Teil 4
[CODE]==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedMaxPc
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\ProgramData\SpeedMaxPc
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\Program Files (x86)\SpeedMaxPc
2014-09-02 11:49 - 2014-09-03 08:17 - 00000000 ____D () C:\FRST
2014-09-02 09:52 - 2014-09-02 10:40 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Nico Mak Computing
2014-09-02 07:09 - 2014-09-02 07:09 - 00000000 _____ () C:\autoexec.bat
2014-09-02 07:08 - 2014-09-02 07:08 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-09-02 07:07 - 2014-09-02 08:45 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-09-01 14:33 - 2014-09-01 14:33 - 00003073 _____ () C:\AdwCleaner[R17].txt
2014-08-31 18:21 - 2014-08-31 18:21 - 00003050 _____ () C:\AdwCleaner[S14].txt
2014-08-31 18:21 - 2014-08-31 18:21 - 00002951 _____ () C:\AdwCleaner[R16].txt
2014-08-30 20:38 - 2014-08-30 20:38 - 00110730 _____ () C:\AdwCleaner[S13].txt
2014-08-30 20:37 - 2014-08-30 20:37 - 00110629 _____ () C:\AdwCleaner[R15].txt
2014-08-30 16:25 - 2014-08-30 19:11 - 00000000 ____D () C:\Users\Martina\.birdfont
2014-08-30 16:20 - 2014-08-30 16:20 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Birdfont
2014-08-30 16:20 - 2014-08-30 16:20 - 00000000 ____D () C:\Program Files (x86)\Birdfont
2014-08-30 16:18 - 2014-08-30 16:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InetStat
2014-08-30 16:16 - 2014-09-01 21:49 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2014-08-30 16:16 - 2014-08-30 16:17 - 00000000 _____ () C:\END
2014-08-30 16:16 - 2014-08-30 16:16 - 00000000 ____D () C:\Users\Martina\AppData\Local\SearchProtect
2014-08-28 21:00 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 21:00 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-28 21:00 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 20:00 - 2014-08-27 20:00 - 00003072 _____ () C:\AdwCleaner[S12].txt
2014-08-27 20:00 - 2014-08-27 20:00 - 00003003 _____ () C:\AdwCleaner[R14].txt
2014-08-25 23:05 - 2014-09-03 07:47 - 00000470 _____ () C:\Windows\Tasks\SPBIW_UpdateTask_Time_323935343339393034362d5b784a456c2a23342a325557.job
2014-08-23 12:40 - 2014-08-23 21:29 - 00000470 _____ () C:\Windows\Tasks\SPBIW_UpdateTask_Time_323935343339393034362d2d37505a2a6c55326c342341.job
2014-08-22 18:23 - 2014-08-22 18:23 - 00000000 ____D () C:\ProgramData\374311380
2014-08-21 16:15 - 2014-09-01 22:20 - 00000000 ____D () C:\Program Files (x86)\TheGoPhoto.it V10
2014-08-21 16:15 - 2014-08-21 16:15 - 00004492 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-11.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001818 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-1.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001700 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-5_user.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001680 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-5.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001410 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-2.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00000896 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore1cfbd4a5e77343e.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001826 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-1.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001704 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-5_user.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001684 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-5.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001414 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-2.job
2014-08-21 16:13 - 2014-09-01 22:20 - 00000000 ____D () C:\Program Files (x86)\TheHDvid-Codec V10
2014-08-21 16:13 - 2014-08-21 16:14 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-08-21 16:13 - 2014-08-21 16:13 - 00004494 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-11.job
2014-08-21 16:13 - 2014-08-21 16:13 - 00000000 ____D () C:\Users\Martina\AppData\Local\globalUpdate
2014-08-21 16:12 - 2014-09-01 22:21 - 00000000 ____D () C:\Program Files (x86)\FLVPlayer
2014-08-21 16:12 - 2014-08-21 16:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FLVPlayer
2014-08-21 16:10 - 2014-08-21 16:10 - 00000260 _____ () C:\Windows\Tasks\Launch 21752.job
2014-08-21 16:10 - 2014-08-21 16:10 - 00000000 ____D () C:\ProgramData\YTAHelper
2014-08-21 16:10 - 2014-08-21 16:10 - 00000000 ____D () C:\ProgramData\ShopperPro
2014-08-21 16:09 - 2014-09-03 07:46 - 00000000 ____D () C:\ProgramData\TEMP
2014-08-21 16:09 - 2014-08-23 10:00 - 00000000 ____D () C:\Program Files (x86)\YouTube Accelerator
2014-08-21 16:09 - 2014-08-21 16:10 - 00000000 ____D () C:\Program Files (x86)\YTAHelper
2014-08-21 16:09 - 2014-08-21 16:10 - 00000000 ____D () C:\Program Files (x86)\ShopperPro
2014-08-21 16:09 - 2014-08-21 16:09 - 00172032 _____ (Jin Hui E-mail: jinhui@jcomsoft.com Web: hxxp://www.jcomsoft.com) C:\Windows\SysWOW64\AniGIF.ocx
2014-08-21 16:09 - 2014-08-21 16:09 - 00001109 _____ () C:\Users\Martina\Desktop\YouTube Accelerator.lnk
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\Users\Martina\AppData\Local\CrashRpt
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\Program Files\Common Files\ShopperPro
2014-08-21 16:08 - 2014-09-02 07:15 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\istartsurf
2014-08-21 16:08 - 2014-08-21 16:08 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\High-Logic FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\AppData\Local\FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\High-Logic FontCreator
2014-08-21 09:48 - 2013-01-24 13:43 - 01415352 _____ (High-Logic B.V.) C:\Windows\SysWOW64\FontInstaller2.dll
2014-08-21 09:06 - 2014-08-21 09:06 - 00000000 __SHD () C:\Users\Martina\AppData\Local\EmieUserList
2014-08-21 09:06 - 2014-08-21 09:06 - 00000000 __SHD () C:\Users\Martina\AppData\Local\EmieSiteList
2014-08-20 21:09 - 2014-08-20 21:09 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\DesktopIconGoodgame
2014-08-20 20:31 - 2014-08-20 20:31 - 00000366 _____ () C:\Windows\Tasks\Updater scan.job
2014-08-20 20:31 - 2014-08-20 20:31 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Abelssoft
2014-08-20 20:31 - 2014-08-20 20:31 - 00000000 ____D () C:\ProgramData\XDMessagingv4
2014-08-20 20:30 - 2014-08-20 20:46 - 00000000 ____D () C:\Users\Martina\AppData\Local\Abelssoft
2014-08-20 20:29 - 2014-08-20 20:29 - 00001013 _____ () C:\Users\Public\Desktop\CHIP Updater.lnk
2014-08-20 20:29 - 2014-08-20 20:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater
2014-08-20 20:29 - 2014-08-20 20:29 - 00000000 ____D () C:\Program Files (x86)\CHIP Updater
2014-08-20 20:28 - 2014-08-20 21:09 - 00000000 ____D () C:\Program Files (x86)\FontForge
2014-08-20 20:28 - 2014-08-20 20:28 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FontForge
2014-08-19 15:23 - 2014-08-19 15:23 - 00001100 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-16 10:48 - 2014-08-31 19:56 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\dvdcss
2014-08-14 14:22 - 2014-08-19 15:23 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-14 07:27 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-14 07:27 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-14 07:27 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-14 07:27 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-14 07:27 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-14 07:27 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-14 07:26 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-14 07:26 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-13 20:44 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-13 20:44 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-13 20:44 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-13 20:44 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-13 20:44 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-13 20:44 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-13 20:44 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-13 20:44 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-13 20:44 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-13 20:44 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-13 20:44 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-13 20:44 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-13 20:44 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-13 20:44 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-13 20:44 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-13 20:44 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-13 20:44 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-13 20:44 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-13 20:44 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-13 20:44 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-13 20:44 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-13 20:43 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-13 20:43 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-13 20:43 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-13 20:43 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-13 20:43 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 20:43 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-13 20:43 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-13 20:43 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-13 20:43 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-13 20:43 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-13 20:43 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-13 20:43 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-13 20:43 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-13 20:43 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-13 20:43 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-13 20:43 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-13 20:43 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-13 20:43 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-13 20:43 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 20:43 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-13 20:43 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-13 20:43 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-13 20:43 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-13 20:43 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-13 20:43 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-13 20:43 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 20:43 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-13 20:43 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-13 20:43 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-13 20:43 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-13 20:43 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-13 20:43 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-13 20:43 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-13 20:43 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-13 20:43 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-13 20:43 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-13 20:43 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-13 20:43 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-13 20:43 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-13 20:43 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-13 20:43 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-13 20:43 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-13 20:43 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-13 20:43 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-13 20:43 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-13 20:43 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-13 20:43 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-13 20:43 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-13 20:43 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-13 20:43 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-13 20:43 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-13 20:43 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-13 20:43 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-13 20:43 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-13 20:43 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-13 20:43 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-13 20:43 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-13 20:43 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-13 20:43 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-13 20:42 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-13 20:42 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-13 20:41 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 20:41 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-07 08:58 - 2014-08-07 08:58 - 00000000 ____D () C:\Users\Martina\restore
2014-08-06 12:12 - 2014-08-11 09:18 - 00000000 ____D () C:\ProgramData\tmp
2014-08-06 12:12 - 2014-08-06 14:31 - 00000000 ____D () C:\ProgramData\hps
2014-08-06 12:12 - 2014-08-06 12:12 - 00001174 _____ () C:\Users\Public\Desktop\Hartlauer Fotoviewer.lnk
2014-08-06 12:12 - 2014-08-06 12:12 - 00001174 _____ () C:\Users\Public\Desktop\Hartlauer Foto World.lnk
2014-08-06 12:12 - 2014-08-06 12:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hartlauer Foto World
2014-08-06 12:00 - 2014-08-06 12:00 - 00000000 ____D () C:\Program Files\Hartlauer Foto World
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-03 08:17 - 2014-09-02 11:49 - 00000000 ____D () C:\FRST
2014-09-03 07:54 - 2009-07-14 06:45 - 00015104 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-03 07:54 - 2009-07-14 06:45 - 00015104 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-03 07:53 - 2013-06-14 23:43 - 01758725 _____ () C:\Windows\WindowsUpdate.log
2014-09-03 07:47 - 2014-08-25 23:05 - 00000470 _____ () C:\Windows\Tasks\SPBIW_UpdateTask_Time_323935343339393034362d5b784a456c2a23342a325557.job
2014-09-03 07:47 - 2013-06-16 16:47 - 00000000 ____D () C:\Users\Martina\AppData\Local\Adobe
2014-09-03 07:46 - 2014-08-21 16:09 - 00000000 ____D () C:\ProgramData\TEMP
2014-09-03 07:46 - 2013-09-18 15:26 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-03 07:44 - 2009-07-14 06:51 - 00075101 _____ () C:\Windows\setupact.log
2014-09-02 21:44 - 2013-10-27 07:21 - 00000000 ____D () C:\Users\Martina\AppData\Local\CrashDumps
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedMaxPc
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\ProgramData\SpeedMaxPc
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\Program Files (x86)\SpeedMaxPc
2014-09-02 14:02 - 2013-08-09 13:39 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Skype
2014-09-02 10:40 - 2014-09-02 09:52 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Nico Mak Computing
2014-09-02 08:45 - 2014-09-02 07:07 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-09-02 07:15 - 2014-08-21 16:08 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\istartsurf
2014-09-02 07:09 - 2014-09-02 07:09 - 00000000 _____ () C:\autoexec.bat
2014-09-02 07:08 - 2014-09-02 07:08 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-09-01 22:35 - 2013-06-15 03:18 - 00323572 _____ () C:\Windows\PFRO.log
2014-09-01 22:21 - 2014-08-21 16:12 - 00000000 ____D () C:\Program Files (x86)\FLVPlayer
2014-09-01 22:20 - 2014-08-21 16:15 - 00000000 ____D () C:\Program Files (x86)\TheGoPhoto.it V10
2014-09-01 22:20 - 2014-08-21 16:13 - 00000000 ____D () C:\Program Files (x86)\TheHDvid-Codec V10
2014-09-01 21:49 - 2014-08-30 16:16 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2014-09-01 14:33 - 2014-09-01 14:33 - 00003073 _____ () C:\AdwCleaner[R17].txt
2014-09-01 11:43 - 2013-11-29 17:31 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-09-01 11:18 - 2009-07-14 19:58 - 00699666 _____ () C:\Windows\system32\perfh007.dat
2014-09-01 11:18 - 2009-07-14 19:58 - 00149774 _____ () C:\Windows\system32\perfc007.dat
2014-09-01 11:18 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-31 20:35 - 2013-06-15 00:30 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\vlc
2014-08-31 19:56 - 2014-08-16 10:48 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\dvdcss
2014-08-31 18:21 - 2014-08-31 18:21 - 00003050 _____ () C:\AdwCleaner[S14].txt
2014-08-31 18:21 - 2014-08-31 18:21 - 00002951 _____ () C:\AdwCleaner[R16].txt
2014-08-30 20:38 - 2014-08-30 20:38 - 00110730 _____ () C:\AdwCleaner[S13].txt
2014-08-30 20:37 - 2014-08-30 20:37 - 00110629 _____ () C:\AdwCleaner[R15].txt
2014-08-30 19:11 - 2014-08-30 16:25 - 00000000 ____D () C:\Users\Martina\.birdfont
2014-08-30 16:25 - 2013-06-14 23:48 - 00000000 ____D () C:\Users\Martina
2014-08-30 16:20 - 2014-08-30 16:20 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Birdfont
2014-08-30 16:20 - 2014-08-30 16:20 - 00000000 ____D () C:\Program Files (x86)\Birdfont
2014-08-30 16:18 - 2014-08-30 16:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InetStat
2014-08-30 16:17 - 2014-08-30 16:16 - 00000000 _____ () C:\END
2014-08-30 16:16 - 2014-08-30 16:16 - 00000000 ____D () C:\Users\Martina\AppData\Local\SearchProtect
2014-08-29 20:07 - 2009-07-14 06:45 - 05101376 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-27 20:00 - 2014-08-27 20:00 - 00003072 _____ () C:\AdwCleaner[S12].txt
2014-08-27 20:00 - 2014-08-27 20:00 - 00003003 _____ () C:\AdwCleaner[R14].txt
2014-08-23 21:29 - 2014-08-23 12:40 - 00000470 _____ () C:\Windows\Tasks\SPBIW_UpdateTask_Time_323935343339393034362d2d37505a2a6c55326c342341.job
2014-08-23 10:00 - 2014-08-21 16:09 - 00000000 ____D () C:\Program Files (x86)\YouTube Accelerator
2014-08-23 04:07 - 2014-08-28 21:00 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-08-28 21:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-08-28 21:00 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 18:23 - 2014-08-22 18:23 - 00000000 ____D () C:\ProgramData\374311380
2014-08-21 16:15 - 2014-08-21 16:15 - 00004492 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-11.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001818 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-1.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001700 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-5_user.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001680 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-5.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001410 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-2.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00000896 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore1cfbd4a5e77343e.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001826 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-1.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001704 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-5_user.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001684 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-5.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001414 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-2.job
2014-08-21 16:14 - 2014-08-21 16:13 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-08-21 16:13 - 2014-08-21 16:13 - 00004494 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-11.job
2014-08-21 16:13 - 2014-08-21 16:13 - 00000000 ____D () C:\Users\Martina\AppData\Local\globalUpdate
2014-08-21 16:12 - 2014-08-21 16:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FLVPlayer
2014-08-21 16:10 - 2014-08-21 16:10 - 00000260 _____ () C:\Windows\Tasks\Launch 21752.job
2014-08-21 16:10 - 2014-08-21 16:10 - 00000000 ____D () C:\ProgramData\YTAHelper
2014-08-21 16:10 - 2014-08-21 16:10 - 00000000 ____D () C:\ProgramData\ShopperPro
2014-08-21 16:10 - 2014-08-21 16:09 - 00000000 ____D () C:\Program Files (x86)\YTAHelper
2014-08-21 16:10 - 2014-08-21 16:09 - 00000000 ____D () C:\Program Files (x86)\ShopperPro
2014-08-21 16:09 - 2014-08-21 16:09 - 00172032 _____ (Jin Hui E-mail: jinhui@jcomsoft.com Web: hxxp://www.jcomsoft.com) C:\Windows\SysWOW64\AniGIF.ocx
2014-08-21 16:09 - 2014-08-21 16:09 - 00001109 _____ () C:\Users\Martina\Desktop\YouTube Accelerator.lnk
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\Users\Martina\AppData\Local\CrashRpt
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\Program Files\Common Files\ShopperPro
2014-08-21 16:08 - 2014-08-21 16:08 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-08-21 16:08 - 2013-06-16 16:53 - 00002354 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-21 16:08 - 2013-06-15 00:32 - 00001358 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-21 16:08 - 2013-06-14 23:49 - 00001649 _____ () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\High-Logic FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\AppData\Local\FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\High-Logic FontCreator
2014-08-21 09:06 - 2014-08-21 09:06 - 00000000 __SHD () C:\Users\Martina\AppData\Local\EmieUserList
2014-08-21 09:06 - 2014-08-21 09:06 - 00000000 __SHD () C:\Users\Martina\AppData\Local\EmieSiteList
2014-08-20 21:09 - 2014-08-20 21:09 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\DesktopIconGoodgame
2014-08-20 21:09 - 2014-08-20 20:28 - 00000000 ____D () C:\Program Files (x86)\FontForge
2014-08-20 20:46 - 2014-08-20 20:30 - 00000000 ____D () C:\Users\Martina\AppData\Local\Abelssoft
2014-08-20 20:31 - 2014-08-20 20:31 - 00000366 _____ () C:\Windows\Tasks\Updater scan.job
2014-08-20 20:31 - 2014-08-20 20:31 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Abelssoft
2014-08-20 20:31 - 2014-08-20 20:31 - 00000000 ____D () C:\ProgramData\XDMessagingv4
2014-08-20 20:30 - 2013-06-15 00:32 - 00113576 _____ () C:\Users\Martina\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-20 20:29 - 2014-08-20 20:29 - 00001013 _____ () C:\Users\Public\Desktop\CHIP Updater.lnk
2014-08-20 20:29 - 2014-08-20 20:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater
2014-08-20 20:29 - 2014-08-20 20:29 - 00000000 ____D () C:\Program Files (x86)\CHIP Updater
2014-08-20 20:28 - 2014-08-20 20:28 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FontForge
2014-08-19 15:23 - 2014-08-19 15:23 - 00001100 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-19 15:23 - 2014-08-14 14:22 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-19 15:23 - 2013-08-18 13:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-08-19 15:22 - 2013-08-18 13:04 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-08-14 14:22 - 2013-08-18 13:04 - 00000000 ____D () C:\ProgramData\Avira
2014-08-14 08:08 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-14 07:52 - 2013-06-16 18:01 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-14 07:42 - 2013-08-14 20:07 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-14 07:36 - 2013-06-15 01:38 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-14 07:25 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-11 09:18 - 2014-08-06 12:12 - 00000000 ____D () C:\ProgramData\tmp
2014-08-07 08:58 - 2014-08-07 08:58 - 00000000 ____D () C:\Users\Martina\restore
2014-08-07 04:06 - 2014-08-13 20:41 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 04:01 - 2014-08-13 20:41 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-06 14:31 - 2014-08-06 12:12 - 00000000 ____D () C:\ProgramData\hps
2014-08-06 12:12 - 2014-08-06 12:12 - 00001174 _____ () C:\Users\Public\Desktop\Hartlauer Fotoviewer.lnk
2014-08-06 12:12 - 2014-08-06 12:12 - 00001174 _____ () C:\Users\Public\Desktop\Hartlauer Foto World.lnk
2014-08-06 12:12 - 2014-08-06 12:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hartlauer Foto World
2014-08-06 12:00 - 2014-08-06 12:00 - 00000000 ____D () C:\Program Files\Hartlauer Foto World
Some content of TEMP:
====================
C:\Users\Martina\AppData\Local\Temp\avgnt.exe
C:\Users\Martina\AppData\Local\Temp\SHSetup.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2013-08-29 06:40
==================== End Of Log ============================ndows\system32\aepdu.dll
2014-08-07 04:01 - 2014-08-13 20:41 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-06 14:31 - 2014-08-06 12:12 - 00000000 ____D () C:\ProgramData\hps
2014-08-06 12:12 - 2014-08-06 12:12 - 00001174 _____ () C:\Users\Public\Desktop\Hartlauer Fotoviewer.lnk
2014-08-06 12:12 - 2014-08-06 12:12 - 00001174 _____ () C:\Users\Public\Desktop\Hartlauer Foto World.lnk
2014-08-06 12:12 - 2014-08-06 12:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hartlauer Foto World
2014-08-06 12:00 - 2014-08-06 12:00 - 00000000 ____D () C:\Program Files\Hartlauer Foto World
Some content of TEMP:
====================
C:\Users\Martina\AppData\Local\Temp\avgnt.exe
C:\Users\Martina\AppData\Local\Temp\SHSetup.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2013-08-29 06:40
==================== End Of Log ============================
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2014
Ran by Martina (administrator) on NB01KRZBMA on 03-09-2014 08:21:16
Running from D:\Martina\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Fuyu LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(ShopperPro) C:\Program Files\Common Files\ShopperPro\spbiu.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(GOOBZO) C:\Program Files (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Client Connect LTD) C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Client Connect LTD) C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe
(Client Connect LTD) C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
() C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.486\jsdrv.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(globalUpdate) C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) D:\Martina\Desktop\FRST64 (1).exe
(Farbar) D:\Martina\Desktop\FRST64 (1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [790176 2011-03-31] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [657056 2011-03-31] (Atheros Commnucations)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-09-25] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-14] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-11-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [161584 2014-08-04] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.486\jsdrv.exe [3211776 2014-08-07] ()
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-06-15] (Microsoft Corporation)
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21446272 2014-05-08] (Skype Technologies S.A.)
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\Run: [LiveSupport] => "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\Run: [GoobzoYouTubeAccelerator] => C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe [2227048 2014-08-21] (GOOBZO)
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\Run: [SPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.486\jsdrv.exe [3211776 2014-08-07] ()
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-06-16] (Google Inc.)
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\RunOnce: [Uninstall C:\Users\Martina\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112_1\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martina\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112_1\amd64"
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\RunOnce: [Uninstall C:\Users\Martina\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martina\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\MountPoints2: F - F:\AutoRun.exe
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\MountPoints2: {9f0476a4-d6a2-11e2-b1ce-90004eb858ed} - F:\AutoRun.exe
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\MountPoints2: {9f0476aa-d6a2-11e2-b1ce-90004eb858ed} - F:\AutoRun.exe
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\MountPoints2: {9f0476d6-d6a2-11e2-b1ce-90004eb858ed} - F:\AutoRun.exe
HKU\S-1-5-21-2921778440-697364257-2174348754-1000\...\MountPoints2: {c3dde93d-99b1-11e3-9283-90004eb858ee} - F:\Startme.exe
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [232408 2014-08-31] (Client Connect LTD)
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [187352 2014-08-31] (Client Connect LTD)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk
ShortcutTarget: simplicheck.lnk -> C:\Program Files (x86)\simplitec\simplicheck\simplicheck.exe (simplitec)
ShellIconOverlayIdentifiers: AccExtIco1 -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: AccExtIco2 -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: AccExtIco3 -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.trovi.com/?gd=&ctid=CT3325386&octid=EB_ORIGINAL_CTID&ISID=MBE1B69C2-1A5C-4CA3-9376-6B92DBDE9BCF&SearchSource=55&CUI=&UM=6&UP=SPAA41E917-BF56-450F-9DCA-0EBCA6938BAD&SSPV=
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x46388F1AA669CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hp&ts=1408630080&from=smt&uid=HitachiXHTS545025A7E380_TA8A123VCMXWMTCMXWMTX
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
URLSearchHook: HKCU - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1408630080&from=smt&uid=HitachiXHTS545025A7E380_TA8A123VCMXWMTCMXWMTX
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325386&octid=EB_ORIGINAL_CTID&ISID=MBE1B69C2-1A5C-4CA3-9376-6B92DBDE9BCF&SearchSource=58&CUI=&UM=6&UP=SPAA41E917-BF56-450F-9DCA-0EBCA6938BAD&q={searchTerms}&SSPV=
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325386&octid=EB_ORIGINAL_CTID&ISID=MBE1B69C2-1A5C-4CA3-9376-6B92DBDE9BCF&SearchSource=58&CUI=&UM=6&UP=SPAA41E917-BF56-450F-9DCA-0EBCA6938BAD&q={searchTerms}&SSPV=
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Avira SearchFree Toolbar -> {41564952-412D-5637-00A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Shopper Pro -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> C:\ProgramData\ShopperPro\ShopperPro64.dll (Goobzo Ltd.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: DVDVideoSoft WebPageAdjuster Class -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
BHO: YTAHelper -> {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} -> C:\ProgramData\YTAHelper\YTAHelper64.dll (Goobzo Ltd.)
BHO-x32: Avira SearchFree Toolbar -> {41564952-412D-5637-00A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: No Name -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> No File
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: FindRight -> {cf710881-c002-4ea4-860a-b6931b040948} -> C:\Program Files (x86)\FindRight\FindRightbho.dll (FindRight)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: DVDVideoSoft WebPageAdjuster Class -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
BHO-x32: YTAHelper -> {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} -> C:\ProgramData\YTAHelper\YTAHelper.dll (Goobzo Ltd.)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKLM-x32 - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\1.8.21.0\mysearchdialTlbr.dll No File
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default
FF NewTab: hxxp://www.istartsurf.com/newtab/?type=nt&ts=1408630080&from=smt&uid=HitachiXHTS545025A7E380_TA8A123VCMXWMTCMXWMTX
FF DefaultSearchEngine: istartsurf
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: istartsurf
FF Homepage: hxxp://www.istartsurf.com/?type=hp&ts=1408630080&from=smt&uid=HitachiXHTS545025A7E380_TA8A123VCMXWMTCMXWMTX
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF SearchPlugin: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\searchplugins\bingp.xml
FF SearchPlugin: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\searchplugins\BrowserDefender.xml
FF SearchPlugin: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\searchplugins\delta.xml
FF SearchPlugin: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\searchplugins\Mysearchdial.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\istartsurf.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: TheHDvid-Codec V10 - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\Extensions\43f13f31-cec7-4ac7-ad4a-18dfdaeae120@gmail.com [2014-08-21]
FF Extension: TheGoPhoto.it V10 - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\Extensions\EWBNO58637124@CLP39222015.com [2014-08-21]
FF Extension: Fast Start - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\Extensions\faststartff@gmail.com [2014-08-21]
FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\Extensions\toolbar_AVIRA-V7@apn.ask.com [2013-08-18]
FF Extension: Youtube Accelerator Helper - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\Extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E} [2014-08-21]
FF Extension: Shopper-Pro - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [2014-08-21]
FF Extension: FindRight - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\Extensions\firefox@myfindright.com.xpi [2014-02-18]
FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi [2014-02-21]
FF HKLM-x32\...\Firefox\Extensions: [fiddlerhook@fiddler2.com] - C:\Program Files (x86)\Fiddler2\FiddlerHook
FF Extension: FiddlerHook - C:\Program Files (x86)\Fiddler2\FiddlerHook [2013-06-16]
FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2013-07-13]
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\8qahtb8s.default\extensions\faststartff@gmail.com
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.istartsurf.com/?type=sc&ts=1408630080&from=smt&uid=HitachiXHTS545025A7E380_TA8A123VCMXWMTCMXWMTX
Chrome:
=======
CHR StartupUrls: Default -> "https://www.google.at/?gws_rd=ssl#q=was+ist+it+surf%3F"
CHR DefaultSuggestURL: Default ->
CHR Profile: C:\Users\Martina\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-31]
CHR Extension: (Google Drive) - C:\Users\Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-31]
CHR Extension: (YouTube) - C:\Users\Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-31]
CHR Extension: (Google-Suche) - C:\Users\Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-31]
CHR Extension: (DVDVideoSoft) - C:\Users\Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2013-07-14]
CHR Extension: (Google Wallet) - C:\Users\Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-27]
CHR Extension: (Google Mail) - C:\Users\Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-31]
CHR Extension: (Extutil) - C:\Users\Martina\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B [2014-08-31]
CHR Extension: (Managera) - C:\Users\Martina\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42 [2014-08-31]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-07-13]
CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [2014-02-21]
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.istartsurf.com/?type=sc&ts=1408630080&from=smt&uid=HitachiXHTS545025A7E380_TA8A123VCMXWMTCMXWMTX
==================== Services (Whitelisted) =================
Teil 5
Code:
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1021008 2014-08-14] (Avira Operations GmbH & Co. KG)
S4 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] () [File not signed]
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-03-31] (Atheros) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [75936 2011-03-31] (Atheros Commnucations) [File not signed]
S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2356408 2014-06-19] (Microsoft Corporation)
R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2998232 2014-08-31] (Client Connect LTD)
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-08-21] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-08-21] (globalUpdate) [File not signed]
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
R2 SPBIUpd; C:\Program Files\Common Files\ShopperPro\spbiu.exe [2346880 2014-08-07] (ShopperPro)
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [528896 2014-08-21] (Fuyu LIMITED) [File not signed]
R2 YouTubeAcceleratorService; C:\Program Files (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe [1510248 2014-08-21] (GOOBZO)
S2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe -service [X]
S2 Wajam Internet Enhancer Service; C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-10] (Avira Operations GmbH & Co. KG)
R3 SPBIUpdd; C:\Program Files\Common Files\ShopperPro\spbiw.sys [41856 2014-08-07] ()
R2 SPDRIVER_1.37.0.486; C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.486\jsdrv.sys [52584 2014-08-07] ()
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
R3 SPPD; \??\C:\Windows\system32\drivers\SPPD.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedMaxPc
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\ProgramData\SpeedMaxPc
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\Program Files (x86)\SpeedMaxPc
2014-09-02 11:49 - 2014-09-03 08:21 - 00000000 ____D () C:\FRST
2014-09-02 09:52 - 2014-09-02 10:40 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Nico Mak Computing
2014-09-02 07:09 - 2014-09-02 07:09 - 00000000 _____ () C:\autoexec.bat
2014-09-02 07:08 - 2014-09-02 07:08 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-09-02 07:07 - 2014-09-02 08:45 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-09-01 14:33 - 2014-09-01 14:33 - 00003073 _____ () C:\AdwCleaner[R17].txt
2014-08-31 18:21 - 2014-08-31 18:21 - 00003050 _____ () C:\AdwCleaner[S14].txt
2014-08-31 18:21 - 2014-08-31 18:21 - 00002951 _____ () C:\AdwCleaner[R16].txt
2014-08-30 20:38 - 2014-08-30 20:38 - 00110730 _____ () C:\AdwCleaner[S13].txt
2014-08-30 20:37 - 2014-08-30 20:37 - 00110629 _____ () C:\AdwCleaner[R15].txt
2014-08-30 16:25 - 2014-08-30 19:11 - 00000000 ____D () C:\Users\Martina\.birdfont
2014-08-30 16:20 - 2014-08-30 16:20 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Birdfont
2014-08-30 16:20 - 2014-08-30 16:20 - 00000000 ____D () C:\Program Files (x86)\Birdfont
2014-08-30 16:18 - 2014-08-30 16:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InetStat
2014-08-30 16:16 - 2014-09-01 21:49 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2014-08-30 16:16 - 2014-08-30 16:17 - 00000000 _____ () C:\END
2014-08-30 16:16 - 2014-08-30 16:16 - 00000000 ____D () C:\Users\Martina\AppData\Local\SearchProtect
2014-08-28 21:00 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 21:00 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-28 21:00 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 20:00 - 2014-08-27 20:00 - 00003072 _____ () C:\AdwCleaner[S12].txt
2014-08-27 20:00 - 2014-08-27 20:00 - 00003003 _____ () C:\AdwCleaner[R14].txt
2014-08-25 23:05 - 2014-09-03 07:47 - 00000470 _____ () C:\Windows\Tasks\SPBIW_UpdateTask_Time_323935343339393034362d5b784a456c2a23342a325557.job
2014-08-23 12:40 - 2014-08-23 21:29 - 00000470 _____ () C:\Windows\Tasks\SPBIW_UpdateTask_Time_323935343339393034362d2d37505a2a6c55326c342341.job
2014-08-22 18:23 - 2014-08-22 18:23 - 00000000 ____D () C:\ProgramData\374311380
2014-08-21 16:15 - 2014-09-01 22:20 - 00000000 ____D () C:\Program Files (x86)\TheGoPhoto.it V10
2014-08-21 16:15 - 2014-08-21 16:15 - 00004492 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-11.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001818 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-1.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001700 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-5_user.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001680 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-5.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001410 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-2.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00000896 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore1cfbd4a5e77343e.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001826 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-1.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001704 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-5_user.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001684 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-5.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001414 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-2.job
2014-08-21 16:13 - 2014-09-01 22:20 - 00000000 ____D () C:\Program Files (x86)\TheHDvid-Codec V10
2014-08-21 16:13 - 2014-08-21 16:14 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-08-21 16:13 - 2014-08-21 16:13 - 00004494 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-11.job
2014-08-21 16:13 - 2014-08-21 16:13 - 00000000 ____D () C:\Users\Martina\AppData\Local\globalUpdate
2014-08-21 16:12 - 2014-09-01 22:21 - 00000000 ____D () C:\Program Files (x86)\FLVPlayer
2014-08-21 16:12 - 2014-08-21 16:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FLVPlayer
2014-08-21 16:10 - 2014-08-21 16:10 - 00000260 _____ () C:\Windows\Tasks\Launch 21752.job
2014-08-21 16:10 - 2014-08-21 16:10 - 00000000 ____D () C:\ProgramData\YTAHelper
2014-08-21 16:10 - 2014-08-21 16:10 - 00000000 ____D () C:\ProgramData\ShopperPro
2014-08-21 16:09 - 2014-09-03 07:46 - 00000000 ____D () C:\ProgramData\TEMP
2014-08-21 16:09 - 2014-08-23 10:00 - 00000000 ____D () C:\Program Files (x86)\YouTube Accelerator
2014-08-21 16:09 - 2014-08-21 16:10 - 00000000 ____D () C:\Program Files (x86)\YTAHelper
2014-08-21 16:09 - 2014-08-21 16:10 - 00000000 ____D () C:\Program Files (x86)\ShopperPro
2014-08-21 16:09 - 2014-08-21 16:09 - 00172032 _____ (Jin Hui E-mail: jinhui@jcomsoft.com Web: hxxp://www.jcomsoft.com) C:\Windows\SysWOW64\AniGIF.ocx
2014-08-21 16:09 - 2014-08-21 16:09 - 00001109 _____ () C:\Users\Martina\Desktop\YouTube Accelerator.lnk
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\Users\Martina\AppData\Local\CrashRpt
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\Program Files\Common Files\ShopperPro
2014-08-21 16:08 - 2014-09-02 07:15 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\istartsurf
2014-08-21 16:08 - 2014-08-21 16:08 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\High-Logic FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\AppData\Local\FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\High-Logic FontCreator
2014-08-21 09:48 - 2013-01-24 13:43 - 01415352 _____ (High-Logic B.V.) C:\Windows\SysWOW64\FontInstaller2.dll
2014-08-21 09:06 - 2014-08-21 09:06 - 00000000 __SHD () C:\Users\Martina\AppData\Local\EmieUserList
2014-08-21 09:06 - 2014-08-21 09:06 - 00000000 __SHD () C:\Users\Martina\AppData\Local\EmieSiteList
2014-08-20 21:09 - 2014-08-20 21:09 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\DesktopIconGoodgame
2014-08-20 20:31 - 2014-08-20 20:31 - 00000366 _____ () C:\Windows\Tasks\Updater scan.job
2014-08-20 20:31 - 2014-08-20 20:31 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Abelssoft
2014-08-20 20:31 - 2014-08-20 20:31 - 00000000 ____D () C:\ProgramData\XDMessagingv4
2014-08-20 20:30 - 2014-08-20 20:46 - 00000000 ____D () C:\Users\Martina\AppData\Local\Abelssoft
2014-08-20 20:29 - 2014-08-20 20:29 - 00001013 _____ () C:\Users\Public\Desktop\CHIP Updater.lnk
2014-08-20 20:29 - 2014-08-20 20:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater
2014-08-20 20:29 - 2014-08-20 20:29 - 00000000 ____D () C:\Program Files (x86)\CHIP Updater
2014-08-20 20:28 - 2014-08-20 21:09 - 00000000 ____D () C:\Program Files (x86)\FontForge
2014-08-20 20:28 - 2014-08-20 20:28 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FontForge
2014-08-19 15:23 - 2014-08-19 15:23 - 00001100 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-16 10:48 - 2014-08-31 19:56 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\dvdcss
2014-08-14 14:22 - 2014-08-19 15:23 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-14 07:27 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-14 07:27 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-14 07:27 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-14 07:27 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-14 07:27 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-14 07:27 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-14 07:26 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-14 07:26 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-13 20:44 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-13 20:44 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-13 20:44 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-13 20:44 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-13 20:44 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-13 20:44 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-13 20:44 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-13 20:44 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-13 20:44 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-13 20:44 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-13 20:44 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-13 20:44 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-13 20:44 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-13 20:44 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-13 20:44 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-13 20:44 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-13 20:44 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-13 20:44 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-13 20:44 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-13 20:44 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-13 20:44 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-13 20:43 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-13 20:43 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-13 20:43 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-13 20:43 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-13 20:43 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 20:43 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-13 20:43 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-13 20:43 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-13 20:43 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-13 20:43 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-13 20:43 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-13 20:43 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-13 20:43 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-13 20:43 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-13 20:43 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-13 20:43 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-13 20:43 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-13 20:43 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-13 20:43 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 20:43 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-13 20:43 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-13 20:43 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-13 20:43 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-13 20:43 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-13 20:43 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-13 20:43 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 20:43 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-13 20:43 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-13 20:43 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-13 20:43 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-13 20:43 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-13 20:43 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-13 20:43 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-13 20:43 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-13 20:43 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-13 20:43 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-13 20:43 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-13 20:43 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-13 20:43 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-13 20:43 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-13 20:43 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-13 20:43 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-13 20:43 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-13 20:43 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-13 20:43 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-13 20:43 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-13 20:43 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-13 20:43 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-13 20:43 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-13 20:43 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-13 20:43 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-13 20:43 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-13 20:43 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-13 20:43 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-13 20:43 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-13 20:43 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-13 20:43 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-13 20:43 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-13 20:43 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-13 20:42 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-13 20:42 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-13 20:41 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 20:41 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-07 08:58 - 2014-08-07 08:58 - 00000000 ____D () C:\Users\Martina\restore
2014-08-06 12:12 - 2014-08-11 09:18 - 00000000 ____D () C:\ProgramData\tmp
2014-08-06 12:12 - 2014-08-06 14:31 - 00000000 ____D () C:\ProgramData\hps
2014-08-06 12:12 - 2014-08-06 12:12 - 00001174 _____ () C:\Users\Public\Desktop\Hartlauer Fotoviewer.lnk
2014-08-06 12:12 - 2014-08-06 12:12 - 00001174 _____ () C:\Users\Public\Desktop\Hartlauer Foto World.lnk
2014-08-06 12:12 - 2014-08-06 12:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hartlauer Foto World
2014-08-06 12:00 - 2014-08-06 12:00 - 00000000 ____D () C:\Program Files\Hartlauer Foto World
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-03 08:21 - 2014-09-02 11:49 - 00000000 ____D () C:\FRST
2014-09-03 07:54 - 2009-07-14 06:45 - 00015104 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-03 07:54 - 2009-07-14 06:45 - 00015104 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-03 07:53 - 2013-06-14 23:43 - 01758725 _____ () C:\Windows\WindowsUpdate.log
2014-09-03 07:47 - 2014-08-25 23:05 - 00000470 _____ () C:\Windows\Tasks\SPBIW_UpdateTask_Time_323935343339393034362d5b784a456c2a23342a325557.job
2014-09-03 07:47 - 2013-06-16 16:47 - 00000000 ____D () C:\Users\Martina\AppData\Local\Adobe
2014-09-03 07:46 - 2014-08-21 16:09 - 00000000 ____D () C:\ProgramData\TEMP
2014-09-03 07:46 - 2013-09-18 15:26 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-03 07:44 - 2009-07-14 06:51 - 00075101 _____ () C:\Windows\setupact.log
2014-09-02 21:44 - 2013-10-27 07:21 - 00000000 ____D () C:\Users\Martina\AppData\Local\CrashDumps
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedMaxPc
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\ProgramData\SpeedMaxPc
2014-09-02 14:08 - 2014-09-02 14:08 - 00000000 ____D () C:\Program Files (x86)\SpeedMaxPc
2014-09-02 14:02 - 2013-08-09 13:39 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Skype
2014-09-02 10:40 - 2014-09-02 09:52 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Nico Mak Computing
2014-09-02 08:45 - 2014-09-02 07:07 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-09-02 07:15 - 2014-08-21 16:08 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\istartsurf
2014-09-02 07:09 - 2014-09-02 07:09 - 00000000 _____ () C:\autoexec.bat
2014-09-02 07:08 - 2014-09-02 07:08 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-09-01 22:35 - 2013-06-15 03:18 - 00323572 _____ () C:\Windows\PFRO.log
2014-09-01 22:21 - 2014-08-21 16:12 - 00000000 ____D () C:\Program Files (x86)\FLVPlayer
2014-09-01 22:20 - 2014-08-21 16:15 - 00000000 ____D () C:\Program Files (x86)\TheGoPhoto.it V10
2014-09-01 22:20 - 2014-08-21 16:13 - 00000000 ____D () C:\Program Files (x86)\TheHDvid-Codec V10
2014-09-01 21:49 - 2014-08-30 16:16 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2014-09-01 14:33 - 2014-09-01 14:33 - 00003073 _____ () C:\AdwCleaner[R17].txt
2014-09-01 11:43 - 2013-11-29 17:31 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-09-01 11:18 - 2009-07-14 19:58 - 00699666 _____ () C:\Windows\system32\perfh007.dat
2014-09-01 11:18 - 2009-07-14 19:58 - 00149774 _____ () C:\Windows\system32\perfc007.dat
2014-09-01 11:18 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-31 20:35 - 2013-06-15 00:30 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\vlc
2014-08-31 19:56 - 2014-08-16 10:48 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\dvdcss
2014-08-31 18:21 - 2014-08-31 18:21 - 00003050 _____ () C:\AdwCleaner[S14].txt
2014-08-31 18:21 - 2014-08-31 18:21 - 00002951 _____ () C:\AdwCleaner[R16].txt
2014-08-30 20:38 - 2014-08-30 20:38 - 00110730 _____ () C:\AdwCleaner[S13].txt
2014-08-30 20:37 - 2014-08-30 20:37 - 00110629 _____ () C:\AdwCleaner[R15].txt
2014-08-30 19:11 - 2014-08-30 16:25 - 00000000 ____D () C:\Users\Martina\.birdfont
2014-08-30 16:25 - 2013-06-14 23:48 - 00000000 ____D () C:\Users\Martina
2014-08-30 16:20 - 2014-08-30 16:20 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Birdfont
2014-08-30 16:20 - 2014-08-30 16:20 - 00000000 ____D () C:\Program Files (x86)\Birdfont
2014-08-30 16:18 - 2014-08-30 16:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InetStat
2014-08-30 16:17 - 2014-08-30 16:16 - 00000000 _____ () C:\END
2014-08-30 16:16 - 2014-08-30 16:16 - 00000000 ____D () C:\Users\Martina\AppData\Local\SearchProtect
2014-08-29 20:07 - 2009-07-14 06:45 - 05101376 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-27 20:00 - 2014-08-27 20:00 - 00003072 _____ () C:\AdwCleaner[S12].txt
2014-08-27 20:00 - 2014-08-27 20:00 - 00003003 _____ () C:\AdwCleaner[R14].txt
2014-08-23 21:29 - 2014-08-23 12:40 - 00000470 _____ () C:\Windows\Tasks\SPBIW_UpdateTask_Time_323935343339393034362d2d37505a2a6c55326c342341.job
2014-08-23 10:00 - 2014-08-21 16:09 - 00000000 ____D () C:\Program Files (x86)\YouTube Accelerator
2014-08-23 04:07 - 2014-08-28 21:00 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-08-28 21:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-08-28 21:00 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 18:23 - 2014-08-22 18:23 - 00000000 ____D () C:\ProgramData\374311380
2014-08-21 16:15 - 2014-08-21 16:15 - 00004492 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-11.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001818 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-1.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001700 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-5_user.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001680 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-5.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00001410 _____ () C:\Windows\Tasks\16e09ab7-bf32-41db-a5e3-0520997d5fd9-2.job
2014-08-21 16:15 - 2014-08-21 16:15 - 00000896 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore1cfbd4a5e77343e.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001826 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-1.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001704 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-5_user.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001684 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-5.job
2014-08-21 16:14 - 2014-08-21 16:14 - 00001414 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-2.job
2014-08-21 16:14 - 2014-08-21 16:13 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-08-21 16:13 - 2014-08-21 16:13 - 00004494 _____ () C:\Windows\Tasks\3bd2a66d-6045-4320-bce5-355ba9209e38-11.job
2014-08-21 16:13 - 2014-08-21 16:13 - 00000000 ____D () C:\Users\Martina\AppData\Local\globalUpdate
2014-08-21 16:12 - 2014-08-21 16:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FLVPlayer
2014-08-21 16:10 - 2014-08-21 16:10 - 00000260 _____ () C:\Windows\Tasks\Launch 21752.job
2014-08-21 16:10 - 2014-08-21 16:10 - 00000000 ____D () C:\ProgramData\YTAHelper
2014-08-21 16:10 - 2014-08-21 16:10 - 00000000 ____D () C:\ProgramData\ShopperPro
2014-08-21 16:10 - 2014-08-21 16:09 - 00000000 ____D () C:\Program Files (x86)\YTAHelper
2014-08-21 16:10 - 2014-08-21 16:09 - 00000000 ____D () C:\Program Files (x86)\ShopperPro
2014-08-21 16:09 - 2014-08-21 16:09 - 00172032 _____ (Jin Hui E-mail: jinhui@jcomsoft.com Web: hxxp://www.jcomsoft.com) C:\Windows\SysWOW64\AniGIF.ocx
2014-08-21 16:09 - 2014-08-21 16:09 - 00001109 _____ () C:\Users\Martina\Desktop\YouTube Accelerator.lnk
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\Users\Martina\AppData\Local\CrashRpt
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
2014-08-21 16:09 - 2014-08-21 16:09 - 00000000 ____D () C:\Program Files\Common Files\ShopperPro
2014-08-21 16:08 - 2014-08-21 16:08 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-08-21 16:08 - 2013-06-16 16:53 - 00002354 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-21 16:08 - 2013-06-15 00:32 - 00001358 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-21 16:08 - 2013-06-14 23:49 - 00001649 _____ () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\High-Logic FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\Users\Martina\AppData\Local\FontCreator
2014-08-21 09:48 - 2014-08-21 09:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\High-Logic FontCreator
2014-08-21 09:06 - 2014-08-21 09:06 - 00000000 __SHD () C:\Users\Martina\AppData\Local\EmieUserList
2014-08-21 09:06 - 2014-08-21 09:06 - 00000000 __SHD () C:\Users\Martina\AppData\Local\EmieSiteList
2014-08-20 21:09 - 2014-08-20 21:09 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\DesktopIconGoodgame
2014-08-20 21:09 - 2014-08-20 20:28 - 00000000 ____D () C:\Program Files (x86)\FontForge
2014-08-20 20:46 - 2014-08-20 20:30 - 00000000 ____D () C:\Users\Martina\AppData\Local\Abelssoft
2014-08-20 20:31 - 2014-08-20 20:31 - 00000366 _____ () C:\Windows\Tasks\Updater scan.job
2014-08-20 20:31 - 2014-08-20 20:31 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Abelssoft
2014-08-20 20:31 - 2014-08-20 20:31 - 00000000 ____D () C:\ProgramData\XDMessagingv4
2014-08-20 20:30 - 2013-06-15 00:32 - 00113576 _____ () C:\Users\Martina\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-20 20:29 - 2014-08-20 20:29 - 00001013 _____ () C:\Users\Public\Desktop\CHIP Updater.lnk
2014-08-20 20:29 - 2014-08-20 20:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater
2014-08-20 20:29 - 2014-08-20 20:29 - 00000000 ____D () C:\Program Files (x86)\CHIP Updater
2014-08-20 20:28 - 2014-08-20 20:28 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FontForge
2014-08-19 15:23 - 2014-08-19 15:23 - 00001100 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-19 15:23 - 2014-08-14 14:22 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-19 15:23 - 2013-08-18 13:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-08-19 15:22 - 2013-08-18 13:04 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-08-14 14:22 - 2013-08-18 13:04 - 00000000 ____D () C:\ProgramData\Avira
2014-08-14 08:08 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-14 07:52 - 2013-06-16 18:01 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-14 07:42 - 2013-08-14 20:07 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-14 07:36 - 2013-06-15 01:38 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-14 07:25 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-11 09:18 - 2014-08-06 12:12 - 00000000 ____D () C:\ProgramData\tmp
2014-08-07 08:58 - 2014-08-07 08:58 - 00000000 ____D () C:\Users\Martina\restore
2014-08-07 04:06 - 2014-08-13 20:41 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 04:01 - 2014-08-13 20:41 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-06 14:31 - 2014-08-06 12:12 - 00000000 ____D () C:\ProgramData\hps
2014-08-06 12:12 - 2014-08-06 12:12 - 00001174 _____ () C:\Users\Public\Desktop\Hartlauer Fotoviewer.lnk
2014-08-06 12:12 - 2014-08-06 12:12 - 00001174 _____ () C:\Users\Public\Desktop\Hartlauer Foto World.lnk
2014-08-06 12:12 - 2014-08-06 12:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hartlauer Foto World
2014-08-06 12:00 - 2014-08-06 12:00 - 00000000 ____D () C:\Program Files\Hartlauer Foto World
Some content of TEMP:
====================
C:\Users\Martina\AppData\Local\Temp\avgnt.exe
C:\Users\Martina\AppData\Local\Temp\SHSetup.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2013-08-29 06:40
==================== End Of Log ============================
--- --- ---