Silke12345 | 30.04.2015 01:32 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 30.04.2015
Suchlauf-Zeit: 07:27:31
Logdatei: MBAM.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.04.29.06
Rootkit Datenbank: v2015.04.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Silke Laptop
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 439053
Verstrichene Zeit: 21 Min, 52 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 8
PUP.Optional.Binkiland.A, HKLM\SOFTWARE\CLASSES\APPID\{a5bbb804-8009-4246-bed3-2d3335981ef6}, In Quarantäne, [dd7df77bcbbfb1850ecdd171669df10f],
PUP.Optional.Binkiland.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{A5BBB804-8009-4246-BED3-2D3335981EF6}, In Quarantäne, [dd7df77bcbbfb1850ecdd171669df10f],
PUP.Optional.Binkiland.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{A5BBB804-8009-4246-BED3-2D3335981EF6}, In Quarantäne, [dd7df77bcbbfb1850ecdd171669df10f],
PUP.Optional.Binkiland.C, HKLM\SOFTWARE\CLASSES\APPID\{A5BBB804-8009-4246-BED3-2D3335981EF6}\INSTL\DATA, In Quarantäne, [ed6da6ccc0ca60d62e1df9cfe41f827e],
PUP.Optional.Binkiland.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{A5BBB804-8009-4246-BED3-2D3335981EF6}\INSTL\DATA, In Quarantäne, [c3976d050b7fe0561e2dc2060df6e41c],
PUP.Optional.IntelliTerm.A, HKLM\SOFTWARE\WOW6432NODE\IntelliTerm_1.10.0.8, In Quarantäne, [6febef83ddad62d4e137d1870500da26],
PUP.Optional.Binkiland.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{A5BBB804-8009-4246-BED3-2D3335981EF6}\INSTL\DATA, In Quarantäne, [2b2f3a386a2049edc5864e7a0af93dc3],
PUP.Optional.BabylonToolBar.A, HKU\S-1-5-21-3889148614-2962051019-789845505-1000\SOFTWARE\BabylonToolbar, In Quarantäne, [3c1edb976327c96d2698fb35ba4b11ef],
Registrierungswerte: 4
PUP.Optional.Binkiland.C, HKLM\SOFTWARE\CLASSES\APPID\{a5bbb804-8009-4246-bed3-2d3335981ef6}\INSTL\DATA|tlbrSrchUrl, hxxp://binkiland.com/?f=3&a=bnk_soft_15_07&cd=2XzuyEtN2Y1L1Qzu0D0CtD0E0AtC0F0EtBtAyDtAtD0C0B0AtN0D0Tzu0StCtCtAyCtN1L2XzutAtFyBtFyBtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyBtAyEtByDyCtAzytG0E0DtBtBtGyD0F0BtAtGtCyE0E0BtGyE0FtB0B0C0F0EyB0CyEzy0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyCyD0D0BzzyE0EtGzz0A0C0BtGyE0C0EyEtGzzyCzytDtGtDyB0AyE0C0AyCtDyE0Ezy0C2Q&cr=1013186760&ir=&q=, In Quarantäne, [ed6da6ccc0ca60d62e1df9cfe41f827e]
PUP.Optional.Binkiland.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{a5bbb804-8009-4246-bed3-2d3335981ef6}\INSTL\DATA|tlbrSrchUrl, hxxp://binkiland.com/?f=3&a=bnk_soft_15_07&cd=2XzuyEtN2Y1L1Qzu0D0CtD0E0AtC0F0EtBtAyDtAtD0C0B0AtN0D0Tzu0StCtCtAyCtN1L2XzutAtFyBtFyBtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyBtAyEtByDyCtAzytG0E0DtBtBtGyD0F0BtAtGtCyE0E0BtGyE0FtB0B0C0F0EyB0CyEzy0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyCyD0D0BzzyE0EtGzz0A0C0BtGyE0C0EyEtGzzyCzytDtGtDyB0AyE0C0AyCtDyE0Ezy0C2Q&cr=1013186760&ir=&q=, In Quarantäne, [c3976d050b7fe0561e2dc2060df6e41c]
PUP.Optional.Binkiland.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{a5bbb804-8009-4246-bed3-2d3335981ef6}\INSTL\DATA|tlbrSrchUrl, hxxp://binkiland.com/?f=3&a=bnk_soft_15_07&cd=2XzuyEtN2Y1L1Qzu0D0CtD0E0AtC0F0EtBtAyDtAtD0C0B0AtN0D0Tzu0StCtCtAyCtN1L2XzutAtFyBtFyBtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyBtAyEtByDyCtAzytG0E0DtBtBtGyD0F0BtAtGtCyE0E0BtGyE0FtB0B0C0F0EyB0CyEzy0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyCyD0D0BzzyE0EtGzz0A0C0BtGyE0C0EyEtGzzyCzytDtGtDyB0AyE0C0AyCtDyE0Ezy0C2Q&cr=1013186760&ir=&q=, In Quarantäne, [2b2f3a386a2049edc5864e7a0af93dc3]
PUP.Optional.Binkiland.C, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\WSE_Binkiland\\, In Quarantäne, [e179531f593169cdc88d5375df24e818]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 0
(Keine schädliche Elemente gefunden)
Dateien: 5
PUP.Optional.OnlySearch.A, C:\Users\Silke Laptop\AppData\Local\Temp\bus3763\update.exe, In Quarantäne, [5406b4be8505f343d4c879e5996705fb],
PUP.Optional.Vitruvian.A, C:\Users\Silke Laptop\AppData\Local\Temp\vitruvian-installer-hardwareprofile-v0001, In Quarantäne, [5109cfa38cfe60d65a914311db2adf21],
PUP.Optional.Vitruvian.A, C:\Users\Silke Laptop\AppData\Local\Temp\vitruvian-installer-install-v0003, In Quarantäne, [6ceee48e9ceee94d25c6fb59ce37bf41],
PUP.Optional.Vitruvian.A, C:\Users\Silke Laptop\AppData\Local\Temp\vitruvian-installer-processes-v0002, In Quarantäne, [a0ba7101f4960d29b2397fd5788d8a76],
PUP.Optional.Vitruvian.A, C:\Users\Silke Laptop\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001, In Quarantäne, [293162107119142226c50c489f669967],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.6 (04.28.2015:1)
OS: Windows 7 Home Premium x64
Ran by Silke Laptop on 30.04.2015 at 8:10:11,37
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{03FE0228-607B-407F-A604-C17B87BB7C35}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{065F2561-4C54-4B74-9541-34B3D2680514}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{1066AB70-745A-4561-9E68-5332AE1765D6}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{160DB1E5-E752-4053-8A9C-C5F6722899B2}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{164195B1-7F2C-4296-9E1B-86F85120D5B4}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{1709C929-03A5-4883-83C7-5486641CF1EC}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{1889EAB8-18FD-4FF1-BEBE-FA072136F8F8}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{1B8CCC47-FE89-4777-888F-161E46EF0C0B}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{1CE2E273-0182-4AC7-B51A-DB27AB5BC684}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{1EA08129-0880-4F11-8C24-74938AC465DD}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{23662E53-D8F5-4587-A394-16230142963A}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{2853F18B-6FBC-4075-BBBA-8BEB64771014}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{2E213564-6763-4721-BDE0-8B691F5C307B}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{30A4F14E-0E8D-4191-92B7-2416A8E0BBB9}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{324B49B7-A72F-4ADA-9E79-26EC719C1CB6}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{33A57856-F88E-4911-AA43-6BB9C8087945}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{3548271E-6A15-4D25-8A80-F62AAC8A5CED}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{36677548-CE5A-47D3-9475-7C77C4527ECE}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{3793E05A-0BAE-467E-8042-39933236A71E}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{40893CD3-E295-49AC-ADE6-51B7D69783DD}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{4135735A-8BF4-4E45-B4FA-A5739514F9A4}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{44463440-2E73-46B2-B7AB-EE85CFFB701E}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{44AEB431-7078-4C2A-B9B2-139816AD10B0}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{466CE0EB-033C-4552-B888-BA31D7C799EC}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{4901A17A-A170-444B-8E5E-87FA72C89FBC}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{4AD57B73-33B1-40F2-BA3C-C1340A9A2C4D}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{4C59C220-8AC2-46A7-8226-4680F055F50D}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{50097228-7E54-4912-A61C-515C8E519693}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{5137DC15-9719-498A-96BD-FD08B5A76B58}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{520CECC2-5F0A-42C5-A0E8-C1D506CA78C3}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{5210624A-B124-47E1-9CE6-3016FDD6CB13}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{57CA22C3-A809-40AE-9A28-3F43C5CC3742}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{5998C65A-EC65-4FF7-B1AF-E5FFDBB52977}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{59B606D6-CFAB-45C2-BB31-4C3079564041}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{5B7D6154-A7BF-447A-B130-456784483EA8}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{5B843C79-60AB-4A57-A021-5E10C1477B9D}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{5D65CFAC-E1C1-4989-A2EB-91EDA9A6C0CA}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{5D897D4C-BF0B-4970-A64D-EC993C0AD2AF}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{5D9EC1D9-7595-4703-BD18-D7FA87DDE38C}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{63A01B90-CCE1-4CD9-BD90-E2CFE899399E}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{64DB2A7B-3A99-4E0E-B18B-BA4C6DBE6D2E}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{6842F585-1063-41FF-B507-A85C60ED5C6E}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{697F10F3-B8BC-4C64-A480-D3D78FB83CBD}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{6A46431D-CEDC-468D-8E48-31DB525E29FC}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{6C37E225-8AB9-4D44-AF74-E0F91C7DBF19}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{6CEE8F80-8047-4444-8EE6-030FD6E870CC}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{6D285282-97B2-4111-9E2E-7813E9688928}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{72D9A6ED-7C83-4902-94C6-37B8AC8C51D9}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{7392EFD3-8D72-4139-B210-4F697DD90825}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{741057A5-9399-4721-BE60-9BC8B83B5B3B}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{74BAA508-732D-418B-AA98-C81A4C8E4B35}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{74F3B308-5FF1-4436-A71B-F283EE6930A0}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{7A290FE7-A19B-4022-AA9B-B930BEBC7EF9}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{7A6011B7-3582-453E-8EAB-FB686A9FC16F}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{7F0C573E-6B49-4394-A707-FA4C5F410365}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{8444C8D7-55FA-46F7-AB43-28B473FD143E}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{84D529F7-4471-48F2-8D7E-6F8A44440D66}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{85AF6497-7FA5-4554-9C6E-61325E431F27}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{8770C036-2644-46FB-9E13-C9CA12CE32CC}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{877289ED-AE2A-421D-B890-D93872101028}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{89791653-ADA3-41B4-8906-F579EB2D1FDC}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{8D0E91BF-C1AE-437C-AD58-237C8C0E5B49}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{973745E0-F92A-4C2A-AB9F-926E11A9BF5A}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{9C6B1581-DC0D-4D71-B052-47B5B23B36CA}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{9E333299-2B71-447A-8003-56D1929AE52F}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{A17E3B0A-F910-4626-AA70-CF84A35353AD}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{A1968988-87B5-4FA0-975A-04C17149DB33}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{A3993BE9-8E48-4214-A99F-ACBB2B232128}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{A4831FC4-DDD4-42D8-8767-5E22BE120546}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{A77EA137-CDE1-419B-A95D-7AD07D8366D7}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{A7B1806F-738C-49E2-A207-618A152B4666}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{A7F0C83C-3EE5-423B-9E1E-F1865526A6DB}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{A90FAC89-EFDB-4F28-A42E-EDBD5EFA9FD6}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{AC4A3ADF-C6D3-4F3A-9643-A36EAB9DFD74}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{AE01197B-63D9-49A5-9EED-AFA7A59EC7CA}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{B30DB045-BAC8-446A-A5B8-910304B69CB0}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{B5407F99-6BC9-4478-B0C3-C4EEEC28E215}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{B5E48F17-04C3-4ECF-99CF-CE712DA70FFF}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{BC15B390-B805-485A-A1D2-1C6BE8AAA63A}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{BC91AFED-BA90-40F8-866F-A26F16C70B13}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{BF3F271A-B217-4D38-9BB5-8853C7708259}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{C0211EA8-D68F-4291-AD22-FF6F2A9FACC5}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{C34C10AE-0FDD-4699-B77A-3312A54863A9}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{C63CDACD-65EA-41A6-AF43-D417FD0742C4}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{C6EA1A7A-6F0F-4874-AE6F-F98C0869C277}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{C940FB57-6DD2-4171-84D1-4876F5119680}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{CC7E87FD-90A7-406A-A052-6E4F6EB7039A}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{CFFB0052-1272-4724-9F5C-CC6FB3AD2E14}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{D1CC9E9E-639A-4D15-97BF-ED69ECE31E69}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{D2E9EEEA-5A1A-4795-B74F-C1C589E95B83}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{D473D13D-C1B0-4175-82B5-2A45D6FCF3D3}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{D79517C3-CEEF-4F56-B70C-5B98359F32E7}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{D92CE70D-DB4D-4205-BF45-28534CB5F24C}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{DD3022B1-899B-42DF-AED8-0E3A96E91F95}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{DFF9549C-CABF-4618-9EB5-E227F4E45C1D}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{E1FB70B2-F6E9-4721-836A-6A78A4C3EDD4}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{E5F16E9C-B876-4ACA-9CF9-BB78942B3B0D}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{E92FDBA6-43A2-42FE-9FB2-B706580F9E7B}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{EE548651-00F7-48C1-995B-B26F3D764514}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{EEC4DC78-6223-486D-82F8-629CE483977F}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{F12B6BB6-087D-487F-A51A-8AC0822237CD}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{F21577DE-CD4C-42E4-9316-425B6BC44A0B}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{F227C935-90B1-42BF-A466-11091C0170CD}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{F26DF76F-835B-4990-9CC8-CA891AC6B272}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{F47F0457-CE89-4D6D-B854-9A074081BCE2}
Successfully deleted: [Empty Folder] C:\Users\Silke Laptop\appdata\local\{F51E741D-CB5B-4E7B-B6A7-C36848144D99}
Successfully deleted: [Folder] C:\Program Files (x86)\myfree codec
~~~ FireFox
Emptied folder: C:\Users\Silke Laptop\AppData\Roaming\mozilla\firefox\profiles\6su7ocoe.default\minidumps [3 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.04.2015 at 8:13:28,18
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-04-2015 01
Ran by Silke Laptop (administrator) on SILKELENOVO on 30-04-2015 08:25:16
Running from C:\Users\Silke Laptop\Desktop
Loaded Profiles: Silke Laptop (Available profiles: UpdatusUser & Silke Laptop)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [564352 2011-12-15] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2809856 2012-01-17] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\btvstack.exe [1022592 2012-04-28] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\athbttray.exe [801920 2012-04-28] (Atheros Commnucations)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8079408 2012-07-18] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6202416 2012-07-18] (Lenovo(beijing) Limited)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1793736 2015-02-23] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-30] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [507744 2011-12-20] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [548864 2011-12-09] (Vimicro)
HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2012-01-26] (Lenovo, Inc.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-07-18] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [LockKey] => C:\Program Files (x86)\LockKey\LockKey.exe [337776 2011-08-26] ( )
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-02-03] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-23] (Hewlett-Packard)
HKLM-x32\...\Run: [AllShareAgent] => C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe [285072 2012-03-02] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3889148614-2962051019-789845505-1001\...\Run: [KiesAirMessage] => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe [578560 2013-05-22] (Samsung Electronics)
HKU\S-1-5-21-3889148614-2962051019-789845505-1001\...\Run: [] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-03] (Samsung)
HKU\S-1-5-21-3889148614-2962051019-789845505-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3889148614-2962051019-789845505-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3889148614-2962051019-789845505-1001\...\MountPoints2: {6a3de366-b655-11e2-b103-74e5437befb1} - G:\Setup.exe
HKU\S-1-5-21-3889148614-2962051019-789845505-1001\...\MountPoints2: {9ad3446a-cab9-11e3-800a-74e5437befb1} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\start.exe
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174856 2015-02-23] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156840 2015-02-23] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2012-12-23]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Silke Laptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-03-06]
ShortcutTarget: Dropbox.lnk -> C:\Users\Silke Laptop\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Silke Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Silke Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Silke Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Silke Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Silke Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Silke Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Silke Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Silke Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-02-15] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-02-15] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-02-15] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-02-15] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\Windows\system32\IcnOvrly.dll [2012-07-18] ()
BootExecute: autocheck autochk * FbDefrag
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3889148614-2962051019-789845505-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.de/
HKU\S-1-5-21-3889148614-2962051019-789845505-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKLM -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3889148614-2962051019-789845505-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-05-28] (Kaspersky Lab ZAO)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-05-28] (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-05-28] (Kaspersky Lab ZAO)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-05-28] (Kaspersky Lab ZAO)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-24] (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-04-28] (Atheros Commnucations)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-05-28] (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-24] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-05-28] (Kaspersky Lab ZAO)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKU\S-1-5-21-3889148614-2962051019-789845505-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://cortalconsors.webex.com/client/WBXclient-T28L10NSP12EP6-17378/nbr/ieatgpc1.cab
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 202.106.195.68 202.106.46.151
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Silke Laptop\AppData\Roaming\Mozilla\Firefox\Profiles\6su7ocoe.default
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-16] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-16] ()
FF Plugin-x32: @cfca.com/SecEditCtl.BOC,version=1.0.0.9 -> C:\Windows\system32\npSecEditCtl.BOC.x86.dll No File
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-08] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-24] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-25] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-10] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: Astrill Proxy Switcher - C:\Users\Silke Laptop\AppData\Roaming\Mozilla\Firefox\Profiles\6su7ocoe.default\Extensions\addon@astrill.com [2015-01-25]
FF Extension: Yahoo! Toolbar - C:\Users\Silke Laptop\AppData\Roaming\Mozilla\Firefox\Profiles\6su7ocoe.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2015-04-27]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-12-23]
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-24]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-24]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-24]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-24]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-24]
FF HKU\S-1-5-21-3889148614-2962051019-789845505-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR Profile: C:\Users\Silke Laptop\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2014-05-28]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2014-05-28]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2014-05-28]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2014-05-28]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2014-05-28]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 ASOVPNHelper; C:\Program Files (x86)\Astrill\ASOvpnSvc.exe [434016 2014-09-08] (Astrill)
S3 ASProxy; C:\Program Files (x86)\Astrill\ASProxy.exe [2169368 2014-11-16] (Astrill)
S2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [119424 2012-04-28] (Atheros Commnucations) [File not signed]
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2014-05-28] (Kaspersky Lab ZAO)
S4 DamageGuardSvc; C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe [572976 2012-03-26] (Lenovo (Beijing) Limited)
S2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3736520 2015-01-29] (devolo AG)
S2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-28] (Intel Corporation)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [30184 2013-08-08] ()
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [163456 2012-04-28] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 asvpndrv; C:\Windows\System32\DRIVERS\asvpndrv.sys [31744 2014-05-17] (Astrill)
S4 DamageGuard; C:\Windows\System32\DRIVERS\DamageGuardX64.sys [217392 2012-02-10] (Lenovo)
S4 dgFltr; C:\Windows\System32\drivers\dgFltrX64.sys [23648 2011-12-13] (Lenovo)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-05-22] () [File not signed]
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-05-28] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-05-28] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-05-28] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2014-05-28] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-05-28] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2014-05-28] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-05-28] (Kaspersky Lab ZAO)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104048 2012-03-02] (Qualcomm Atheros Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2015-01-29] (CACE Technologies)
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-06-11] (Audials AG)
U3 BcmSqlStartupSvc; No ImagePath
U2 CLKMSVC10_3A60B698; No ImagePath
U2 CLKMSVC10_C3B3B687; No ImagePath
U2 DriverService; No ImagePath
U2 iATAgentService; No ImagePath
U2 idealife Update Service; No ImagePath
U3 IGRS; No ImagePath
U2 IviRegMgr; No ImagePath
U2 Oasis2Service; No ImagePath
U2 PCCarerService; No ImagePath
U2 ReadyComm.DirectRouter; No ImagePath
U2 RichVideo; No ImagePath
U2 RtLedService; No ImagePath
U2 SeaPort; No ImagePath
U2 SoftwareService; No ImagePath
U3 SQLWriter; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 08:16 - 2015-04-30 08:16 - 00000000 ____D () C:\Users\Silke Laptop\Downloads\FRST-OlderVersion
2015-04-30 08:13 - 2015-04-30 08:13 - 00012793 _____ () C:\Users\Silke Laptop\Desktop\JRT.txt
2015-04-30 08:10 - 2015-04-30 08:10 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-SILKELENOVO-Windows-7-Home-Premium-(64-bit).dat
2015-04-30 08:10 - 2015-04-30 08:10 - 00000000 ____D () C:\RegBackup
2015-04-30 08:09 - 2015-04-30 08:09 - 02716174 _____ (Thisisu) C:\Users\Silke Laptop\Downloads\JRT.exe
2015-04-30 08:07 - 2015-04-30 08:07 - 00004993 _____ () C:\Users\Silke Laptop\Desktop\MBAM.txt
2015-04-30 07:55 - 2015-04-30 07:55 - 00065536 ___HT () C:\Users\Silke Laptop\Documents\~Outlook.pst.tmp
2015-04-30 07:26 - 2015-04-30 08:01 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-30 07:26 - 2015-04-30 07:26 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-30 07:26 - 2015-04-30 07:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-30 07:26 - 2015-04-30 07:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-30 07:26 - 2015-04-30 07:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-04-30 07:26 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-30 07:26 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-30 07:26 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-30 07:24 - 2015-04-30 07:24 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Silke Laptop\Downloads\mbam-setup-2.1.6.1022.exe
2015-04-28 09:23 - 2015-04-28 09:27 - 00059768 _____ () C:\Users\Silke Laptop\Downloads\Addition.txt
2015-04-28 09:22 - 2015-04-30 08:25 - 00027610 _____ () C:\Users\Silke Laptop\Desktop\FRST.txt
2015-04-28 09:22 - 2015-04-30 08:25 - 00000000 ____D () C:\FRST
2015-04-28 09:20 - 2015-04-30 08:16 - 02101248 _____ (Farbar) C:\Users\Silke Laptop\Desktop\FRST64.exe
2015-04-28 08:23 - 2014-12-12 01:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-04-28 08:23 - 2014-09-05 10:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-04-28 08:23 - 2014-09-05 09:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-04-27 19:25 - 2015-04-27 19:25 - 00001170 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-27 19:25 - 2015-04-27 19:25 - 00001158 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-04-27 19:25 - 2015-04-27 19:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-27 15:20 - 2015-04-27 15:31 - 00000000 ____D () C:\AdwCleaner
2015-04-27 15:18 - 2015-04-27 15:19 - 02224640 _____ () C:\Users\Silke Laptop\Downloads\adwcleaner_4.202.exe
2015-04-27 14:08 - 2015-04-27 14:08 - 00000000 ____D () C:\Users\Silke Laptop\AppData\Local\NVIDIA
2015-04-27 14:07 - 2015-04-27 14:07 - 00000000 ____D () C:\Windows\SysWOW64\NV
2015-04-27 14:07 - 2015-04-27 14:07 - 00000000 ____D () C:\Windows\system32\NV
2015-04-27 13:59 - 2013-10-02 10:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-04-27 13:59 - 2013-10-02 10:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-04-27 13:59 - 2013-10-02 10:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-04-27 13:59 - 2013-10-02 09:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-04-27 13:59 - 2013-10-02 09:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-04-27 13:59 - 2013-10-02 09:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-04-27 13:59 - 2013-10-02 09:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-04-27 13:59 - 2013-10-02 08:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-04-27 13:59 - 2013-10-02 08:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2015-04-27 13:59 - 2013-10-02 08:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2015-04-27 13:59 - 2013-10-02 08:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-04-27 13:59 - 2013-10-02 07:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-04-27 13:59 - 2013-10-02 07:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-04-27 13:59 - 2013-10-02 07:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-04-27 13:59 - 2013-10-02 06:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2015-04-27 13:41 - 2015-03-14 11:21 - 01632768 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-04-27 13:41 - 2015-03-14 11:21 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-04-27 13:41 - 2015-03-14 11:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-04-27 13:41 - 2015-03-14 11:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-04-27 13:41 - 2015-01-29 11:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-04-27 13:41 - 2015-01-29 11:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2015-04-25 14:57 - 2015-04-25 14:57 - 00000165 ____H () C:\Users\Silke Laptop\Desktop\~$China.xlsx
2015-04-19 13:18 - 2015-04-29 17:06 - 00037979 _____ () C:\Users\Silke Laptop\Desktop\China.xlsx
2015-04-19 11:30 - 2015-04-19 11:30 - 00750672 _____ () C:\Windows\Minidump\041915-21200-01.dmp
2015-04-17 12:36 - 2015-04-17 12:36 - 01234944 _____ () C:\Windows\Minidump\041715-21309-01.dmp
2015-04-16 17:55 - 2015-04-16 17:55 - 00003204 _____ () C:\Windows\System32\Tasks\{86DF11BE-D0F2-4081-913E-B4FF56BAB479}
2015-04-16 17:31 - 2015-04-16 17:54 - 42096984 _____ (Apple Inc.) C:\Users\Silke Laptop\Downloads\QuickTimeInstaller (2).exe
2015-04-16 16:02 - 2015-04-16 16:04 - 00618671 _____ () C:\Users\Silke Laptop\Desktop\Motto 2014.pptx
2015-04-16 15:18 - 2015-04-16 16:18 - 18178736 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-04-16 15:13 - 2015-04-16 15:14 - 42096984 _____ (Apple Inc.) C:\Users\Silke Laptop\Downloads\QuickTimeInstaller (1).exe
2015-04-15 07:33 - 2015-03-25 11:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 07:33 - 2015-03-25 11:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 07:33 - 2015-03-25 11:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-15 07:33 - 2015-03-25 11:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 07:33 - 2015-03-25 11:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 07:33 - 2015-03-25 11:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 07:33 - 2015-03-25 11:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-15 07:33 - 2015-03-25 11:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 07:33 - 2015-03-25 11:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 07:33 - 2015-03-25 11:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 07:33 - 2015-03-25 11:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 07:33 - 2015-03-25 11:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-04-15 07:33 - 2015-03-25 11:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-04-15 07:33 - 2015-03-25 11:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-04-15 07:33 - 2015-03-25 11:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-04-15 07:33 - 2015-03-25 11:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-04-15 07:32 - 2015-04-02 08:17 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 07:32 - 2015-04-02 07:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-04-15 07:32 - 2015-03-23 11:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 07:32 - 2015-03-23 11:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 07:32 - 2015-03-23 11:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 07:32 - 2015-03-23 11:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 07:32 - 2015-03-23 11:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 07:32 - 2015-03-23 11:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-15 07:32 - 2015-03-23 11:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 07:32 - 2015-03-23 11:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 07:32 - 2015-03-17 13:22 - 05557696 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 07:32 - 2015-03-17 13:22 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 07:32 - 2015-03-17 13:22 - 00095672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 07:32 - 2015-03-17 13:19 - 01727904 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 07:32 - 2015-03-17 13:17 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-04-15 07:32 - 2015-03-17 13:17 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-04-15 07:32 - 2015-03-17 13:17 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 07:32 - 2015-03-17 13:16 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 07:32 - 2015-03-17 13:16 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 07:32 - 2015-03-17 13:16 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-04-15 07:32 - 2015-03-17 13:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-04-15 07:32 - 2015-03-17 13:15 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 07:32 - 2015-03-17 13:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 07:32 - 2015-03-17 13:13 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 07:32 - 2015-03-17 13:13 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 13:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-04-15 07:32 - 2015-03-17 13:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-04-15 07:32 - 2015-03-17 12:59 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-04-15 07:32 - 2015-03-17 12:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-04-15 07:32 - 2015-03-17 12:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-04-15 07:32 - 2015-03-17 12:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-04-15 07:32 - 2015-03-17 12:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-04-15 07:32 - 2015-03-17 12:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-04-15 07:32 - 2015-03-17 12:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-04-15 07:32 - 2015-03-17 12:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-04-15 07:32 - 2015-03-17 12:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-04-15 07:32 - 2015-03-17 12:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-04-15 07:32 - 2015-03-17 12:56 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-04-15 07:32 - 2015-03-17 12:56 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-04-15 07:32 - 2015-03-17 12:56 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-04-15 07:32 - 2015-03-17 12:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-04-15 07:32 - 2015-03-17 12:56 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-04-15 07:32 - 2015-03-17 12:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-04-15 07:32 - 2015-03-17 12:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-04-15 07:32 - 2015-03-17 12:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-04-15 07:32 - 2015-03-17 12:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 11:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-04-15 07:32 - 2015-03-17 11:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-04-15 07:32 - 2015-03-17 11:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 11:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 11:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 07:32 - 2015-03-17 11:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-15 07:32 - 2015-03-13 12:32 - 24980480 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 07:32 - 2015-03-13 12:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 07:32 - 2015-03-13 12:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 07:32 - 2015-03-13 12:09 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 07:32 - 2015-03-13 12:08 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 07:32 - 2015-03-13 12:08 - 00417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 07:32 - 2015-03-13 12:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 07:32 - 2015-03-13 12:07 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 07:32 - 2015-03-13 12:06 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 07:32 - 2015-03-13 12:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 07:32 - 2015-03-13 11:59 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 07:32 - 2015-03-13 11:55 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 07:32 - 2015-03-13 11:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 07:32 - 2015-03-13 11:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 07:32 - 2015-03-13 11:53 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 07:32 - 2015-03-13 11:50 - 06025216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 07:32 - 2015-03-13 11:44 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 07:32 - 2015-03-13 11:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-04-15 07:32 - 2015-03-13 11:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-04-15 07:32 - 2015-03-13 11:40 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 07:32 - 2015-03-13 11:32 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 07:32 - 2015-03-13 11:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-04-15 07:32 - 2015-03-13 11:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-04-15 07:32 - 2015-03-13 11:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-04-15 07:32 - 2015-03-13 11:27 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 07:32 - 2015-03-13 11:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-04-15 07:32 - 2015-03-13 11:26 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 07:32 - 2015-03-13 11:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-04-15 07:32 - 2015-03-13 11:23 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 07:32 - 2015-03-13 11:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-04-15 07:32 - 2015-03-13 11:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-04-15 07:32 - 2015-03-13 11:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-04-15 07:32 - 2015-03-13 11:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-04-15 07:32 - 2015-03-13 11:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-04-15 07:32 - 2015-03-13 11:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-04-15 07:32 - 2015-03-13 11:08 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 07:32 - 2015-03-13 11:07 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 07:32 - 2015-03-13 11:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-04-15 07:32 - 2015-03-13 11:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 07:32 - 2015-03-13 11:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 07:32 - 2015-03-13 11:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-04-15 07:32 - 2015-03-13 11:00 - 14397440 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 07:32 - 2015-03-13 10:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-04-15 07:32 - 2015-03-13 10:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-04-15 07:32 - 2015-03-13 10:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-04-15 07:32 - 2015-03-13 10:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-04-15 07:32 - 2015-03-13 10:45 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 07:32 - 2015-03-13 10:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-04-15 07:32 - 2015-03-13 10:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-04-15 07:32 - 2015-03-13 10:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-04-15 07:32 - 2015-03-13 10:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-04-15 07:32 - 2015-03-13 10:33 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 07:32 - 2015-03-13 10:22 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 07:32 - 2015-03-13 10:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-04-15 07:32 - 2015-03-13 10:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-04-15 07:32 - 2015-03-13 10:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-04-15 07:32 - 2015-03-10 11:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 07:32 - 2015-03-10 11:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-15 07:32 - 2015-03-10 11:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-04-15 07:32 - 2015-03-10 11:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-04-15 07:32 - 2015-03-05 13:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 07:32 - 2015-03-05 12:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-04-15 07:32 - 2015-02-25 11:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 07:31 - 2015-03-04 12:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 07:31 - 2015-03-04 12:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 07:31 - 2015-03-04 12:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-04-15 07:24 - 2015-04-15 07:25 - 00000000 ____D () C:\Users\Silke Laptop\Documents\Urlaub
2015-04-13 14:03 - 2015-04-17 10:41 - 02687831 _____ () C:\Users\Silke Laptop\Desktop\Beijing.pptx
2015-04-12 00:46 - 2015-04-12 00:47 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-12 00:46 - 2015-04-12 00:46 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-04-11 19:18 - 2015-04-11 19:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 08:25 - 2012-11-03 19:56 - 98550784 _____ () C:\Users\Silke Laptop\Documents\Outlook.pst
2015-04-30 08:18 - 2012-10-21 15:39 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-30 08:10 - 2013-10-26 13:05 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-30 08:04 - 2015-03-06 13:28 - 00000000 ___RD () C:\Users\Silke Laptop\Dropbox
2015-04-30 08:04 - 2015-03-06 13:25 - 00000000 ____D () C:\Users\Silke Laptop\AppData\Roaming\Dropbox
2015-04-30 08:04 - 2009-07-14 12:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-30 08:04 - 2009-07-14 12:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-30 08:01 - 2012-07-17 23:32 - 01829819 _____ () C:\Windows\WindowsUpdate.log
2015-04-30 07:56 - 2012-11-03 19:29 - 00000000 ____D () C:\Users\Silke Laptop\Documents\Outlook-Dateien
2015-04-30 07:56 - 2012-10-21 04:09 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-04-30 07:54 - 2012-07-18 00:18 - 00000000 ____D () C:\ProgramData\VeriFace
2015-04-30 07:53 - 2013-10-26 13:05 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-30 07:53 - 2012-10-21 09:38 - 08346020 _____ () C:\FaceProv.log
2015-04-30 07:53 - 2010-11-21 11:47 - 00321358 _____ () C:\Windows\PFRO.log
2015-04-30 07:53 - 2009-07-14 13:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-30 07:53 - 2009-07-14 12:51 - 00146030 _____ () C:\Windows\setupact.log
2015-04-30 07:51 - 2009-07-14 13:32 - 00000000 ____D () C:\Windows\Performance
2015-04-30 07:22 - 2012-07-18 09:18 - 00700010 _____ () C:\Windows\system32\perfh007.dat
2015-04-30 07:22 - 2012-07-18 09:18 - 00150304 _____ () C:\Windows\system32\perfc007.dat
2015-04-30 07:22 - 2009-07-14 13:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-29 22:17 - 2014-10-26 14:02 - 00000000 ____D () C:\Users\Silke Laptop\Documents\Garfrescha
2015-04-29 21:59 - 2014-09-21 02:35 - 00000000 ____D () C:\Users\Silke Laptop\AppData\Roaming\Skype
2015-04-29 18:08 - 2015-03-22 10:37 - 00000000 ____D () C:\Users\Silke Laptop\Documents\Rezepte
2015-04-28 19:56 - 2009-07-14 11:20 - 00000000 ____D () C:\Windows\rescache
2015-04-28 09:10 - 2013-06-10 20:29 - 00000000 ____D () C:\Users\Silke Laptop\Documents\Steuer
2015-04-27 19:24 - 2013-01-13 05:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-04-27 16:32 - 2014-06-06 22:23 - 00000000 ____D () C:\Users\Silke Laptop\Documents\Fitnesscenter Kirchheim Asahi
2015-04-27 14:07 - 2012-07-17 23:50 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-27 14:06 - 2009-07-14 11:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-27 14:05 - 2009-07-14 11:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-04-27 13:58 - 2012-07-17 23:50 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-04-27 13:58 - 2012-07-17 23:50 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2015-04-26 20:45 - 2012-10-21 04:17 - 00000000 ____D () C:\Users\Silke Laptop\AppData\Roaming\Adobe
2015-04-25 16:35 - 2015-03-06 13:28 - 00001053 _____ () C:\Users\Silke Laptop\Desktop\Dropbox.lnk
2015-04-25 16:35 - 2015-03-06 13:27 - 00000000 ____D () C:\Users\Silke Laptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-04-25 15:06 - 2014-09-21 16:18 - 00000000 ____D () C:\Users\Silke Laptop\Documents\china
2015-04-21 15:37 - 2013-04-09 00:39 - 01426432 ___SH () C:\Users\Silke Laptop\Desktop\Thumbs.db
2015-04-19 11:30 - 2013-04-08 13:02 - 00000000 ____D () C:\Windows\Minidump
2015-04-19 11:30 - 2013-04-08 13:01 - 869054771 _____ () C:\Windows\MEMORY.DMP
2015-04-19 09:26 - 2013-11-06 03:46 - 00178688 ___SH () C:\Users\Silke Laptop\Documents\Thumbs.db
2015-04-17 15:26 - 2015-02-03 18:09 - 00035607 _____ () C:\Users\Silke Laptop\Desktop\Ausgaben China.xlsx
2015-04-17 08:34 - 2009-07-14 11:20 - 00000000 ____D () C:\Windows\AppCompat
2015-04-16 19:32 - 2014-12-11 22:10 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-16 19:32 - 2014-05-07 12:58 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-16 19:32 - 2009-07-14 11:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-04-16 19:31 - 2014-02-27 14:21 - 01596482 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-04-16 19:31 - 2012-11-03 19:20 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-16 19:27 - 2013-07-19 13:51 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-16 19:22 - 2012-11-03 20:51 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-16 19:22 - 2009-07-14 10:34 - 00000537 _____ () C:\Windows\win.ini
2015-04-16 19:05 - 2012-10-21 15:55 - 00000000 ____D () C:\Users\Silke Laptop\AppData\Local\CrashDumps
2015-04-16 16:18 - 2012-10-21 15:39 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-16 16:18 - 2012-10-21 15:39 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-16 16:18 - 2012-10-21 15:39 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-16 14:28 - 2015-03-22 11:25 - 00000000 ____D () C:\Users\Silke Laptop\Desktop\Bilder
2015-04-15 07:18 - 2013-07-15 00:47 - 00000000 ____D () C:\Users\Silke Laptop\Documents\Finanzen
2015-04-13 20:38 - 2013-04-11 19:24 - 00000000 ____D () C:\Users\Silke Laptop\Documents\Eigene Scans
2015-04-12 17:32 - 2014-09-21 02:34 - 00000000 ____D () C:\ProgramData\Skype
2015-04-12 16:55 - 2014-01-22 01:37 - 00000000 ____D () C:\Users\Silke Laptop\Documents\Spullersee
2015-04-12 12:58 - 2015-01-13 16:34 - 00000000 ____D () C:\Users\Silke Laptop\Documents\Postbank Kontoauszüge
2015-04-12 11:45 - 2015-03-14 20:13 - 00000000 ____D () C:\Users\Silke Laptop\Documents\TS
2015-04-11 19:18 - 2013-06-02 16:13 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-04-11 19:18 - 2012-11-20 14:14 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2015-04-02 18:40 - 2009-07-14 11:20 - 00000000 ____D () C:\Windows\system32\NDF
==================== Files in the root of some directories =======
2014-07-04 20:26 - 2014-07-04 20:26 - 0001181 _____ () C:\Users\Silke Laptop\AppData\Roaming\trace_FilterInstaller.1.txt
2014-07-04 20:26 - 2014-07-04 20:59 - 0000919 _____ () C:\Users\Silke Laptop\AppData\Roaming\trace_FilterInstaller.txt
2014-07-04 20:26 - 2014-07-04 20:59 - 0000000 _____ () C:\Users\Silke Laptop\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt
2012-11-04 19:06 - 2012-11-04 19:06 - 0004096 ____H () C:\Users\Silke Laptop\AppData\Local\keyfile3.drm
2014-09-15 01:52 - 2014-12-21 00:47 - 0007602 _____ () C:\Users\Silke Laptop\AppData\Local\resmon.resmoncfg
2013-09-17 04:36 - 2013-09-17 04:36 - 0017408 _____ () C:\Users\Silke Laptop\AppData\Local\WebpageIcons.db
2012-12-23 22:16 - 2014-06-16 19:26 - 0001321 _____ () C:\ProgramData\hpzinstall.log
Some content of TEMP:
====================
C:\Users\Silke Laptop\AppData\Local\Temp\BlackBerryDeviceManager.exe
C:\Users\Silke Laptop\AppData\Local\Temp\BlackBerryLauncher.exe
C:\Users\Silke Laptop\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpnhh7jk.dll
C:\Users\Silke Laptop\AppData\Local\Temp\Execute2App.exe
C:\Users\Silke Laptop\AppData\Local\Temp\msvcp90.dll
C:\Users\Silke Laptop\AppData\Local\Temp\msvcr90.dll
C:\Users\Silke Laptop\AppData\Local\Temp\Quarantine.exe
C:\Users\Silke Laptop\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Silke Laptop\AppData\Local\Temp\sqlite3.dll
C:\Users\Silke Laptop\AppData\Local\Temp\vlc-2.1.5-win32.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-24 18:48
==================== End Of Log ============================ --- --- ---
--- --- --- |