Malwarebytes Anti-Malware (Test) 1.75.0.1300
Malwarebytes : Free anti-malware download
Datenbank Version: v2013.11.14.07
Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16438
Saturn :: SAMSUNG [Administrator]
Schutz: Aktiviert
14.11.2013 20:59:14
mbam-log-2013-11-14 (20-59-14).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 222453
Laufzeit: 9 Minute(n), 7 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 4
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DigitalSite (PUP.Optional.DigitalSites.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\Software\BabSolution\Updater (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 1
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0L1N1H2O1S -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 7
C:\Users\Saturn\AppData\Roaming\DigitalSite\UpdateProc (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\DealPly (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\DealPly\UpdateProc (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\OPENCANDY (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\OPENCANDY\2150236BFC7E49AFA08776D6AA76964A (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\OPENCANDY\A4DEFE1971D448DB80E29196067481ED (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 15
C:\Users\Saturn\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe (PUP.Optional.DigitalSites.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\OpenCandy\2150236BFC7E49AFA08776D6AA76964A\LatestDLMgr.exe (PUP.Optional.OpenCandy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\Downloads\Free31213YouTubeToMP3Converter.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\Downloads\rcpafterdownloadcp_ntb_ad_13271_cpntb1.exe (PUP.Optional.RegCleanerPro) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\Downloads\ZipExtractorSetup (1).exe (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\DigitalSite\UpdateProc\config.dat (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\DigitalSite\UpdateProc\prod.dat (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\DigitalSite\UpdateProc\STTL.DAT (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\DigitalSite\UpdateProc\TTL.DAT (PUP.Optional.DigitalSite.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\DealPly\UPDATEPROC\config.dat (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\DealPly\UPDATEPROC\UpdateTask.exe (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\OPENCANDY\2150236BFC7E49AFA08776D6AA76964A\Setup1004732_DE-1.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\OPENCANDY\2150236BFC7E49AFA08776D6AA76964A\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Saturn\AppData\Roaming\OPENCANDY\A4DEFE1971D448DB80E29196067481ED\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende)AdwCleaner Logfile:
Code:
# AdwCleaner v3.012 - Bericht erstellt am 14/11/2013 um 22:51:58
# Updated 11/11/2013 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Saturn - SAMSUNG
# Gestartet von : C:\Users\Saturn\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\boost_interprocess
Ordner Gelöscht : C:\Users\Saturn\AppData\Local\Babylon
Ordner Gelöscht : C:\Users\Saturn\AppData\Roaming\Advanced System Protector
Ordner Gelöscht : C:\Users\Saturn\AppData\Roaming\digitalsite
Ordner Gelöscht : C:\Users\Saturn\AppData\Roaming\DSite
Ordner Gelöscht : C:\Users\Saturn\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Saturn\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Extensions\ffxtlbr@babylon.com
Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe
Datei Gelöscht : C:\Users\Saturn\AppData\Roaming\Mozilla\Firefox\Profiles\axxb4zd0.default\searchplugins\zonealarm.xml
Datei Gelöscht : C:\Users\Saturn\AppData\Roaming\Mozilla\Firefox\Profiles\axxb4zd0.default\user.js
Datei Gelöscht : C:\WINDOWS\System32\Tasks\Advanced System Protector
Datei Gelöscht : C:\WINDOWS\System32\Tasks\Dealply
Datei Gelöscht : C:\WINDOWS\Tasks\digitalsite.job
Datei Gelöscht : C:\WINDOWS\System32\Tasks\digitalsite
Datei Gelöscht : C:\WINDOWS\Tasks\DSite.job
Datei Gelöscht : C:\WINDOWS\System32\Tasks\DSite
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\InstalledThirdPartyPrograms
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledThirdPartyPrograms
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16384
-\\ Mozilla Firefox v25.0 (de)
[ Datei : C:\Users\Saturn\AppData\Roaming\Mozilla\Firefox\Profiles\axxb4zd0.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.delta.admin", false);
Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gelöscht : user_pref("extensions.delta.id", "c62f3709000000000000000000000000");
Zeile gelöscht : user_pref("extensions.delta.instlDay", "15963");
Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.delta.newTab", false);
Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.619:47:34");
Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta_i.babExt", "");
Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=119357&tsp=5006");
Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
*************************
AdwCleaner[R0].txt - [7046 octets] - [14/11/2013 21:48:52]
AdwCleaner[S0].txt - [6673 octets] - [14/11/2013 22:51:58]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6733 octets] ##########
--- --- ---
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 8.1 x64
Ran by Saturn on 15.11.2013 at 10:51:03,09
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Failed to delete: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
Failed to delete: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
~~~ Files
~~~ Folders
Failed to delete: [Folder] "C:\ProgramData\apn"
~~~ FireFox
Successfully deleted: [File] C:\Users\Saturn\AppData\Roaming\mozilla\firefox\profiles\axxb4zd0.default\extensions\toolbar_avira-v7@apn.ask.com.xpi
Successfully deleted: [Folder] C:\Users\Saturn\AppData\Roaming\mozilla\firefox\profiles\axxb4zd0.default\extensions\staged
~~~ Event Viewer Logs wereJRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 8.1 x64
Ran by Saturn on 15.11.2013 at 10:51:03,09
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Failed to delete: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
Failed to delete: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
~~~ Files
~~~ Folders
Failed to delete: [Folder] "C:\ProgramData\apn"
~~~ FireFox
Successfully deleted: [File] C:\Users\Saturn\AppData\Roaming\mozilla\firefox\profiles\axxb4zd0.default\extensions\toolbar_avira-v7@apn.ask.com.xpi
Successfully deleted: [Folder] C:\Users\Saturn\AppData\Roaming\mozilla\firefox\profiles\axxb4zd0.default\extensions\staged
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.11.2013 at 11:01:09,43
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-11-2013
Ran by Saturn (administrator) on SAMSUNG on 15-11-2013 11:32:11
Running from C:\Users\Saturn\Downloads
Windows 8.1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\WINDOWS\system32\atiesrxx.exe
(AMD) C:\WINDOWS\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Intel Corporation) C:\WINDOWS\system32\igfxext.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
() C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
() C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Intel Corporation) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Opera Software) C:\Program Files (x86)\Opera\17.0.1241.53\opera.exe
() C:\Program Files (x86)\Opera\17.0.1241.53\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\17.0.1241.53\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\17.0.1241.53\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\17.0.1241.53\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\17.0.1241.53\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\17.0.1241.53\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\17.0.1241.53\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\17.0.1241.53\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\17.0.1241.53\opera.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE
(Microsoft Corporation) C:\WINDOWS\splwow64.exe
(Opera Software) C:\Program Files (x86)\Opera\17.0.1241.53\opera.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Quick Starter\Quick Starter.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] - C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [766080 2012-12-05] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [128640 2012-12-05] (Atheros Communications)
HKLM\...\Run: [Bitcasa] - C:\Program Files\Bitcasa\Bitcasa.exe [3952128 2012-11-27] (Bitcasa, Inc)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917688 2012-10-16] (Synaptics Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Policies\system: [DisableLockWorkstation] 0
MountPoints2: {4b6315e7-4863-11e3-824f-806e6f6e6963} - "F:\.\Setup.exe" AUTORUN=1
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe [40312 2013-09-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [97392 2012-08-15] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1673680 2013-10-23] (APN)
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Search
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
SearchScopes: HKLM - DefaultScope {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM-x32 - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKCU - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL =
SearchScopes: HKCU - {F1A12AE8-3E1C-4DFC-B7F3-EF4D85106328} URL = hxxp://search.zonealarm.com/search?src=sp&tbid=goughGA&Lan=de&q={searchTerms}&gu=99a6beb3d4854a81ae0daf86b86d8d80&tu=10G9y00Az1C01g0&sku=&tstsId=&ver=&&r=546
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\..\Interfaces\{48454AFF-049F-41D2-908F-8728E1BBCBA5}: [NameServer]212.23.115.150 212.23.115.132
FireFox:
========
FF ProfilePath: C:\Users\Saturn\AppData\Roaming\Mozilla\Firefox\Profiles\axxb4zd0.default
FF Homepage: hxxp://search.zonealarm.com/?src=hp&tbid=goughGA&Lan=de&gu=99a6beb3d4854a81ae0daf86b86d8d80&tu=10G9y00Az1C01g0&sku=&tstsId=&ver=&
FF SelectedSearchEngine: Search By ZoneAlarm
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
==================== Services (Whitelisted) =================
R2 ALDITALKVerbindungsassistent_Service; C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [358968 2013-09-03] ()
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [815160 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [231552 2012-12-05] (Qualcomm Atheros Commnucations)
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1591176 2012-11-30] (Samsung Electronics CO., LTD.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-05] (Atheros)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132088 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [82136 2013-09-04] (Avira Operations GmbH & Co. KG)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
R1 cbfs3; C:\windows\system32\drivers\cbfs3.sys [352456 2012-08-06] (EldoS Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 ewsercd; C:\Windows\system32\DRIVERS\ewsercd.sys [112896 2013-06-11] (Huawei Technologies Co., Ltd.)
R3 ewusbnet; C:\Windows\system32\DRIVERS\ewusbnet.sys [138752 2013-07-31] (Huawei Technologies Co., Ltd.)
R3 ewusbnet; C:\Windows\SysWow64\DRIVERS\ewusbnet.sys [138752 2013-07-31] (Huawei Technologies Co., Ltd.)
S3 ew_hwusbdev; C:\Windows\SysWow64\DRIVERS\ew_hwusbdev.sys [117248 2013-07-31] (Huawei Technologies Co., Ltd.)
R3 hwdatacard; C:\Windows\SysWow64\DRIVERS\ewusbmdm.sys [121600 2013-07-31] (Huawei Technologies Co., Ltd.)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-09-30] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146272 2013-08-22] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [56672 2013-08-22] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 BTATH_LWFLT; \SystemRoot\system32\DRIVERS\btath_lwflt.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-15 11:01 - 2013-11-15 11:01 - 00001645 _____ C:\Users\Saturn\Desktop\JRT.txt
2013-11-15 10:51 - 2013-11-15 10:51 - 00000000 ____D C:\WINDOWS\ERUNT
2013-11-15 10:47 - 2013-11-15 10:50 - 01034531 _____ (Thisisu) C:\Users\Saturn\Downloads\JRT.exe
2013-11-15 08:32 - 2013-11-15 09:38 - 05744657 _____ (pdfforge GmbH) C:\Users\Saturn\Downloads\PDFCreator-1_7_1_setup.exe
2013-11-14 21:48 - 2013-11-14 22:52 - 00000000 ____D C:\AdwCleaner
2013-11-14 21:30 - 2013-11-14 21:42 - 01085542 _____ C:\Users\Saturn\Downloads\adwcleaner.exe
2013-11-14 20:40 - 2013-11-14 20:40 - 00000000 ____D C:\Users\Saturn\AppData\Roaming\Malwarebytes
2013-11-14 20:39 - 2013-11-14 20:39 - 00001121 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-14 20:39 - 2013-11-14 20:39 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-14 20:39 - 2013-11-14 20:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-14 20:39 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-11-14 20:12 - 2013-11-14 20:38 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Saturn\Downloads\mbam-setup-1.75.0.1300 (1).exe
2013-11-14 19:44 - 2013-11-14 19:52 - 02594124 _____ (Malwarebytes Corporation ) C:\Users\Saturn\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-13 19:37 - 2013-11-13 19:37 - 00000000 ____D C:\Users\Saturn\Desktop\How to spot a dangerous man
2013-11-13 18:25 - 2013-11-14 07:25 - 00000097 _____ C:\Users\Saturn\AppData\Roaming\WB.CFG
2013-11-13 18:25 - 2013-11-14 07:25 - 00000006 _____ C:\Users\Saturn\AppData\Roaming\WBPU-TTL.DAT
2013-11-13 18:13 - 2013-11-13 18:15 - 00031780 _____ C:\Users\Saturn\Downloads\Addition.txt
2013-11-13 18:11 - 2013-11-15 11:32 - 00017978 _____ C:\Users\Saturn\Downloads\FRST.txt
2013-11-13 18:11 - 2013-11-13 18:11 - 00000000 ____D C:\FRST
2013-11-13 18:02 - 2013-11-13 18:10 - 01957610 _____ (Farbar) C:\Users\Saturn\Downloads\FRST64.exe
2013-11-13 15:53 - 2013-11-13 15:55 - 00053788 _____ C:\Users\Saturn\Downloads\ZipExtractorSetup.exe
2013-11-13 10:52 - 2013-10-19 09:08 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-13 10:52 - 2013-10-19 07:37 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-11-13 10:52 - 2013-10-19 07:02 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-13 10:52 - 2013-10-19 05:37 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-13 10:52 - 2013-10-19 04:56 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-11-13 10:52 - 2013-10-19 04:23 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-11-13 10:51 - 2013-10-19 06:37 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2013-11-13 10:51 - 2013-10-19 06:19 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-13 10:51 - 2013-10-19 06:10 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-13 10:51 - 2013-10-19 05:52 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-11-13 10:51 - 2013-10-19 05:44 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-11-13 10:51 - 2013-10-19 05:31 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-11-13 10:51 - 2013-10-19 04:55 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-11-13 10:51 - 2013-10-19 04:53 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-13 10:51 - 2013-10-19 04:09 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-11-13 10:51 - 2013-10-19 04:02 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-11-13 07:33 - 2013-10-13 03:48 - 00136536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2013-11-13 07:33 - 2013-10-12 22:48 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2013-11-13 07:33 - 2013-10-12 22:34 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2013-11-13 07:31 - 2013-10-05 15:21 - 01341288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2013-11-13 07:31 - 2013-10-05 09:39 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2013-11-13 07:21 - 2013-10-16 16:58 - 01943536 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2013-11-13 07:21 - 2013-10-16 14:54 - 01581968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2013-11-12 15:24 - 2013-11-15 09:50 - 00015344 _____ C:\WINDOWS\PFRO.log
2013-11-12 11:16 - 2013-11-12 11:16 - 00000000 ____D C:\ProgramData\CheckPoint
2013-11-12 11:07 - 2013-11-12 11:13 - 02462696 _____ (Check Point Software Technologies LTD) C:\Users\Saturn\Downloads\zafwSetupWeb_120_104_000.exe
2013-11-12 06:37 - 2013-11-13 10:26 - 00000680 _____ C:\WINDOWS\setupact.log
2013-11-12 06:37 - 2013-11-12 06:37 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-11-12 06:32 - 2013-11-12 06:32 - 753001719 _____ C:\WINDOWS\MEMORY.DMP
2013-11-12 06:32 - 2013-11-12 06:32 - 00743480 _____ C:\WINDOWS\Minidump\111213-27078-01.dmp
2013-11-12 06:32 - 2013-11-12 06:32 - 00000000 ____D C:\WINDOWS\Minidump
2013-11-11 17:41 - 2013-11-11 17:41 - 103792856 _____ C:\WINDOWS\SysWOW64\䔠旵Lÿ
2013-11-10 11:02 - 2013-11-13 07:44 - 00000000 ___RD C:\WINDOWS\BrowserChoice
2013-11-08 20:45 - 2013-11-08 20:45 - 00004096 ____H C:\Users\Saturn\AppData\Local\keyfile3.drm
2013-11-08 12:23 - 2013-11-08 12:23 - 00001450 _____ C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-08 12:22 - 2013-11-08 12:22 - 00000020 ___SH C:\Users\Saturn\ntuser.ini
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Vorlagen
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Startmenü
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2013-11-08 12:19 - 2013-11-15 11:12 - 01554239 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-08 12:18 - 2013-11-08 12:18 - 00022960 _____ C:\WINDOWS\system32\emptyregdb.dat
2013-11-08 11:57 - 2013-11-08 11:57 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2013-11-08 11:56 - 2013-11-11 06:46 - 00000000 ____D C:\Users\Saturn
2013-11-08 11:56 - 2013-11-11 06:44 - 00000000 ___RD C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-08 11:56 - 2013-11-11 06:44 - 00000000 ___RD C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-08 11:56 - 2013-11-11 06:44 - 00000000 ___RD C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-08 11:56 - 2013-11-08 12:19 - 00020958 _____ C:\WINDOWS\diagwrn.xml
2013-11-08 11:56 - 2013-11-08 12:19 - 00020958 _____ C:\WINDOWS\diagerr.xml
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Vorlagen
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Startmenü
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Netzwerkumgebung
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Lokale Einstellungen
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Eigene Dateien
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Druckumgebung
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Documents\Eigene Musik
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Documents\Eigene Bilder
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\AppData\Local\Verlauf
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\AppData\Local\Anwendungsdaten
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Anwendungsdaten
2013-11-08 11:56 - 2013-08-22 16:36 - 00000000 ____D C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-08 11:51 - 2013-11-08 11:51 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2013-11-08 11:51 - 2013-11-08 11:51 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
2013-11-08 11:51 - 2013-11-08 11:51 - 00000000 ____D C:\Program Files\Realtek
2013-11-08 11:50 - 2013-11-08 11:50 - 00000264 _____ C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job
2013-11-08 11:50 - 2013-11-08 11:50 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2013-11-08 11:50 - 2013-11-08 11:50 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2013-11-08 11:50 - 2013-11-08 11:50 - 00000000 ____D C:\Program Files\Synaptics
2013-11-08 11:50 - 2013-11-08 11:50 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2013-11-08 11:50 - 2013-11-08 11:50 - 00000000 ____D C:\Program Files\AMD
2013-11-08 11:48 - 2013-11-11 07:01 - 00000000 ___DC C:\WINDOWS\Panther
2013-11-08 11:48 - 2013-11-08 11:48 - 00000000 __SHD C:\Recovery
2013-11-08 11:46 - 2013-11-08 11:46 - 02144768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 01537880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-11-08 11:46 - 2013-11-08 11:46 - 01286552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 01018960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00977408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00837120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00698880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-11-08 11:46 - 2013-11-08 11:46 - 00294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-08 11:45 - 2013-11-08 11:45 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2013-11-08 11:42 - 2013-11-08 11:42 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2013-11-08 11:42 - 2013-11-08 11:42 - 00000000 ____D C:\Program Files\Reference Assemblies
2013-11-08 11:42 - 2013-11-08 11:42 - 00000000 ____D C:\Program Files\MSBuild
2013-11-08 11:42 - 2013-11-08 11:42 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2013-11-08 11:42 - 2013-11-08 11:42 - 00000000 ____D C:\Program Files (x86)\MSBuild
2013-11-08 11:41 - 2013-08-03 05:48 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2013-11-08 11:41 - 2013-08-03 05:48 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2013-11-08 11:41 - 2013-08-03 05:48 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2013-11-08 11:41 - 2013-08-03 05:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2013-11-08 11:41 - 2013-08-03 05:41 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-11-08 11:41 - 2013-08-03 05:41 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2013-11-08 10:18 - 2013-11-08 10:18 - 04954736 _____ (Microsoft Corporation) C:\Users\Saturn\Downloads\WindowsUpgradeAssistant.exe
2013-11-08 06:47 - 2013-11-08 06:47 - 00001956 _____ C:\Users\Public\Desktop\SW Update.lnk
2013-11-08 06:36 - 2013-11-08 06:36 - 00001582 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-11-08 06:35 - 2013-11-08 06:36 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-11-08 06:31 - 2013-11-08 06:33 - 32206488 _____ (DVDVideoSoft Ltd. ) C:\Users\Saturn\Downloads\FreeYouTubeToMP3Converter.exe
2013-11-07 16:20 - 2013-11-07 16:32 - 03864904 _____ (Secunia) C:\Users\Saturn\Downloads\PSISetup_30b8013.exe
2013-11-07 09:04 - 2013-11-11 14:00 - 00000000 ____D C:\Users\Saturn\Documents\Familie
2013-10-23 13:48 - 2013-11-04 10:59 - 00000000 ____D C:\Users\Saturn\Documents\Müller-Künnemann
2013-10-18 08:32 - 2013-10-18 08:32 - 00000000 ____D C:\ProgramData\DriverGenius
2013-10-18 07:59 - 2013-10-18 08:29 - 11360472 _____ (Driver-Soft Inc. ) C:\Users\Saturn\Downloads\Driver_Genius_Professional_DE_PPC_Content.exe
2013-10-16 13:15 - 2013-10-16 13:43 - 00000000 ____D C:\Users\Saturn\Downloads\Jojo_Moyes-Ein_Ganzes_Halbes_Jahr-Abook-DE-2013-NoGroup-CannaPower
2013-10-16 13:11 - 2013-10-16 13:11 - 00000000 ____D C:\Users\Saturn\Downloads\Jojo_Moyes-Ein_Ganzes_Halbes_Jahr-Abook-DE-2013-NoGroup-CannaPower (1)
2013-10-16 09:26 - 2013-10-16 09:26 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
==================== One Month Modified Files and Folders =======
2013-11-15 11:32 - 2013-11-13 18:11 - 00017978 _____ C:\Users\Saturn\Downloads\FRST.txt
2013-11-15 11:17 - 2013-09-03 16:13 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-11-15 11:15 - 2013-01-25 04:10 - 00000360 _____ C:\WINDOWS\Tasks\Xerox PhotoCafe Communicator.job
2013-11-15 11:12 - 2013-11-08 12:19 - 01554239 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-15 11:06 - 2013-05-14 01:56 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2669165515-361187302-876288576-1001
2013-11-15 11:01 - 2013-11-15 11:01 - 00001645 _____ C:\Users\Saturn\Desktop\JRT.txt
2013-11-15 11:01 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2013-11-15 11:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru
2013-11-15 10:51 - 2013-11-15 10:51 - 00000000 ____D C:\WINDOWS\ERUNT
2013-11-15 10:50 - 2013-11-15 10:47 - 01034531 _____ (Thisisu) C:\Users\Saturn\Downloads\JRT.exe
2013-11-15 10:02 - 2013-05-14 01:46 - 00000000 ____D C:\Users\Saturn\AppData\Local\Packages
2013-11-15 10:00 - 2013-01-25 03:48 - 00000870 _____ C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2013-11-15 09:54 - 2013-01-25 03:58 - 00000000 ____D C:\ProgramData\WinClon
2013-11-15 09:50 - 2013-11-12 15:24 - 00015344 _____ C:\WINDOWS\PFRO.log
2013-11-15 09:50 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-11-15 09:50 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2013-11-15 09:50 - 2013-01-25 03:48 - 00000868 _____ C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-11-15 09:48 - 2013-11-12 11:16 - 00000000 ____D C:\ProgramData\CheckPoint
2013-11-15 09:38 - 2013-11-15 08:32 - 05744657 _____ (pdfforge GmbH) C:\Users\Saturn\Downloads\PDFCreator-1_7_1_setup.exe
2013-11-14 22:52 - 2013-11-14 21:48 - 00000000 ____D C:\AdwCleaner
2013-11-14 21:42 - 2013-11-14 21:30 - 01085542 _____ C:\Users\Saturn\Downloads\adwcleaner.exe
2013-11-14 20:40 - 2013-11-14 20:40 - 00000000 ____D C:\Users\Saturn\AppData\Roaming\Malwarebytes
2013-11-14 20:39 - 2013-11-14 20:39 - 00001121 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-14 20:39 - 2013-11-14 20:39 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-14 20:39 - 2013-11-14 20:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-14 20:38 - 2013-11-14 20:12 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Saturn\Downloads\mbam-setup-1.75.0.1300 (1).exe
2013-11-14 19:52 - 2013-11-14 19:44 - 02594124 _____ (Malwarebytes Corporation ) C:\Users\Saturn\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-14 07:25 - 2013-11-13 18:25 - 00000097 _____ C:\Users\Saturn\AppData\Roaming\WB.CFG
2013-11-14 07:25 - 2013-11-13 18:25 - 00000006 _____ C:\Users\Saturn\AppData\Roaming\WBPU-TTL.DAT
2013-11-13 23:15 - 2013-09-30 05:14 - 01780340 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-11-13 23:15 - 2013-09-30 04:56 - 00766620 _____ C:\WINDOWS\system32\perfh007.dat
2013-11-13 23:15 - 2013-09-30 04:56 - 00159902 _____ C:\WINDOWS\system32\perfc007.dat
2013-11-13 19:37 - 2013-11-13 19:37 - 00000000 ____D C:\Users\Saturn\Desktop\How to spot a dangerous man
2013-11-13 18:15 - 2013-11-13 18:13 - 00031780 _____ C:\Users\Saturn\Downloads\Addition.txt
2013-11-13 18:11 - 2013-11-13 18:11 - 00000000 ____D C:\FRST
2013-11-13 18:10 - 2013-11-13 18:02 - 01957610 _____ (Farbar) C:\Users\Saturn\Downloads\FRST64.exe
2013-11-13 15:55 - 2013-11-13 15:53 - 00053788 _____ C:\Users\Saturn\Downloads\ZipExtractorSetup.exe
2013-11-13 11:51 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache
2013-11-13 11:00 - 2013-09-02 17:32 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-13 10:58 - 2013-06-11 10:48 - 82896128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-13 10:26 - 2013-11-12 06:37 - 00000680 _____ C:\WINDOWS\setupact.log
2013-11-13 07:44 - 2013-11-10 11:02 - 00000000 ___RD C:\WINDOWS\BrowserChoice
2013-11-12 11:13 - 2013-11-12 11:07 - 02462696 _____ (Check Point Software Technologies LTD) C:\Users\Saturn\Downloads\zafwSetupWeb_120_104_000.exe
2013-11-12 06:37 - 2013-11-12 06:37 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-11-12 06:32 - 2013-11-12 06:32 - 753001719 _____ C:\WINDOWS\MEMORY.DMP
2013-11-12 06:32 - 2013-11-12 06:32 - 00743480 _____ C:\WINDOWS\Minidump\111213-27078-01.dmp
2013-11-12 06:32 - 2013-11-12 06:32 - 00000000 ____D C:\WINDOWS\Minidump
2013-11-11 22:04 - 2013-10-11 09:25 - 00000000 ____D C:\Users\Saturn\Documents\Innere Stärke
2013-11-11 17:41 - 2013-11-11 17:41 - 103792856 _____ C:\WINDOWS\SysWOW64\䔠旵Lÿ
2013-11-11 14:00 - 2013-11-07 09:04 - 00000000 ____D C:\Users\Saturn\Documents\Familie
2013-11-11 07:01 - 2013-11-08 11:48 - 00000000 ___DC C:\WINDOWS\Panther
2013-11-11 06:46 - 2013-11-08 11:56 - 00000000 ____D C:\Users\Saturn
2013-11-11 06:44 - 2013-11-08 11:56 - 00000000 ___RD C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-11 06:44 - 2013-11-08 11:56 - 00000000 ___RD C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-11 06:44 - 2013-11-08 11:56 - 00000000 ___RD C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-11 06:44 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2013-11-11 06:26 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\registration
2013-11-11 06:26 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2013-11-10 09:11 - 2013-06-11 03:22 - 00000000 ____D C:\Users\Saturn\AppData\Local\CrashDumps
2013-11-08 20:45 - 2013-11-08 20:45 - 00004096 ____H C:\Users\Saturn\AppData\Local\keyfile3.drm
2013-11-08 19:06 - 2013-09-02 15:23 - 00000000 ____D C:\Users\Saturn\AppData\Local\Mozilla
2013-11-08 13:20 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\restore
2013-11-08 12:47 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\tracing
2013-11-08 12:23 - 2013-11-08 12:23 - 00001450 _____ C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-08 12:23 - 2013-05-14 01:49 - 00000000 ___RD C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-08 12:23 - 2013-05-14 01:49 - 00000000 ___RD C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-08 12:22 - 2013-11-08 12:22 - 00000020 ___SH C:\Users\Saturn\ntuser.ini
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Vorlagen
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Startmenü
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2013-11-08 12:20 - 2013-11-08 12:20 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2013-11-08 12:20 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Windows NT
2013-11-08 12:20 - 2013-08-22 14:36 - 00000000 __RHD C:\Users\Default
2013-11-08 12:19 - 2013-11-08 11:56 - 00020958 _____ C:\WINDOWS\diagwrn.xml
2013-11-08 12:19 - 2013-11-08 11:56 - 00020958 _____ C:\WINDOWS\diagerr.xml
2013-11-08 12:18 - 2013-11-08 12:18 - 00022960 _____ C:\WINDOWS\system32\emptyregdb.dat
2013-11-08 12:08 - 2013-08-22 16:36 - 00000000 __RSD C:\WINDOWS\Media
2013-11-08 12:08 - 2013-01-25 03:58 - 01804472 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2013-11-08 12:07 - 2013-08-22 16:36 - 00000000 __RHD C:\Users\Public\Libraries
2013-11-08 12:03 - 2013-08-22 15:44 - 02194128 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-08 12:02 - 2013-08-22 14:25 - 00008192 ___SH C:\WINDOWS\system32\config\ELAM
2013-11-08 12:01 - 2012-07-26 06:37 - 00000000 ____D C:\Users\Default.migrated
2013-11-08 12:00 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2013-11-08 12:00 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2013-11-08 12:00 - 2013-09-30 04:56 - 00000000 ____D C:\WINDOWS\system32\WCN
2013-11-08 12:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2013-11-08 12:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2013-11-08 12:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2013-11-08 12:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\spool
2013-11-08 12:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2013-11-08 12:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\MUI
2013-11-08 12:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\IME
2013-11-08 12:00 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2013-11-08 12:00 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\system32\oobe
2013-11-08 12:00 - 2013-01-25 03:46 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2013-11-08 11:59 - 2013-09-30 04:59 - 00000000 ____D C:\WINDOWS\ShellNew
2013-11-08 11:59 - 2013-08-22 16:43 - 00000000 ____D C:\WINDOWS\DigitalLocker
2013-11-08 11:59 - 2013-08-22 16:36 - 00000000 __SHD C:\Program Files\Windows Sidebar
2013-11-08 11:59 - 2013-08-22 16:36 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2013-11-08 11:59 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2013-11-08 11:59 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\IME
2013-11-08 11:59 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Help
2013-11-08 11:59 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\System
2013-11-08 11:59 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-11-08 11:59 - 2013-01-25 20:09 - 00000000 ____D C:\WINDOWS\en-GB
2013-11-08 11:59 - 2013-01-25 04:10 - 00000000 ____D C:\WINDOWS\de
2013-11-08 11:59 - 2013-01-25 04:09 - 00000000 ____D C:\WINDOWS\it
2013-11-08 11:59 - 2013-01-25 04:09 - 00000000 ____D C:\WINDOWS\fr
2013-11-08 11:59 - 2012-08-05 22:11 - 00000000 ____D C:\ProgramData\PRICache
2013-11-08 11:57 - 2013-11-08 11:57 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2013-11-08 11:57 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\Recovery
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Vorlagen
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Startmenü
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Netzwerkumgebung
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Lokale Einstellungen
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Eigene Dateien
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Druckumgebung
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Documents\Eigene Musik
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Documents\Eigene Bilder
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\AppData\Local\Verlauf
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\AppData\Local\Anwendungsdaten
2013-11-08 11:56 - 2013-11-08 11:56 - 00000000 _SHDL C:\Users\Saturn\Anwendungsdaten
2013-11-08 11:51 - 2013-11-08 11:51 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2013-11-08 11:51 - 2013-11-08 11:51 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
2013-11-08 11:51 - 2013-11-08 11:51 - 00000000 ____D C:\Program Files\Realtek
2013-11-08 11:50 - 2013-11-08 11:50 - 00000264 _____ C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job
2013-11-08 11:50 - 2013-11-08 11:50 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2013-11-08 11:50 - 2013-11-08 11:50 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2013-11-08 11:50 - 2013-11-08 11:50 - 00000000 ____D C:\Program Files\Synaptics
2013-11-08 11:50 - 2013-11-08 11:50 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2013-11-08 11:50 - 2013-11-08 11:50 - 00000000 ____D C:\Program Files\AMD
2013-11-08 11:48 - 2013-11-08 11:48 - 00000000 __SHD C:\Recovery
2013-11-08 11:47 - 2013-08-22 16:36 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template
2013-11-08 11:46 - 2013-11-08 11:46 - 02144768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 01537880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-11-08 11:46 - 2013-11-08 11:46 - 01286552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 01018960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00977408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00837120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00698880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-11-08 11:46 - 2013-11-08 11:46 - 00294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2013-11-08 11:46 - 2013-11-08 11:46 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-08 11:46 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore
2013-11-08 11:46 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Camera
2013-11-08 11:45 - 2013-11-08 11:45 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2013-11-08 11:42 - 2013-11-08 11:42 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2013-11-08 11:42 - 2013-11-08 11:42 - 00000000 ____D C:\Program Files\Reference Assemblies
2013-11-08 11:42 - 2013-11-08 11:42 - 00000000 ____D C:\Program Files\MSBuild
2013-11-08 11:42 - 2013-11-08 11:42 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2013-11-08 11:42 - 2013-11-08 11:42 - 00000000 ____D C:\Program Files (x86)\MSBuild
2013-11-08 11:42 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2013-11-08 10:18 - 2013-11-08 10:18 - 04954736 _____ (Microsoft Corporation) C:\Users\Saturn\Downloads\WindowsUpgradeAssistant.exe
2013-11-08 09:29 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2013-11-08 06:47 - 2013-11-08 06:47 - 00001956 _____ C:\Users\Public\Desktop\SW Update.lnk
2013-11-08 06:36 - 2013-11-08 06:36 - 00001582 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-11-08 06:36 - 2013-11-08 06:35 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-11-08 06:35 - 2013-10-08 18:11 - 00000000 ___RD C:\Users\Public\Desktop\DVDVideoSoft
2013-11-08 06:35 - 2013-10-08 18:11 - 00000000 ____D C:\Users\Saturn\AppData\Roaming\DVDVideoSoft
2013-11-08 06:33 - 2013-11-08 06:31 - 32206488 _____ (DVDVideoSoft Ltd. ) C:\Users\Saturn\Downloads\FreeYouTubeToMP3Converter.exe
2013-11-08 05:38 - 2013-09-03 15:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-08 05:38 - 2013-09-02 15:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-08 05:37 - 2013-09-15 19:24 - 00001004 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-11-08 05:26 - 2013-09-03 18:02 - 00000000 ____D C:\Program Files (x86)\Opera
2013-11-08 05:21 - 2013-09-03 13:32 - 00000000 ____D C:\Users\Saturn\AppData\Roaming\ALDITALKVerbindungsassistent
2013-11-07 18:33 - 2013-10-11 09:24 - 00000000 ____D C:\Users\Saturn\Documents\Übungsordner
2013-11-07 16:32 - 2013-11-07 16:20 - 03864904 _____ (Secunia) C:\Users\Saturn\Downloads\PSISetup_30b8013.exe
2013-11-06 00:31 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2013-11-06 00:31 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-04 11:30 - 2013-10-15 09:08 - 00000000 ___RD C:\Users\Saturn\SkyDrive
2013-11-04 10:59 - 2013-10-23 13:48 - 00000000 ____D C:\Users\Saturn\Documents\Müller-Künnemann
2013-10-19 09:08 - 2013-11-13 10:52 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-10-19 07:58 - 2013-09-15 19:24 - 00000000 ____D C:\Users\Saturn\AppData\Roaming\vlc
2013-10-19 07:37 - 2013-11-13 10:52 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-10-19 07:02 - 2013-11-13 10:52 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-10-19 06:37 - 2013-11-13 10:51 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2013-10-19 06:19 - 2013-11-13 10:51 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-10-19 06:10 - 2013-11-13 10:51 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-10-19 05:52 - 2013-11-13 10:51 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-10-19 05:44 - 2013-11-13 10:51 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-10-19 05:37 - 2013-11-13 10:52 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-10-19 05:31 - 2013-11-13 10:51 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-10-19 04:56 - 2013-11-13 10:52 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-10-19 04:55 - 2013-11-13 10:51 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-10-19 04:53 - 2013-11-13 10:51 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-10-19 04:23 - 2013-11-13 10:52 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-10-19 04:09 - 2013-11-13 10:51 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-10-19 04:02 - 2013-11-13 10:51 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-10-18 08:32 - 2013-10-18 08:32 - 00000000 ____D C:\ProgramData\DriverGenius
2013-10-18 08:29 - 2013-10-18 07:59 - 11360472 _____ (Driver-Soft Inc. ) C:\Users\Saturn\Downloads\Driver_Genius_Professional_DE_PPC_Content.exe
2013-10-16 16:58 - 2013-11-13 07:21 - 01943536 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2013-10-16 14:54 - 2013-11-13 07:21 - 01581968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2013-10-16 13:43 - 2013-10-16 13:15 - 00000000 ____D C:\Users\Saturn\Downloads\Jojo_Moyes-Ein_Ganzes_Halbes_Jahr-Abook-DE-2013-NoGroup-CannaPower
2013-10-16 13:11 - 2013-10-16 13:11 - 00000000 ____D C:\Users\Saturn\Downloads\Jojo_Moyes-Ein_Ganzes_Halbes_Jahr-Abook-DE-2013-NoGroup-CannaPower (1)
2013-10-16 09:26 - 2013-10-16 09:26 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey\EasySurvey.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-08 11:48
==================== End Of Log ============================
--- --- ---