|
Plagegeister aller Art und deren Bekämpfung: Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen aufWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
15.06.2013, 08:39 | #46 |
/// the machine /// TB-Ausbilder | Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.06.2013, 21:23 | #47 |
| Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Die online Spiele halten sich zurück und die Werbung ebenfalls. Sieht gut aus, muss aber noch genauer beobachten. Nur der Neustart dauert immer ewig. Wenn ich es mit dem Anfang, als ich ihn neu hatte und jetzt vergleiche braucht er ewig bis der oben ist. Meine Eltern haben ebenfalls Win8 mit ähnlicher Hardware, ihr Rechner ist innerhalb 1 Minute soweit. Hab vielleicht irgend welche Dienste oder Programme im Autostart oder zumindest irgend etwas beschäftigt ihn beim Neustart.
__________________Und mein Kabel Deutschland Launch (Fsecure) beschäftigt mich noch. Und die updatetask.exe. Screen shorts hatte ich schon mal rein gestellt. War laut den Log Files etwas auf meinem Rechner was nicht drauf gehört? Danke das du dir Zeit genommen hast. Sams |
15.06.2013, 21:26 | #48 |
/// the machine /// TB-Ausbilder | Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf schauen wir mal
__________________Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
__________________ |
15.06.2013, 21:33 | #49 |
| Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Das ging ja aber flott mit dem Scan. Hier die Log Files Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-06-2013 Ran by Oksana at 2013-06-15 22:31:42 Run: Running from C:\Users\Oksana\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) Adobe Flash Player 11 Plugin (Version: 11.7.700.224) Adobe Reader XI (11.0.03) - Deutsch (Version: 11.0.03) ArcSoft TV 5.0 (Version: 5.0.8.145) Ashampoo AppLauncher (Medion) v.1.0.0 (Version: 1.0.0) Ashampoo WinOptimizer 6.60 (Version: 6.6.0) Avira Free Antivirus (Version: 13.0.0.3640) AVM FRITZ!Box Dokumentation Brother MFL-Pro Suite DCP-165C (Version: 2.0.0.0) CDBurnerXP (Version: 4.5.0.3717) Computer Security 12.77.100.0 (release) (Version: 12.77.100.0) ConvertHelper 2.2 CyberLink LabelPrint 2.5 (Version: 2.5.5415) CyberLink MediaEspresso 6.5 (Version: 6.5.3111_44883) CyberLink PhotoDirector 3 (Version: 3.0.3530) CyberLink PhotoNow (Version: 1.1.7717) CyberLink Power2Go 8 (Version: 8.0.0.1920) CyberLink PowerDirector (Version: 9.0.0.3815c) CyberLink PowerDVD 10 (Version: 10.0.4125.02) CyberLink PowerDVD Copy 1.5 (Version: 1.5.2715b) CyberLink PowerRecover (Version: 5.7.0.0913) CyberLink YouCam 5 (Version: 5.0.1930) D3DX10 (Version: 15.4.2368.0902) DC-Bass Source 1.3.0 DivX-Setup (Version: 2.6.1.41) Dolby Home Theater v4 (Version: 7.2.8000.17) Express Zip ffdshow v1.1.4399 [2012-03-22] (Version: 1.1.4399.0) Fotogalerie (Version: 16.4.3505.0912) Fotogalerija (Version: 16.4.3505.0912) Fotótár (Version: 16.4.3505.0912) Free Mp3 Wma Converter V 2.2 (Version: 2.2.0.0) F-Secure CCF Reputation (Version: 1.0.25.1756) F-Secure CCF Scanning 1.23.124.8831 (release) (Version: 1.23.124.8831) F-Secure Network CCF 1.02.128 (Version: 1.02.128) Galería de fotos (Version: 16.4.3505.0912) Galerie de photos (Version: 16.4.3505.0912) Google Earth (Version: 7.0.3.8542) Google Update Helper (Version: 1.3.21.145) Haali Media Splitter Intel PROSet Wireless Intel(R) Management Engine Components (Version: 8.1.0.1252) Intel(R) Processor Graphics (Version: 9.17.10.2875) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 15.5.4.0423) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 2.6.1210.0278) Intel(R) Rapid Storage Technology (Version: 11.6.0.1030) Intel(R) SDK for OpenCL - CPU Only Runtime Package (Version: 2.0.0.37149) Intel(R) WiDi (Version: 3.5.40.0) Intel® PROSet/Wireless WiFi Software (Version: 15.05.6000.1620) Intel® Trusted Connect Service Client (Version: 1.24.388.1) IT9130 Driver v12.2.3.1 Java 7 Update 21 (Version: 7.0.210) Java Auto Updater (Version: 2.1.9.5) Kabel Deutschland Launchpad (Version: 1.77.243.0) Lagarith Lossless Codec (1.3.27) LAME v3.99.3 (for Windows) Mail.Ru ????? 6.1 (?????? 6578) (Version: 6.1.6578.0) Mediathek (Version: 1.4.0) Medion Home Cinema 10 (Version: 10.0) Medion Home Cinema 10 (Version: 10.1924) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office (Version: 14.0.6120.5004) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Movie Maker (Version: 16.4.3505.0912) Mozilla Firefox 21.0 (x86 de) (Version: 21.0) Mozilla Maintenance Service (Version: 21.0) MSVCRT (Version: 15.4.2862.0708) MSVCRT110 (Version: 16.4.1108.0727) MSVCRT110_amd64 (Version: 16.4.1109.0912) NVIDIA Control Panel 307.17 (Version: 307.17) NVIDIA Graphics Driver 307.17 (Version: 307.17) NVIDIA Install Application (Version: 2.1002.85.551) NVIDIA Optimus 1.10.8 (Version: 1.10.8) NVIDIA Update Components (Version: 1.10.8) Online Safety 2.77.1170.803 (Version: 2.77.1170.803) OpenOffice.org 3.4.1 (Version: 3.41.9593) OpenSource Flash Video Splitter 1.0.0.5 (Version: 1.0.0.5) PDF24 Creator 5.2.0 Photo Common (Version: 16.4.3505.0912) Photo Gallery (Version: 16.4.3505.0912) ProfiCAD 7.5.1 QuickLaunch (Version: 1.00.0019) Raccolta foto (Version: 16.4.3505.0912) Realtek Ethernet Controller Driver (Version: 8.3.730.2012) Realtek High Definition Audio Driver (Version: 6.0.1.6722) Realtek USB 2.0 Card Reader (Version: 6.1.8400.30136) Skype™ 6.3 (Version: 6.3.107) SuperEasy Audio Converter 2 v.2.1.2143 (Version: 2.1.2143) Synaptics Pointing Device Driver (Version: 16.2.12.12) TeamViewer 8 (Version: 8.0.18930) Tube Karaoke UltraVnc (Version: 1.1.8) Update for Codec Pack VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0) VideoPerformer VLC media player 2.0.6 (Version: 2.0.6) Windows Live (Version: 16.4.3505.0912) Windows Live Communications Platform (Version: 16.4.3505.0912) Windows Live Essentials (Version: 16.4.3505.0912) Windows Live Installer (Version: 16.4.3505.0912) Windows Live Photo Common (Version: 16.4.3505.0912) Windows Live PIMT Platform (Version: 16.4.3505.0912) Windows Live SOXE (Version: 16.4.3505.0912) Windows Live SOXE Definitions (Version: 16.4.3505.0912) Windows Live UX Platform (Version: 16.4.3505.0912) Windows Live UX Platform Language Pack (Version: 16.4.3505.0912) WinZip Packages Xvid Video Codec (Version: 1.3.2) ==================== Restore Points ========================= 28-05-2013 09:17:12 Geplanter Prüfpunkt 06-06-2013 19:33:25 Installiert PhotoDirector 12-06-2013 20:42:28 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/15/2013 10:29:39 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/14/2013 10:39:19 PM) (Source: Brother BrLog) (User: ) Description: WDLMW BrtWDLMW: [2013/06/14 22:39:19.711]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:18 PM) (Source: Brother BrLog) (User: ) Description: WDLMW BrtWDLMW: [2013/06/14 22:39:18.164]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:16 PM) (Source: Brother BrLog) (User: ) Description: WDLMW BrtWDLMW: [2013/06/14 22:39:16.617]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:15 PM) (Source: Brother BrLog) (User: ) Description: WDLMW BrtWDLMW: [2013/06/14 22:39:15.070]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:13 PM) (Source: Brother BrLog) (User: ) Description: WDLMW BrtWDLMW: [2013/06/14 22:39:13.523]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:11 PM) (Source: Brother BrLog) (User: ) Description: WDLMW BrtWDLMW: [2013/06/14 22:39:11.976]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:10 PM) (Source: Brother BrLog) (User: ) Description: WDLMW BrtWDLMW: [2013/06/14 22:39:10.429]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:08 PM) (Source: Brother BrLog) (User: ) Description: WDLMW BrtWDLMW: [2013/06/14 22:39:08.882]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:07 PM) (Source: Brother BrLog) (User: ) Description: WDLMW BrtWDLMW: [2013/06/14 22:39:07.335]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 System errors: ============= Error: (06/15/2013 09:50:52 PM) (Source: ipnathlp) (User: ) Description: 188.193.210.76192.168.137.0255.255.255.0 Error: (06/15/2013 09:50:49 PM) (Source: ipnathlp) (User: ) Description: 169.254.218.176192.168.137.0255.255.255.0 Error: (06/14/2013 10:39:22 PM) (Source: DCOM) (User: Laptop) Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793} Error: (06/14/2013 10:39:22 PM) (Source: DCOM) (User: Laptop) Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793} Error: (06/14/2013 10:39:22 PM) (Source: DCOM) (User: Laptop) Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793} Error: (06/14/2013 10:02:31 PM) (Source: ipnathlp) (User: ) Description: 188.193.201.201192.168.137.0255.255.255.0 Error: (06/14/2013 09:48:12 PM) (Source: ipnathlp) (User: ) Description: 188.193.201.201192.168.137.0255.255.255.0 Error: (06/14/2013 09:48:12 PM) (Source: ipnathlp) (User: ) Description: Error: (06/14/2013 09:48:11 PM) (Source: DCOM) (User: Laptop) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}LaptopOksanaS-1-5-21-174320049-3726716400-672341874-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (06/14/2013 09:48:11 PM) (Source: DCOM) (User: Laptop) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}LaptopOksanaS-1-5-21-174320049-3726716400-672341874-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Microsoft Office Sessions: ========================= Error: (06/15/2013 10:29:39 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Oksana\Downloads\esetsmartinstaller_enu.exe Error: (06/14/2013 10:39:19 PM) (Source: Brother BrLog)(User: ) Description: WDLMWBrtWDLMW: [2013/06/14 22:39:19.711]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:18 PM) (Source: Brother BrLog)(User: ) Description: WDLMWBrtWDLMW: [2013/06/14 22:39:18.164]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:16 PM) (Source: Brother BrLog)(User: ) Description: WDLMWBrtWDLMW: [2013/06/14 22:39:16.617]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:15 PM) (Source: Brother BrLog)(User: ) Description: WDLMWBrtWDLMW: [2013/06/14 22:39:15.070]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:13 PM) (Source: Brother BrLog)(User: ) Description: WDLMWBrtWDLMW: [2013/06/14 22:39:13.523]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:11 PM) (Source: Brother BrLog)(User: ) Description: WDLMWBrtWDLMW: [2013/06/14 22:39:11.976]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:10 PM) (Source: Brother BrLog)(User: ) Description: WDLMWBrtWDLMW: [2013/06/14 22:39:10.429]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:08 PM) (Source: Brother BrLog)(User: ) Description: WDLMWBrtWDLMW: [2013/06/14 22:39:08.882]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 Error: (06/14/2013 10:39:07 PM) (Source: Brother BrLog)(User: ) Description: WDLMWBrtWDLMW: [2013/06/14 22:39:07.335]: [00006516]: lperrcode->api = 1 , lperrcode->code = 2 ==================== Memory info =========================== Percentage of memory in use: 31% Total physical RAM: 8070.57 MB Available physical RAM: 5544.79 MB Total Pagefile: 9286.57 MB Available Pagefile: 6491.73 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:869.8 GB) (Free:803.82 GB) NTFS Drive d: (Recover) (Fixed) (Total:60 GB) (Free:40.91 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 462A80D0) Partition: GPT Partition Type ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013 Ran by Oksana (administrator) on 15-06-2013 22:30:49 Running from C:\Users\Oksana\Desktop Windows 8 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Reputation\fsorsp.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\FSGK32.EXE (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSMA32.EXE (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSHDLL64.EXE (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\fssm32.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\ArcSoft TV 5.0\TMTV5Monitor.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin () C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSM32.EXE (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe (F-Secure Corporation) C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Microsoft Corporation) C:\Windows\system32\wwahost.exe (Microsoft Corporation) C:\Windows\system32\wwahost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe\LiveComm.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [13192848 2012-08-30] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 [1215632 2012-08-17] (Realtek Semiconductor) HKLM\...\Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp [11582848 2012-09-30] (Motorola Solutions, Inc.) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2917176 2012-09-05] (Synaptics Incorporated) HKCU\...\Run: [MAgent] C:\Users\Oksana\AppData\Roaming\Mail.Ru\Agent\magent.exe -CU [30171168 2013-05-27] (Mail.Ru) HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18678376 2013-04-19] (Skype Technologies S.A.) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [CLMLServer_For_P2G8] "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" [111120 2012-06-08] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R [491120 2012-07-20] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [93296 2012-07-13] (CyberLink Corp.) HKLM-x32\...\Run: [YouCam Service] "C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe" /s [258576 2012-07-30] (CyberLink Corp.) HKLM-x32\...\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN [1163264 2012-09-25] () HKLM-x32\...\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun [114688 2008-12-24] (Brother Industries, Ltd.) HKLM-x32\...\Run: [F-Secure Manager] "C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSM32.EXE" /splash [311432 2013-01-03] (F-Secure Corporation) HKLM-x32\...\Run: [bdinstaller] "C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\setupdownloader.exe" /args:"/after_restart" [x] HKLM-x32\...\Run: [F-Secure Hoster (44553)] "C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe" -app -hosterid:1 [188400 2013-01-18] (F-Secure Corporation) HKLM-x32\...\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-04-15] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1263952 2013-02-13] () HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345312 2013-04-04] (Avira Operations GmbH & Co. KG) AppInit_DLLs: C:\Windows\system32\nvinitx.dll [247144 2012-10-11] (NVIDIA Corporation) Startup: C:\ProgramData\Start Menu\Programs\Startup\TMMonitor.lnk ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\ArcSoft TV 5.0\TMTV5Monitor.exe (ArcSoft, Inc.) Startup: C:\Users\Oksana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?utf8in=1&fr=ietb&q={SearchTerms} BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: No Name - {8984B388-A5BB-4DF7-B274-77B879E179DB} - No File BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Tube Karaoke - {F351B686-F6AF-45F1-9EB9-684C805B25B1} - C:\Program Files (x86)\YTKaraoke\ytkaraoke.dll (Dacotta SoftEngineering) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 83.169.184.225 83.169.184.161 FireFox: ======== FF ProfilePath: C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default FF SelectedSearchEngine: Google FF Homepage: hxxp://www.web.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: ??????? @Mail.Ru - C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default\Extensions\{37964A3C-4EE8-47b1-8321-34DE2C39BA4D} FF Extension: Wajam - C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default\Extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2} FF Extension: DownloadHelper - C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: adblockpopups - C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default\Extensions\adblockpopups@jessehakanen.net.xpi FF Extension: artur.dubovoy - C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default\Extensions\artur.dubovoy@gmail.com.xpi FF Extension: elemhidehelper - C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default\Extensions\elemhidehelper@adblockplus.org.xpi FF Extension: info - C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default\Extensions\info@sharkcube.com.xpi FF Extension: toolbar - C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default\Extensions\toolbar@web.de.xpi FF Extension: uploader - C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default\Extensions\uploader@adblockfilters.mozdev.org.xpi FF Extension: No Name - C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi FF Extension: No Name - C:\Users\Oksana\AppData\Roaming\Mozilla\Firefox\Profiles\bohjm6te.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86752 2013-02-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110816 2013-02-25] (Avira Operations GmbH & Co. KG) R2 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [70952 2011-04-13] (CyberLink) R2 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [312616 2011-04-13] (CyberLink) S3 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [544768 2009-08-24] (mst software GmbH, Germany) R2 fshoster; C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe [188400 2013-01-18] (F-Secure Corporation) R3 FSMA; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSMA32.EXE [209032 2013-01-03] (F-Secure Corporation) R2 FSORSPClient; C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Reputation\fsorsp.exe [61152 2012-05-25] (F-Secure Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-09-24] () R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2012-10-19] () S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [1153840 2012-09-24] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-02-26] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130016 2013-02-26] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-02-26] (Avira Operations GmbH & Co. KG) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [132480 2012-10-01] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1337216 2012-10-01] (Motorola Solutions, Inc.) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R3 F-Secure Gatekeeper; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [200760 2013-04-12] () R3 F-Secure Gatekeeper; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [200760 2013-04-12] () R1 F-Secure HIPS; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\HIPS\drivers\fshs.sys [68608 2013-04-23] (F-Secure Corporation) R1 F-Secure HIPS; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\HIPS\drivers\fshs.sys [68608 2013-04-23] (F-Secure Corporation) R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [56016 2013-04-12] () R0 fsbts; C:\Windows\SysWow64\Drivers\fsbts.sys [42248 2013-04-12] () R3 fsni; C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\fsni64.sys [80832 2013-04-25] (F-Secure Corporation) R3 fsni; C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\fsni64.sys [80832 2013-04-25] (F-Secure Corporation) R1 fsvista; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [14472 2013-01-03] () R1 fsvista; C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [14472 2013-01-03] () S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [165504 2012-11-14] (ITE ) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4309032 2012-10-10] (Intel Corporation) R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider) R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-15 22:29 - 2013-06-15 22:29 - 00000000 ____D C:\FRST 2013-06-15 22:28 - 2013-06-15 22:28 - 01920546 ____A (Farbar) C:\Users\Oksana\Desktop\FRST64.exe 2013-06-14 21:51 - 2013-06-14 21:51 - 00001259 ____A C:\Users\Oksana\Desktop\AdwCleaner2.txt 2013-06-14 21:50 - 2013-06-14 21:50 - 00001259 ____A C:\AdwCleaner[R5].txt 2013-06-14 21:45 - 2013-06-14 21:45 - 00014455 ____A C:\AdwCleaner[S1].txt 2013-06-14 21:44 - 2013-06-14 21:44 - 00014516 ____A C:\AdwCleaner[R4].txt 2013-06-14 18:23 - 2013-06-14 18:23 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\Avira 2013-06-14 18:20 - 2013-06-14 18:20 - 00083160 ____A (Avira GmbH) C:\Windows\System32\Drivers\avnetflt.sys 2013-06-14 18:18 - 2013-06-14 18:18 - 00002076 ____A C:\Users\Public\Desktop\Avira Control Center.lnk 2013-06-14 18:17 - 2013-06-14 18:17 - 00000000 ____D C:\Program Files (x86)\Avira 2013-06-14 18:17 - 2013-02-26 16:56 - 00130016 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avipbb.sys 2013-06-14 18:17 - 2013-02-26 16:56 - 00100712 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avgntflt.sys 2013-06-14 18:17 - 2013-02-26 16:56 - 00028600 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avkmgr.sys 2013-06-14 18:08 - 2013-06-14 18:16 - 00007941 ____A C:\Users\Oksana\Desktop\JRT.txt 2013-06-14 17:49 - 2013-06-14 17:34 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Oksana\Desktop\JRT.exe 2013-06-14 17:48 - 2013-06-14 17:48 - 00017633 ____A C:\Users\Oksana\Desktop\AdwCleaner[R3].txt 2013-06-14 17:47 - 2013-06-14 17:47 - 00017633 ____A C:\AdwCleaner[R3].txt 2013-06-14 17:40 - 2013-06-05 00:09 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-14 17:40 - 2013-06-05 00:09 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-14 17:38 - 2013-06-14 17:38 - 00017572 ____A C:\AdwCleaner[R2].txt 2013-06-14 17:19 - 2013-06-14 17:20 - 00648201 ____A C:\Users\Oksana\Desktop\adwcleaner(1).exe 2013-06-13 22:19 - 2013-06-13 22:19 - 00001098 ____A C:\Users\Public\Desktop\TeamViewer 8.lnk 2013-06-13 10:22 - 2013-06-14 22:01 - 00143150 ____A C:\Users\Oksana\Desktop\OTL.Txt 2013-06-13 10:16 - 2013-05-04 09:45 - 02233600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-13 10:16 - 2013-04-27 07:20 - 00733184 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-13 09:48 - 2013-06-13 09:48 - 04327136 ____A (Systweak Inc ) C:\Users\Oksana\Downloads\sysrc_trial_9407_german01.exe 2013-06-13 09:45 - 2013-04-04 05:35 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-06-13 09:45 - 2013-04-04 05:30 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-06-13 09:45 - 2013-04-04 05:29 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-06-13 09:44 - 2013-06-13 09:45 - 00004032 ____A C:\Windows\SysWOW64\jupdate-1.7.0_21-b11.log 2013-06-13 09:42 - 2013-06-13 09:42 - 00903072 ____A (Oracle Corporation) C:\Users\Oksana\Downloads\jxpiinstall(2).exe 2013-06-13 09:41 - 2013-04-24 01:13 - 01013248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-13 09:41 - 2013-04-24 01:12 - 01569792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-13 09:41 - 2013-04-24 01:12 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-13 09:41 - 2013-04-24 00:56 - 01255936 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-13 09:41 - 2013-04-24 00:55 - 01889280 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-13 09:41 - 2013-04-24 00:55 - 00141312 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-13 09:41 - 2013-04-24 00:55 - 00068096 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-13 09:17 - 2013-04-03 01:37 - 00025088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-13 09:17 - 2013-04-03 01:12 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll 2013-06-12 22:46 - 2013-05-16 00:36 - 14320640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-12 22:46 - 2013-05-16 00:35 - 19230720 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-12 22:46 - 2013-04-29 00:30 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-12 22:46 - 2013-04-29 00:30 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-12 22:46 - 2013-04-29 00:30 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-12 22:46 - 2013-04-29 00:30 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-12 22:46 - 2013-04-29 00:28 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-12 22:46 - 2013-04-29 00:28 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-12 22:46 - 2013-04-29 00:28 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-12 22:46 - 2013-04-29 00:27 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-12 22:46 - 2013-04-29 00:27 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-12 22:45 - 2013-05-16 00:37 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-06-12 22:45 - 2013-05-16 00:35 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll 2013-06-12 22:45 - 2013-05-14 15:14 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-12 22:45 - 2013-05-14 11:23 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-12 22:45 - 2013-04-29 00:30 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-12 22:45 - 2013-04-29 00:30 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-12 22:45 - 2013-04-29 00:30 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-12 22:45 - 2013-04-29 00:28 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll 2013-06-12 22:45 - 2013-04-29 00:28 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-12 22:45 - 2013-04-29 00:28 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-12 22:45 - 2013-04-29 00:27 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-10 21:59 - 2013-06-14 17:50 - 00000000 ____D C:\JRT 2013-06-10 21:59 - 2013-06-10 21:59 - 00000000 ____D C:\Windows\ERUNT 2013-06-10 20:46 - 2013-06-10 20:46 - 00024607 ____A C:\AdwCleaner[R1].txt 2013-06-10 17:49 - 2013-06-13 09:32 - 00083968 __ASH C:\Users\Oksana\Desktop\Thumbs.db 2013-06-10 17:38 - 2013-06-14 21:47 - 00194598 ____A C:\Windows\PFRO.log 2013-06-07 09:40 - 2013-06-15 21:00 - 00000390 ____A C:\Windows\Tasks\Tube Karaoke Update.job 2013-06-06 21:44 - 2013-06-06 21:44 - 00000000 ____D C:\Users\Oksana\Documents\Lucas 2013-06-06 21:32 - 2013-06-06 21:32 - 16481056 ____A C:\Users\Oksana\Downloads\MEDIONAG.v3530_45147_Spr_PTD121130-03.exe 2013-06-06 21:31 - 2013-06-06 21:31 - 00967200 ____A (CyberLink) C:\Users\Oksana\Downloads\CyberLink_PhotoDirector_Downloader.exe 2013-06-03 23:19 - 2013-06-03 23:19 - 00000000 ____D C:\Users\Oksana\Documents\Luise Krening 2013-06-01 18:54 - 2013-06-01 18:54 - 00000000 ____D C:\Users\Oksana\AppData\Local\DDMSettings 2013-05-30 22:08 - 2013-05-30 22:08 - 00009565 ____A C:\Users\Oksana\Documents\MeineZip.zip 2013-05-30 19:55 - 2013-05-30 19:55 - 01110476 ____A C:\Users\Oksana\Downloads\7z920(1).exe 2013-05-30 19:55 - 2013-05-30 19:55 - 00000000 ____D C:\Program Files (x86)\7-Zip 2013-05-30 19:04 - 2013-05-30 19:03 - 00377856 ____A C:\Users\Oksana\Desktop\gmer_2.1.19163.exe 2013-05-30 19:03 - 2013-05-30 19:03 - 00377856 ____A C:\Users\Oksana\Downloads\gmer_2.1.19163.exe 2013-05-30 18:31 - 2013-03-27 13:37 - 00602112 ____A (OldTimer Tools) C:\Users\Oksana\Desktop\OTL.exe 2013-05-30 18:30 - 2013-05-30 18:30 - 00602112 ____A (OldTimer Tools) C:\Users\Oksana\Downloads\OTL(1).exe 2013-05-29 23:41 - 2013-05-30 18:29 - 00000474 ____A C:\Users\Oksana\Downloads\defogger_disable.log 2013-05-29 23:41 - 2013-05-29 23:41 - 00000246 ____A C:\Users\Oksana\Downloads\defogger_enable.log 2013-05-29 23:41 - 2013-05-29 23:41 - 00000000 ____A C:\Users\Oksana\defogger_reenable 2013-05-29 23:40 - 2013-05-29 23:40 - 00050477 ____A C:\Users\Oksana\Downloads\Defogger.exe 2013-05-29 23:09 - 2013-05-29 23:09 - 00000000 ____D C:\Program Files (x86)\YTKaraoke 2013-05-29 22:44 - 2013-05-29 22:44 - 00335656 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-28 23:34 - 2013-05-28 23:45 - 00000000 ____A C:\Windows\SysWOW64\SystemPreferences.xml 2013-05-28 22:30 - 2013-05-28 22:30 - 00001614 ____A C:\Users\Oksana\Desktop\DivX Movies.lnk 2013-05-28 22:30 - 2013-05-28 22:30 - 00001132 ____A C:\Users\Public\Desktop\DivX Plus Player.lnk 2013-05-28 22:29 - 2013-05-28 22:29 - 00001178 ____A C:\Users\Public\Desktop\DivX Plus Converter.lnk 2013-05-28 22:27 - 2013-05-28 22:27 - 00955712 ____A (DivX, LLC) C:\Users\Oksana\Downloads\DivXInstaller.exe 2013-05-28 22:13 - 2013-05-29 23:09 - 00000000 ____D C:\Program Files (x86)\LyricsFinder 2013-05-28 22:12 - 2013-05-28 22:29 - 00000000 ____D C:\Program Files\DivX 2013-05-28 22:11 - 2013-05-28 22:30 - 00000000 ____D C:\ProgramData\DivX 2013-05-28 22:11 - 2013-05-28 22:30 - 00000000 ____D C:\Program Files (x86)\DivX 2013-05-28 22:11 - 2013-05-28 22:11 - 00715038 ____A C:\Windows\unins000.exe 2013-05-28 22:11 - 2013-05-28 22:11 - 00001989 ____A C:\Windows\unins000.dat 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\LavFilters 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\CDXReader 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\Xvid 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\OpenSource Flash Video Splitter 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\Haali 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\ffdshow 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\DSP-worx 2013-05-28 22:11 - 2012-02-26 16:47 - 00079360 ____A C:\Windows\SysWOW64\ff_vfw.dll 2013-05-28 22:11 - 2011-12-07 19:37 - 00148992 ____A ( ) C:\Windows\System32\lagarith.dll 2013-05-28 22:11 - 2011-12-07 19:32 - 00216064 ____A ( ) C:\Windows\SysWOW64\lagarith.dll 2013-05-28 22:11 - 2011-05-30 15:42 - 00255488 ____A C:\Windows\System32\xvidvfw.dll 2013-05-28 22:11 - 2011-05-30 15:42 - 00240640 ____A C:\Windows\SysWOW64\xvidvfw.dll 2013-05-28 22:11 - 2011-05-23 11:52 - 00153088 ____A C:\Windows\SysWOW64\xvid.ax 2013-05-28 22:11 - 2011-05-23 09:49 - 00173568 ____A C:\Windows\System32\xvid.ax 2013-05-28 22:11 - 2011-05-23 09:46 - 00645632 ____A C:\Windows\SysWOW64\xvidcore.dll 2013-05-28 22:11 - 2011-05-23 09:45 - 00696832 ____A C:\Windows\System32\xvidcore.dll 2013-05-28 22:08 - 2013-05-28 22:08 - 00774080 ____A C:\Users\Oksana\Downloads\CodecPack.exe 2013-05-28 21:32 - 2013-05-28 21:32 - 00000000 ___RD C:\Users\Oksana\AppData\Roaming\Brother 2013-05-28 11:04 - 2013-05-28 11:11 - 00000000 ____D C:\Users\Oksana\Documents\Oksana 2013-05-27 12:28 - 2013-05-27 12:28 - 00000000 ____D C:\Program Files (x86)\ConvertHelper 2013-05-27 12:27 - 2013-05-27 12:27 - 03782822 ____A (DownloadHelper ) C:\Users\Oksana\Downloads\ConvertHelperSetup.exe 2013-05-27 12:22 - 2013-05-31 17:38 - 00000000 ____D C:\Users\Oksana\dwhelper 2013-05-20 12:50 - 2013-04-09 07:33 - 00489576 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll 2013-05-20 12:50 - 2013-04-09 07:33 - 00446792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll 2013-05-20 12:50 - 2013-04-09 07:33 - 00253544 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe 2013-05-20 12:50 - 2013-04-09 07:27 - 00284424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys 2013-05-20 12:50 - 2013-04-09 07:20 - 00306952 ____A (Microsoft Corporation) C:\Windows\System32\kd_02_10ec.dll 2013-05-20 12:50 - 2013-04-09 07:20 - 00086280 ____A (Microsoft Corporation) C:\Windows\System32\kdnet.dll 2013-05-20 12:50 - 2013-04-09 07:18 - 00077960 ____A (Microsoft Corporation) C:\Windows\System32\kdvm.dll 2013-05-20 12:50 - 2013-04-09 07:17 - 01829408 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll 2013-05-20 12:50 - 2013-04-09 06:52 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe 2013-05-20 12:50 - 2013-04-09 06:52 - 00804352 ____A (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe 2013-05-20 12:50 - 2013-04-09 06:52 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe 2013-05-20 12:50 - 2013-04-09 06:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe 2013-05-20 12:50 - 2013-04-09 06:52 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Robocopy.exe 2013-05-20 12:50 - 2013-04-09 06:51 - 14267904 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll 2013-05-20 12:50 - 2013-04-09 06:51 - 13648384 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll 2013-05-20 12:50 - 2013-04-09 06:51 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll 2013-05-20 12:50 - 2013-04-09 06:51 - 03552768 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll 2013-05-20 12:50 - 2013-04-09 06:51 - 00595456 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll 2013-05-20 12:50 - 2013-04-09 06:51 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-05-20 12:50 - 2013-04-09 06:51 - 00456704 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll 2013-05-20 12:50 - 2013-04-09 06:51 - 00391168 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll 2013-05-20 12:50 - 2013-04-09 06:51 - 00367616 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe 2013-05-20 12:50 - 2013-04-09 06:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll 2013-05-20 12:50 - 2013-04-09 06:50 - 02107904 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll 2013-05-20 12:50 - 2013-04-09 06:50 - 01285632 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll 2013-05-20 12:50 - 2013-04-09 06:50 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll 2013-05-20 12:50 - 2013-04-09 06:50 - 00435200 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll 2013-05-20 12:50 - 2013-04-09 06:50 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2013-05-20 12:50 - 2013-04-09 06:50 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\GenuineCenter.dll 2013-05-20 12:50 - 2013-04-09 06:50 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll 2013-05-20 12:50 - 2013-04-09 06:50 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll 2013-05-20 12:50 - 2013-04-09 06:50 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll 2013-05-20 12:50 - 2013-04-09 06:49 - 01444864 ____A (Microsoft Corporation) C:\Windows\System32\MSAudDecMFT.dll 2013-05-20 12:50 - 2013-04-09 06:49 - 00817152 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll 2013-05-20 12:50 - 2013-04-09 06:49 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll 2013-05-20 12:50 - 2013-04-09 06:49 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll 2013-05-20 12:50 - 2013-04-09 06:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll 2013-05-20 12:50 - 2013-04-09 06:49 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\iuilp.dll 2013-05-20 12:50 - 2013-04-09 06:49 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\dmvdsitf.dll 2013-05-20 12:50 - 2013-04-09 06:49 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll 2013-05-20 12:50 - 2013-04-09 06:49 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\fmifs.dll 2013-05-20 12:50 - 2013-04-09 06:48 - 02303488 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-05-20 12:50 - 2013-04-09 06:48 - 00785408 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll 2013-05-20 12:50 - 2013-04-09 06:48 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl 2013-05-20 12:50 - 2013-04-09 06:48 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll 2013-05-20 12:50 - 2013-04-09 04:35 - 04038144 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-05-20 12:50 - 2013-04-09 04:34 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys 2013-05-20 12:50 - 2013-04-09 04:34 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys 2013-05-20 12:50 - 2013-04-09 04:34 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys 2013-05-20 12:50 - 2013-04-09 04:33 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys 2013-05-20 12:50 - 2013-04-09 04:33 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys 2013-05-20 12:50 - 2013-04-09 04:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys 2013-05-20 12:50 - 2013-04-09 04:31 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys 2013-05-20 12:50 - 2013-04-09 04:31 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys 2013-05-20 12:50 - 2013-04-09 01:44 - 00123880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll 2013-05-20 12:50 - 2013-04-09 01:39 - 01408896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-05-20 12:50 - 2013-04-09 01:37 - 00426024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2013-05-20 12:50 - 2013-04-09 01:37 - 00324368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2013-05-20 12:50 - 2013-04-08 23:52 - 11878912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-05-20 12:50 - 2013-04-08 23:52 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2013-05-20 12:50 - 2013-04-08 23:52 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-05-20 12:50 - 2013-04-08 23:52 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2013-05-20 12:50 - 2013-04-08 23:52 - 00171008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2013-05-20 12:50 - 2013-04-08 23:52 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe 2013-05-20 12:50 - 2013-04-08 23:51 - 10789888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 02767360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 02035200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 01593344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 01113600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00659456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00656896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00403968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl 2013-05-20 12:50 - 2013-04-08 23:51 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00324096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00155648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2013-05-20 12:50 - 2013-04-08 23:51 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2013-05-20 12:50 - 2013-04-05 01:30 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll 2013-05-20 12:50 - 2013-03-30 20:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi 2013-05-20 12:50 - 2013-03-30 20:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe 2013-05-20 12:50 - 2013-03-29 00:09 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi 2013-05-20 12:50 - 2013-03-29 00:09 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe 2013-05-20 12:50 - 2013-03-16 00:05 - 00298456 ____A (Microsoft Corporation) C:\Windows\System32\rsaenh.dll 2013-05-20 12:50 - 2013-03-16 00:05 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll 2013-05-20 12:49 - 2013-04-03 00:08 - 00387688 ____A C:\Windows\System32\ApnDatabase.xml 2013-05-20 12:49 - 2012-12-13 06:00 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll 2013-05-20 12:49 - 2012-12-13 05:59 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-05-20 08:43 - 2013-05-20 08:43 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-05-20 08:43 - 2013-05-20 08:43 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-05-20 08:05 - 2013-03-22 05:49 - 02382336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll 2013-05-20 08:05 - 2013-03-22 00:47 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll 2013-05-19 23:08 - 2013-05-19 23:09 - 02141192 ____A (Solid State Networks) C:\Users\Oksana\Downloads\install_flashplayer11x32_mssd_aih(1).exe 2013-05-19 23:02 - 2013-05-19 23:03 - 02141192 ____A (Solid State Networks) C:\Users\Oksana\Downloads\install_flashplayer11x32_mssd_aih.exe 2013-05-19 22:38 - 2013-05-19 22:39 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\FreeCDRipper 2013-05-16 20:34 - 2013-05-16 20:34 - 01026480 ____A (Koyote-Lab Inc.) C:\Users\Oksana\Downloads\FreeEasyCDDVDBurnerSetup.exe 2013-05-16 20:34 - 2013-05-16 20:34 - 00000000 ____D C:\Program Files (x86)\Free Easy CD DVD Burner 2013-05-16 12:00 - 2013-04-16 04:34 - 01455368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-05-16 11:59 - 2013-05-16 11:59 - 00001342 ____A C:\Users\Oksana\Desktop\Easy Audio Cutter.lnk 2013-05-16 11:59 - 2013-05-16 11:59 - 00001326 ____A C:\Users\Oksana\Desktop\Free CD Ripper.lnk 2013-05-16 11:59 - 2013-05-16 11:59 - 00001322 ____A C:\Users\Oksana\Desktop\Free Mp3 Wma Converter.lnk 2013-05-16 11:59 - 2013-03-06 08:31 - 19758592 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-05-16 11:59 - 2013-03-06 07:03 - 17561600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-05-16 11:59 - 2011-09-29 14:20 - 00164144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\COMCT232.OCX 2013-05-16 11:58 - 2013-05-16 11:59 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\FreeAudioPack 2013-05-16 11:58 - 2013-05-16 11:59 - 00000000 ____D C:\Program Files (x86)\Free mp3 Wma Converter 2013-05-16 11:58 - 2013-04-11 08:40 - 06987528 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-05-16 11:58 - 2013-03-15 02:17 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys 2013-05-16 11:58 - 2013-03-06 09:10 - 00112872 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-05-16 11:58 - 2013-03-06 08:31 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-05-16 11:58 - 2013-03-06 08:29 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-05-16 11:58 - 2013-03-06 07:03 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-05-16 11:58 - 2011-09-29 14:20 - 02084864 ____A (NCT Company Ltd.) C:\Windows\SysWOW64\AudDesign.dll 2013-05-16 11:58 - 2011-09-29 14:20 - 01986560 ____A (NCT Company Ltd.) C:\Windows\SysWOW64\AudFile.dll 2013-05-16 11:58 - 2011-09-29 14:20 - 01212416 ____A (NCT Company Ltd.) C:\Windows\SysWOW64\AudioInfos.dll 2013-05-16 11:58 - 2011-09-29 14:20 - 00484352 ____A C:\Windows\SysWOW64\lame_enc.dll 2013-05-16 11:58 - 2011-09-29 14:20 - 00479232 ____A (NCT Company Ltd.) C:\Windows\SysWOW64\AudioVisu.dll 2013-05-16 11:58 - 2011-09-29 14:20 - 00458752 ____A (NCT Company Ltd.) C:\Windows\SysWOW64\AudPlayer.dll 2013-05-16 11:58 - 2011-09-29 14:20 - 00454656 ____A (NCT Company Ltd.) C:\Windows\SysWOW64\AudioRecord.dll 2013-05-16 11:58 - 2011-09-29 14:20 - 00417792 ____A (NCT Company Ltd.) C:\Windows\SysWOW64\AudDisplay.dll 2013-05-16 11:58 - 2011-09-29 14:20 - 00348160 ____A (NCT Company Ltd.) C:\Windows\SysWOW64\WMAFile.dll 2013-05-16 11:58 - 2011-09-29 14:20 - 00307200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr70.dll 2013-05-16 11:58 - 2011-09-29 14:20 - 00116296 ____A C:\Windows\SysWOW64\NCTWMAProfiles.prx 2013-05-16 11:58 - 2011-09-29 14:19 - 01081616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl.ocx 2013-05-16 11:58 - 2011-09-29 14:19 - 01060864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFC71.dll 2013-05-16 11:58 - 2011-09-29 14:19 - 00662288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX 2013-05-16 11:58 - 2011-09-29 14:19 - 00224016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\TABCTL32.OCX 2013-05-16 11:58 - 2011-09-29 14:19 - 00152848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\COMDLG32.OCX 2013-05-16 11:58 - 2011-09-29 14:19 - 00141312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCFR.DLL 2013-05-16 11:58 - 2011-09-29 14:19 - 00119568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\VB6FR.DLL 2013-05-16 11:58 - 2011-09-29 14:19 - 00115920 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msinet.OCX 2013-05-16 11:58 - 2011-09-29 14:19 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\VB6STKIT.DLL 2013-05-16 11:58 - 2011-09-29 14:19 - 00059904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Mscc2fr.dll 2013-05-16 11:58 - 2011-09-29 14:19 - 00032768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\CMDLGFR.DLL 2013-05-16 11:58 - 2011-09-29 14:19 - 00021504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\TABCTFR.DLL 2013-05-16 11:58 - 2011-09-29 14:19 - 00015360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetfr.DLL 2013-05-16 11:57 - 2013-05-16 11:58 - 00458744 ____A (Bandoo Media Inc) C:\Users\Oksana\Downloads\Setup21_FreeConverter.exe ==================== One Month Modified Files and Folders ======= 2013-06-15 22:30 - 2013-01-17 18:54 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\Skype 2013-06-15 22:29 - 2013-06-15 22:29 - 00000000 ____D C:\FRST 2013-06-15 22:28 - 2013-06-15 22:28 - 01920546 ____A (Farbar) C:\Users\Oksana\Desktop\FRST64.exe 2013-06-15 22:20 - 2013-02-13 16:05 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-15 22:20 - 2013-02-13 16:05 - 00001120 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-15 22:17 - 2013-03-06 14:00 - 01967112 ____A C:\Windows\WindowsUpdate.log 2013-06-15 22:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\System32\sru 2013-06-15 21:50 - 2013-04-01 18:09 - 00000436 ____A C:\Windows\System32\Drivers\etc\hosts.ics 2013-06-15 21:07 - 2013-01-27 22:05 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\vlc 2013-06-15 21:00 - 2013-06-07 09:40 - 00000390 ____A C:\Windows\Tasks\Tube Karaoke Update.job 2013-06-15 20:59 - 2012-11-14 07:45 - 00754172 ____A C:\Windows\System32\perfh007.dat 2013-06-15 20:59 - 2012-11-14 07:45 - 00156362 ____A C:\Windows\System32\perfc007.dat 2013-06-15 20:59 - 2012-07-26 09:28 - 01748838 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-15 20:58 - 2013-01-17 12:16 - 00000000 ____D C:\Users\Oksana\Documents\Youcam 2013-06-14 22:01 - 2013-06-13 10:22 - 00143150 ____A C:\Users\Oksana\Desktop\OTL.Txt 2013-06-14 21:51 - 2013-06-14 21:51 - 00001259 ____A C:\Users\Oksana\Desktop\AdwCleaner2.txt 2013-06-14 21:50 - 2013-06-14 21:50 - 00001259 ____A C:\AdwCleaner[R5].txt 2013-06-14 21:47 - 2013-06-10 17:38 - 00194598 ____A C:\Windows\PFRO.log 2013-06-14 21:47 - 2013-03-31 19:46 - 00000000 ____D C:\Program Files (x86)\Kabel Deutschland 2013-06-14 21:47 - 2012-07-26 09:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-14 21:45 - 2013-06-14 21:45 - 00014455 ____A C:\AdwCleaner[S1].txt 2013-06-14 21:44 - 2013-06-14 21:44 - 00014516 ____A C:\AdwCleaner[R4].txt 2013-06-14 21:42 - 2013-01-17 19:15 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-06-14 18:23 - 2013-06-14 18:23 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\Avira 2013-06-14 18:20 - 2013-06-14 18:20 - 00083160 ____A (Avira GmbH) C:\Windows\System32\Drivers\avnetflt.sys 2013-06-14 18:18 - 2013-06-14 18:18 - 00002076 ____A C:\Users\Public\Desktop\Avira Control Center.lnk 2013-06-14 18:17 - 2013-06-14 18:17 - 00000000 ____D C:\Program Files (x86)\Avira 2013-06-14 18:17 - 2013-02-04 10:32 - 00000000 ____D C:\ProgramData\Avira 2013-06-14 18:16 - 2013-06-14 18:08 - 00007941 ____A C:\Users\Oksana\Desktop\JRT.txt 2013-06-14 17:50 - 2013-06-10 21:59 - 00000000 ____D C:\JRT 2013-06-14 17:48 - 2013-06-14 17:48 - 00017633 ____A C:\Users\Oksana\Desktop\AdwCleaner[R3].txt 2013-06-14 17:47 - 2013-06-14 17:47 - 00017633 ____A C:\AdwCleaner[R3].txt 2013-06-14 17:38 - 2013-06-14 17:38 - 00017572 ____A C:\AdwCleaner[R2].txt 2013-06-14 17:34 - 2013-06-14 17:49 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Oksana\Desktop\JRT.exe 2013-06-14 17:20 - 2013-06-14 17:19 - 00648201 ____A C:\Users\Oksana\Desktop\adwcleaner(1).exe 2013-06-14 10:50 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache 2013-06-13 22:19 - 2013-06-13 22:19 - 00001098 ____A C:\Users\Public\Desktop\TeamViewer 8.lnk 2013-06-13 22:09 - 2012-07-26 07:26 - 00524288 __ASH C:\Windows\System32\config\BBI 2013-06-13 09:48 - 2013-06-13 09:48 - 04327136 ____A (Systweak Inc ) C:\Users\Oksana\Downloads\sysrc_trial_9407_german01.exe 2013-06-13 09:45 - 2013-06-13 09:44 - 00004032 ____A C:\Windows\SysWOW64\jupdate-1.7.0_21-b11.log 2013-06-13 09:45 - 2013-03-12 12:53 - 00000000 ____D C:\Program Files (x86)\Java 2013-06-13 09:42 - 2013-06-13 09:42 - 00903072 ____A (Oracle Corporation) C:\Users\Oksana\Downloads\jxpiinstall(2).exe 2013-06-13 09:32 - 2013-06-10 17:49 - 00083968 __ASH C:\Users\Oksana\Desktop\Thumbs.db 2013-06-12 22:45 - 2012-11-14 08:51 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-11 09:21 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-06-10 22:48 - 2013-04-22 09:11 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-10 22:48 - 2013-01-17 18:54 - 00000000 ____D C:\ProgramData\Skype 2013-06-10 21:59 - 2013-06-10 21:59 - 00000000 ____D C:\Windows\ERUNT 2013-06-10 20:46 - 2013-06-10 20:46 - 00024607 ____A C:\AdwCleaner[R1].txt 2013-06-06 21:44 - 2013-06-06 21:44 - 00000000 ____D C:\Users\Oksana\Documents\Lucas 2013-06-06 21:33 - 2012-11-14 09:41 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-06-06 21:32 - 2013-06-06 21:32 - 16481056 ____A C:\Users\Oksana\Downloads\MEDIONAG.v3530_45147_Spr_PTD121130-03.exe 2013-06-06 21:32 - 2012-11-14 09:41 - 00000000 ____D C:\ProgramData\CyberLink 2013-06-06 21:31 - 2013-06-06 21:31 - 00967200 ____A (CyberLink) C:\Users\Oksana\Downloads\CyberLink_PhotoDirector_Downloader.exe 2013-06-05 00:09 - 2013-06-14 17:40 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-05 00:09 - 2013-06-14 17:40 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-04 13:13 - 2013-02-13 14:57 - 00000000 ____D C:\Users\Oksana\Documents\Rezepte 2013-06-04 13:12 - 2013-03-06 20:55 - 00000000 ____D C:\Users\Oksana\Documents\Irina 2013-06-03 23:19 - 2013-06-03 23:19 - 00000000 ____D C:\Users\Oksana\Documents\Luise Krening 2013-06-01 18:54 - 2013-06-01 18:54 - 00000000 ____D C:\Users\Oksana\AppData\Local\DDMSettings 2013-06-01 18:13 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\System32\NDF 2013-05-31 17:38 - 2013-05-27 12:22 - 00000000 ____D C:\Users\Oksana\dwhelper 2013-05-30 22:08 - 2013-05-30 22:08 - 00009565 ____A C:\Users\Oksana\Documents\MeineZip.zip 2013-05-30 19:55 - 2013-05-30 19:55 - 01110476 ____A C:\Users\Oksana\Downloads\7z920(1).exe 2013-05-30 19:55 - 2013-05-30 19:55 - 00000000 ____D C:\Program Files (x86)\7-Zip 2013-05-30 19:03 - 2013-05-30 19:04 - 00377856 ____A C:\Users\Oksana\Desktop\gmer_2.1.19163.exe 2013-05-30 19:03 - 2013-05-30 19:03 - 00377856 ____A C:\Users\Oksana\Downloads\gmer_2.1.19163.exe 2013-05-30 18:30 - 2013-05-30 18:30 - 00602112 ____A (OldTimer Tools) C:\Users\Oksana\Downloads\OTL(1).exe 2013-05-30 18:29 - 2013-05-29 23:41 - 00000474 ____A C:\Users\Oksana\Downloads\defogger_disable.log 2013-05-29 23:41 - 2013-05-29 23:41 - 00000246 ____A C:\Users\Oksana\Downloads\defogger_enable.log 2013-05-29 23:41 - 2013-05-29 23:41 - 00000000 ____A C:\Users\Oksana\defogger_reenable 2013-05-29 23:41 - 2013-01-17 12:10 - 00000000 ____D C:\users\Oksana 2013-05-29 23:40 - 2013-05-29 23:40 - 00050477 ____A C:\Users\Oksana\Downloads\Defogger.exe 2013-05-29 23:09 - 2013-05-29 23:09 - 00000000 ____D C:\Program Files (x86)\YTKaraoke 2013-05-29 23:09 - 2013-05-28 22:13 - 00000000 ____D C:\Program Files (x86)\LyricsFinder 2013-05-29 22:44 - 2013-05-29 22:44 - 00335656 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-29 22:43 - 2013-01-17 12:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-05-28 23:45 - 2013-05-28 23:34 - 00000000 ____A C:\Windows\SysWOW64\SystemPreferences.xml 2013-05-28 22:30 - 2013-05-28 22:30 - 00001614 ____A C:\Users\Oksana\Desktop\DivX Movies.lnk 2013-05-28 22:30 - 2013-05-28 22:30 - 00001132 ____A C:\Users\Public\Desktop\DivX Plus Player.lnk 2013-05-28 22:30 - 2013-05-28 22:11 - 00000000 ____D C:\ProgramData\DivX 2013-05-28 22:30 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\DivX 2013-05-28 22:29 - 2013-05-28 22:29 - 00001178 ____A C:\Users\Public\Desktop\DivX Plus Converter.lnk 2013-05-28 22:29 - 2013-05-28 22:12 - 00000000 ____D C:\Program Files\DivX 2013-05-28 22:27 - 2013-05-28 22:27 - 00955712 ____A (DivX, LLC) C:\Users\Oksana\Downloads\DivXInstaller.exe 2013-05-28 22:12 - 2013-02-06 10:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-05-28 22:11 - 2013-05-28 22:11 - 00715038 ____A C:\Windows\unins000.exe 2013-05-28 22:11 - 2013-05-28 22:11 - 00001989 ____A C:\Windows\unins000.dat 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\LavFilters 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\CDXReader 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\Xvid 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\OpenSource Flash Video Splitter 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\Haali 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\ffdshow 2013-05-28 22:11 - 2013-05-28 22:11 - 00000000 ____D C:\Program Files (x86)\DSP-worx 2013-05-28 22:08 - 2013-05-28 22:08 - 00774080 ____A C:\Users\Oksana\Downloads\CodecPack.exe 2013-05-28 21:32 - 2013-05-28 21:32 - 00000000 ___RD C:\Users\Oksana\AppData\Roaming\Brother 2013-05-28 11:11 - 2013-05-28 11:04 - 00000000 ____D C:\Users\Oksana\Documents\Oksana 2013-05-27 12:28 - 2013-05-27 12:28 - 00000000 ____D C:\Program Files (x86)\ConvertHelper 2013-05-27 12:27 - 2013-05-27 12:27 - 03782822 ____A (DownloadHelper ) C:\Users\Oksana\Downloads\ConvertHelperSetup.exe 2013-05-24 17:03 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData 2013-05-24 17:03 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore 2013-05-20 08:43 - 2013-05-20 08:43 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-05-20 08:43 - 2013-05-20 08:43 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-05-19 23:09 - 2013-05-19 23:08 - 02141192 ____A (Solid State Networks) C:\Users\Oksana\Downloads\install_flashplayer11x32_mssd_aih(1).exe 2013-05-19 23:03 - 2013-05-19 23:02 - 02141192 ____A (Solid State Networks) C:\Users\Oksana\Downloads\install_flashplayer11x32_mssd_aih.exe 2013-05-19 22:39 - 2013-05-19 22:38 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\FreeCDRipper 2013-05-16 20:34 - 2013-05-16 20:34 - 01026480 ____A (Koyote-Lab Inc.) C:\Users\Oksana\Downloads\FreeEasyCDDVDBurnerSetup.exe 2013-05-16 20:34 - 2013-05-16 20:34 - 00000000 ____D C:\Program Files (x86)\Free Easy CD DVD Burner 2013-05-16 11:59 - 2013-05-16 11:59 - 00001342 ____A C:\Users\Oksana\Desktop\Easy Audio Cutter.lnk 2013-05-16 11:59 - 2013-05-16 11:59 - 00001326 ____A C:\Users\Oksana\Desktop\Free CD Ripper.lnk 2013-05-16 11:59 - 2013-05-16 11:59 - 00001322 ____A C:\Users\Oksana\Desktop\Free Mp3 Wma Converter.lnk 2013-05-16 11:59 - 2013-05-16 11:58 - 00000000 ____D C:\Users\Oksana\AppData\Roaming\FreeAudioPack 2013-05-16 11:59 - 2013-05-16 11:58 - 00000000 ____D C:\Program Files (x86)\Free mp3 Wma Converter 2013-05-16 11:58 - 2013-05-16 11:57 - 00458744 ____A (Bandoo Media Inc) C:\Users\Oksana\Downloads\Setup21_FreeConverter.exe 2013-05-16 00:37 - 2013-06-12 22:45 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-05-16 00:36 - 2013-06-12 22:46 - 14320640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-16 00:35 - 2013-06-12 22:46 - 19230720 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-16 00:35 - 2013-06-12 22:45 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll Files to move or delete: ==================== C:\ProgramData\ntuser.dat ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-11 09:30 ==================== End Of Log ============================ |
16.06.2013, 05:52 | #50 |
/// the machine /// TB-Ausbilder | Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Windows 8: Task-Manager verwaltet Autostart - Neue Funktion - Windows 8 - PC-WELT da findest Du ne Anleitung wie man den Autostart bearbeitet. Alles raus bis auf System-sachen und AV Programm. Und Du hast F-Secure und Avira laufen, deinstalliere Avira.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.06.2013, 12:24 | #51 |
| Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Hallo Schruaber, hab Avira deinstalliert. Neu gestartet, F-secure war kurz grün geworden, dann ging ein Fenster auf, mein Rechner sei nicht ausreichend geschütz ich soll ihn neu starten. Gleichzeitig ging Windows Defender auf, ich soll die Datenbank aktualiesieren. Hab ich gemacht. Fsecure beibt dennoch rot die Meldung neu staren kommt immer wieder. Hab nun bedenken das mein rechner nun offene Scheunen Toren hat Dienste und Programme im Autostart hab ich deaktiviert. Nun ist mein Rechner beim Booten schneller. Was mir noch aufgefallen ist, es taucht immer noch zwar selten Werbung für Deals auf. Danke Sams |
17.06.2013, 12:52 | #52 |
/// the machine /// TB-Ausbilder | Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf In welchem Browser? Poste mal ein frisches OTL log, vorher aber bitte F-Secure deinstallieren und neu installieren.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.06.2013, 20:43 | #53 |
| Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Hallo Schrauber, hier die OTL nach deinstallation und neu installation von Fsecure. Bin über Mozila im Netz. Code:
ATTFilter OTL logfile created on: 17.06.2013 21:26:18 - Run 10 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Oksana\Desktop 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16599) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,88 Gb Total Physical Memory | 6,55 Gb Available Physical Memory | 83,11% Memory free 9,07 Gb Paging File | 7,71 Gb Available in Paging File | 85,02% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 869,80 Gb Total Space | 804,22 Gb Free Space | 92,46% Space Free | Partition Type: NTFS Drive D: | 60,00 Gb Total Space | 40,91 Gb Free Space | 68,18% Space Free | Partition Type: NTFS Computer Name: LAPTOP | User Name: Oksana | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.06.17 21:22:08 | 001,035,200 | ---- | M] (F-Secure Corporation) -- C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\fssm32.exe PRC - [2013.06.17 21:22:07 | 000,621,504 | ---- | M] (F-Secure Corporation) -- C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\FSGK32.EXE PRC - [2013.06.07 14:39:25 | 004,150,112 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe PRC - [2013.06.07 14:39:24 | 011,077,984 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe PRC - [2013.06.07 14:31:02 | 000,195,936 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe PRC - [2013.05.16 22:15:26 | 000,216,968 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe PRC - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2013.03.27 13:37:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Oksana\Desktop\OTL.exe PRC - [2013.01.18 11:06:36 | 000,188,400 | ---- | M] (F-Secure Corporation) -- C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe PRC - [2013.01.03 16:56:12 | 000,311,432 | ---- | M] (F-Secure Corporation) -- C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSM32.EXE PRC - [2013.01.03 16:56:12 | 000,209,032 | ---- | M] (F-Secure Corporation) -- C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSMA32.EXE PRC - [2012.09.30 14:00:56 | 001,112,000 | ---- | M] (Motorola Solutions, Inc.) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe PRC - [2012.07.17 18:10:16 | 000,165,760 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe PRC - [2012.05.25 12:00:44 | 000,061,152 | ---- | M] (F-Secure Corporation) -- C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Reputation\fsorsp.exe PRC - [2011.04.13 17:37:06 | 000,312,616 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe PRC - [2011.04.13 17:37:04 | 000,070,952 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe ========== Modules (No Company Name) ========== MOD - [2013.04.12 10:12:13 | 000,593,464 | ---- | M] () -- C:\Windows\WinSxS\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.482.65_none_b59e1e0911fd55ab\QtMultimediaKit1.dll MOD - [2013.01.03 15:28:18 | 000,086,016 | ---- | M] () -- C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\FSGUI\strres.eng MOD - [2013.01.03 15:28:18 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\FSGUI\fsavures.eng ========== Services (SafeList) ========== SRV:64bit: - [2013.04.09 06:48:42 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder) SRV:64bit: - [2013.03.02 04:45:07 | 000,171,008 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker) SRV:64bit: - [2013.03.02 04:45:05 | 000,180,224 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker) SRV:64bit: - [2013.02.02 10:21:45 | 000,467,456 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm) SRV:64bit: - [2013.01.29 03:57:14 | 000,014,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend) SRV:64bit: - [2013.01.10 01:23:16 | 001,964,544 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc) SRV:64bit: - [2013.01.10 01:22:35 | 000,438,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM) SRV:64bit: - [2012.11.06 06:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify) SRV:64bit: - [2012.10.19 13:27:10 | 000,386,344 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\Shared files\RichVideo64.exe -- (RichVideo64) SRV:64bit: - [2012.09.24 18:03:12 | 001,153,840 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService) SRV:64bit: - [2012.09.24 18:02:54 | 000,272,176 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS) SRV:64bit: - [2012.09.24 18:02:42 | 000,617,776 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) SRV:64bit: - [2012.09.24 18:02:16 | 000,149,296 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) SRV:64bit: - [2012.09.20 11:10:47 | 002,367,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService) SRV:64bit: - [2012.09.20 08:31:18 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc) SRV:64bit: - [2012.09.20 08:30:41 | 000,179,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure) SRV:64bit: - [2012.09.13 06:33:50 | 000,731,688 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3) SRV:64bit: - [2012.08.15 19:08:14 | 000,135,984 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr) SRV:64bit: - [2012.07.26 05:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc) SRV:64bit: - [2012.07.26 05:07:42 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc) SRV:64bit: - [2012.07.26 05:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc) SRV:64bit: - [2012.07.26 05:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc) SRV:64bit: - [2012.07.26 05:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon) SRV:64bit: - [2012.07.26 05:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc) SRV:64bit: - [2012.07.26 05:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup) SRV:64bit: - [2012.07.26 05:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso) SRV:64bit: - [2012.07.26 05:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS) SRV:64bit: - [2012.07.26 05:05:28 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc) SRV:64bit: - [2012.07.26 05:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService) SRV:64bit: - [2012.07.26 05:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent) SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss) SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync) SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown) SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv) SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange) SRV:64bit: - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat) SRV:64bit: - [2012.04.20 16:16:12 | 000,635,104 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R) SRV - [2013.06.11 21:47:28 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.06.07 14:39:25 | 004,150,112 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8) SRV - [2013.05.26 10:20:04 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2013.02.28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2013.01.18 11:06:36 | 000,188,400 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe -- (fshoster) SRV - [2013.01.03 16:56:12 | 000,209,032 | ---- | M] (F-Secure Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSMA32.EXE -- (FSMA) SRV - [2012.11.06 06:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify) SRV - [2012.10.22 19:40:30 | 000,277,024 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs) SRV - [2012.10.11 21:41:20 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012.09.30 14:01:24 | 001,132,480 | ---- | M] (Motorola Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service) SRV - [2012.09.30 14:00:56 | 001,112,000 | ---- | M] (Motorola Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor) SRV - [2012.09.01 20:07:22 | 000,014,904 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV - [2012.07.26 05:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc) SRV - [2012.07.17 18:10:32 | 000,364,416 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2012.07.17 18:10:30 | 000,276,864 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2012.07.17 18:10:16 | 000,165,760 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service) SRV - [2012.05.25 12:00:44 | 000,061,152 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Reputation\fsorsp.exe -- (FSORSPClient) SRV - [2011.04.13 17:37:06 | 000,312,616 | ---- | M] (CyberLink) [Auto | Running] -- C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe -- (CyberLink PowerDVD 10 MS Service) SRV - [2011.04.13 17:37:04 | 000,070,952 | ---- | M] (CyberLink) [Auto | Running] -- C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe -- (CyberLink PowerDVD 10 MS Monitor Service) SRV - [2009.08.24 23:16:12 | 000,544,768 | ---- | M] (mst software GmbH, Germany) [On_Demand | Stopped] -- C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe -- (DfSdkS) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013.04.09 07:27:43 | 000,284,424 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport) DRV:64bit: - [2013.03.02 12:57:48 | 000,337,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI) DRV:64bit: - [2013.03.02 12:57:46 | 000,077,544 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\storahci.sys -- (storahci) DRV:64bit: - [2013.03.02 12:45:20 | 000,148,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\tpm.sys -- (TPM) DRV:64bit: - [2013.03.02 12:45:19 | 000,194,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus) DRV:64bit: - [2013.03.02 12:39:38 | 000,069,864 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\pdc.sys -- (pdc) DRV:64bit: - [2013.02.02 13:19:44 | 000,446,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3) DRV:64bit: - [2013.02.02 09:25:23 | 000,037,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg) DRV:64bit: - [2013.01.29 03:57:05 | 000,035,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot) DRV:64bit: - [2013.01.29 01:08:22 | 000,230,904 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter) DRV:64bit: - [2013.01.10 03:53:32 | 000,028,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32) DRV:64bit: - [2012.11.27 05:55:44 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid) DRV:64bit: - [2012.11.20 06:54:31 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c) DRV:64bit: - [2012.11.14 10:19:48 | 000,165,504 | ---- | M] (ITE ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\IT9135BDA.sys -- (IT9135BDA) DRV:64bit: - [2012.11.06 05:55:44 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM) DRV:64bit: - [2012.10.22 19:40:12 | 005,332,896 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2012.10.12 10:08:01 | 000,027,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:64bit: - [2012.10.11 21:41:20 | 000,030,056 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\nvpciflt.sys -- (nvpciflt) DRV:64bit: - [2012.10.11 09:25:48 | 000,056,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor) DRV:64bit: - [2012.10.11 09:13:49 | 000,058,088 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\Drivers\dam.sys -- (dam) DRV:64bit: - [2012.10.10 13:18:16 | 004,309,032 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\NETwew00.sys -- (NETwNe64) DRV:64bit: - [2012.10.09 20:48:50 | 000,035,296 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\intelaud.sys -- (intaud_WaveExtensible) DRV:64bit: - [2012.10.09 20:48:50 | 000,025,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\iwdbus.sys -- (iwdbus) DRV:64bit: - [2012.10.09 20:48:48 | 000,188,896 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\xHCIPort.sys -- (XHCIPort) DRV:64bit: - [2012.10.09 20:48:48 | 000,047,072 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\usb3Hub.sys -- (usb3Hub) DRV:64bit: - [2012.10.01 16:41:40 | 001,337,216 | ---- | M] (Motorola Solutions, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\btmhsf.sys -- (btmhsf) DRV:64bit: - [2012.10.01 16:41:38 | 000,132,480 | ---- | M] (Motorola Solutions, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\btmaux.sys -- (btmaux) DRV:64bit: - [2012.09.20 09:55:33 | 000,212,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000) DRV:64bit: - [2012.09.20 09:55:30 | 000,120,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101) DRV:64bit: - [2012.09.20 09:55:27 | 003,265,256 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2012.09.20 09:55:24 | 000,533,224 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2012.09.13 06:35:08 | 000,162,344 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\AmpPal.sys -- (AMPPALP) DRV:64bit: - [2012.09.13 06:35:08 | 000,162,344 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\AmpPal.sys -- (AMPPAL) DRV:64bit: - [2012.09.05 04:54:26 | 000,454,456 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\SynTP.sys -- (SynTP) DRV:64bit: - [2012.09.01 20:01:56 | 000,647,736 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\iaStorA.sys -- (iaStorA) DRV:64bit: - [2012.08.06 13:07:08 | 000,068,136 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\iBtFltCoex.sys -- (ibtfltcoex) DRV:64bit: - [2012.07.31 01:04:12 | 000,690,832 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\Rt630x64.sys -- (RTL8168) DRV:64bit: - [2012.07.26 07:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2012.07.26 07:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\condrv.sys -- (condrv) DRV:64bit: - [2012.07.26 07:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID) DRV:64bit: - [2012.07.26 07:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt) DRV:64bit: - [2012.07.26 07:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor) DRV:64bit: - [2012.07.26 07:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex) DRV:64bit: - [2012.07.26 07:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis) DRV:64bit: - [2012.07.26 07:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2012.07.26 07:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2012.07.26 07:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS) DRV:64bit: - [2012.07.26 07:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2012.07.26 07:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv) DRV:64bit: - [2012.07.26 07:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass) DRV:64bit: - [2012.07.26 07:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2012.07.26 07:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\3ware.sys -- (3ware) DRV:64bit: - [2012.07.26 07:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2012.07.26 07:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2012.07.26 06:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\clfs.sys -- (CLFS) DRV:64bit: - [2012.07.26 06:54:34 | 000,096,496 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS) DRV:64bit: - [2012.07.26 06:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpci.sys -- (vpci) DRV:64bit: - [2012.07.26 05:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt) DRV:64bit: - [2012.07.26 04:29:47 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WSDPrint.sys -- (WSDPrintDevice) DRV:64bit: - [2012.07.26 04:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf) DRV:64bit: - [2012.07.26 04:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay) DRV:64bit: - [2012.07.26 04:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo) DRV:64bit: - [2012.07.26 04:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender) DRV:64bit: - [2012.07.26 04:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter) DRV:64bit: - [2012.07.26 04:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic) DRV:64bit: - [2012.07.26 04:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime) DRV:64bit: - [2012.07.26 04:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig) DRV:64bit: - [2012.07.26 04:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr) DRV:64bit: - [2012.07.26 04:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr) DRV:64bit: - [2012.07.26 04:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd) DRV:64bit: - [2012.07.26 04:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx) DRV:64bit: - [2012.07.26 04:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx) DRV:64bit: - [2012.07.26 04:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2012.07.26 04:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum) DRV:64bit: - [2012.07.26 04:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc) DRV:64bit: - [2012.07.26 04:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2012.07.26 04:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr) DRV:64bit: - [2012.07.26 04:25:02 | 000,202,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\BthLEEnum.sys -- (BthLEEnum) DRV:64bit: - [2012.07.26 04:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform) DRV:64bit: - [2012.07.26 04:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp) DRV:64bit: - [2012.07.26 04:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu) DRV:64bit: - [2012.07.02 16:16:02 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2012.06.25 12:24:50 | 000,092,536 | ---- | M] (CyberLink) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\CLVirtualDrive.sys -- (CLVirtualDrive) DRV:64bit: - [2012.06.19 09:40:52 | 000,342,528 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\IntcDAud.sys -- (IntcDAud) DRV:64bit: - [2012.06.13 19:24:00 | 000,252,048 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RtsUStor.sys -- (RSUSBSTOR) DRV - [2013.06.17 21:22:38 | 000,200,760 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys -- (F-Secure Gatekeeper) DRV - [2013.06.17 21:22:08 | 000,068,608 | ---- | M] (F-Secure Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\HIPS\drivers\fshs.sys -- (F-Secure HIPS) DRV - [2013.04.25 12:52:40 | 000,080,832 | ---- | M] (F-Secure Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Kabel Deutschland\apps\CCF_Scanning\fsni64.sys -- (fsni) DRV - [2013.01.03 16:56:16 | 000,014,472 | ---- | M] () [Kernel | System | Running] -- C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys -- (fsvista) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-174320049-3726716400-672341874-1001\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-174320049-3726716400-672341874-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-174320049-3726716400-672341874-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com IE - HKU\S-1-5-21-174320049-3726716400-672341874-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-174320049-3726716400-672341874-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-174320049-3726716400-672341874-1002\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-174320049-3726716400-672341874-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-174320049-3726716400-672341874-1002\..\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}: "URL" = hxxp://go.mail.ru/search?utf8in=1&fr=ietb&q={SearchTerms} IE - HKU\S-1-5-21-174320049-3726716400-672341874-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Bing " FF - prefs.js..browser.search.order.3: "Bing " FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.suggest.enabled: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.web.de/" FF - prefs.js..extensions.enabledAddons: info%40sharkcube.com:0.1 FF - prefs.js..extensions.enabledAddons: artur.dubovoy%40gmail.com:3.8.7 FF - prefs.js..extensions.enabledAddons: %7B37964A3C-4EE8-47b1-8321-34DE2C39BA4D%7D:2.5.3.58 FF - prefs.js..extensions.enabledAddons: %7B9AA46F4F-4DC7-4c06-97AF-5035170634FE%7D:5.5 FF - prefs.js..extensions.enabledAddons: toolbar%40web.de:2.6.1 FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.15 FF - prefs.js..extensions.enabledAddons: %7B5a95a9e0-59dd-4314-bd84-4d18ca83a0e2%7D:1.26 FF - prefs.js..extensions.enabledAddons: %7B23fcfd51-4958-4f00-80a3-ae97e717ed8b%7D:2.1.2.172 FF - prefs.js..extensions.enabledAddons: YTKaraoke%40DacSoft.org:1.114 FF - prefs.js..extensions.enabledAddons: uploader%40adblockfilters.mozdev.org:2.1 FF - prefs.js..extensions.enabledAddons: adblockpopups%40jessehakanen.net:0.7 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Plus Web Player Plug-In,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013.05.28 22:30:24 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.05.28 22:12:50 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\YTKaraoke@DacSoft.org: C:\Program Files (x86)\YTKaraoke\FF\ [2013.05.29 23:09:16 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.05.28 22:12:50 | 000,000,000 | ---D | M] [2013.02.04 20:43:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Oksana\AppData\Roaming\mozilla\Extensions [2013.02.04 20:43:00 | 000,000,000 | ---D | M] (Smiley Bar for Facebook) -- C:\Users\Oksana\AppData\Roaming\mozilla\Extensions\statuswinks@StatusWinks [2013.06.14 21:45:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Oksana\AppData\Roaming\mozilla\Firefox\Profiles\bohjm6te.default\extensions [2013.04.05 11:45:49 | 000,000,000 | ---D | M] (Спутник @Mail.Ru) -- C:\Users\Oksana\AppData\Roaming\mozilla\Firefox\Profiles\bohjm6te.default\extensions\{37964A3C-4EE8-47b1-8321-34DE2C39BA4D} [2013.05.28 22:14:31 | 000,000,000 | ---D | M] (Wajam) -- C:\Users\Oksana\AppData\Roaming\mozilla\Firefox\Profiles\bohjm6te.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2} [2013.05.28 22:31:43 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Oksana\AppData\Roaming\mozilla\Firefox\Profiles\bohjm6te.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013.06.12 14:16:50 | 000,134,804 | ---- | M] () (No name found) -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\extensions\adblockpopups@jessehakanen.net.xpi [2013.03.08 21:19:32 | 000,275,665 | ---- | M] () (No name found) -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\extensions\artur.dubovoy@gmail.com.xpi [2013.06.12 14:16:07 | 000,123,385 | ---- | M] () (No name found) -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\extensions\elemhidehelper@adblockplus.org.xpi [2013.02.18 22:21:53 | 000,020,272 | ---- | M] () (No name found) -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\extensions\info@sharkcube.com.xpi [2013.05.26 10:20:10 | 000,620,338 | ---- | M] () (No name found) -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\extensions\toolbar@web.de.xpi [2013.06.12 14:16:50 | 000,075,438 | ---- | M] () (No name found) -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\extensions\uploader@adblockfilters.mozdev.org.xpi [2013.05.19 22:39:57 | 000,117,280 | ---- | M] () (No name found) -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2013.06.12 14:15:45 | 000,870,680 | ---- | M] () (No name found) -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013.04.22 21:07:58 | 000,002,402 | ---- | M] () -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\searchplugins\bingp.xml [2013.05.26 10:20:25 | 000,002,418 | ---- | M] () -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\searchplugins\englische-ergebnisse.xml [2013.05.26 10:20:24 | 000,010,701 | ---- | M] () -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\searchplugins\gmx-suche.xml [2013.05.26 10:20:25 | 000,002,432 | ---- | M] () -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\searchplugins\lastminute.xml [2013.04.05 11:46:01 | 000,001,510 | ---- | M] () -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\searchplugins\mailru.xml [2013.05.26 10:20:24 | 000,005,682 | ---- | M] () -- C:\Users\Oksana\AppData\Roaming\mozilla\firefox\profiles\bohjm6te.default\searchplugins\webde-suche.xml [2013.05.26 11:40:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\Extensions [2013.05.26 10:20:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions [2013.05.26 10:20:05 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2013.05.28 22:30:24 | 000,000,000 | ---D | M] (No name found) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5 [2013.05.29 23:09:16 | 000,000,000 | ---D | M] ("Tube Karaoke") -- C:\PROGRAM FILES (X86)\YTKARAOKE\FF O1 HOSTS File: ([2012.07.26 07:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (no name) - {8984B388-A5BB-4DF7-B274-77B879E179DB} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (Tube Karaoke) - {F351B686-F6AF-45F1-9EB9-684C805B25B1} - C:\Program Files (x86)\YTKaraoke\ytkaraoke.dll (Dacotta SoftEngineering) O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll (Motorola Solutions, Inc.) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [bdinstaller] "C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\setupdownloader.exe" /args:"/after_restart" File not found O4 - HKLM..\Run: [CLMLServer_For_P2G8] C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink) O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.) O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [F-Secure Hoster (44553)] C:\Program Files (x86)\Kabel Deutschland\fshoster32.exe (F-Secure Corporation) O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files (x86)\Kabel Deutschland\apps\ComputerSecurity\Common\FSM32.EXE (F-Secure Corporation) O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH) O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.) O4 - HKLM..\Run: [YouCam Service] C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (CyberLink Corp.) O4 - HKU\S-1-5-21-174320049-3726716400-672341874-1001..\Run: [AppLauncher] C:\Program Files (x86)\Medion MediaPack 3\Ashampoo AppLauncher (Medion)\AppLauncher.exe (Ashampoo) O4 - HKU\S-1-5-21-174320049-3726716400-672341874-1002..\Run: [MAgent] C:\Users\Oksana\AppData\Roaming\Mail.Ru\Agent\magent.exe (Mail.Ru) O4 - Startup: C:\Users\Oksana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ConfirmFileDelete = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1 O7 - HKU\S-1-5-21-174320049-3726716400-672341874-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8:64bit: - Extra context menu item: An Bluetooth senden - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm () O8 - Extra context menu item: An Bluetooth senden - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm () O9:64bit: - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-154514-44482-15/4 File not found O9:64bit: - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-154514-44482-15/4 File not found O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9A34807A-9833-43AC-A876-5346935872C5}: DhcpNameServer = 83.169.184.225 83.169.184.161 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D93110B3-007B-4A4A-8BAC-33DF59D2732D}: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\Skype4COM.dll (Skype Technologies) O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O30 - LSA: Security Packages - (livessp) - File not found O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.06.17 21:13:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kabel Deutschland [2013.06.17 21:13:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Kabel Deutschland [2013.06.15 22:29:03 | 000,000,000 | ---D | C] -- C:\FRST [2013.06.15 22:28:13 | 001,920,546 | ---- | C] (Farbar) -- C:\Users\Oksana\Desktop\FRST64.exe [2013.06.14 17:49:34 | 000,545,954 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Oksana\Desktop\JRT.exe [2013.06.13 09:46:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2013.06.10 21:59:49 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT [2013.06.10 21:59:07 | 000,000,000 | ---D | C] -- C:\JRT [2013.06.06 21:44:03 | 000,000,000 | ---D | C] -- C:\Users\Oksana\Documents\Lucas [2013.06.03 23:19:26 | 000,000,000 | ---D | C] -- C:\Users\Oksana\Documents\Luise Krening [2013.06.01 18:54:18 | 000,000,000 | ---D | C] -- C:\Users\Oksana\AppData\Local\DDMSettings [2013.06.01 18:43:35 | 000,000,000 | ---D | C] -- C:\Users\Oksana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games [2013.05.30 19:55:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip [2013.05.30 18:31:48 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Oksana\Desktop\OTL.exe [2013.05.29 23:09:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\YTKaraoke [2013.05.28 22:13:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LyricsFinder [2013.05.28 22:12:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus [2013.05.28 22:12:15 | 000,000,000 | ---D | C] -- C:\Program Files\DivX [2013.05.28 22:12:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DivX Shared [2013.05.28 22:11:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid [2013.05.28 22:11:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow [2013.05.28 22:11:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xvid [2013.05.28 22:11:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX [2013.05.28 22:11:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.05.28 22:11:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ffdshow [2013.05.28 22:11:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lame For Audacity [2013.05.28 22:11:26 | 000,000,000 | ---D | C] -- C:\Users\Oksana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.05.28 22:11:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Haali [2013.05.28 22:11:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DSP-worx [2013.05.28 22:11:25 | 000,000,000 | ---D | C] -- C:\Users\Oksana\AppData\Roaming\LavFilters [2013.05.28 22:11:25 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX [2013.05.28 22:11:25 | 000,000,000 | ---D | C] -- C:\Users\Oksana\AppData\Roaming\CDXReader [2013.05.28 22:11:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenSource Flash Video Splitter [2013.05.28 21:32:35 | 000,000,000 | R--D | C] -- C:\Users\Oksana\AppData\Roaming\Brother [2013.05.28 11:04:44 | 000,000,000 | ---D | C] -- C:\Users\Oksana\Documents\Oksana [2013.05.27 12:28:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ConvertHelper [2013.05.27 12:22:58 | 000,000,000 | ---D | C] -- C:\Users\Oksana\dwhelper [2013.05.20 08:43:26 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\searchplugins [2013.05.20 08:43:26 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Extensions [2013.05.19 22:38:22 | 000,000,000 | ---D | C] -- C:\Users\Oksana\AppData\Roaming\FreeCDRipper ========== Files - Modified Within 30 Days ========== [2013.06.17 21:30:01 | 000,056,016 | ---- | M] () -- C:\Windows\SysNative\drivers\fsbts.sys [2013.06.17 21:25:31 | 000,067,584 | -H-- | M] () -- C:\Windows\bootstat.dat [2013.06.17 21:24:29 | 000,000,390 | ---- | M] () -- C:\Windows\tasks\Tube Karaoke Update.job [2013.06.17 21:24:03 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.06.17 21:23:29 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys [2013.06.17 21:23:23 | 2475,114,495 | -HS- | M] () -- C:\hiberfil.sys [2013.06.17 21:20:01 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.06.17 21:19:10 | 000,042,248 | ---- | M] () -- C:\Windows\SysWow64\drivers\fsbts.sys [2013.06.17 21:18:32 | 000,019,474 | ---- | M] () -- C:\Windows\prodsett_copy.ini [2013.06.17 21:13:47 | 000,002,051 | ---- | M] () -- C:\Users\Public\Desktop\Kabel Deutschland Launchpad.lnk [2013.06.17 20:42:01 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.06.17 20:38:37 | 001,748,838 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.06.17 20:38:37 | 000,754,172 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.06.17 20:38:37 | 000,711,282 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.06.17 20:38:37 | 000,156,362 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.06.17 20:38:37 | 000,133,150 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.06.15 22:28:19 | 001,920,546 | ---- | M] (Farbar) -- C:\Users\Oksana\Desktop\FRST64.exe [2013.06.14 17:34:20 | 000,545,954 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Oksana\Desktop\JRT.exe [2013.06.14 17:20:00 | 000,648,201 | ---- | M] () -- C:\Users\Oksana\Desktop\adwcleaner(1).exe [2013.06.13 22:19:27 | 000,001,098 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.05.30 22:08:46 | 000,009,565 | ---- | M] () -- C:\Users\Oksana\Documents\MeineZip.zip [2013.05.30 19:03:28 | 000,377,856 | ---- | M] () -- C:\Users\Oksana\Desktop\gmer_2.1.19163.exe [2013.05.29 23:41:34 | 000,000,000 | ---- | M] () -- C:\Users\Oksana\defogger_reenable [2013.05.29 22:44:22 | 000,335,656 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013.05.28 23:45:26 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\SystemPreferences.xml [2013.05.28 22:30:25 | 000,001,614 | ---- | M] () -- C:\Users\Oksana\Desktop\DivX Movies.lnk [2013.05.28 22:30:12 | 000,001,132 | ---- | M] () -- C:\Users\Public\Desktop\DivX Plus Player.lnk [2013.05.28 22:29:49 | 000,001,178 | ---- | M] () -- C:\Users\Public\Desktop\DivX Plus Converter.lnk [2013.05.28 22:11:29 | 000,001,989 | ---- | M] () -- C:\Windows\unins000.dat [2013.05.28 22:11:23 | 000,715,038 | ---- | M] () -- C:\Windows\unins000.exe ========== Files Created - No Company Name ========== [2013.06.17 21:30:01 | 000,056,016 | ---- | C] () -- C:\Windows\SysNative\drivers\fsbts.sys [2013.06.17 21:19:09 | 000,042,248 | ---- | C] () -- C:\Windows\SysWow64\drivers\fsbts.sys [2013.06.17 21:13:47 | 000,002,051 | ---- | C] () -- C:\Users\Public\Desktop\Kabel Deutschland Launchpad.lnk [2013.06.14 17:19:54 | 000,648,201 | ---- | C] () -- C:\Users\Oksana\Desktop\adwcleaner(1).exe [2013.06.13 22:19:27 | 000,001,110 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk [2013.06.13 22:19:27 | 000,001,098 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.06.07 09:40:59 | 000,000,390 | ---- | C] () -- C:\Windows\tasks\Tube Karaoke Update.job [2013.05.30 22:08:46 | 000,009,565 | ---- | C] () -- C:\Users\Oksana\Documents\MeineZip.zip [2013.05.30 19:04:06 | 000,377,856 | ---- | C] () -- C:\Users\Oksana\Desktop\gmer_2.1.19163.exe [2013.05.29 23:41:34 | 000,000,000 | ---- | C] () -- C:\Users\Oksana\defogger_reenable [2013.05.29 22:44:14 | 000,335,656 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013.05.28 23:34:37 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\SystemPreferences.xml [2013.05.28 22:30:25 | 000,001,614 | ---- | C] () -- C:\Users\Oksana\Desktop\DivX Movies.lnk [2013.05.28 22:30:12 | 000,001,132 | ---- | C] () -- C:\Users\Public\Desktop\DivX Plus Player.lnk [2013.05.28 22:29:49 | 000,001,178 | ---- | C] () -- C:\Users\Public\Desktop\DivX Plus Converter.lnk [2013.05.28 22:11:42 | 000,255,488 | ---- | C] () -- C:\Windows\SysNative\xvidvfw.dll [2013.05.28 22:11:41 | 000,696,832 | ---- | C] () -- C:\Windows\SysNative\xvidcore.dll [2013.05.28 22:11:41 | 000,173,568 | ---- | C] () -- C:\Windows\SysNative\xvid.ax [2013.05.28 22:11:40 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2013.05.28 22:11:40 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2013.05.28 22:11:40 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax [2013.05.28 22:11:35 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2013.05.28 22:11:28 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll [2013.05.28 22:11:27 | 000,148,992 | ---- | C] ( ) -- C:\Windows\SysNative\lagarith.dll [2013.05.28 22:11:26 | 000,715,038 | ---- | C] () -- C:\Windows\unins000.exe [2013.05.28 22:11:26 | 000,001,989 | ---- | C] () -- C:\Windows\unins000.dat [2013.05.20 12:49:59 | 000,387,688 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml [2013.05.19 22:42:05 | 000,002,471 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk [2013.05.16 11:58:54 | 000,484,352 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll [2013.04.06 14:01:23 | 000,007,605 | ---- | C] () -- C:\Users\Oksana\AppData\Local\Resmon.ResmonCfg [2013.03.31 19:49:32 | 000,019,474 | ---- | C] () -- C:\Windows\prodsett_copy.ini [2013.03.22 15:07:25 | 000,003,584 | ---- | C] () -- C:\Users\Oksana\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2013.03.15 14:42:21 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI [2013.03.15 14:42:21 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI [2013.01.27 16:01:34 | 000,000,125 | ---- | C] () -- C:\Windows\wininit.ini [2013.01.25 21:40:15 | 000,077,671 | ---- | C] () -- C:\Users\Oksana\AppData\Local\funmoods_2.0.1.crx [2012.11.14 10:31:46 | 007,024,928 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2012.11.14 10:19:05 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl [2012.11.14 10:03:57 | 000,598,780 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng700.bin [2012.11.14 10:03:50 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll [2012.11.14 10:03:49 | 000,755,048 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng700.bin [2012.11.14 08:55:38 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll [2012.07.26 10:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat [2012.07.26 10:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT [2012.07.26 09:21:26 | 000,067,584 | -H-- | C] () -- C:\Windows\bootstat.dat [2012.07.26 03:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2012.07.25 22:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2012.07.25 22:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2012.06.02 16:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat [2012.04.20 15:59:44 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll ========== ZeroAccess Check ========== [2012.11.14 10:30:56 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2013.03.06 08:31:28 | 019,758,592 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013.03.06 07:03:37 | 017,561,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012.07.26 05:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2012.07.26 05:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012.07.26 05:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013.01.25 21:40:26 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\0T1F0D1F2W1G1I1F1T1Q [2013.01.19 20:25:38 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\Canneverbe Limited [2013.05.28 22:11:26 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\CDXReader [2013.05.16 11:59:22 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\FreeAudioPack [2013.05.19 22:39:02 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\FreeCDRipper [2013.01.27 10:19:08 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\HoolappForAndroid [2013.05.28 22:11:28 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\LavFilters [2013.01.17 12:22:33 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\Lenovo [2013.01.21 15:13:44 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\MAGIX [2013.01.22 10:37:13 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\Mail.Ru [2013.02.12 18:47:24 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\Mra [2013.01.17 19:08:17 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\OpenOffice.org [2013.04.28 11:14:09 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\ProfiCAD [2013.04.05 21:31:32 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\QuickScan [2013.01.21 15:03:26 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\SuperEasy Software [2013.03.07 21:23:59 | 000,000,000 | ---D | M] -- C:\Users\Oksana\AppData\Roaming\TeamViewer [2013.05.02 19:54:03 | 000,000,000 | ---D | M] -- C:\Users\Oksana_2\AppData\Roaming\Lenovo ========== Purity Check ========== < End of report > Danke |
18.06.2013, 06:37 | #54 |
/// the machine /// TB-Ausbilder | Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Hi, sieht gut aus. Nutzt Du das Firefox Addon Adblock Plus?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.06.2013, 09:17 | #55 |
| Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Hab ein Screen Short von meinen Addons gemacht. Danke |
18.06.2013, 12:27 | #56 |
/// the machine /// TB-Ausbilder | Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Wajam und Download Helper raus, reboot. Noch Probleme mit Firefox? oder dem Rechner?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.06.2013, 21:42 | #57 |
| Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Hallo Schrauber, Danke, es scheint alles Ok zu sein. Soll ich nun die Tools deinstallieren? Waren Vieren auf meinem Rechner oder nur Malware Software? Danke noch mal Sams |
19.06.2013, 08:05 | #58 |
/// the machine /// TB-Ausbilder | Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Jap, aufräumen Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.06.2013, 10:08 | #59 |
| Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Hallo Schrauber, hab nun so weit alles durchgeführt nur mit Securina System Score meckert ein Programm an. Wenn ich auf das Programm "hier Klicken" gehe, geht ein neuer Tab auf mit dem Programm auf, hier der Link hxxp://www.python.org/getit/ weiß nicht was ich davon wählen soll, ist weiter verlinkt.... Bevor ich was falsches auswähle wollte ich nachfragen. Danke Sams Geändert von Sams (23.06.2013 um 10:10 Uhr) Grund: Link erscheint nicht |
23.06.2013, 16:01 | #60 |
/// the machine /// TB-Ausbilder | Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf Ehm welches Programm wird angemeckert?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Medion P7818 Win8, Extrem langsam beim Starten, dauernd gehen Fenster mit online Spielen auf |
antivir, beim starten, deaktiviert, fehler, folge, gesucht, hochfahren, internet, kabel, langsam, laptop, meldung, neues, online, rechner, rum, software, spiele, spielen, starten, system, tab, total, vieren, win |