| wickedsick2k |  04.07.2014 15:35 |        Alles wie beschrieben erledigt, hier noch die einzelnen Logfiles:  
Fixlog   Code:  
 Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:01-07-2014 
Ran by Natalie at 2014-07-04 16:23:16 Run:1 
Running from C:\Users\Natalie\Desktop 
Boot Mode: Normal   
==============================================   
Content of fixlist: 
***************** 
start 
HKU\S-1-5-21-71110408-726262554-3037163554-1001\...\Run: [wkkjkaji] => C:\Users\Natalie\AppData\Local\Bpgd\pgokwyokaji.exe 
C:\Users\Natalie\AppData\Local\Bpgd 
Reboot: 
end 
*****************   
HKU\S-1-5-21-71110408-726262554-3037163554-1001\Software\Microsoft\Windows\CurrentVersion\Run\\wkkjkaji => value deleted successfully. 
C:\Users\Natalie\AppData\Local\Bpgd => Moved successfully.     
The system needed a reboot.    
==== End of Fixlog ====   FRST  
FRST Logfile:  
FRST Logfile:   Code:  
 Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:01-07-2014 
Ran by Natalie (administrator) on SCHNADDL on 04-07-2014 16:26:34 
Running from C:\Users\Natalie\Desktop 
Platform: Microsoft Windows 8.1 Pro (X86) OS Language: Deutsch (Deutschland) 
Internet Explorer Version 11 
Boot Mode: Normal       
==================== Processes (Whitelisted) =================   
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe 
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe 
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe 
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe 
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe 
(Microsoft Corporation) C:\Windows\System32\dasHost.exe 
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe 
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\livecomm.exe 
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe 
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe 
(Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe 
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe 
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe 
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe 
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe 
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe 
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe 
(Dropbox, Inc.) C:\Users\Natalie\AppData\Roaming\Dropbox\bin\Dropbox.exe 
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe     
==================== Registry (Whitelisted) ==================   
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [835584 2008-01-30] (Synaptics, Inc.) 
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated) 
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) 
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-10-01] (Apple Inc.) 
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) 
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) 
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5179408 2014-06-17] (AVG Technologies CZ, s.r.o.) 
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,"C:\Program Files\NoTilesPlease\ntpload.exe", 
HKU\S-1-5-21-71110408-726262554-3037163554-1001\...\Run: [EPSON26D8A9 (Epson Stylus SX235)] => C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_FATIHLE.EXE [212480 2011-01-20] (SEIKO EPSON CORPORATION) 
Startup: C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 
ShortcutTarget: Dropbox.lnk -> C:\Users\Natalie\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) 
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File 
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File 
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File 
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File   
==================== Internet (Whitelisted) ====================   
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4B00A63109D0CD01 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE 
URLSearchHook: HKCU - (No Name) - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} -  No File 
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) 
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) 
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) 
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) 
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) 
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) 
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) 
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1   
FireFox: 
======== 
FF ProfilePath: C:\Users\Natalie\AppData\Roaming\Mozilla\Firefox\Profiles\92znsytt.default 
FF DefaultSearchEngine: Ask Search 
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); 
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); 
FF Homepage: hxxp://www.google.de/ 
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () 
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () 
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) 
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) 
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) 
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) 
FF Plugin: @videolan.org/vlc,version=2.0.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) 
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml 
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml 
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml 
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml 
FF Extension: Adblock Plus - C:\Users\Natalie\AppData\Roaming\Mozilla\Firefox\Profiles\92znsytt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-12-21] 
FF Extension: Greasemonkey - C:\Users\Natalie\AppData\Roaming\Mozilla\Firefox\Profiles\92znsytt.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2012-12-21]   
========================== Services (Whitelisted) =================   
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3241488 2014-06-27] (AVG Technologies CZ, s.r.o.) 
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-06-17] (AVG Technologies CZ, s.r.o.) 
S3 ScDeviceEnum; C:\WINDOWS\System32\ScDeviceEnum.dll [105472 2013-08-22] (Microsoft Corporation) 
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [279784 2014-06-16] (Microsoft Corporation) 
S3 WEPHOSTSVC; C:\WINDOWS\system32\wephostsvc.dll [20992 2013-08-22] (Microsoft Corporation) 
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22224 2014-06-16] (Microsoft Corporation) 
S3 workfolderssvc; C:\WINDOWS\system32\workfolderssvc.dll [1210368 2014-06-16] (Microsoft Corporation)   
==================== Drivers (Whitelisted) ====================   
R3 athr; C:\WINDOWS\system32\DRIVERS\athwn.sys [2795520 2013-06-18] (Qualcomm Atheros Communications, Inc.) 
S0 Avgbootx; C:\WINDOWS\System32\DRIVERS\avgbootx.sys [17424 2013-09-04] (AVG Technologies CZ, s.r.o.) 
R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [121624 2014-06-17] (AVG Technologies CZ, s.r.o.) 
R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdriverx.sys [199960 2014-06-17] (AVG Technologies CZ, s.r.o.) 
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.) 
R1 AVGIDSShim; C:\WINDOWS\system32\DRIVERS\avgidsshimw8x.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.) 
R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [188696 2014-06-17] (AVG Technologies CZ, s.r.o.) 
R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.) 
R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [98584 2014-06-17] (AVG Technologies CZ, s.r.o.) 
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.) 
R1 Avgwfpx; C:\WINDOWS\system32\DRIVERS\avgwfpx.sys [213784 2014-05-14] (AVG Technologies CZ, s.r.o.) 
R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [25600 2014-03-18] (Microsoft Corporation) 
S3 GPIO; C:\WINDOWS\System32\drivers\iaiogpio.sys [22016 2013-07-23] (Intel Corporation) 
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [92504 2014-06-16] (Microsoft Corporation) 
R0 Wof; C:\WINDOWS\system32\Drivers\Wof.sys [138584 2014-06-16] (Microsoft Corporation) 
R3 yukonw8; C:\WINDOWS\system32\DRIVERS\yk63x86.sys [249288 2013-06-18] (Marvell)   
==================== NetSvcs (Whitelisted) ===================     
==================== One Month Created Files and Folders ========   
2014-07-04 16:26 - 2014-07-04 16:27 - 00010285 _____ () C:\Users\Natalie\Desktop\FRST.txt 
2014-07-03 20:20 - 2014-07-03 20:20 - 00002085 _____ () C:\Users\Natalie\Desktop\mbam.txt 
2014-07-03 20:01 - 2014-07-03 20:19 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 
2014-07-03 20:00 - 2014-07-03 20:00 - 00001068 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\ProgramData\Malwarebytes 
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 
2014-07-03 20:00 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 
2014-07-03 20:00 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 
2014-07-03 20:00 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 
2014-07-03 19:59 - 2014-07-03 19:59 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Natalie\Desktop\mbam-setup-2.0.2.1012.exe 
2014-07-03 18:49 - 2014-07-03 18:49 - 00005046 _____ () C:\Users\Natalie\Desktop\avg scan.csv 
2014-07-03 17:55 - 2014-07-03 17:55 - 00021562 _____ () C:\Users\Natalie\Addition.txt 
2014-07-03 17:54 - 2014-07-03 17:55 - 00090228 _____ () C:\Users\Natalie\FRST.txt 
2014-07-03 17:53 - 2014-07-04 16:26 - 00000000 ____D () C:\FRST 
2014-07-03 17:52 - 2014-07-03 17:52 - 00000476 _____ () C:\Users\Natalie\Desktop\defogger_disable.log 
2014-07-03 17:52 - 2014-07-03 17:52 - 00000000 _____ () C:\Users\Natalie\defogger_reenable 
2014-07-03 17:50 - 2014-07-03 17:50 - 01073664 _____ (Farbar) C:\Users\Natalie\Desktop\FRST.exe 
2014-07-03 17:50 - 2014-07-03 17:50 - 00380416 _____ () C:\Users\Natalie\Desktop\v87lo16c.exe 
2014-07-03 17:48 - 2014-07-03 17:48 - 00050477 _____ () C:\Users\Natalie\Desktop\Defogger.exe 
2014-07-02 22:03 - 2014-07-02 22:03 - 00000967 _____ () C:\Users\Public\Desktop\AVG 2014.lnk 
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\TuneUp Software 
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\AVG2014 
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 
2014-07-02 22:02 - 2014-07-02 22:23 - 00000000 ____D () C:\ProgramData\AVG2014 
2014-07-02 22:02 - 2014-07-02 22:02 - 00000000 ___HD () C:\$AVG 
2014-07-02 22:01 - 2014-07-02 22:01 - 00000000 ____D () C:\Program Files\AVG 
2014-07-02 21:57 - 2014-07-04 16:21 - 00000000 ____D () C:\ProgramData\MFAData 
2014-07-02 21:57 - 2014-07-02 22:07 - 00000000 ____D () C:\Users\Natalie\AppData\Local\Avg2014 
2014-07-02 21:57 - 2014-07-02 21:57 - 00000000 ____D () C:\Users\Natalie\AppData\Local\MFAData 
2014-07-02 21:29 - 2014-07-02 21:30 - 00000000 ___HD () C:\Users\Natalie\AppData\Local\Ebakhwicoj 
2014-06-24 19:58 - 2014-06-24 19:59 - 00000000 ____D () C:\Program Files\Mozilla Firefox 
2014-06-24 15:11 - 2014-06-24 15:11 - 00000000 ___RD () C:\WINDOWS\BrowserChoice 
2014-06-17 20:17 - 2014-06-17 20:17 - 00000000 ____D () C:\Users\Natalie\Desktop\Programme 
2014-06-17 19:59 - 2014-05-19 07:33 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvcfg.exe 
2014-06-17 19:59 - 2014-05-19 07:23 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe 
2014-06-17 16:22 - 2014-06-17 16:22 - 00188696 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgldx86.sys 
2014-06-17 16:18 - 2014-06-17 16:18 - 00241944 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avglogx.sys 
2014-06-17 16:17 - 2014-06-17 16:17 - 00147736 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidshx.sys 
2014-06-17 16:06 - 2014-06-17 16:06 - 00199960 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdriverx.sys 
2014-06-17 16:06 - 2014-06-17 16:06 - 00121624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgdiskx.sys 
2014-06-17 16:06 - 2014-06-17 16:06 - 00098584 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx86.sys 
2014-06-17 16:06 - 2014-06-17 16:06 - 00027416 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgrkx86.sys 
2014-06-17 16:05 - 2014-06-17 16:05 - 00021272 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsshimw8x.sys 
2014-06-16 12:46 - 2014-06-16 12:37 - 00000000 ___DC () C:\WINDOWS\Panther 
2014-06-16 12:44 - 2014-06-16 12:44 - 17271296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 11725312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 04244992 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 
2014-06-16 12:44 - 2014-06-16 12:44 - 01790976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 01143296 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 
2014-06-16 12:44 - 2014-06-16 12:44 - 00592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe 
2014-06-16 12:44 - 2014-06-16 12:44 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe 
2014-06-16 12:44 - 2014-06-16 12:44 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll 
2014-06-16 12:43 - 2014-06-16 12:43 - 01871704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 
2014-06-16 12:43 - 2014-06-16 12:43 - 01090296 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 
2014-06-16 12:43 - 2014-06-16 12:43 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 
2014-06-16 12:43 - 2014-06-16 12:43 - 00286040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 
2014-06-16 12:43 - 2014-06-16 12:43 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 
2014-06-16 12:43 - 2014-06-16 12:43 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe 
2014-06-16 12:42 - 2014-07-04 16:25 - 00000000 __RDO () C:\Users\Natalie\OneDrive 
2014-06-16 12:42 - 2014-06-16 12:42 - 02826240 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 
2014-06-16 12:42 - 2014-06-16 12:42 - 01312256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll 
2014-06-16 12:42 - 2014-06-16 12:42 - 00219992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys 
2014-06-16 12:42 - 2014-06-16 12:42 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 
2014-06-16 12:42 - 2014-06-16 12:42 - 00092504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys 
2014-06-16 12:42 - 2014-06-16 12:42 - 00030224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 02270208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 02088160 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 
2014-06-16 12:41 - 2014-06-16 12:41 - 02030080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01779800 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01679704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 01679128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01351168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01326936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01095488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01037504 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00887296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00863552 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00731648 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 
2014-06-16 12:41 - 2014-06-16 12:41 - 00731648 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 
2014-06-16 12:41 - 2014-06-16 12:41 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00491008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe 
2014-06-16 12:41 - 2014-06-16 12:41 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdmTmpl.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00406912 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00390488 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00387210 _____ () C:\WINDOWS\system32\ApnDatabase.xml 
2014-06-16 12:41 - 2014-06-16 12:41 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlangpui.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00376152 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 
2014-06-16 12:41 - 2014-06-16 12:41 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00355832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00321880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe 
2014-06-16 12:41 - 2014-06-16 12:41 - 00283992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL 
2014-06-16 12:41 - 2014-06-16 12:41 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDScDrv.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\spp.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00138584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpnpmgr.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevPropMgr.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00094016 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00092160 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32tm.exe 
2014-06-16 12:41 - 2014-06-16 12:41 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\IPMIDrv.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\l2gpstore.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpipreg.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SetNetworkLocation.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxproxy.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00020992 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys 
2014-06-16 12:39 - 2014-06-16 12:39 - 02818048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 
2014-06-16 12:39 - 2014-06-16 12:39 - 02366976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 02257608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 
2014-06-16 12:39 - 2014-06-16 12:39 - 02045440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 01634304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00419928 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00049544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 
2014-06-16 12:39 - 2014-06-16 12:39 - 00046512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys 
2014-06-16 12:39 - 2014-06-16 12:39 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe 
2014-06-16 12:39 - 2014-06-16 12:39 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 18755672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 12711424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 05833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 05786968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 05774848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 05104640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 03563008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 03497472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 02144984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 02130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01309184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01210368 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01209616 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01200288 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01167360 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01159520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01089536 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01029120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00834560 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00707048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00672256 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00669856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00629760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00518544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00482416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00406504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00387896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 
2014-06-16 12:38 - 2014-06-16 12:38 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00333656 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00328984 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00311128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00305768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00294744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00285144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00271192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00264704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00264536 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00240472 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00230808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00229344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00194752 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00178184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00147800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00111528 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00098584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00080032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt_map.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00069632 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\srclient.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\tlscsp.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00026784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt100.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll 
2014-06-16 12:36 - 2014-06-16 12:36 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff 
2014-06-16 12:34 - 2014-06-16 12:34 - 00001446 _____ () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 
2014-06-16 12:34 - 2014-06-16 12:34 - 00000020 ___SH () C:\Users\Natalie\ntuser.ini 
2014-06-16 12:34 - 2014-06-16 12:34 - 00000000 ____D () C:\WINDOWS\system32\XPSViewer 
2014-06-16 12:34 - 2014-06-16 12:34 - 00000000 ____D () C:\Program Files\Reference Assemblies 
2014-06-16 12:34 - 2014-06-16 12:08 - 00000000 ____D () C:\Program Files\MSBuild 
2014-06-16 12:34 - 2013-08-03 06:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 
2014-06-16 12:34 - 2013-08-03 06:41 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 
2014-06-16 12:34 - 2013-08-03 06:41 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 
2014-06-16 12:33 - 2014-06-16 11:53 - 00000000 ____D () C:\Recovery 
2014-06-16 12:18 - 2014-07-04 16:23 - 01099055 _____ () C:\WINDOWS\WindowsUpdate.log 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Startmenü 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 
2014-06-16 12:17 - 2014-06-16 12:17 - 00021532 _____ () C:\WINDOWS\system32\emptyregdb.dat 
2014-06-16 12:06 - 2014-06-16 12:06 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 
2014-06-16 12:01 - 2014-06-16 12:08 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate 
2014-06-16 11:59 - 2014-07-04 16:22 - 00000000 ____D () C:\Users\Natalie 
2014-06-16 11:59 - 2014-06-16 12:17 - 00038103 _____ () C:\WINDOWS\diagwrn.xml 
2014-06-16 11:59 - 2014-06-16 12:17 - 00038103 _____ () C:\WINDOWS\diagerr.xml 
2014-06-16 11:59 - 2014-06-16 12:12 - 00000000 ____D () C:\Users\Gast 
2014-06-16 11:59 - 2014-06-16 12:01 - 00000000 ___RD () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 
2014-06-16 11:59 - 2014-06-16 12:01 - 00000000 ___RD () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 
2014-06-16 11:59 - 2014-06-16 12:00 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 
2014-06-16 11:59 - 2014-06-16 12:00 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Startmenü 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Netzwerkumgebung 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Druckumgebung 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Documents\Eigene Musik 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Documents\Eigene Bilder 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\AppData\Local\Verlauf 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Startmenü 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Netzwerkumgebung 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Druckumgebung 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Musik 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Bilder 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Verlauf 
2014-06-16 11:59 - 2014-03-18 10:08 - 00000369 _____ () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk 
2014-06-16 11:59 - 2014-03-18 10:08 - 00000369 _____ () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk 
2014-06-16 11:59 - 2014-03-18 10:08 - 00000369 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk 
2014-06-16 11:59 - 2014-03-18 10:08 - 00000369 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk 
2014-06-16 11:59 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 
2014-06-16 11:59 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 
2014-06-16 11:59 - 2013-08-22 10:17 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 
2014-06-16 11:59 - 2013-08-22 10:17 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01000.Wdf 
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 _____ () C:\WINDOWS\system32\atiicdxx.dat 
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 _____ () C:\WINDOWS\ativpsrm.bin 
2014-06-16 11:48 - 2014-06-16 11:48 - 00000000 ____D () C:\Program Files\Synaptics 
2014-06-16 11:13 - 2014-06-16 12:17 - 00006700 _____ () C:\WINDOWS\comsetup.log 
2014-06-08 15:43 - 2014-06-08 15:43 - 00001943 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk 
2014-06-08 15:43 - 2014-06-08 15:43 - 00001932 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk 
2014-06-08 15:43 - 2014-06-08 15:43 - 00001866 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk 
2014-06-08 15:42 - 2014-06-08 15:58 - 00000000 ____D () C:\Program Files\JDownloader 
2014-06-08 15:41 - 2014-06-08 15:41 - 00076456 _____ (AppWork GmbH) C:\Users\Natalie\Downloads\WebInstaller.exe   
==================== One Month Modified Files and Folders =======   
2014-07-04 16:27 - 2014-07-04 16:26 - 00010285 _____ () C:\Users\Natalie\Desktop\FRST.txt 
2014-07-04 16:26 - 2014-07-03 17:53 - 00000000 ____D () C:\FRST 
2014-07-04 16:25 - 2014-06-16 12:42 - 00000000 __RDO () C:\Users\Natalie\OneDrive 
2014-07-04 16:25 - 2013-08-22 09:23 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 
2014-07-04 16:24 - 2014-03-18 01:54 - 00002512 _____ () C:\WINDOWS\PFRO.log 
2014-07-04 16:23 - 2014-06-16 12:18 - 01099055 _____ () C:\WINDOWS\WindowsUpdate.log 
2014-07-04 16:23 - 2013-08-22 08:13 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI 
2014-07-04 16:23 - 2012-12-02 12:05 - 00000000 ___RD () C:\Users\Natalie\Dropbox 
2014-07-04 16:22 - 2014-06-16 11:59 - 00000000 ____D () C:\Users\Natalie 
2014-07-04 16:21 - 2014-07-02 21:57 - 00000000 ____D () C:\ProgramData\MFAData 
2014-07-04 00:24 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\sru 
2014-07-03 20:20 - 2014-07-03 20:20 - 00002085 _____ () C:\Users\Natalie\Desktop\mbam.txt 
2014-07-03 20:19 - 2014-07-03 20:01 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 
2014-07-03 20:17 - 2014-02-09 13:20 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\DropboxMaster 
2014-07-03 20:17 - 2012-12-02 11:47 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Dropbox 
2014-07-03 20:15 - 2012-07-26 08:53 - 00000000 ____D () C:\WINDOWS\LiveKernelReports 
2014-07-03 20:00 - 2014-07-03 20:00 - 00001068 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\ProgramData\Malwarebytes 
2014-07-03 20:00 - 2014-07-03 20:00 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 
2014-07-03 19:59 - 2014-07-03 19:59 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Natalie\Desktop\mbam-setup-2.0.2.1012.exe 
2014-07-03 18:49 - 2014-07-03 18:49 - 00005046 _____ () C:\Users\Natalie\Desktop\avg scan.csv 
2014-07-03 18:25 - 2012-12-02 11:45 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 
2014-07-03 17:55 - 2014-07-03 17:55 - 00021562 _____ () C:\Users\Natalie\Addition.txt 
2014-07-03 17:55 - 2014-07-03 17:54 - 00090228 _____ () C:\Users\Natalie\FRST.txt 
2014-07-03 17:52 - 2014-07-03 17:52 - 00000476 _____ () C:\Users\Natalie\Desktop\defogger_disable.log 
2014-07-03 17:52 - 2014-07-03 17:52 - 00000000 _____ () C:\Users\Natalie\defogger_reenable 
2014-07-03 17:50 - 2014-07-03 17:50 - 01073664 _____ (Farbar) C:\Users\Natalie\Desktop\FRST.exe 
2014-07-03 17:50 - 2014-07-03 17:50 - 00380416 _____ () C:\Users\Natalie\Desktop\v87lo16c.exe 
2014-07-03 17:48 - 2014-07-03 17:48 - 00050477 _____ () C:\Users\Natalie\Desktop\Defogger.exe 
2014-07-03 00:08 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\Microsoft.NET 
2014-07-02 23:32 - 2012-12-02 11:44 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 
2014-07-02 22:23 - 2014-07-02 22:02 - 00000000 ____D () C:\ProgramData\AVG2014 
2014-07-02 22:07 - 2014-07-02 21:57 - 00000000 ____D () C:\Users\Natalie\AppData\Local\Avg2014 
2014-07-02 22:07 - 2013-08-22 08:13 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 
2014-07-02 22:03 - 2014-07-02 22:03 - 00000967 _____ () C:\Users\Public\Desktop\AVG 2014.lnk 
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\TuneUp Software 
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\AVG2014 
2014-07-02 22:03 - 2014-07-02 22:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 
2014-07-02 22:03 - 2012-07-26 08:53 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP 
2014-07-02 22:02 - 2014-07-02 22:02 - 00000000 ___HD () C:\$AVG 
2014-07-02 22:01 - 2014-07-02 22:01 - 00000000 ____D () C:\Program Files\AVG 
2014-07-02 21:57 - 2014-07-02 21:57 - 00000000 ____D () C:\Users\Natalie\AppData\Local\MFAData 
2014-07-02 21:30 - 2014-07-02 21:29 - 00000000 ___HD () C:\Users\Natalie\AppData\Local\Ebakhwicoj 
2014-06-29 12:55 - 2014-03-18 10:04 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 
2014-06-29 12:53 - 2013-08-22 09:23 - 00331768 _____ () C:\WINDOWS\setupact.log 
2014-06-25 18:23 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\AppReadiness 
2014-06-24 19:59 - 2014-06-24 19:58 - 00000000 ____D () C:\Program Files\Mozilla Firefox 
2014-06-24 15:40 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\rescache 
2014-06-24 15:12 - 2012-07-26 08:43 - 00000000 ____D () C:\WINDOWS\CbsTemp 
2014-06-24 15:11 - 2014-06-24 15:11 - 00000000 ___RD () C:\WINDOWS\BrowserChoice 
2014-06-17 20:17 - 2014-06-17 20:17 - 00000000 ____D () C:\Users\Natalie\Desktop\Programme 
2014-06-17 19:48 - 2013-10-17 20:12 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Samsung 
2014-06-17 19:48 - 2012-12-02 12:12 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 
2014-06-17 19:48 - 2012-12-02 12:11 - 00000000 ____D () C:\ProgramData\Samsung 
2014-06-17 19:48 - 2012-12-02 12:11 - 00000000 ____D () C:\Program Files\Samsung 
2014-06-17 16:22 - 2014-06-17 16:22 - 00188696 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgldx86.sys 
2014-06-17 16:18 - 2014-06-17 16:18 - 00241944 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avglogx.sys 
2014-06-17 16:17 - 2014-06-17 16:17 - 00147736 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidshx.sys 
2014-06-17 16:06 - 2014-06-17 16:06 - 00199960 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdriverx.sys 
2014-06-17 16:06 - 2014-06-17 16:06 - 00121624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgdiskx.sys 
2014-06-17 16:06 - 2014-06-17 16:06 - 00098584 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx86.sys 
2014-06-17 16:06 - 2014-06-17 16:06 - 00027416 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgrkx86.sys 
2014-06-17 16:05 - 2014-06-17 16:05 - 00021272 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsshimw8x.sys 
2014-06-16 12:53 - 2012-12-02 11:17 - 00000000 ____D () C:\WINDOWS\system32\appmgmt 
2014-06-16 12:52 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\restore 
2014-06-16 12:44 - 2014-06-16 12:44 - 17271296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 11725312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 04244992 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 
2014-06-16 12:44 - 2014-06-16 12:44 - 01790976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 01143296 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 
2014-06-16 12:44 - 2014-06-16 12:44 - 00592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe 
2014-06-16 12:44 - 2014-06-16 12:44 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe 
2014-06-16 12:44 - 2014-06-16 12:44 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll 
2014-06-16 12:44 - 2014-06-16 12:44 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll 
2014-06-16 12:44 - 2013-08-22 10:17 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template 
2014-06-16 12:43 - 2014-06-16 12:43 - 01871704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 
2014-06-16 12:43 - 2014-06-16 12:43 - 01090296 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 
2014-06-16 12:43 - 2014-06-16 12:43 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 
2014-06-16 12:43 - 2014-06-16 12:43 - 00286040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 
2014-06-16 12:43 - 2014-06-16 12:43 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 
2014-06-16 12:43 - 2014-06-16 12:43 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe 
2014-06-16 12:43 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\WinStore 
2014-06-16 12:42 - 2014-06-16 12:42 - 02826240 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 
2014-06-16 12:42 - 2014-06-16 12:42 - 01312256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll 
2014-06-16 12:42 - 2014-06-16 12:42 - 00219992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys 
2014-06-16 12:42 - 2014-06-16 12:42 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 
2014-06-16 12:42 - 2014-06-16 12:42 - 00092504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys 
2014-06-16 12:42 - 2014-06-16 12:42 - 00030224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys 
2014-06-16 12:42 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 
2014-06-16 12:42 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 
2014-06-16 12:42 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Windows Defender 
2014-06-16 12:41 - 2014-06-16 12:41 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 02270208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 02088160 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 
2014-06-16 12:41 - 2014-06-16 12:41 - 02030080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01779800 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01679704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 01679128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01351168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01326936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01095488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 01037504 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00887296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00863552 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00731648 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 
2014-06-16 12:41 - 2014-06-16 12:41 - 00731648 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 
2014-06-16 12:41 - 2014-06-16 12:41 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00491008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe 
2014-06-16 12:41 - 2014-06-16 12:41 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdmTmpl.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00406912 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00390488 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00387210 _____ () C:\WINDOWS\system32\ApnDatabase.xml 
2014-06-16 12:41 - 2014-06-16 12:41 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlangpui.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00376152 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 
2014-06-16 12:41 - 2014-06-16 12:41 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00355832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00321880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe 
2014-06-16 12:41 - 2014-06-16 12:41 - 00283992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL 
2014-06-16 12:41 - 2014-06-16 12:41 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDScDrv.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\spp.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00138584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpnpmgr.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevPropMgr.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00094016 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00092160 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32tm.exe 
2014-06-16 12:41 - 2014-06-16 12:41 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\IPMIDrv.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\l2gpstore.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpipreg.sys 
2014-06-16 12:41 - 2014-06-16 12:41 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SetNetworkLocation.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxproxy.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll 
2014-06-16 12:41 - 2014-06-16 12:41 - 00020992 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys 
2014-06-16 12:39 - 2014-06-16 12:39 - 02818048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 
2014-06-16 12:39 - 2014-06-16 12:39 - 02366976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 02257608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 
2014-06-16 12:39 - 2014-06-16 12:39 - 02045440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 01634304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00419928 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 
2014-06-16 12:39 - 2014-06-16 12:39 - 00049544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 
2014-06-16 12:39 - 2014-06-16 12:39 - 00046512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys 
2014-06-16 12:39 - 2014-06-16 12:39 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe 
2014-06-16 12:39 - 2014-06-16 12:39 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 
2014-06-16 12:39 - 2013-08-22 10:17 - 00000000 ___RD () C:\WINDOWS\ToastData 
2014-06-16 12:39 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\SecureBootUpdates 
2014-06-16 12:38 - 2014-06-16 12:38 - 18755672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 12711424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 05833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 05786968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 05774848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 05104640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 03563008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 03497472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 02144984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 02130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01309184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01210368 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01209616 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01200288 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01167360 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01159520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01089536 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 01029120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00834560 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00707048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00672256 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00669856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00629760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00518544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00482416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00406504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00387896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 
2014-06-16 12:38 - 2014-06-16 12:38 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00333656 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00328984 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00311128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00305768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00294744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00285144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00271192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00264704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00264536 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00240472 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00230808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00229344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00194752 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 
2014-06-16 12:38 - 2014-06-16 12:38 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00178184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00147800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00111528 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00098584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00080032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt_map.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00069632 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys 
2014-06-16 12:38 - 2014-06-16 12:38 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\srclient.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\tlscsp.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00026784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt100.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll 
2014-06-16 12:38 - 2014-06-16 12:38 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll 
2014-06-16 12:38 - 2014-03-18 09:30 - 00000000 ____D () C:\WINDOWS\system32\Drivers\de-DE 
2014-06-16 12:38 - 2013-08-22 10:17 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel 
2014-06-16 12:37 - 2014-06-16 12:46 - 00000000 ___DC () C:\WINDOWS\Panther 
2014-06-16 12:36 - 2014-06-16 12:36 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff 
2014-06-16 12:34 - 2014-06-16 12:34 - 00001446 _____ () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 
2014-06-16 12:34 - 2014-06-16 12:34 - 00000020 ___SH () C:\Users\Natalie\ntuser.ini 
2014-06-16 12:34 - 2014-06-16 12:34 - 00000000 ____D () C:\WINDOWS\system32\XPSViewer 
2014-06-16 12:34 - 2014-06-16 12:34 - 00000000 ____D () C:\Program Files\Reference Assemblies 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Startmenü 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 
2014-06-16 12:18 - 2014-06-16 12:18 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 
2014-06-16 12:18 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Windows NT 
2014-06-16 12:18 - 2013-08-22 08:21 - 00000000 __RHD () C:\Users\Default 
2014-06-16 12:17 - 2014-06-16 12:17 - 00021532 _____ () C:\WINDOWS\system32\emptyregdb.dat 
2014-06-16 12:17 - 2014-06-16 11:59 - 00038103 _____ () C:\WINDOWS\diagwrn.xml 
2014-06-16 12:17 - 2014-06-16 11:59 - 00038103 _____ () C:\WINDOWS\diagerr.xml 
2014-06-16 12:17 - 2014-06-16 11:13 - 00006700 _____ () C:\WINDOWS\comsetup.log 
2014-06-16 12:17 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\LogFiles 
2014-06-16 12:17 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\Registration 
2014-06-16 12:15 - 2013-08-22 10:17 - 00000000 __RSD () C:\WINDOWS\Media 
2014-06-16 12:15 - 2013-08-22 10:17 - 00000000 __RHD () C:\Users\Public\Libraries 
2014-06-16 12:15 - 2013-08-22 08:21 - 00000000 ___RD () C:\Users\Public 
2014-06-16 12:12 - 2014-06-16 11:59 - 00000000 ____D () C:\Users\Gast 
2014-06-16 12:10 - 2013-08-22 09:22 - 00477584 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 
2014-06-16 12:08 - 2014-06-16 12:34 - 00000000 ____D () C:\Program Files\MSBuild 
2014-06-16 12:08 - 2014-06-16 12:01 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate 
2014-06-16 12:08 - 2014-03-18 09:45 - 00000000 ____D () C:\WINDOWS\ShellNew 
2014-06-16 12:08 - 2014-01-18 10:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 
2014-06-16 12:08 - 2014-01-17 08:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 
2014-06-16 12:08 - 2013-10-10 22:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 
2014-06-16 12:08 - 2013-08-29 19:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Müller Foto 
2014-06-16 12:08 - 2013-07-24 20:06 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Suite 
2014-06-16 12:08 - 2012-12-02 11:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 
2014-06-16 12:08 - 2012-12-02 11:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 
2014-06-16 12:08 - 2012-12-02 11:48 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 
2014-06-16 12:08 - 2012-12-02 11:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 
2014-06-16 12:08 - 2012-12-02 11:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack 
2014-06-16 12:08 - 2012-12-02 11:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator 
2014-06-16 12:08 - 2012-12-02 11:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ 
2014-06-16 12:08 - 2012-12-02 11:45 - 00000000 ____D () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 
2014-06-16 12:08 - 2012-12-02 11:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 
2014-06-16 12:08 - 2012-12-02 11:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 
2014-06-16 12:08 - 2012-12-02 11:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView 
2014-06-16 12:08 - 2012-12-02 11:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quadsoft NoTilesPlease 
2014-06-16 12:07 - 2013-08-22 10:18 - 00004893 _____ () C:\WINDOWS\DtcInstall.log 
2014-06-16 12:07 - 2012-07-26 06:43 - 00000000 ____D () C:\Users\Default.migrated 
2014-06-16 12:06 - 2014-06-16 12:06 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 
2014-06-16 12:06 - 2014-03-18 09:30 - 00000000 ____D () C:\WINDOWS\system32\WCN 
2014-06-16 12:06 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\WinBioPlugIns 
2014-06-16 12:06 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\spool 
2014-06-16 12:06 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\MUI 
2014-06-16 12:06 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\IME 
2014-06-16 12:06 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\de-DE 
2014-06-16 12:05 - 2013-08-22 10:17 - 00000000 __SHD () C:\Program Files\Windows Sidebar 
2014-06-16 12:05 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\Help 
2014-06-16 12:05 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Microsoft.NET 
2014-06-16 12:05 - 2012-12-02 12:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 
2014-06-16 12:05 - 2012-12-01 23:12 - 00000000 ____D () C:\ProgramData\PRICache 
2014-06-16 12:04 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Common Files\System 
2014-06-16 12:04 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 
2014-06-16 12:01 - 2014-06-16 11:59 - 00000000 ___RD () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 
2014-06-16 12:01 - 2014-06-16 11:59 - 00000000 ___RD () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 
2014-06-16 12:01 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\Recovery 
2014-06-16 12:00 - 2014-06-16 11:59 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 
2014-06-16 12:00 - 2014-06-16 11:59 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Startmenü 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Netzwerkumgebung 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Druckumgebung 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Documents\Eigene Musik 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\Documents\Eigene Bilder 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Natalie\AppData\Local\Verlauf 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Startmenü 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Netzwerkumgebung 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Druckumgebung 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Musik 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\Documents\Eigene Bilder 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 
2014-06-16 11:59 - 2014-06-16 11:59 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Verlauf 
2014-06-16 11:53 - 2014-06-16 12:33 - 00000000 ____D () C:\Recovery 
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01000.Wdf 
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 _____ () C:\WINDOWS\system32\atiicdxx.dat 
2014-06-16 11:49 - 2014-06-16 11:49 - 00000000 _____ () C:\WINDOWS\ativpsrm.bin 
2014-06-16 11:48 - 2014-06-16 11:48 - 00000000 ____D () C:\Program Files\Synaptics 
2014-06-16 11:21 - 2012-12-01 23:03 - 01269679 _____ () C:\WINDOWS\WindowsUpdate (1).log 
2014-06-16 11:19 - 2009-03-05 19:21 - 00008192 __RSH () C:\BOOTSECT.BAK 
2014-06-16 10:49 - 2012-07-26 08:53 - 00000000 ____D () C:\WINDOWS\AUInstallAgent 
2014-06-16 06:31 - 2013-08-19 20:55 - 00000000 ____D () C:\WINDOWS\system32\MRT 
2014-06-16 06:29 - 2012-12-13 21:03 - 92708840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 
2014-06-08 21:27 - 2012-12-12 21:01 - 02784768 ___SH () C:\Users\Natalie\Desktop\Thumbs.db 
2014-06-08 15:58 - 2014-06-08 15:42 - 00000000 ____D () C:\Program Files\JDownloader 
2014-06-08 15:43 - 2014-06-08 15:43 - 00001943 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk 
2014-06-08 15:43 - 2014-06-08 15:43 - 00001932 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk 
2014-06-08 15:43 - 2014-06-08 15:43 - 00001866 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk 
2014-06-08 15:41 - 2014-06-08 15:41 - 00076456 _____ (AppWork GmbH) C:\Users\Natalie\Downloads\WebInstaller.exe   
Files to move or delete: 
==================== 
C:\Users\Natalie\netscan.exe     
Some content of TEMP: 
==================== 
C:\Users\Natalie\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpydtue8.dll     
==================== Bamital & volsnap Check =================   
C:\WINDOWS\explorer.exe => File is digitally signed 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed 
C:\WINDOWS\system32\wininit.exe => File is digitally signed 
C:\WINDOWS\system32\svchost.exe => File is digitally signed 
C:\WINDOWS\system32\services.exe => File is digitally signed 
C:\WINDOWS\system32\User32.dll => File is digitally signed 
C:\WINDOWS\system32\userinit.exe => File is digitally signed 
C:\WINDOWS\system32\rpcss.dll => File is digitally signed 
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed     
LastRegBack: 2014-07-03 19:57   
==================== End Of Log ============================   --- --- ---  
--- --- ---  
--- --- ---   
Addition   Code:  
 Additional scan result of Farbar Recovery Scan Tool (x86) Version:01-07-2014 
Ran by Natalie at 2014-07-04 16:28:34 
Running from C:\Users\Natalie\Desktop 
Boot Mode: Normal 
==========================================================     
==================== Security Center ========================   
AV: AVG AntiVirus 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
AS: AVG AntiVirus 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}   
==================== Installed Programs ======================   
2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft) 
2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM\...\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft) 
2007 Microsoft Office Suite Service Pack 3 (SP3) (Version:  - Microsoft) Hidden 
Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) 
Adobe Reader XI - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated) 
Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) 
Apple Mobile Device Support (HKLM\...\{0592EF96-69D8-4E4B-9CC9-88F58EA86F01}) (Version: 7.0.0.117 - Apple Inc.) 
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) 
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4716 - AVG Technologies) 
AVG 2014 (Version: 14.0.3986 - AVG Technologies) Hidden 
AVG 2014 (Version: 14.0.4716 - AVG Technologies) Hidden 
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) 
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.3868 - CDBurnerXP) 
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.) 
EPSON SX235 Series Printer Uninstall (HKLM\...\EPSON SX235 Series) (Version:  - SEIKO EPSON Corporation) 
Google Earth (HKLM\...\{3E8A20E1-223F-11E2-9116-B8AC6F98CCE3}) (Version: 7.0.1.8244 - Google) 
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.35 - Irfan Skiljan) 
iTunes (HKLM\...\{E05D82D8-FE70-4228-B073-B0C07FE27595}) (Version: 11.1.1.11 - Apple Inc.) 
Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) 
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden 
JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) 
K-Lite Codec Pack 9.5.5 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 9.5.5 - ) 
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) 
Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x86__8wekyb3d8bbwe (x86) (Version: 1.0.0.0 - Microsoft Corporation) Hidden 
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) 
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Professional 2007 (HKLM\...\PROR) (Version: 12.0.6612.1000 - Microsoft Corporation) 
Microsoft Office Professional 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden 
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden 
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.10411.0 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) 
Mozilla Firefox 30.0 (x86 de) (HKLM\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla) 
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) 
Müller Foto (HKLM\...\Müller Foto) (Version: 5.0.4 - CEWE COLOR AG u Co. OHG) 
Notepad++ (HKLM\...\Notepad++) (Version: 6.2.2 - ) 
NoTilesPlease Version 1.0.4.3 (HKLM\...\{DCBDAEAB-6AE9-42CC-92A6-9E2E31792FD4}_is1) (Version: 1.0.4.3 - Quadsoft) 
Nur Entfernen der CopyTrans Suite möglich (HKCU\...\CopyTrans Suite) (Version: 2.37 - WindSolutions) 
Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41417}) (Version: 3.61.0 - dotPDN LLC) 
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.6.0 - Frank Heindörfer, Philip Chinery) 
Skype™ 6.0 (HKLM\...\{1845470B-EB14-4ABC-835B-E36C693DC07D}) (Version: 6.0.126 - Skype Technologies S.A.) 
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 9.1.13.0 - Synaptics) 
TeamViewer 7 (HKLM\...\TeamViewer 7) (Version: 7.0.15723 - TeamViewer) 
VAIO Energie Verwaltung (HKLM\...\{5F5867F0-2D23-4338-A206-01A76C823924}) (Version: 3.3.0.12190 - Sony Corporation) 
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) 
VLC media player 2.0.4 (HKLM\...\VLC media player) (Version: 2.0.4 - VideoLAN) 
WinRAR 4.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)   
==================== Restore Points  =========================   
17-06-2014 17:46:20 Removed Samsung Kies 
24-06-2014 13:08:24 Windows Update 
24-06-2014 13:09:59 Windows Modules Installer 
02-07-2014 20:00:33 Installed AVG 2014 
02-07-2014 20:01:32 Installed AVG 2014   
==================== Hosts content: ==========================   
2013-08-22 08:13 - 2013-08-22 08:13 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts   
==================== Scheduled Tasks (whitelisted) =============   
Task: {00BC77BF-3352-4FE8-9617-4F1B27BEC19A} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup 
Task: {01BCC00A-C6A8-474C-BA2D-3076F3CE544D} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\WINDOWS\system32\cleanmgr.exe [2014-03-18] (Microsoft Corporation) 
Task: {02B97B27-29F3-4F0D-B9D9-1A218C58AD6F} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics 
Task: {03F00483-DFF0-469F-88A0-E7C9E3D9F4A7} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation 
Task: {17233BE9-87E9-40B0-B003-AE9D2B92CBBE} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask 
Task: {247BD142-0549-4E91-84B0-172C25563718} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) 
Task: {2BE65564-89D1-4396-A5CC-D7D9283FC4A1} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task 
Task: {392EB017-207C-42BF-A061-F3BE721F456C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState 
Task: {4B7EF56A-8A42-4BD2-BB5C-7C389AC54A37} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask 
Task: {5700ACE8-D0AF-4BA7-98B6-1033521A877A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask 
Task: {6E84A59B-1863-4B21-8BD8-C9B20FD15484} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask 
Task: {7276DEEA-6ED2-4091-AF19-079E9B8C56C7} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management 
Task: {7C7CF1DA-F461-4850-96B2-ADCA8A67E59C} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing 
Task: {8B5819AE-7B44-478B-A3D3-8846AF160A8F} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate 
Task: {92ED6570-4654-4BFA-9A6C-1084C6939C16} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work 
Task: {997C8BBD-710B-4E66-B5BC-CC09575A58D2} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance 
Task: {9CEE4DCC-1FE8-4B69-A843-9B17C48332AE} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-06-16] (Microsoft Corporation) 
Task: {A5D45ED3-F524-4574-8F39-527F3729D1E2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\WINDOWS\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) 
Task: {A8734EF2-F2EB-418C-83A5-1F82BE3C83B8} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated) 
Task: {BFA82644-4CCF-4E7B-AFB6-10A75D2E3720} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload 
Task: {C0D0F7C4-419F-41B3-90A2-FE79270B828A} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask 
Task: {CF5A1DDC-D14D-4D59-AD49-A19A645B087B} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization 
Task: {DCF55BED-B1DF-4ABF-8D85-6542C7007799} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE 
Task: {E4C8774A-2818-45A4-8A6D-11DDF6348886} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task 
Task: {F3B2EE7D-84A7-4DB4-ADBF-AFF5946E84A3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) 
Task: {F89ED03A-029C-4D8E-9B6D-868369BA6354} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv 
Task: {FAB49829-3EE7-4234-BE84-277862F2A57C} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe   
==================== Loaded Modules (whitelisted) =============   
2013-09-13 19:51 - 2013-09-13 19:51 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 
2013-09-13 19:51 - 2013-09-13 19:51 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 
2014-07-04 16:26 - 2014-07-04 16:26 - 00043008 _____ () c:\users\natalie\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpydtue8.dll 
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Natalie\AppData\Roaming\Dropbox\bin\libcef.dll   
==================== Alternate Data Streams (whitelisted) =========   
AlternateDataStreams: C:\Users\Natalie\OneDrive:ms-properties   
==================== Safe Mode (whitelisted) ===================     
==================== EXE Association (whitelisted) =============     
==================== MSCONFIG/TASK MANAGER disabled items =========   
HKCU\...\StartupApproved\Run: => "Pokki"   
==================== Faulty Device Manager Devices =============   
Name: Basissystemgerät 
Description: Basissystemgerät 
Class Guid:  
Manufacturer:  
Service:  
Problem: : The drivers for this device are not installed. (Code 28) 
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.   
Name:  
Description:  
Class Guid:  
Manufacturer:  
Service:  
Problem: : The drivers for this device are not installed. (Code 28) 
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.     
==================== Event log errors: =========================   
Application errors: 
================== 
Error: (07/03/2014 06:18:12 PM) (Source: Application Error) (EventID: 1000) (User: ) 
Description: Name der fehlerhaften Anwendung: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83 
Name des fehlerhaften Moduls: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83 
Ausnahmecode: 0xc0000005 
Fehleroffset: 0x00012298 
ID des fehlerhaften Prozesses: 0x7e4 
Startzeit der fehlerhaften Anwendung: 0xv87lo16c.exe0 
Pfad der fehlerhaften Anwendung: v87lo16c.exe1 
Pfad des fehlerhaften Moduls: v87lo16c.exe2 
Berichtskennung: v87lo16c.exe3 
Vollständiger Name des fehlerhaften Pakets: v87lo16c.exe4 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: v87lo16c.exe5   
Error: (07/03/2014 06:06:03 PM) (Source: Application Error) (EventID: 1000) (User: ) 
Description: Name der fehlerhaften Anwendung: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83 
Name des fehlerhaften Moduls: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83 
Ausnahmecode: 0xc0000005 
Fehleroffset: 0x00012298 
ID des fehlerhaften Prozesses: 0xebc 
Startzeit der fehlerhaften Anwendung: 0xv87lo16c.exe0 
Pfad der fehlerhaften Anwendung: v87lo16c.exe1 
Pfad des fehlerhaften Moduls: v87lo16c.exe2 
Berichtskennung: v87lo16c.exe3 
Vollständiger Name des fehlerhaften Pakets: v87lo16c.exe4 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: v87lo16c.exe5   
Error: (07/03/2014 06:02:38 PM) (Source: Application Error) (EventID: 1000) (User: ) 
Description: Name der fehlerhaften Anwendung: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83 
Name des fehlerhaften Moduls: v87lo16c.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83 
Ausnahmecode: 0xc0000005 
Fehleroffset: 0x00012298 
ID des fehlerhaften Prozesses: 0xf7c 
Startzeit der fehlerhaften Anwendung: 0xv87lo16c.exe0 
Pfad der fehlerhaften Anwendung: v87lo16c.exe1 
Pfad des fehlerhaften Moduls: v87lo16c.exe2 
Berichtskennung: v87lo16c.exe3 
Vollständiger Name des fehlerhaften Pakets: v87lo16c.exe4 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: v87lo16c.exe5   
Error: (07/03/2014 05:46:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledSPRetry 43109313   
Error: (07/03/2014 05:46:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledEvent 43109313   
Error: (07/03/2014 05:46:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: Continuously busy for more than a second   
Error: (07/03/2014 05:46:31 AM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledSPRetry 17480265   
Error: (07/03/2014 05:46:31 AM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledEvent 17480265   
Error: (07/03/2014 05:46:31 AM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: Continuously busy for more than a second   
Error: (07/02/2014 10:52:58 PM) (Source: Application Hang) (EventID: 1002) (User: ) 
Description: Programm LiveComm.exe, Version 17.5.9600.20498 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.   
Prozess-ID: 7fc   
Startzeit: 01cf9636e3ef83b9   
Endzeit: 4294967295   
Anwendungspfad: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe   
Berichts-ID: d764a3d9-022a-11e4-afce-001dbaea63f2   
Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe   
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ppleae38af2e007f4358a809ac99a64a67c1     
System errors: 
============= 
Error: (07/03/2014 08:24:15 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: ) 
Description: 4   
Error: (07/03/2014 06:54:08 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: ) 
Description: 4   
Error: (07/03/2014 06:18:32 PM) (Source: DCOM) (EventID: 10005) (User: SCHNADDL) 
Description: 1084WSearchNicht verfügbar{9E175B68-F52A-11D8-B9A5-505054503030}   
Error: (07/03/2014 06:18:31 PM) (Source: DCOM) (EventID: 10005) (User: SCHNADDL) 
Description: 1084ShellHWDetectionNicht verfügbar{DD522ACC-F821-461A-A407-50B198B896DC}   
Error: (07/03/2014 06:17:50 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) 
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" ist vom Dienst "DHCP-Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  
%%1068   
Error: (07/03/2014 06:17:50 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) 
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" ist vom Dienst "DHCP-Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  
%%1068   
Error: (07/03/2014 06:17:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) 
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" ist vom Dienst "DHCP-Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  
%%1068   
Error: (07/03/2014 06:17:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) 
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" ist vom Dienst "DHCP-Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  
%%1068   
Error: (07/03/2014 06:17:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) 
Description: Der Dienst "WinHTTP-Web Proxy Auto-Discovery-Dienst" ist vom Dienst "DHCP-Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  
%%1068   
Error: (07/03/2014 06:17:25 PM) (Source: DCOM) (EventID: 10005) (User: SCHNADDL) 
Description: 1084ShellHWDetectionNicht verfügbar{DD522ACC-F821-461A-A407-50B198B896DC}     
Microsoft Office Sessions: 
=========================   
CodeIntegrity Errors: 
=================================== 
  Date: 2014-07-02 21:55:48.018 
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.   
  Date: 2014-07-02 21:55:47.987 
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.   
  Date: 2014-07-02 21:55:47.940 
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.   
  Date: 2014-07-02 21:55:47.893 
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.   
  Date: 2014-07-02 21:55:47.815 
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.   
  Date: 2014-07-02 21:55:47.753 
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.   
  Date: 2014-07-02 21:55:47.690 
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.   
  Date: 2014-07-02 21:55:47.659 
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.   
  Date: 2014-07-02 21:55:47.581 
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.   
  Date: 2014-07-02 21:55:47.503 
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.     
==================== Memory info ===========================    
Percentage of memory in use: 27% 
Total physical RAM: 3039.04 MB 
Available physical RAM: 2196.07 MB 
Total Pagefile: 3551.04 MB 
Available Pagefile: 2693.45 MB 
Total Virtual: 2047.88 MB 
Available Virtual: 1904.98 MB   
==================== Drives ================================   
Drive c: () (Fixed) (Total:288.22 GB) (Free:199.01 GB) NTFS ==>[Drive with boot components (obtained from BCD)]   
==================== MBR & Partition Table ==================   
======================================================== 
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: 6C473DE3) 
Partition 1: (Not Active) - (Size=10 GB) - (Type=27) 
Partition 2: (Active) - (Size=288 GB) - (Type=07 NTFS)   
==================== End Of Log ============================      |