1.xlsx
2014-05-29 11:09 - 2013-08-09 14:54 - 00014332 _____ () C:\Users\******\Desktop\schönheitschirurgie_berlin.xlsx
2014-05-28 17:00 - 2014-05-28 17:00 - 00001215 _____ () C:\Users\******\Desktop\HotelsHannover.txt
2014-05-28 11:34 - 2014-05-28 11:34 - 00000000 ____D () C:\Users\******\AppData\OICE_15_974FA576_32C1D314_33CE
2014-05-28 08:10 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-05-27 15:42 - 2014-05-27 15:42 - 00043008 _____ () C:\Users\******\Desktop\neue Liste.xls
2014-05-27 13:45 - 2014-01-13 10:41 - 00000000 ____D () C:\Users\***\Desktop\KIDS UND CO VERTRÄGE
2014-05-26 13:48 - 2014-04-17 13:55 - 00000000 ____D () C:\Users\******\AppData\Roaming\vlc
2014-05-26 13:13 - 2014-05-26 13:08 - 00000000 ____D () C:\Users\******\Desktop\anhang2
2014-05-26 10:49 - 2013-01-28 10:20 - 00000000 ____D () C:\Users\******\texte_linkpartner, teliad, anschreiben
2014-05-26 10:33 - 2013-06-14 09:51 - 00000000 ____D () C:\Users\******\Desktop\Anzeigen
2014-05-26 10:00 - 2014-05-26 13:20 - 373190979 _____ () C:\Users\******\Desktop\ISYbe_Erklaerfilm.mp4
2014-05-26 10:00 - 2014-05-26 13:19 - 175801613 _____ () C:\Users\******\Desktop\ISYbe_Erklaerfilm.mov
2014-05-22 15:02 - 2014-05-22 15:02 - 00074472 _____ () C:\Users\******\Desktop\anhang2.zip
2014-05-22 13:01 - 2012-05-07 14:12 - 00000000 ____D () C:\Users\******\AppData\Local\FreePDF_XP
2014-05-21 15:47 - 2014-05-21 15:47 - 00000000 ____D () C:\Users\******\AppData\Local\NVIDIA
2014-05-20 17:37 - 2014-05-20 17:37 - 00067046 _____ () C:\Users\******\Desktop\Präsentation Auswertung 2014_BadSaarow.pptx
2014-05-19 13:48 - 2014-05-19 13:48 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-19 13:39 - 2014-05-19 13:39 - 00088576 _____ () C:\Users\******\Desktop\Kinderläden_1.xls
2014-05-19 13:31 - 2014-05-19 13:31 - 00037376 _____ () C:\Users\******\Desktop\Kopie von Dresden.xls
2014-05-19 13:17 - 2014-05-19 13:17 - 00000000 ____D () C:\Users\******\AppData\Local\NVIDIA
2014-05-19 13:14 - 2014-05-19 13:14 - 00000000 ____D () C:\Users\******\AppData\Local\NVIDIA
2014-05-19 13:08 - 2014-05-19 13:08 - 00000000 ____D () C:\Users\******\AppData\Local\NVIDIA
2014-05-19 11:38 - 2014-05-19 11:38 - 00000000 ____D () C:\Users\***\AppData\Local\NVIDIA
2014-05-19 11:38 - 2014-05-19 11:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-05-19 10:25 - 2011-02-14 13:39 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-05-19 10:25 - 2011-02-14 13:38 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-05-19 10:13 - 2013-10-25 14:14 - 00129864 _____ () C:\Users\******\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-19 09:42 - 2011-02-10 20:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server
2014-05-19 09:42 - 2009-07-14 20:18 - 00000000 ____D () C:\Windows\ShellNew
2014-05-19 09:35 - 2009-07-14 04:34 - 00000478 _____ () C:\Windows\win.ini
2014-05-15 16:21 - 2014-05-12 10:37 - 00011958 _____ () C:\Users\******\Desktop\Kochloft 13.05.-Zusagen.xlsx
2014-05-15 14:41 - 2014-05-15 14:41 - 00028672 _____ () C:\Users\******\Desktop\Teilnehmerliste.xls
2014-05-15 14:14 - 2011-12-05 11:35 - 00000000 ___RD () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 14:14 - 2011-12-05 11:35 - 00000000 ___RD () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 14:10 - 2013-10-11 17:22 - 00000000 ___RD () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 14:10 - 2013-10-11 17:22 - 00000000 ___RD () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 14:10 - 2013-10-11 17:21 - 00000680 __RSH () C:\Users\******\ntuser.pol
2014-05-15 14:10 - 2013-10-11 13:57 - 00000000 ____D () C:\Users\******
2014-05-15 12:52 - 2011-02-14 14:19 - 00000000 ____D () C:\Users\******\AppData\Roaming\UseNeXT
2014-05-15 12:44 - 2014-05-15 12:44 - 00000000 ____D () C:\Users\******\AppData\Roaming\Realtime Soft
2014-05-15 12:34 - 2011-02-13 15:38 - 00002334 ____H () C:\Users\******\Documents\Default.rdp
2014-05-15 12:07 - 2014-05-15 12:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SplitView
2014-05-15 12:07 - 2014-05-15 12:07 - 00000000 ____D () C:\Program Files (x86)\SplitView 2014
2014-05-15 12:02 - 2014-05-15 12:02 - 01190912 _____ () C:\Users\******\Downloads\SplitView.msi
2014-05-15 09:45 - 2013-10-25 14:13 - 00000000 ___RD () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 08:54 - 2011-02-10 20:03 - 00000000 ___RD () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 08:54 - 2011-02-10 20:03 - 00000000 ___RD () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 08:05 - 2014-05-15 08:05 - 00000000 ___RD () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 08:05 - 2014-05-15 08:05 - 00000000 ___RD () C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 08:05 - 2013-11-07 17:14 - 00000000 ___RD () C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 08:05 - 2013-11-04 09:56 - 00000000 ___RD () C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 08:04 - 2012-07-03 14:14 - 00000680 __RSH () C:\Users\******\ntuser.pol
2014-05-15 08:04 - 2012-07-03 14:14 - 00000000 ____D () C:\Users\******
2014-05-15 03:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-13 11:53 - 2014-05-13 11:11 - 00011492 _____ () C:\Users\******\Desktop\Immobilien Berlin.xlsx
Files to move or delete:
====================
C:\Users\Public\OutlookConfigurator.exe
Some content of TEMP:
====================
C:\Users\******\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxu1s5q.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-08 00:53
==================== End Of Log ============================ --- --- ---
--- --- --- |