|
Log-Analyse und Auswertung: Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglichWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
12.09.2013, 13:19 | #1 |
| Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich Ich habe mir vor kurzem ohne vorher zu googeln leider SpyHunter 4 aufgespielt und habespäter,bzw.heute gemerkt ,dass es selbst Malware ist. Ich habe es mit CC-Cleaner deinstalliert und anschließend die Registry gesäubert.Dann habe ich den Pc neu gestartet und noch immer startet er mit folgendem:Spyhunter,Windows XP,Windows7/8 und muss dann manuell ein Betriebssystem wählen zum booten,was dann auch funktioniert Nachdem ich gelesen hatte ,dass SpyHunter mit Malewarebytes komplett zu entfernen wäre,was ich dann auch probierte(diesen Logfile mit vielen Funden habe ich nicht mehr),anschließend bootete das System wieder wie gehabt mit SpyHunter usw.und ich probierte es mit Adware-cleaner zu beseitigen, wo auch einiges gefunden und gelöscht wurde.Diesen siehe logfile . Dann scannte ich das System # AdwCleaner v3.003 - Bericht erstellt am 12/09/2013 um 12:24:26 # Updated 07/09/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : PvB - PVB-PC # Gestartet von : C:\Users\PvB\Downloads\3003-adwcleaner.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\END Datei Gefunden : C:\Users\PvB\AppData\Roaming\Mozilla\Firefox\Profiles\oah0l3t3.default\searchplugins\Babylon.xml Datei Gefunden : C:\Users\PvB\AppData\Roaming\Mozilla\Firefox\Profiles\tg7dw9os.default-1378141527687\foxydeal.sqlite Datei Gefunden : C:\Windows\System32\Tasks\DSite Datei Gefunden : C:\Windows\System32\Uninstall.exe Datei Gefunden : C:\Windows\Tasks\DSite.job Ordner Gefunden : C:\Program Files (x86)\Mozilla Firefox\Extensions\ffxtlbr@babylon.com Ordner Gefunden C:\Program Files (x86)\Common Files\337 Ordner Gefunden C:\Program Files (x86)\driver-soft Ordner Gefunden C:\Program Files (x86)\Lyrics_Monkey Ordner Gefunden C:\Program Files (x86)\MyAshampoo Ordner Gefunden C:\Program Files (x86)\SoftwareUpdater Ordner Gefunden C:\Program Files (x86)\TelevisionFanaticEI Ordner Gefunden C:\Program Files (x86)\XingHaoLyrics Ordner Gefunden C:\Program Files\SoftwareUpdater Ordner Gefunden C:\ProgramData\Babylon Ordner Gefunden C:\ProgramData\Splashtop Ordner Gefunden C:\ProgramData\StarApp Ordner Gefunden C:\Users\PvB\AppData\Local\lollipop Ordner Gefunden C:\Users\PvB\AppData\LocalLow\boost_interprocess Ordner Gefunden C:\Users\PvB\AppData\LocalLow\delta Ordner Gefunden C:\Users\PvB\AppData\LocalLow\MyAshampoo Ordner Gefunden C:\Users\PvB\AppData\Roaming\DSite Ordner Gefunden C:\Users\PvB\AppData\Roaming\Splashtop ***** [ Verknüpfungen ] ***** Verknüpfung Gefunden : C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( hxxp://www.portaldosites.com/?utm_source=b&utm_medium=spfs1&utm_campaign=&utm_content=sc&from=spfs1&uid=SAMSUNGXSSDX830XSeries_S0WJNYABC08199&ts=1377676036 ) Verknüpfung Gefunden : C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( hxxp://www.portaldosites.com/?utm_source=b&utm_medium=spfs1&utm_campaign=&utm_content=sc&from=spfs1&uid=SAMSUNGXSSDX830XSeries_S0WJNYABC08199&ts=1377676036 ) Verknüpfung Gefunden : C:\Users\PvB\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( hxxp://www.portaldosites.com/?utm_source=b&utm_medium=spfs1&utm_campaign=&utm_content=sc&from=spfs1&uid=SAMSUNGXSSDX830XSeries_S0WJNYABC08199&ts=1377676036 ) ***** [ Registrierungsdatenbank ] ***** Daten Gefunden : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.portaldosites.com/?utm_source=b&utm_medium=spfs1&utm_campaign=&utm_content=sc&from=spfs1&uid=SAMSUNGXSSDX830XSeries_S0WJNYABC08199&ts=1377676036 Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\MyAshampoo Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\MyAshampoo\toolbar Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\XingHaoLyrics Schlüssel Gefunden : HKCU\Software\AppDataLow\Toolbar Schlüssel Gefunden : HKCU\Software\BI Schlüssel Gefunden : HKCU\Software\dsiteproducts Schlüssel Gefunden : HKCU\Software\Imesh Schlüssel Gefunden : HKCU\Software\lollipop Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D162BEE0-76A5-4D80-B348-B92F393D184D} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFE66D00-A56A-4F7F-81D7-4A28C5816D6C} Schlüssel Gefunden : HKCU\Software\MyAshampoo Schlüssel Gefunden : HKCU\Software\MyAshampoo\toolbar Schlüssel Gefunden : HKCU\Software\OCS Schlüssel Gefunden : HKCU\Software\powerpack Schlüssel Gefunden : HKCU\Software\Softonic Schlüssel Gefunden : [x64] HKCU\Software\BI Schlüssel Gefunden : [x64] HKCU\Software\dsiteproducts Schlüssel Gefunden : [x64] HKCU\Software\Imesh Schlüssel Gefunden : [x64] HKCU\Software\lollipop Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gefunden : [x64] HKCU\Software\MyAshampoo Schlüssel Gefunden : [x64] HKCU\Software\MyAshampoo\toolbar Schlüssel Gefunden : [x64] HKCU\Software\OCS Schlüssel Gefunden : [x64] HKCU\Software\powerpack Schlüssel Gefunden : [x64] HKCU\Software\Softonic Schlüssel Gefunden : HKLM\Software\Babylon Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\driverscanner Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Schlüssel Gefunden : HKLM\Software\DataMngr Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0ABE0FED-50E7-4E42-A125-57C0A11DBCDE} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{98A604FD-84D5-48F3-AD10-AE1776F55993} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D9D5A8C8-01A9-4F33-A167-15482E9CD2CE} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\tracing\askpartnercobrandingtool_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7C3B01BC-53A5-48A0-A43B-0C67731134B9} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D162BEE0-76A5-4D80-B348-B92F393D184D} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\lrcspal@xinghao.net Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyAshampoo Toolbar Schlüssel Gefunden : HKLM\SOFTWARE\MozillaPlugins\@ei.TelevisionFanatic.com/Plugin Schlüssel Gefunden : HKLM\Software\MyAshampoo Schlüssel Gefunden : HKLM\Software\MyAshampoo\toolbar Schlüssel Gefunden : HKLM\Software\Uniblue\DriverScanner Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Tarma Installer Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}] Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}] Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gefunden : HKCU\Software\Mozilla\Firefox\Extensions [lrcspal@xinghao.net] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}] ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16660 -\\ Mozilla Firefox v23.0.1 (de) [ Datei : C:\Users\PvB\AppData\Roaming\Mozilla\Firefox\Profiles\tg7dw9os.default-1378141527687\prefs.js ] Zeile gefunden : user_pref("extensions.crossrider.bic", "14110194bf74f4ec50c64447d3b0284b"); -\\ Google Chrome v [ Datei : C:\Users\PvB\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [9722 octets] - [12/09/2013 12:24:26] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [9782 octets] ########## erneut mit Malewarebytes und es wurde nicht mehr gefunden,doch der Pc bootet immer noch über SpyHunter.Ansonsten benutze ich aussser Malewarebytes und Adwarecleaner noch Microsoft essentials. Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.09.12.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16660 PvB :: PVB-PC [Administrator] Schutz: Aktiviert 12.09.2013 13:37:58 mbam-log-2013-09-12 (13-37-58).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 427612 Laufzeit: 16 Minute(n), 30 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
12.09.2013, 13:34 | #2 |
/// the machine /// TB-Ausbilder | Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
12.09.2013, 14:04 | #3 |
| Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich FRST Logfile:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-09-2013 02 Ran by PvB (administrator) on PVB-PC on 12-09-2013 14:58:48 Running from C:\Users\PvB\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Rocket Division Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Hercules®) C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe () C:\Windows\SysWOW64\C2MP\UpdateChecker.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe (Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\cpl2\HDJSeries2CPL.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1356240 2013-07-18] (Microsoft Corporation) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13260944 2012-11-20] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1253520 2012-11-19] (Realtek Semiconductor) HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-07-31] (Logitech, Inc.) HKLM\...\Run: [Hercules DJ Series TrayAgent] - C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe [3572048 2013-05-10] (Hercules®) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) MountPoints2: {161f3e22-71d2-11e2-9882-902b3415b62d} - H:\LaunchU3.exe -a ==================== Internet (Whitelisted) ==================== HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = PortalDoSites HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = PortalDoSites HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {63EE8684-4E15-469b-823D-D703A41BADC3} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH SearchScopes: HKCU - {68BDEDD4-9936-4744-8927-4F8AEFD89207} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\PvB\AppData\Roaming\Mozilla\Firefox\Profiles\tg7dw9os.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass64.dll (LastPass) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@holasearch.com FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt Chrome: ======= CHR Extension: () - C:\Users\PvB\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\0.0.4.1 CHR Extension: (LyricsPal) - C:\Users\PvB\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmiopbgcekanlhpjkonogoljpfmhpkhf\1.111 CHR Extension: (Plus-HD-3.8) - C:\Users\PvB\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjgnhihlklpobkaloamkankaaoclfjh\1.23.19_0 CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - \User Data\Default\Extensions\newtab.crx CHR HKLM-x32\...\Chrome\Extension: [mmiopbgcekanlhpjkonogoljpfmhpkhf] - C:\Program Files (x86)\XingHaoLyrics\Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () S2 CLKMSVC10_9EC60124; C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [240112 2010-11-18] (CyberLink) R2 HerculesDJControlMP3; C:\Program Files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE [47104 2013-05-21] (Hercules®) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165664 2012-08-23] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2013-07-18] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-07-18] (Microsoft Corporation) R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [275968 2007-05-28] (Rocket Division Software) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () R3 Bulk; C:\Windows\System32\Drivers\HDJBulk.sys [258352 2013-05-21] (© Guillemot R&D, 2013. All rights reserved.) R1 CLBStor; C:\Windows\System32\DRIVERS\CLBStor.sys [24560 2009-10-07] (Cyberlink Co.,Ltd.) R2 CLBUDF; C:\Windows\System32\Drivers\CLBUDF.sys [376304 2009-10-07] (CyberLink Corporation.) R3 HDJAsioK; C:\Windows\System32\Drivers\HDJAsioK.sys [320816 2013-05-21] (© Guillemot R&D, 2013. All rights reserved.) R3 HDJMidi; C:\Windows\System32\DRIVERS\HDJMidi.sys [274736 2013-05-21] (© Guillemot R&D, 2013. All rights reserved.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation) R1 MpKslb2311cf7; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2826F299-94E1-4018-A497-5FD3297419CC}\MpKslb2311cf7.sys [35664 2013-09-12] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation) S3 prwntdrv; C:\Windows\system32\prwntdrv.sys [16776 2010-08-25] () S3 prwntdrv; C:\Windows\system32\prwntdrv.sys [16776 2010-08-25] () R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [868848 2012-06-27] () U3 anp155l8; C:\Windows\System32\Drivers\anp155l8.sys [0 ] (Microsoft Corporation) S3 gdrv; \??\C:\Windows\gdrv.sys [x] S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [x] S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-12 14:47 - 2013-09-12 14:58 - 01949642 _____ (Farbar) C:\Users\PvB\Downloads\FRST64.exe 2013-09-12 12:56 - 2013-09-12 12:56 - 00000056 _____ C:\Windows\setupact.log 2013-09-12 12:56 - 2013-09-12 12:56 - 00000000 _____ C:\Windows\setuperr.log 2013-09-12 12:22 - 2013-09-12 12:32 - 00000000 ____D C:\AdwCleaner 2013-09-12 12:22 - 2013-09-12 12:22 - 01037278 _____ C:\Users\PvB\Downloads\3003-adwcleaner.exe 2013-09-12 11:24 - 2013-09-12 11:24 - 00000108 _____ C:\index.ini 2013-09-12 10:03 - 2013-09-12 10:03 - 00001127 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Malwarebytes 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-12 10:03 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-12 06:35 - 2013-05-14 16:50 - 00248832 _____ ( Hercules) C:\Windows\system32\HDJusbaudioapi_x64.dll 2013-09-12 06:32 - 2013-05-21 15:44 - 00320816 _____ (© Guillemot R&D, 2013. All rights reserved.) C:\Windows\system32\Drivers\HDJAsioK.sys 2013-09-12 06:32 - 2013-05-21 15:44 - 00274736 _____ (© Guillemot R&D, 2013. All rights reserved.) C:\Windows\system32\Drivers\HDJMidi.sys 2013-09-12 06:32 - 2013-05-21 15:44 - 00258352 _____ (© Guillemot R&D, 2013. All rights reserved.) C:\Windows\system32\Drivers\HDJBulk.sys 2013-09-12 06:32 - 2013-05-21 15:44 - 00038704 _____ (© Guillemot R&D, 2012. All rights reserved.) C:\Windows\system32\Drivers\HDJCtrl.sys 2013-09-12 06:32 - 2013-05-21 15:35 - 00091648 _____ (Hercules®) C:\Windows\system32\HDJAsiou.dll 2013-09-12 06:32 - 2013-05-21 15:35 - 00078336 _____ (Hercules®) C:\Windows\SysWOW64\HDJAsiou.dll 2013-09-12 06:32 - 2013-03-05 15:30 - 00079872 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\HerculesDJUSBAudioDevices_x64.dll 2013-09-12 06:32 - 2013-02-04 16:56 - 00000365 ____R C:\Windows\SysWOW64\HDJcustom.ini 2013-09-12 06:32 - 2013-02-04 16:56 - 00000365 ____R C:\Windows\system32\HDJcustom.ini 2013-09-12 06:27 - 2013-07-17 14:23 - 00065408 _____ (Etron Technology Inc) C:\Windows\system32\Drivers\EtronHub3.sys 2013-09-12 06:25 - 2013-06-18 16:22 - 00872152 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2013-09-12 06:25 - 2013-06-18 16:22 - 00074456 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll 2013-09-12 06:24 - 2013-09-12 06:24 - 00000000 ____D C:\Program Files\Logitech 2013-09-12 06:22 - 2013-09-12 06:22 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-09-12 06:22 - 2012-11-28 04:52 - 04222096 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2013-09-12 06:22 - 2012-11-28 02:30 - 00381365 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2013-09-12 06:22 - 2012-11-27 22:25 - 10612736 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat 2013-09-12 06:22 - 2012-11-21 00:32 - 00118928 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2013-09-12 06:22 - 2012-11-20 01:18 - 02714720 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2013-09-12 06:22 - 2012-11-16 21:30 - 03673232 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2013-09-12 06:22 - 2012-10-23 23:03 - 09546616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll 2013-09-12 06:22 - 2012-10-23 23:03 - 02080120 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll 2013-09-12 06:22 - 2012-10-23 02:48 - 01269904 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2013-09-12 06:22 - 2012-10-04 00:56 - 00772224 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll 2013-09-12 06:22 - 2012-10-02 21:41 - 00501192 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll 2013-09-12 06:22 - 2012-10-02 21:41 - 00487368 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll 2013-09-12 06:22 - 2012-10-02 21:41 - 00415688 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll 2013-09-12 06:22 - 2012-09-21 05:44 - 01460600 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek264.dll 2013-09-12 06:22 - 2012-09-20 07:59 - 00869752 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll 2013-09-12 06:22 - 2012-09-12 16:51 - 02743440 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2013-09-12 06:22 - 2012-09-09 21:34 - 02028920 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll 2013-09-12 06:22 - 2012-09-01 02:18 - 07164176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll 2013-09-12 06:22 - 2012-09-01 02:17 - 00434960 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll 2013-09-12 06:22 - 2012-09-01 02:17 - 00141584 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll 2013-09-12 06:22 - 2012-09-01 02:17 - 00124176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll 2013-09-12 06:22 - 2012-09-01 02:17 - 00075024 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll 2013-09-12 06:22 - 2012-08-21 21:51 - 00881808 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2013-09-12 06:22 - 2012-08-14 01:06 - 01561744 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2013-09-12 06:22 - 2012-07-16 04:13 - 00394616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll 2013-09-12 06:22 - 2012-07-16 04:13 - 00394616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll 2013-09-12 06:22 - 2012-06-21 00:26 - 00110592 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2013-09-12 06:22 - 2012-03-08 18:47 - 00202336 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2013-09-12 06:22 - 2012-03-08 18:47 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2013-09-12 06:22 - 2012-01-30 18:43 - 00836544 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll 2013-09-12 06:22 - 2012-01-10 17:20 - 00065944 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll 2013-09-12 06:22 - 2011-12-20 22:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2013-09-12 06:22 - 2011-11-22 23:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll 2013-09-12 06:22 - 2011-09-02 21:21 - 00221024 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll 2013-09-12 06:22 - 2011-09-02 21:21 - 00081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll 2013-09-12 06:22 - 2011-09-02 21:21 - 00078688 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll 2013-09-12 06:22 - 2011-08-24 00:00 - 00603984 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00712296 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00241768 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll 2013-09-12 06:22 - 2011-03-17 19:17 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll 2013-09-12 06:22 - 2011-03-08 00:11 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2013-09-12 06:22 - 2010-11-04 01:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2013-09-12 06:22 - 2010-09-27 16:34 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2013-09-12 06:22 - 2010-07-22 23:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll 2013-09-12 06:22 - 2009-11-24 16:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2013-09-12 06:22 - 2009-11-24 16:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll 2013-09-12 06:22 - 2009-11-24 16:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll 2013-09-12 06:22 - 2009-11-24 16:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2013-09-12 06:15 - 2013-09-12 14:45 - 00278317 _____ C:\Windows\WindowsUpdate.log 2013-09-12 06:12 - 2012-06-05 13:45 - 00237968 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtHDMIVX.sys 2013-09-12 06:12 - 2012-05-17 11:29 - 07163744 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64H.dll 2013-09-12 06:12 - 2012-05-17 11:29 - 00433504 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64H.dll 2013-09-12 06:12 - 2012-05-17 11:29 - 00141152 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64H.dll 2013-09-12 06:12 - 2012-05-17 11:29 - 00123744 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64H.dll 2013-09-12 06:12 - 2012-05-17 11:29 - 00074592 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64H.dll 2013-09-12 06:12 - 2011-12-02 14:20 - 03746408 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkHDM64.dll 2013-09-12 06:12 - 2011-09-27 14:04 - 02526824 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RHDMEx64.dll 2013-09-12 06:12 - 2011-07-06 13:27 - 00092264 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RHCoInst64.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00372056 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64H.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RH3DHT64.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RH3DAA64.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64H.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00097624 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64H.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64H.dll 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\ProgramData\ATI 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-09-12 05:24 - 2012-11-16 23:11 - 06253224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2013-09-12 05:24 - 2012-11-16 23:08 - 11922944 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-09-12 05:24 - 2012-11-16 22:52 - 00245944 _____ C:\Windows\SysWOW64\atiapfxx.blb 2013-09-12 05:24 - 2012-11-16 22:52 - 00245944 _____ C:\Windows\system32\atiapfxx.blb 2013-09-12 05:24 - 2012-11-16 22:51 - 00159744 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-09-12 05:24 - 2012-11-16 22:50 - 00918528 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-09-12 05:24 - 2012-11-16 22:45 - 00514048 _____ (AMD) C:\Windows\system32\atieclxx.exe 2013-09-12 05:24 - 2012-11-16 22:44 - 00238080 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2013-09-12 05:24 - 2012-11-16 22:43 - 00120320 _____ (AMD) C:\Windows\system32\atitmm64.dll 2013-09-12 05:24 - 2012-11-16 22:43 - 00059392 _____ (ATI Technologies, Inc.) C:\Windows\system32\atiedu64.dll 2013-09-12 05:24 - 2012-11-16 22:43 - 00043520 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll 2013-09-12 05:24 - 2012-11-16 22:43 - 00021504 _____ (AMD) C:\Windows\system32\atimuixx.dll 2013-09-12 05:24 - 2012-11-16 22:42 - 06811648 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-09-12 05:24 - 2012-11-16 22:34 - 26017280 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-09-12 05:24 - 2012-11-16 22:29 - 00069632 _____ (AMD) C:\Windows\system32\coinst_8.97.100.7.dll 2013-09-12 05:24 - 2012-11-16 22:17 - 19584512 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-09-12 05:24 - 2012-11-16 22:03 - 01960960 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdmv.dll 2013-09-12 05:24 - 2012-11-16 22:03 - 01053696 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6v.dll 2013-09-12 05:24 - 2012-11-16 21:59 - 00051200 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-09-12 05:24 - 2012-11-16 21:59 - 00046080 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-09-12 05:24 - 2012-11-16 21:59 - 00044544 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-09-12 05:24 - 2012-11-16 21:59 - 00044544 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-09-12 05:24 - 2012-11-16 21:58 - 15827456 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-09-12 05:24 - 2012-11-16 21:54 - 13402112 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-09-12 05:24 - 2012-11-16 21:54 - 04749312 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00364544 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00359936 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-09-12 05:24 - 2012-11-16 21:39 - 00041984 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00033280 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00017920 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00014848 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00014848 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2013-09-12 05:24 - 2012-11-16 21:38 - 00042496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-09-12 05:24 - 2012-11-16 21:37 - 00053248 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2013-09-12 05:24 - 2012-11-16 21:37 - 00032768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-09-12 05:24 - 2012-11-16 21:35 - 00056832 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-09-12 05:24 - 2012-11-16 21:35 - 00056832 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-09-12 05:24 - 2012-11-16 21:35 - 00056320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2013-09-12 05:24 - 2012-11-16 21:35 - 00056320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2013-09-12 04:54 - 2013-09-12 04:54 - 00002279 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12 Compact Mode.lnk 2013-09-12 04:54 - 2013-09-12 04:54 - 00001323 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12.lnk 2013-09-12 04:54 - 2013-09-12 04:54 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ashampoo 2013-09-12 03:37 - 2013-09-12 04:45 - 00000000 ____D C:\ProgramData\FreeDriverScout 2013-09-12 03:37 - 2013-09-12 03:37 - 00000000 ____D C:\Users\PvB\Documents\Freemium Driver Utilities 2013-09-12 03:30 - 2013-09-12 04:45 - 00000000 ____D C:\Program Files (x86)\Plus-HD-3.8 2013-09-12 03:29 - 2013-09-12 03:29 - 00000000 ____D C:\Program Files\Covus Freemium 2013-09-12 03:28 - 2013-09-12 04:45 - 00000000 ____D C:\ProgramData\Package Cache 2013-09-12 03:28 - 2013-09-12 04:45 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-09-12 03:01 - 2013-09-12 03:01 - 00000000 ____D C:\Users\PvB\Documents\Ashampoo Burning Studio 12 2013-09-05 09:26 - 2013-09-12 04:45 - 00000000 ____D C:\Windows\SysWOW64\languages 2013-09-05 09:26 - 2013-09-12 04:45 - 00000000 ____D C:\Windows\SysWOW64\custom matrices 2013-09-05 09:26 - 2013-09-12 04:45 - 00000000 ____D C:\Program Files (x86)\DirectVobSub 2013-09-05 09:26 - 2013-09-05 09:26 - 01180013 _____ C:\Windows\SysWOW64\unins000.exe 2013-09-05 09:26 - 2013-09-05 09:26 - 00715038 _____ C:\Windows\unins000.exe 2013-09-05 09:26 - 2013-09-05 09:26 - 00052895 _____ C:\Windows\SysWOW64\unins000.dat 2013-09-05 09:26 - 2013-09-05 09:26 - 00001890 _____ C:\Windows\unins000.dat 2013-09-05 09:26 - 2013-09-05 09:26 - 00000000 ____D C:\Program Files (x86)\Xvid 2013-09-05 09:26 - 2012-02-26 16:45 - 00328704 _____ C:\Windows\SysWOW64\ff_libfaad2.dll 2013-09-05 09:26 - 2012-02-26 16:40 - 00251392 _____ C:\Windows\SysWOW64\ff_kernelDeint.dll 2013-09-05 09:26 - 2011-12-17 14:59 - 00001695 _____ C:\Windows\SysWOW64\openIE.js 2013-09-05 09:26 - 2011-05-30 15:42 - 00255488 _____ C:\Windows\system32\xvidvfw.dll 2013-09-05 09:26 - 2011-05-30 15:42 - 00240640 _____ C:\Windows\SysWOW64\xvidvfw.dll 2013-09-05 09:26 - 2011-05-23 11:52 - 00153088 _____ C:\Windows\SysWOW64\xvid.ax 2013-09-05 09:26 - 2011-05-23 09:49 - 00173568 _____ C:\Windows\system32\xvid.ax 2013-09-05 09:26 - 2011-05-23 09:45 - 00696832 _____ C:\Windows\system32\xvidcore.dll 2013-09-05 09:26 - 2010-12-12 02:16 - 00017903 _____ C:\Windows\SysWOW64\gnu_license.txt 2013-09-05 09:26 - 2010-12-12 02:16 - 00001563 _____ C:\Windows\SysWOW64\Boost_Software_License_1.0.txt 2013-09-05 09:23 - 2010-11-21 05:24 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll 2013-09-05 08:30 - 2013-09-05 08:30 - 00000110 ___RH C:\Users\PvB\Downloads\Stinger.opt 2013-09-05 08:24 - 2013-09-05 08:30 - 00000000 ____D C:\Program Files\stinger 2013-09-05 07:46 - 2013-09-05 07:46 - 00000000 ____D C:\Program Files\Realtek 2013-09-05 06:41 - 2013-09-05 08:09 - 00000000 ___DC C:\Users\PvB\AppData\Local\MigWiz 2013-09-05 03:19 - 2013-09-12 09:51 - 00000000 ____D C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP 2013-09-05 03:06 - 2013-09-05 03:06 - 67108864 ____H (Piriform Ltd) C:\Users\PvB\AppData\Roaming\fixmapi.exe 2013-09-05 03:06 - 2013-09-05 03:06 - 00003242 _____ C:\Windows\System32\Tasks\{65FACB05-279E-462F-BE27-B5B7E41F5E11} 2013-09-05 02:29 - 2013-09-05 02:37 - 00000000 ____D C:\Windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP 2013-09-05 02:29 - 2013-09-05 02:29 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-09-05 02:29 - 2013-09-05 02:29 - 00000000 _____ C:\autoexec.bat 2013-09-05 02:12 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2013-09-05 02:12 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2013-09-05 02:12 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2013-09-05 02:12 - 2012-08-23 16:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2013-09-05 02:12 - 2012-08-23 15:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-09-05 02:12 - 2012-08-23 15:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-09-05 02:12 - 2012-08-23 15:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-09-05 02:12 - 2012-08-23 15:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-09-05 02:12 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2013-09-05 02:12 - 2012-08-23 15:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2013-09-05 02:12 - 2012-08-23 15:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-09-05 02:12 - 2012-08-23 15:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2013-09-05 02:12 - 2012-08-23 15:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2013-09-05 02:12 - 2012-08-23 14:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-09-05 02:12 - 2012-08-23 13:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2013-09-05 02:12 - 2012-08-23 13:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-09-05 02:12 - 2012-08-23 13:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2013-09-05 02:12 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2013-09-05 02:12 - 2012-08-23 12:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-09-05 02:12 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2013-09-05 02:12 - 2012-08-23 12:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-09-05 02:12 - 2012-08-23 12:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-09-05 02:12 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-09-05 02:12 - 2012-08-23 10:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-09-05 02:12 - 2012-08-23 10:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-09-05 02:07 - 2012-08-24 20:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-09-05 02:07 - 2012-08-24 20:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-09-05 02:07 - 2012-08-24 20:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-09-05 02:07 - 2012-08-24 20:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-09-05 02:07 - 2012-08-24 18:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-09-05 02:07 - 2012-08-24 18:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-09-05 02:07 - 2012-08-24 18:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-09-05 02:07 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-09-05 02:07 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-09-03 21:19 - 2013-09-03 21:19 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-09-03 21:19 - 2013-09-03 21:19 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-09-03 03:52 - 2013-09-12 04:45 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-09-02 21:46 - 2013-09-02 21:46 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-09-02 21:46 - 2013-09-02 21:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-09-02 20:16 - 2013-09-02 20:16 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00000000 ____D C:\ProgramData\Sun 2013-09-02 20:16 - 2013-09-02 20:16 - 00000000 ____D C:\Program Files (x86)\Java 2013-09-02 20:14 - 2013-09-03 04:13 - 00000000 ____D C:\Program Files\Java 2013-09-02 20:14 - 2013-09-02 20:14 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-09-02 19:48 - 2013-09-02 19:48 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-02 19:48 - 2013-09-02 19:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-02 19:20 - 2013-09-05 07:37 - 00003232 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-09-02 19:20 - 2013-09-02 19:20 - 00000000 ____D C:\Users\PvB\AppData\Roaming\AVG2013 2013-09-02 19:19 - 2013-09-02 21:42 - 00000000 ___HD C:\$AVG 2013-09-02 19:19 - 2013-09-02 21:42 - 00000000 ____D C:\ProgramData\AVG2013 2013-09-02 19:18 - 2013-09-02 21:43 - 00000000 ____D C:\ProgramData\MFAData 2013-09-02 19:18 - 2013-09-02 19:21 - 00000000 ____D C:\Users\PvB\AppData\Local\Avg2013 2013-09-02 19:18 - 2013-09-02 19:18 - 00000000 ____D C:\Users\PvB\AppData\Local\MFAData 2013-09-02 18:55 - 2013-09-02 18:55 - 00000000 ____D C:\Program Files (x86)\Emsisoft HiJackFree 2013-09-02 18:43 - 2013-09-02 18:43 - 00003118 _____ C:\Windows\System32\Tasks\{E79E7AF6-22C4-4BFE-B386-A9F49AFCB6E0} 2013-09-02 18:39 - 2013-09-02 18:39 - 00003126 _____ C:\Windows\System32\Tasks\{1901E6CA-FC54-4E2F-86D2-C3156922418E} 2013-09-02 00:23 - 2013-09-02 00:23 - 00039904 _____ C:\Windows\SysWOW64\DiscHandler.exe 2013-09-01 20:38 - 2013-09-01 20:38 - 00000055 _____ C:\Users\PvB\AppData\Roaming\WB.CFG 2013-09-01 20:38 - 2013-09-01 20:38 - 00000005 _____ C:\Users\PvB\AppData\Roaming\WBPU-TTL.DAT 2013-09-01 19:44 - 2013-09-02 19:32 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Ipobc 2013-09-01 19:44 - 2013-09-02 19:03 - 00000000 ____D C:\Users\PvB\AppData\Roaming\tor 2013-09-01 19:44 - 2013-09-02 18:36 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Hetu 2013-09-01 19:44 - 2013-09-01 19:44 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Ruuny 2013-09-01 19:44 - 2013-09-01 19:44 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Effeir 2013-09-01 19:38 - 2013-09-01 19:38 - 00000000 ____D C:\Users\PvB\AppData\Roaming\0D0S1L2Z1P1B 2013-09-01 19:29 - 2013-09-01 19:29 - 00003372 _____ C:\Windows\System32\Tasks\{A4667A53-6E83-40FC-AD5C-A4185730D018} 2013-08-31 11:08 - 2013-08-31 11:18 - 00000000 ____D C:\Users\PvB\AppData\Roaming\vlc 2013-08-31 11:01 - 2013-08-31 11:01 - 00000000 ____D C:\Users\PvB\AppData\Roaming\SeeSimilar 2013-08-31 11:00 - 2013-08-31 11:00 - 00000000 ____D C:\Users\PvB\AppData\Roaming\4Free 2013-08-31 10:45 - 2013-08-31 10:45 - 00000000 ____D C:\Users\PvB\Documents\Tipard Studio 2013-08-31 10:45 - 2013-08-31 10:45 - 00000000 ____D C:\Users\PvB\AppData\Local\Tipard Studio 2013-08-31 10:09 - 2013-08-31 10:20 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Xilisoft 2013-08-31 09:55 - 2013-08-31 09:56 - 00000000 ____D C:\Users\PvB\AppData\Roaming\FreeVideoConverter 2013-08-31 09:47 - 2013-08-31 10:20 - 00000000 ____D C:\Program Files (x86)\AnvSoft 2013-08-31 09:47 - 2013-08-31 09:47 - 00000000 ____D C:\Users\PvB\Documents\Any Video Converter Professional 2013-08-31 09:47 - 2013-08-31 09:47 - 00000000 ____D C:\Users\PvB\Documents\Any Video Converter 2013-08-31 09:40 - 2013-08-31 09:40 - 00000000 ____D C:\Users\PvB\Documents\My Received Files 2013-08-31 09:40 - 2013-08-31 09:40 - 00000000 ____D C:\Users\PvB\AppData\Roaming\MusicNet 2013-08-31 09:30 - 2013-09-05 09:26 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2013-08-31 09:30 - 2013-09-05 09:26 - 00000000 ____D C:\Program Files (x86)\DSP-worx 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\LavFilters 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\CDXReader 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Program Files (x86)\OpenSource Flash Video Splitter 2013-08-31 09:21 - 2013-08-31 11:25 - 00000000 ____D C:\Users\PvB\AppData\Local\VMware 2013-08-31 09:20 - 2013-09-12 05:49 - 00000000 ____D C:\Users\PvB\AppData\Roaming\VMware 2013-08-31 09:01 - 2013-09-12 05:49 - 00000000 ____D C:\ProgramData\VMware 2013-08-30 06:21 - 2013-08-30 06:21 - 04012544 _____ C:\Windows\system32\ffmpeg.dll 2013-08-30 06:20 - 2013-08-30 06:20 - 04374016 _____ C:\Windows\system32\ffdshow.ax 2013-08-30 06:20 - 2013-08-30 06:20 - 00631296 _____ C:\Windows\system32\TomsMoComp_ff.dll 2013-08-30 06:20 - 2013-08-30 06:20 - 00474624 _____ C:\Windows\system32\ff_kernelDeint.dll 2013-08-30 06:20 - 2012-12-13 22:59 - 00127488 _____ C:\Windows\system32\ff_vfw.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 01532928 _____ C:\Windows\system32\ff_samplerate.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00222720 _____ C:\Windows\system32\ff_libdts.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00190464 _____ C:\Windows\system32\libmpeg2_ff.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00183296 _____ C:\Windows\system32\ff_unrar.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00156672 _____ C:\Windows\system32\ff_libmad.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00116224 _____ C:\Windows\system32\ff_liba52.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00114688 _____ C:\Windows\system32\ff_wmv9.dll 2013-08-30 05:54 - 2012-03-22 18:46 - 04417024 _____ C:\Windows\SysWOW64\ffmpeg.dll 2013-08-30 05:53 - 2012-03-22 18:46 - 03471360 _____ C:\Windows\SysWOW64\ffdshow.ax 2013-08-30 05:53 - 2012-02-26 16:47 - 00079360 _____ C:\Windows\SysWOW64\ff_vfw.dll 2013-08-30 05:51 - 2012-02-26 16:46 - 00260608 _____ C:\Windows\SysWOW64\TomsMoComp_ff.dll 2013-08-30 05:51 - 2012-02-26 16:46 - 00158720 _____ C:\Windows\SysWOW64\ff_unrar.dll 2013-08-30 05:51 - 2012-02-26 16:46 - 00099840 _____ C:\Windows\SysWOW64\ff_wmv9.dll 2013-08-30 05:51 - 2012-02-26 16:45 - 01525248 _____ C:\Windows\SysWOW64\ff_samplerate.dll 2013-08-30 05:51 - 2012-02-26 16:45 - 00212480 _____ C:\Windows\SysWOW64\ff_libdts.dll 2013-08-30 05:51 - 2012-02-26 16:45 - 00146944 _____ C:\Windows\SysWOW64\ff_libmad.dll 2013-08-30 05:51 - 2012-02-26 16:45 - 00137728 _____ C:\Windows\SysWOW64\libmpeg2_ff.dll 2013-08-30 05:51 - 2012-02-26 16:45 - 00115200 _____ C:\Windows\SysWOW64\ff_liba52.dll 2013-08-28 09:49 - 2013-08-28 09:52 - 00000000 ____D C:\Users\PvB\AppData\Roaming\ObviousIdea 2013-08-28 09:47 - 2013-08-28 09:47 - 00000000 ____D C:\User Data 2013-08-28 08:25 - 2013-09-03 04:46 - 00000000 ____D C:\Users\PvB\AppData\Local\DeSTRoi 2013-08-28 07:50 - 2013-08-28 07:50 - 00000000 ____D C:\.Trash-999 2013-08-28 04:32 - 2013-08-28 04:32 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Standard 2013-08-28 04:32 - 2013-08-28 04:32 - 00000000 ____D C:\Program Files (x86)\Shark007 2013-08-28 04:31 - 2013-08-28 04:32 - 00000000 ____D C:\ProgramData\Standard 2013-08-28 04:27 - 2013-08-28 04:27 - 00000000 ____D C:\Program Files\K-Lite Codec Pack x64 2013-08-28 04:23 - 2013-09-05 09:23 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Shark007 2013-08-28 04:23 - 2013-09-05 09:23 - 00000000 ____D C:\ProgramData\Shark007 2013-08-28 04:23 - 2007-02-05 17:05 - 00000038 _____ C:\Windows\AviSplitter.INI 2013-08-28 04:22 - 2013-09-05 09:22 - 00000000 ____D C:\Program Files\Shark007 2013-08-28 04:22 - 2013-04-05 21:27 - 02231296 _____ C:\Windows\system32\ac3filter.acm.new 2013-08-28 04:22 - 2013-01-11 09:16 - 04294656 _____ C:\Windows\system32\x264vfw.dll 2013-08-28 04:22 - 2012-07-21 11:55 - 00180736 _____ (fccHandler) C:\Windows\system32\ac3acm.acm 2013-08-28 04:22 - 2012-07-21 11:54 - 00361472 _____ (fccHandler) C:\Windows\system32\aacacm.acm 2013-08-28 04:22 - 2012-07-17 14:21 - 00206336 _____ C:\Windows\system32\unrar64.dll 2013-08-28 04:22 - 2011-12-07 19:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll 2013-08-28 04:22 - 2009-08-11 18:22 - 00580096 _____ C:\Windows\system32\ac3filter.acm.old 2013-08-28 04:22 - 2009-08-11 17:22 - 00580096 _____ C:\Windows\system32\ac3filter.acm 2013-08-28 04:22 - 2009-01-22 21:51 - 00124909 _____ (Open Source Software community project) C:\Windows\system32\pthreadGC2.dll 2013-08-28 04:20 - 2013-08-28 04:20 - 00003584 _____ C:\Users\PvB\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-08-28 04:12 - 2013-08-28 04:12 - 00000000 ____D C:\Windows\SysWOW64\C2MP 2013-08-27 17:24 - 2013-09-05 09:49 - 00002934 _____ C:\Windows\System32\Tasks\{720DB07B-6571-4601-80F7-B3BED7BC3D88} 2013-08-27 17:24 - 2013-09-05 09:49 - 00002934 _____ C:\Windows\System32\Tasks\{12258E8A-F421-41D3-8B14-723E36D317BF} 2013-08-27 00:35 - 2013-08-27 00:35 - 00000000 ____D C:\Users\PvB\Neo 2013-08-26 01:24 - 2013-09-12 05:11 - 00000000 ____D C:\Users\PvB\AppData\Roaming\LumacDaemon 2013-08-26 01:24 - 2013-08-26 01:24 - 00000000 ____D C:\Users\PvB\AppData\Local\Firstload 2013-08-20 11:09 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2013-08-20 11:09 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2013-08-20 11:09 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2013-08-20 11:09 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2013-08-20 11:09 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2013-08-20 11:09 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2013-08-20 10:37 - 2013-08-20 10:37 - 00000219 _____ C:\Users\PvB\Desktop\Counter-Strike Global Offensive.url 2013-08-20 10:37 - 2013-08-20 10:37 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-08-20 10:26 - 2013-08-31 00:07 - 00000000 ____D C:\Program Files (x86)\Steam 2013-08-20 10:26 - 2013-08-20 10:26 - 00000917 _____ C:\Users\Public\Desktop\Steam.lnk 2013-08-15 00:08 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 00:08 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 00:08 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 00:08 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 00:08 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 00:08 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 00:08 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 00:08 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 00:08 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 00:08 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 00:08 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 00:08 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 00:08 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 00:08 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 00:08 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 00:08 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 00:08 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 00:08 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 00:08 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 00:08 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 00:08 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 00:08 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 00:08 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 00:08 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 00:08 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 00:08 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 00:08 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 00:08 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 00:08 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 00:08 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 00:08 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-15 00:05 - 2013-08-15 00:06 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 18:20 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 18:20 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 18:20 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 18:20 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 18:20 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 18:20 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 18:20 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 18:20 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 18:20 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 18:20 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 18:20 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 18:20 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 18:20 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 18:20 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 18:20 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 18:20 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 18:20 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 18:20 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 18:20 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 18:20 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 18:20 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 18:20 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 18:20 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 18:20 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 18:20 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 18:20 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 18:20 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys ==================== One Month Modified Files and Folders ======= 2013-09-12 14:54 - 2012-06-27 17:01 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-12 14:48 - 2013-09-12 14:48 - 00000000 ____D C:\FRST 2013-09-12 14:45 - 2013-09-12 06:15 - 00278317 _____ C:\Windows\WindowsUpdate.log 2013-09-12 13:03 - 2009-07-14 06:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-12 13:03 - 2009-07-14 06:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-12 13:00 - 2011-04-12 09:43 - 00699432 _____ C:\Windows\system32\perfh007.dat 2013-09-12 13:00 - 2011-04-12 09:43 - 00149572 _____ C:\Windows\system32\perfc007.dat 2013-09-12 13:00 - 2009-07-14 07:13 - 01620684 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-12 12:56 - 2013-09-12 12:56 - 00000056 _____ C:\Windows\setupact.log 2013-09-12 12:56 - 2013-09-12 12:56 - 00000000 _____ C:\Windows\setuperr.log 2013-09-12 12:56 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-12 12:50 - 2012-06-27 16:54 - 00000000 ____D C:\Program Files\CCleaner 2013-09-12 12:32 - 2013-09-12 12:22 - 00000000 ____D C:\AdwCleaner 2013-09-12 12:25 - 2012-06-27 16:33 - 00000991 _____ C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-12 12:22 - 2013-09-12 12:22 - 01037278 _____ C:\Users\PvB\Downloads\3003-adwcleaner.exe 2013-09-12 11:36 - 2013-02-28 12:31 - 00000000 ____D C:\Program Files (x86)\7-Zip 2013-09-12 11:24 - 2013-09-12 11:24 - 00000108 _____ C:\index.ini 2013-09-12 10:03 - 2013-09-12 10:03 - 00001127 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Malwarebytes 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-12 09:51 - 2013-09-05 03:19 - 00000000 ____D C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP 2013-09-12 09:38 - 2012-06-27 16:37 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-09-12 06:36 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-12 06:32 - 2012-06-27 17:32 - 00000000 ____D C:\Program Files\Guillemot 2013-09-12 06:25 - 2012-06-27 16:37 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-09-12 06:24 - 2013-09-12 06:24 - 00000000 ____D C:\Program Files\Logitech 2013-09-12 06:24 - 2012-12-14 21:20 - 00000000 ____D C:\ProgramData\Logitech 2013-09-12 06:24 - 2012-06-29 21:14 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2013-09-12 06:24 - 2012-06-29 21:14 - 00000000 ____D C:\ProgramData\Logishrd 2013-09-12 06:24 - 2012-06-29 21:13 - 00000000 ____D C:\Program Files\Common Files\LogiShrd 2013-09-12 06:24 - 2012-06-27 16:33 - 00000000 ___RD C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-12 06:22 - 2013-09-12 06:22 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-09-12 05:54 - 2012-06-27 17:01 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-12 05:54 - 2012-06-27 17:01 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-12 05:54 - 2012-06-27 17:01 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-12 05:49 - 2013-08-31 09:20 - 00000000 ____D C:\Users\PvB\AppData\Roaming\VMware 2013-09-12 05:49 - 2013-08-31 09:01 - 00000000 ____D C:\ProgramData\VMware 2013-09-12 05:29 - 2012-06-29 21:18 - 00018682 _____ C:\Windows\system32\results.xml 2013-09-12 05:27 - 2012-06-27 16:36 - 00000000 ____D C:\Program Files (x86)\Intel 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\ProgramData\ATI 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-09-12 05:25 - 2012-06-27 16:52 - 00000000 ____D C:\ProgramData\AMD 2013-09-12 05:25 - 2012-06-27 16:51 - 00000000 ____D C:\Program Files\ATI Technologies 2013-09-12 05:19 - 2012-12-14 21:06 - 00000000 ____D C:\ProgramData\DriverGenius 2013-09-12 05:11 - 2013-08-26 01:24 - 00000000 ____D C:\Users\PvB\AppData\Roaming\LumacDaemon 2013-09-12 04:54 - 2013-09-12 04:54 - 00002279 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12 Compact Mode.lnk 2013-09-12 04:54 - 2013-09-12 04:54 - 00001323 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12.lnk 2013-09-12 04:54 - 2013-09-12 04:54 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ashampoo 2013-09-12 04:54 - 2012-06-27 17:04 - 00000000 ____D C:\ProgramData\ashampoo 2013-09-12 04:45 - 2013-09-12 03:37 - 00000000 ____D C:\ProgramData\FreeDriverScout 2013-09-12 04:45 - 2013-09-12 03:30 - 00000000 ____D C:\Program Files (x86)\Plus-HD-3.8 2013-09-12 04:45 - 2013-09-12 03:28 - 00000000 ____D C:\ProgramData\Package Cache 2013-09-12 04:45 - 2013-09-12 03:28 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-09-12 04:45 - 2013-09-05 09:26 - 00000000 ____D C:\Windows\SysWOW64\languages 2013-09-12 04:45 - 2013-09-05 09:26 - 00000000 ____D C:\Windows\SysWOW64\custom matrices 2013-09-12 04:45 - 2013-09-05 09:26 - 00000000 ____D C:\Program Files (x86)\DirectVobSub 2013-09-12 04:45 - 2013-09-03 03:52 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-09-12 04:45 - 2012-06-27 17:04 - 00000000 ____D C:\Program Files (x86)\Ashampoo 2013-09-12 04:45 - 2012-06-27 17:01 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2013-09-12 04:45 - 2012-06-27 17:01 - 00000000 ____D C:\Windows\system32\Macromed 2013-09-12 04:45 - 2012-06-27 16:33 - 00000000 ____D C:\Users\PvB 2013-09-12 04:45 - 2011-04-12 09:54 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-09-12 04:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-09-12 04:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\security 2013-09-12 04:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2013-09-12 04:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat 2013-09-12 03:37 - 2013-09-12 03:37 - 00000000 ____D C:\Users\PvB\Documents\Freemium Driver Utilities 2013-09-12 03:29 - 2013-09-12 03:29 - 00000000 ____D C:\Program Files\Covus Freemium 2013-09-12 03:11 - 2012-06-27 17:17 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Ashampoo 2013-09-12 03:01 - 2013-09-12 03:01 - 00000000 ____D C:\Users\PvB\Documents\Ashampoo Burning Studio 12 2013-09-11 21:04 - 2012-06-27 17:04 - 00000000 ____D C:\Users\PvB\AppData\Local\ashampoo 2013-09-05 22:02 - 2012-06-27 16:50 - 01602306 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-09-05 18:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-05 09:52 - 2012-06-27 16:50 - 00002198 _____ C:\Windows\epplauncher.mif 2013-09-05 09:49 - 2013-08-27 17:24 - 00002934 _____ C:\Windows\System32\Tasks\{720DB07B-6571-4601-80F7-B3BED7BC3D88} 2013-09-05 09:49 - 2013-08-27 17:24 - 00002934 _____ C:\Windows\System32\Tasks\{12258E8A-F421-41D3-8B14-723E36D317BF} 2013-09-05 09:26 - 2013-09-05 09:26 - 01180013 _____ C:\Windows\SysWOW64\unins000.exe 2013-09-05 09:26 - 2013-09-05 09:26 - 00715038 _____ C:\Windows\unins000.exe 2013-09-05 09:26 - 2013-09-05 09:26 - 00052895 _____ C:\Windows\SysWOW64\unins000.dat 2013-09-05 09:26 - 2013-09-05 09:26 - 00001890 _____ C:\Windows\unins000.dat 2013-09-05 09:26 - 2013-09-05 09:26 - 00000000 ____D C:\Program Files (x86)\Xvid 2013-09-05 09:26 - 2013-08-31 09:30 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2013-09-05 09:26 - 2013-08-31 09:30 - 00000000 ____D C:\Program Files (x86)\DSP-worx 2013-09-05 09:26 - 2012-07-09 03:58 - 00000000 ____D C:\Program Files (x86)\DivX 2013-09-05 09:26 - 2012-07-09 03:57 - 00000000 ____D C:\ProgramData\DivX 2013-09-05 09:23 - 2013-08-28 04:23 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Shark007 2013-09-05 09:23 - 2013-08-28 04:23 - 00000000 ____D C:\ProgramData\Shark007 2013-09-05 09:22 - 2013-08-28 04:22 - 00000000 ____D C:\Program Files\Shark007 2013-09-05 08:45 - 2013-04-10 13:07 - 00007597 _____ C:\Users\PvB\AppData\Local\resmon.resmoncfg 2013-09-05 08:30 - 2013-09-05 08:30 - 00000110 ___RH C:\Users\PvB\Downloads\Stinger.opt 2013-09-05 08:30 - 2013-09-05 08:24 - 00000000 ____D C:\Program Files\stinger 2013-09-05 08:09 - 2013-09-05 06:41 - 00000000 ___DC C:\Users\PvB\AppData\Local\MigWiz 2013-09-05 07:46 - 2013-09-05 07:46 - 00000000 ____D C:\Program Files\Realtek 2013-09-05 07:37 - 2013-09-02 19:20 - 00003232 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-09-05 07:31 - 2012-06-27 17:08 - 00000000 ____D C:\Program Files\WinRAR 2013-09-05 07:07 - 2013-03-18 19:12 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-09-05 03:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-09-05 03:06 - 2013-09-05 03:06 - 67108864 ____H (Piriform Ltd) C:\Users\PvB\AppData\Roaming\fixmapi.exe 2013-09-05 03:06 - 2013-09-05 03:06 - 00003242 _____ C:\Windows\System32\Tasks\{65FACB05-279E-462F-BE27-B5B7E41F5E11} 2013-09-05 02:37 - 2013-09-05 02:29 - 00000000 ____D C:\Windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP 2013-09-05 02:29 - 2013-09-05 02:29 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-09-05 02:29 - 2013-09-05 02:29 - 00000000 _____ C:\autoexec.bat 2013-09-03 21:19 - 2013-09-03 21:19 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-09-03 21:19 - 2013-09-03 21:19 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-09-03 16:41 - 2012-06-27 17:08 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Winamp 2013-09-03 05:55 - 2012-07-09 03:58 - 00000000 ____D C:\Program Files\DivX 2013-09-03 05:54 - 2012-07-09 03:59 - 00000000 ____D C:\Users\PvB\AppData\Roaming\DivX 2013-09-03 04:46 - 2013-08-28 08:25 - 00000000 ____D C:\Users\PvB\AppData\Local\DeSTRoi 2013-09-03 04:13 - 2013-09-02 20:14 - 00000000 ____D C:\Program Files\Java 2013-09-03 03:50 - 2012-07-01 16:57 - 00000000 ____D C:\Users\PvB\AppData\Local\Adobe 2013-09-02 21:46 - 2013-09-02 21:46 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-09-02 21:46 - 2013-09-02 21:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-09-02 21:43 - 2013-09-02 19:18 - 00000000 ____D C:\ProgramData\MFAData 2013-09-02 21:42 - 2013-09-02 19:19 - 00000000 ___HD C:\$AVG 2013-09-02 21:42 - 2013-09-02 19:19 - 00000000 ____D C:\ProgramData\AVG2013 2013-09-02 20:16 - 2013-09-02 20:16 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00000000 ____D C:\ProgramData\Sun 2013-09-02 20:16 - 2013-09-02 20:16 - 00000000 ____D C:\Program Files (x86)\Java 2013-09-02 20:14 - 2013-09-02 20:14 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-09-02 20:14 - 2012-06-27 16:54 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-09-02 20:14 - 2012-06-27 16:54 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-09-02 19:48 - 2013-09-02 19:48 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-02 19:48 - 2013-09-02 19:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-02 19:48 - 2013-01-11 15:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-02 19:32 - 2013-09-01 19:44 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Ipobc 2013-09-02 19:21 - 2013-09-02 19:18 - 00000000 ____D C:\Users\PvB\AppData\Local\Avg2013 2013-09-02 19:20 - 2013-09-02 19:20 - 00000000 ____D C:\Users\PvB\AppData\Roaming\AVG2013 2013-09-02 19:18 - 2013-09-02 19:18 - 00000000 ____D C:\Users\PvB\AppData\Local\MFAData 2013-09-02 19:12 - 2012-06-27 17:09 - 00000000 ____D C:\Users\PvB\Desktop\Progs 2013-09-02 19:03 - 2013-09-01 19:44 - 00000000 ____D C:\Users\PvB\AppData\Roaming\tor 2013-09-02 18:55 - 2013-09-02 18:55 - 00000000 ____D C:\Program Files (x86)\Emsisoft HiJackFree 2013-09-02 18:43 - 2013-09-02 18:43 - 00003118 _____ C:\Windows\System32\Tasks\{E79E7AF6-22C4-4BFE-B386-A9F49AFCB6E0} 2013-09-02 18:39 - 2013-09-02 18:39 - 00003126 _____ C:\Windows\System32\Tasks\{1901E6CA-FC54-4E2F-86D2-C3156922418E} 2013-09-02 18:36 - 2013-09-01 19:44 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Hetu 2013-09-02 17:37 - 2012-06-27 16:43 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Mozilla 2013-09-02 00:23 - 2013-09-02 00:23 - 00039904 _____ C:\Windows\SysWOW64\DiscHandler.exe 2013-09-01 23:18 - 2012-06-27 16:43 - 00000000 ____D C:\Users\PvB\AppData\Local\Mozilla 2013-09-01 20:38 - 2013-09-01 20:38 - 00000055 _____ C:\Users\PvB\AppData\Roaming\WB.CFG 2013-09-01 20:38 - 2013-09-01 20:38 - 00000005 _____ C:\Users\PvB\AppData\Roaming\WBPU-TTL.DAT 2013-09-01 19:44 - 2013-09-01 19:44 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Ruuny 2013-09-01 19:44 - 2013-09-01 19:44 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Effeir 2013-09-01 19:38 - 2013-09-01 19:38 - 00000000 ____D C:\Users\PvB\AppData\Roaming\0D0S1L2Z1P1B 2013-09-01 19:29 - 2013-09-01 19:29 - 00003372 _____ C:\Windows\System32\Tasks\{A4667A53-6E83-40FC-AD5C-A4185730D018} 2013-08-31 11:25 - 2013-08-31 09:21 - 00000000 ____D C:\Users\PvB\AppData\Local\VMware 2013-08-31 11:18 - 2013-08-31 11:08 - 00000000 ____D C:\Users\PvB\AppData\Roaming\vlc 2013-08-31 11:01 - 2013-08-31 11:01 - 00000000 ____D C:\Users\PvB\AppData\Roaming\SeeSimilar 2013-08-31 11:00 - 2013-08-31 11:00 - 00000000 ____D C:\Users\PvB\AppData\Roaming\4Free 2013-08-31 10:45 - 2013-08-31 10:45 - 00000000 ____D C:\Users\PvB\Documents\Tipard Studio 2013-08-31 10:45 - 2013-08-31 10:45 - 00000000 ____D C:\Users\PvB\AppData\Local\Tipard Studio 2013-08-31 10:20 - 2013-08-31 10:09 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Xilisoft 2013-08-31 10:20 - 2013-08-31 09:47 - 00000000 ____D C:\Program Files (x86)\AnvSoft 2013-08-31 10:12 - 2012-08-16 01:43 - 00000000 ____D C:\Users\PvB\AppData\Roaming\AnvSoft 2013-08-31 09:56 - 2013-08-31 09:55 - 00000000 ____D C:\Users\PvB\AppData\Roaming\FreeVideoConverter 2013-08-31 09:47 - 2013-08-31 09:47 - 00000000 ____D C:\Users\PvB\Documents\Any Video Converter Professional 2013-08-31 09:47 - 2013-08-31 09:47 - 00000000 ____D C:\Users\PvB\Documents\Any Video Converter 2013-08-31 09:40 - 2013-08-31 09:40 - 00000000 ____D C:\Users\PvB\Documents\My Received Files 2013-08-31 09:40 - 2013-08-31 09:40 - 00000000 ____D C:\Users\PvB\AppData\Roaming\MusicNet 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\LavFilters 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\CDXReader 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Program Files (x86)\OpenSource Flash Video Splitter 2013-08-31 00:07 - 2013-08-20 10:26 - 00000000 ____D C:\Program Files (x86)\Steam 2013-08-30 06:21 - 2013-08-30 06:21 - 04012544 _____ C:\Windows\system32\ffmpeg.dll 2013-08-30 06:20 - 2013-08-30 06:20 - 04374016 _____ C:\Windows\system32\ffdshow.ax 2013-08-30 06:20 - 2013-08-30 06:20 - 00631296 _____ C:\Windows\system32\TomsMoComp_ff.dll 2013-08-30 06:20 - 2013-08-30 06:20 - 00474624 _____ C:\Windows\system32\ff_kernelDeint.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 01532928 _____ C:\Windows\system32\ff_samplerate.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00222720 _____ C:\Windows\system32\ff_libdts.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00190464 _____ C:\Windows\system32\libmpeg2_ff.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00183296 _____ C:\Windows\system32\ff_unrar.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00156672 _____ C:\Windows\system32\ff_libmad.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00116224 _____ C:\Windows\system32\ff_liba52.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00114688 _____ C:\Windows\system32\ff_wmv9.dll 2013-08-28 18:43 - 2012-08-13 03:36 - 00000000 ____D C:\Program Files\VideoLAN 2013-08-28 16:33 - 2012-06-27 16:56 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-08-28 16:33 - 2012-06-27 16:56 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-08-28 09:52 - 2013-08-28 09:49 - 00000000 ____D C:\Users\PvB\AppData\Roaming\ObviousIdea 2013-08-28 09:49 - 2013-05-23 06:02 - 00378536 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-28 09:49 - 2013-05-23 06:02 - 00092944 _____ C:\Users\PvB\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-28 09:47 - 2013-08-28 09:47 - 00000000 ____D C:\User Data 2013-08-28 07:50 - 2013-08-28 07:50 - 00000000 ____D C:\.Trash-999 2013-08-28 04:32 - 2013-08-28 04:32 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Standard 2013-08-28 04:32 - 2013-08-28 04:32 - 00000000 ____D C:\Program Files (x86)\Shark007 2013-08-28 04:32 - 2013-08-28 04:31 - 00000000 ____D C:\ProgramData\Standard 2013-08-28 04:27 - 2013-08-28 04:27 - 00000000 ____D C:\Program Files\K-Lite Codec Pack x64 2013-08-28 04:20 - 2013-08-28 04:20 - 00003584 _____ C:\Users\PvB\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-08-28 04:12 - 2013-08-28 04:12 - 00000000 ____D C:\Windows\SysWOW64\C2MP 2013-08-27 22:19 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-08-27 00:36 - 2013-07-15 13:16 - 00000000 ____D C:\Users\PvB\Documents\Calibre Bibliothek 2013-08-27 00:35 - 2013-08-27 00:35 - 00000000 ____D C:\Users\PvB\Neo 2013-08-26 01:24 - 2013-08-26 01:24 - 00000000 ____D C:\Users\PvB\AppData\Local\Firstload 2013-08-20 10:37 - 2013-08-20 10:37 - 00000219 _____ C:\Users\PvB\Desktop\Counter-Strike Global Offensive.url 2013-08-20 10:37 - 2013-08-20 10:37 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-08-20 10:26 - 2013-08-20 10:26 - 00000917 _____ C:\Users\Public\Desktop\Steam.lnk 2013-08-19 00:15 - 2013-08-07 21:14 - 00000000 ____D C:\Users\PvB\Downloads\sft-loader_2009_final 2013-08-18 22:14 - 2012-06-27 17:26 - 00000000 ____D C:\Windows\Panther 2013-08-15 00:06 - 2013-08-15 00:05 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 00:05 - 2009-07-14 04:34 - 00000499 _____ C:\Windows\win.ini ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-11 02:53 ==================== End Of Log ============================ --- --- --- das mit dem Code ,bzw.strg+C klappt bei mir nicht FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-09-2013 02 Ran by PvB at 2013-09-12 15:03:38 Running from C:\Users\PvB\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 7-Zip 9.30 (x64 edition) (Version: 9.30.00.0) Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.168) Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168) Adobe Reader XI (11.0.04) - Deutsch (x32 Version: 11.0.04) Adobe Shockwave Player 12.0 (x32 Version: 12.0.3.133) AMD Accelerated Video Transcoding (Version: 12.5.100.21116) AMD APP SDK Runtime (Version: 10.0.937.2) AMD Catalyst Install Manager (Version: 8.0.911.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.71116.1554) Apple Application Support (x32 Version: 2.3) Apple Software Update (x32 Version: 2.1.3.127) Ashampoo Burning Studio 12 v.12.0.5 (x32 Version: 12.0.5) Ashampoo Burning Studio Elements 10.0.9 (x32 Version: 3.1.1) Audacity 1.3.12 (Unicode) (x32) Audiograbber 1.83 SE (x32 Version: 1.83 SE ) Audiograbber MP3-Plugin (x32 Version: 1.0) Canon Easy-PhotoPrint EX (x32) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2012.1116.1515.27190) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1116.1515.27190) Catalyst Control Center Localization All (x32 Version: 2012.1116.1515.27190) CCC Help Chinese Standard (x32 Version: 2012.1116.1514.27190) CCC Help Chinese Traditional (x32 Version: 2012.1116.1514.27190) CCC Help Czech (x32 Version: 2012.1116.1514.27190) CCC Help Danish (x32 Version: 2012.1116.1514.27190) CCC Help Dutch (x32 Version: 2012.1116.1514.27190) CCC Help English (x32 Version: 2012.1116.1514.27190) CCC Help Finnish (x32 Version: 2012.1116.1514.27190) CCC Help French (x32 Version: 2012.1116.1514.27190) CCC Help German (x32 Version: 2012.1116.1514.27190) CCC Help Greek (x32 Version: 2012.1116.1514.27190) CCC Help Hungarian (x32 Version: 2012.1116.1514.27190) CCC Help Italian (x32 Version: 2012.1116.1514.27190) CCC Help Japanese (x32 Version: 2012.1116.1514.27190) CCC Help Korean (x32 Version: 2012.1116.1514.27190) CCC Help Norwegian (x32 Version: 2012.1116.1514.27190) CCC Help Polish (x32 Version: 2012.1116.1514.27190) CCC Help Portuguese (x32 Version: 2012.1116.1514.27190) CCC Help Russian (x32 Version: 2012.1116.1514.27190) CCC Help Spanish (x32 Version: 2012.1116.1514.27190) CCC Help Swedish (x32 Version: 2012.1116.1514.27190) CCC Help Thai (x32 Version: 2012.1116.1514.27190) CCC Help Turkish (x32 Version: 2012.1116.1514.27190) ccc-utility64 (Version: 2012.1116.1515.27190) CCleaner (Version: 3.28) Counter-Strike: Global Offensive (x32) CyberLink BD_3D Advisor 2.0 (x32) CyberLink Blu-ray Disc Suite (x32 Version: 7.0.3721) CyberLink InstantBurn (x32 Version: 5.0.6210) CyberLink LabelPrint (x32 Version: 2.5.3418) CyberLink MediaShow (x32 Version: 5.0.1423) CyberLink Power2Go (x32 Version: 6.1.3802) CyberLink PowerBackup (x32 Version: 2.5.6023) CyberLink PowerDVD 9 (x32 Version: 9.0.3518.52) CyberLink PowerProducer (x32 Version: 5.0.2.2429) DC-Bass Source 1.3.0 (x32) DirectVobSub 2.40.4209 (x32 Version: 2.40.4209) DivX-Setup (x32 Version: 2.6.1.8) EASEUS Partition Recovery 5.0.1 (x32) Emsisoft HiJackFree 4.5 (x32 Version: 4.5) eReg (x32 Version: 1.20.138.34) Etron USB3.0 Host Controller (x32 Version: 0.118) ffdshow v1.1.4399 [2012-03-22] (x32 Version: 1.1.4399.0) Google Earth (x32 Version: 6.2.2.6613) Hercules DJ Products Series drivers (x32 Version: 2.HDJS.2013) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Management Engine Components (x32 Version: 8.1.20.1337) Intel(R) Processor Graphics (x32 Version: 9.17.10.3062) Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149) Intel® Trusted Connect Service Client (Version: 1.26.242.3) Java 7 Update 25 (64-bit) (Version: 7.0.250) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Java SE Development Kit 7 Update 25 (64-bit) (Version: 1.7.0.250) JDownloader 0.9 (x32 Version: 0.9) K-Lite Codec Pack 9.9.9 (64-bit) (Version: 9.9.9) Lagarith Lossless Codec (1.3.27) (x32) LAME v3.99.3 (for Windows) (x32) LastPass (uninstall only) (x32) Logitech SetPoint 6.61 (Version: 6.61.15) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Media Player Codec Pack 4.2.9 (x32 Version: 4.2.9) Microsoft .NET Framework 4.5 (Version: 4.5.50709) Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.8173.0) Microsoft Security Client (Version: 4.3.0216.0) Microsoft Security Essentials (Version: 4.3.216.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1) Mozilla Maintenance Service (x32 Version: 23.0.1) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) Native Instruments Traktor 2 (Version: 2.6.2.112) Native Instruments Traktor 2 (x32 Version: 2.6.2.112) neroxml (x32 Version: 1.0.0) ON_OFF Charge B11.0110.1 (x32 Version: 1.00.0001) OpenSource Flash Video Splitter 1.0.0.5 (x32 Version: 1.0.0.5) QuickTime (x32 Version: 7.74.80.86) Realtek Ethernet Controller Driver (x32 Version: 7.73.618.2013) Realtek HDMI Audio Driver for ATI (x32 Version: 6.0.1.6650) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6788) Reason 4.0 (x32 Version: 4.0) Shark007 Standard Codecs (x32 Version: 1.6.7) SSD Fresh (x32 Version: 2013) Steam (x32 Version: 1.0.0.0) Streamripper (Remove only) (x32) swMSM (x32 Version: 12.0.0.1) Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) Video Converter Packages (HKCU) Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1) VLC media player 2.0.3 (x32 Version: 2.0.3) Winamp (x32 Version: 5.623 ) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1) WinRAR 5.00 (64-Bit) (Version: 5.00.0) x64 Components v3.9.9 (Version: 3.9.9) x64 Components v4.2.3 (Version: 4.2.3) xp-AntiSpy 3.98-2 (x32) Xvid Video Codec (x32 Version: 1.3.2) ==================== Restore Points ========================= 12-09-2013 03:27:36 Entfernt Hercules DJ Series Drivers 12-09-2013 04:11:45 Vor der Installation neuer Treiber - 12.09.2013 06:11:39 12-09-2013 04:19:17 Vor der Installation neuer Treiber - 12.09.2013 06:19:11 12-09-2013 04:23:16 Vor der Installation neuer Treiber - 12.09.2013 06:23:10 12-09-2013 04:25:46 Installiert Realtek Ethernet Controller Driver 12-09-2013 04:27:35 Configured Etron USB3.0 Host Controller 12-09-2013 04:32:28 Installiert Hercules DJ Series Drivers 12-09-2013 04:33:01 Gerätetreiber-Paketinstallation: Hercules Hercules DJ Devices 12-09-2013 04:33:12 Gerätetreiber-Paketinstallation: Hercules Hercules DJ Devices 12-09-2013 04:33:29 Gerätetreiber-Paketinstallation: Hercules DJ Console ASIO Hercules DJ Devices 12-09-2013 04:33:47 Gerätetreiber-Paketinstallation: Hercules (R) Eingabegeräte (Human Interface Devices) 12-09-2013 04:34:03 Gerätetreiber-Paketinstallation: Hercules 12-09-2013 04:34:20 Gerätetreiber-Paketinstallation: Hercules Audio-, Video- und Gamecontroller 12-09-2013 04:37:36 System OK Nach Updates 12-09-2013 07:38:31 Removed Lumac 12-09-2013 07:51:35 Removed SpyHunter ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-09-12 09:36 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {03A0A785-AFDC-4665-867B-BD0BCF4CF420} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-21] (Microsoft Corporation) Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started Task: {0A267F27-EF47-406B-A308-2517C7C58B00} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd) Task: {1EBDFAF5-E1CA-41B2-BE56-BF12E765A542} - System32\Tasks\{720DB07B-6571-4601-80F7-B3BED7BC3D88} => C:\Program Files (x86)\Lumac\Lumac.exe Task: {40B30844-C6FD-46D6-97E4-BCF30F316E7F} - System32\Tasks\{12258E8A-F421-41D3-8B14-723E36D317BF} => C:\Program Files (x86)\Lumac\Lumac.exe Task: {414B15CC-711B-44A7-B4EB-D24B8571030B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {479A60B8-2547-4780-A938-BC9369757173} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {91668765-A629-4D1F-B0CC-EACD6145F214} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe [2013-07-18] (Microsoft Corporation) Task: {C4C9F006-FC3F-459D-BB3C-46D9761FDB82} - System32\Tasks\Divx-Online-Aktualisierungsprogramm => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2013-02-13] () Task: {C63601A5-6F6F-4315-BDC7-7EB7BCB558C1} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\System32\sdengin2.dll [2010-11-21] (Microsoft Corporation) Task: {C83533EB-FFC0-451C-AB3A-64876A3EDDF2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-12] (Adobe Systems Incorporated) Task: {D76D2A8D-1CED-4850-BCEE-041A5C682C56} - \DSite No Task File Task: {FCDCF46F-429C-4574-AF82-512484D210EB} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-21] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-03-18 19:12 - 2013-08-22 19:01 - 00214104 _____ (Alexander Roshal) C:\Program Files\WinRAR\rarext.dll 2012-06-27 16:37 - 2011-06-10 04:36 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-03-08 19:09 - 2013-03-08 19:09 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrDEU.lrc 2013-09-12 06:22 - 2010-11-04 01:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2013-09-12 06:22 - 2012-11-16 21:30 - 03673232 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2013-09-12 06:12 - 2011-12-02 14:20 - 03746408 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkHDM64.dll 2013-05-15 16:03 - 2013-04-13 07:49 - 00308736 _____ (Microsoft Corporation) C:\Windows\AppPatch\AppPatch64\AcGenral.DLL 2012-06-27 17:32 - 2013-04-30 16:03 - 00665600 _____ (Hercules(R)) C:\Windows\system32\HDJAPI.dll 2012-06-27 17:32 - 2013-04-30 16:02 - 00103936 _____ (Hercules(R)) C:\Windows\system32\HRFDongle.dll 2013-09-12 06:35 - 2013-05-14 16:50 - 00248832 _____ ( Hercules) C:\Windows\system32\hdjusbaudioapi_x64.dll 2013-09-02 19:48 - 2013-08-14 19:55 - 03551640 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-09-12 05:54 - 2013-09-12 05:54 - 16177544 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ==================== Alternate Data Streams (whitelisted) ========== AlternateDataStreams: C:\ProgramData\Temp:661DFA1C AlternateDataStreams: C:\ProgramData\Temp:FB1B13D8 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (09/12/2013 00:57:55 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 00:28:46 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 11:54:57 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 11:33:39 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 11:06:43 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 10:38:41 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 10:34:15 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 09:59:40 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 09:56:47 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 09:55:18 AM) (Source: Windows Search Service) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (09/12/2013 00:56:48 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (09/12/2013 00:56:48 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (09/12/2013 00:56:48 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (09/12/2013 00:56:48 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (09/12/2013 00:56:48 PM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (09/12/2013 00:56:48 PM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (09/12/2013 00:56:37 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (09/12/2013 00:56:37 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (09/12/2013 00:56:37 PM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (09/12/2013 00:55:14 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Microsoft Office Sessions: ========================= Error: (09/12/2013 00:57:55 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 00:28:46 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 11:54:57 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 11:33:39 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 11:06:43 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 10:38:41 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 10:34:15 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 09:59:40 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 09:56:47 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/12/2013 09:55:18 AM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) ==================== Memory info =========================== Percentage of memory in use: 34% Total physical RAM: 8109.12 MB Available physical RAM: 5318.67 MB Total Pagefile: 16216.42 MB Available Pagefile: 13346.84 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:119.14 GB) (Free:45.51 GB) NTFS Drive d: (Filme u. Sonstiges) (Fixed) (Total:244.14 GB) (Free:183.34 GB) NTFS Drive e: (Musik) (Fixed) (Total:221.62 GB) (Free:4.63 GB) NTFS Drive i: ( Backup,Fotos u.Sonstiges ext) (Fixed) (Total:886.45 GB) (Free:140.46 GB) NTFS Drive j: (Filme extern) (Fixed) (Total:488.28 GB) (Free:24.31 GB) NTFS Drive l: (Musik extern) (Fixed) (Total:488.28 GB) (Free:89.67 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 34D641B3) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=119 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 59E3B457) Partition 1: (Not Active) - (Size=244 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=222 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: EFFA6867) Partition 1: (Not Active) - (Size=886 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=488 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=488 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
12.09.2013, 17:45 | #4 | |
/// the machine /// TB-Ausbilder | Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglichCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.09.2013, 16:44 | #5 |
| Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich Combofix Logfile: Code:
ATTFilter ComboFix 13-09-13.01 - PvB 13.09.2013 17:35:24.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8109.6141 [GMT 2:00] ausgeführt von:: c:\users\PvB\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F} SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\xp-AntiSpy c:\program files (x86)\xp-AntiSpy\Uninstall.exe c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.chm c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.exe c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.url c:\programdata\ntuser.dat c:\users\PvB\AppData\Local\Google\Chrome\User Data\Default\preferences c:\users\PvB\AppData\Roaming\Effeir c:\users\PvB\AppData\Roaming\Effeir\itpy.ryy c:\users\PvB\AppData\Roaming\fixmapi.exe c:\users\PvB\AppData\Roaming\Ruuny c:\users\PvB\AppData\Roaming\Ruuny\nowoa.exe c:\windows\SysWow64\DiscHandler.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-08-13 bis 2013-09-13 )))))))))))))))))))))))))))))) . . 2013-09-13 15:37 . 2013-09-13 15:37 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-09-13 13:29 . 2013-08-05 23:58 9515512 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{16A3C507-E783-4A03-AB60-21CA54C3D92C}\mpengine.dll 2013-09-13 07:28 . 2013-09-13 07:28 -------- d-----w- c:\windows\Microsoft Antimalware 2013-09-12 15:35 . 2013-08-02 02:23 5550528 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-09-12 12:48 . 2013-09-12 12:48 -------- d-----w- C:\FRST 2013-09-12 10:22 . 2013-09-12 15:49 -------- d-----w- C:\AdwCleaner 2013-09-12 08:03 . 2013-09-12 08:03 -------- d-----w- c:\users\PvB\AppData\Roaming\Malwarebytes 2013-09-12 08:03 . 2013-09-12 08:03 -------- d-----w- c:\programdata\Malwarebytes 2013-09-12 08:03 . 2013-09-12 08:03 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-09-12 08:03 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-09-12 04:35 . 2013-05-14 14:50 248832 ----a-w- c:\windows\system32\HDJusbaudioapi_x64.dll 2013-09-12 04:32 . 2013-03-05 13:30 79872 ----a-w- c:\windows\system32\HerculesDJUSBAudioDevices_x64.dll 2013-09-12 04:32 . 2013-05-21 13:44 320816 ----a-w- c:\windows\system32\drivers\HDJAsioK.sys 2013-09-12 04:32 . 2013-05-21 13:44 258352 ----a-w- c:\windows\system32\drivers\HDJBulk.sys 2013-09-12 04:32 . 2013-05-21 13:44 38704 ----a-w- c:\windows\system32\drivers\HDJCtrl.sys 2013-09-12 04:32 . 2013-05-21 13:44 274736 ----a-w- c:\windows\system32\drivers\HDJMidi.sys 2013-09-12 04:32 . 2013-05-21 13:35 91648 ----a-w- c:\windows\system32\HDJAsiou.dll 2013-09-12 04:32 . 2013-05-21 13:35 78336 ----a-w- c:\windows\SysWow64\HDJAsiou.dll 2013-09-12 04:27 . 2013-07-17 12:23 65408 ----a-w- c:\windows\system32\drivers\EtronHub3.sys 2013-09-12 04:25 . 2013-06-18 14:22 872152 ----a-w- c:\windows\system32\drivers\Rt64win7.sys 2013-09-12 04:25 . 2013-06-18 14:22 74456 ----a-w- c:\windows\system32\RtNicProp64.dll 2013-09-12 04:24 . 2013-09-12 04:24 53248 ----a-r- c:\users\PvB\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2013-09-12 04:24 . 2013-09-12 04:24 -------- d-----w- c:\program files\Logitech 2013-09-12 04:12 . 2012-06-05 11:45 237968 ----a-w- c:\windows\system32\drivers\RtHDMIVX.sys 2013-09-12 03:25 . 2013-09-12 03:25 -------- d-----w- c:\programdata\ATI 2013-09-12 03:25 . 2013-09-12 03:25 -------- d-----w- c:\program files (x86)\AMD AVT 2013-09-12 03:25 . 2013-09-12 03:25 -------- d-----w- c:\program files (x86)\ATI Technologies 2013-09-12 02:56 . 2013-08-05 23:58 9515512 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-09-12 01:50 . 2013-09-12 02:05 -------- d-----w- C:\temp 2013-09-12 01:37 . 2013-09-12 02:45 -------- d-----w- c:\programdata\FreeDriverScout 2013-09-12 01:30 . 2013-09-12 02:45 -------- d-----w- c:\program files (x86)\Plus-HD-3.8 2013-09-12 01:29 . 2013-09-12 01:29 -------- d-----w- c:\program files\Covus Freemium 2013-09-12 01:28 . 2013-09-12 02:45 -------- d-----w- c:\program files (x86)\Web Check 2013-09-12 01:28 . 2013-09-12 02:45 -------- d-----w- c:\programdata\Package Cache 2013-09-06 23:32 . 2013-09-06 23:31 965008 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2ADD137D-1C96-4BFC-9FB2-1042A2A2501E}\gapaengine.dll 2013-09-06 23:32 . 2013-09-02 19:47 941720 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2013-09-05 14:04 . 2013-09-05 14:04 209272 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll 2013-09-05 07:23 . 2010-11-21 03:24 381440 ----a-w- c:\windows\system32\mfds.dll 2013-09-05 06:24 . 2013-09-05 06:30 -------- d-----w- c:\program files\stinger 2013-09-05 05:46 . 2013-09-05 05:46 -------- d-----w- c:\program files\Realtek 2013-09-05 04:41 . 2013-09-05 06:09 -------- dc----w- c:\users\PvB\AppData\Local\MigWiz 2013-09-05 01:19 . 2013-09-12 07:51 -------- d-----w- c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP 2013-09-05 00:29 . 2013-09-05 01:19 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard 2013-09-05 00:29 . 2013-09-05 00:37 -------- d-----w- c:\windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP 2013-09-05 00:07 . 2012-08-24 18:13 154480 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2013-09-05 00:07 . 2012-08-24 18:09 458712 ----a-w- c:\windows\system32\drivers\cng.sys 2013-09-05 00:07 . 2012-08-24 18:05 340992 ----a-w- c:\windows\system32\schannel.dll 2013-09-05 00:07 . 2012-08-24 18:03 1448448 ----a-w- c:\windows\system32\lsasrv.dll 2013-09-05 00:07 . 2012-08-24 16:57 247808 ----a-w- c:\windows\SysWow64\schannel.dll 2013-09-05 00:07 . 2012-08-24 16:57 22016 ----a-w- c:\windows\SysWow64\secur32.dll 2013-09-05 00:07 . 2012-08-24 16:53 96768 ----a-w- c:\windows\SysWow64\sspicli.dll 2013-09-05 00:07 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll 2013-09-05 00:07 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll 2013-09-03 19:19 . 2013-09-03 19:19 -------- d-----w- c:\program files\Microsoft Silverlight 2013-09-03 19:19 . 2013-09-03 19:19 -------- d-----w- c:\program files (x86)\Microsoft Silverlight 2013-09-03 01:52 . 2013-09-12 02:45 -------- d-----w- c:\windows\SysWow64\Adobe 2013-09-02 19:46 . 2013-09-02 19:46 -------- d-----w- c:\program files (x86)\Microsoft Security Client 2013-09-02 19:46 . 2013-09-02 19:46 -------- d-----w- c:\program files\Microsoft Security Client 2013-09-02 19:43 . 2013-08-19 22:46 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7B3CF4AE-001E-4F7F-AF5F-84839C7D307E}\mpengine.dll 2013-09-02 18:16 . 2013-09-02 18:16 -------- d-----w- c:\program files (x86)\Common Files\Java 2013-09-02 18:16 . 2013-09-02 18:16 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-09-02 18:16 . 2013-09-02 18:16 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-09-02 18:16 . 2013-09-02 18:16 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-09-02 18:16 . 2013-09-02 18:16 -------- d-----w- c:\program files (x86)\Java 2013-09-02 18:14 . 2013-09-02 18:14 312232 ----a-w- c:\windows\system32\javaws.exe 2013-09-02 18:14 . 2013-09-02 18:14 189352 ----a-w- c:\windows\system32\javaw.exe 2013-09-02 18:14 . 2013-09-02 18:14 188840 ----a-w- c:\windows\system32\java.exe 2013-09-02 18:14 . 2013-09-02 18:14 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-09-02 18:14 . 2013-09-03 02:13 -------- d-----w- c:\program files\Java 2013-09-02 17:20 . 2013-09-02 17:20 -------- d-----w- c:\users\PvB\AppData\Roaming\AVG2013 2013-09-02 17:19 . 2013-09-02 19:42 -------- d-----w- c:\programdata\AVG2013 2013-09-02 17:19 . 2013-09-02 19:42 -------- d-----w- C:\$AVG 2013-09-02 17:18 . 2013-09-02 19:43 -------- d-----w- c:\programdata\MFAData 2013-09-02 17:18 . 2013-09-02 17:21 -------- d-----w- c:\users\PvB\AppData\Local\Avg2013 2013-09-02 17:18 . 2013-09-02 17:18 -------- d-----w- c:\users\PvB\AppData\Local\MFAData 2013-09-02 16:55 . 2013-09-02 16:55 -------- d-----w- c:\program files (x86)\Emsisoft HiJackFree 2013-09-01 17:44 . 2013-09-02 17:32 -------- d-----w- c:\users\PvB\AppData\Roaming\Ipobc 2013-09-01 17:44 . 2013-09-02 16:36 -------- d-----w- c:\users\PvB\AppData\Roaming\Hetu 2013-09-01 17:44 . 2013-09-02 17:03 -------- d-----w- c:\users\PvB\AppData\Roaming\tor 2013-09-01 17:38 . 2013-09-01 17:38 -------- d-----w- c:\users\PvB\AppData\Roaming\0D0S1L2Z1P1B 2013-08-31 09:08 . 2013-08-31 09:18 -------- d-----w- c:\users\PvB\AppData\Roaming\vlc 2013-08-31 09:01 . 2013-08-31 09:01 -------- d-----w- c:\users\PvB\AppData\Roaming\SeeSimilar 2013-08-31 09:00 . 2013-08-31 09:00 -------- d-----w- c:\users\PvB\AppData\Roaming\4Free 2013-08-31 08:45 . 2013-08-31 08:45 -------- d-----w- c:\users\PvB\AppData\Local\Tipard Studio 2013-08-31 08:09 . 2013-08-31 08:20 -------- d-----w- c:\users\PvB\AppData\Roaming\Xilisoft 2013-08-31 07:55 . 2013-08-31 07:56 -------- d-----w- c:\users\PvB\AppData\Roaming\FreeVideoConverter 2013-08-31 07:47 . 2013-08-31 08:20 -------- d-----w- c:\program files (x86)\AnvSoft 2013-08-31 07:40 . 2013-08-31 07:40 -------- d-----w- c:\users\PvB\AppData\Roaming\MusicNet 2013-08-31 07:30 . 2013-09-05 07:26 -------- d-----w- c:\program files (x86)\Lame For Audacity 2013-08-31 07:30 . 2013-08-31 07:30 -------- d-----w- c:\users\PvB\AppData\Roaming\LavFilters 2013-08-31 07:30 . 2013-08-31 07:30 -------- d-----w- c:\users\PvB\AppData\Roaming\CDXReader 2013-08-31 07:30 . 2013-09-05 07:26 -------- d-----w- c:\program files (x86)\DSP-worx 2013-08-31 07:30 . 2013-08-31 07:30 -------- d-----w- c:\program files (x86)\OpenSource Flash Video Splitter 2013-08-31 07:21 . 2013-08-31 09:25 -------- d-----w- c:\users\PvB\AppData\Local\VMware 2013-08-31 07:20 . 2013-09-12 03:49 -------- d-----w- c:\users\PvB\AppData\Roaming\VMware 2013-08-31 07:01 . 2013-09-12 03:49 -------- d-----w- c:\programdata\VMware 2013-08-30 04:21 . 2013-08-30 04:21 4012544 ----a-w- c:\windows\system32\ffmpeg.dll 2013-08-30 04:20 . 2013-08-30 04:20 474624 ----a-w- c:\windows\system32\ff_kernelDeint.dll 2013-08-30 04:20 . 2012-12-13 20:59 127488 ----a-w- c:\windows\system32\ff_vfw.dll 2013-08-30 04:20 . 2013-08-30 04:20 4374016 ----a-w- c:\windows\system32\ffdshow.ax 2013-08-30 04:20 . 2013-08-30 04:20 631296 ----a-w- c:\windows\system32\TomsMoComp_ff.dll 2013-08-30 04:19 . 2013-08-30 04:19 114688 ----a-w- c:\windows\system32\ff_wmv9.dll 2013-08-30 04:19 . 2013-08-30 04:19 183296 ----a-w- c:\windows\system32\ff_unrar.dll 2013-08-30 04:19 . 2013-08-30 04:19 156672 ----a-w- c:\windows\system32\ff_libmad.dll 2013-08-30 04:19 . 2013-08-30 04:19 222720 ----a-w- c:\windows\system32\ff_libdts.dll 2013-08-30 04:19 . 2013-08-30 04:19 1532928 ----a-w- c:\windows\system32\ff_samplerate.dll 2013-08-30 04:19 . 2013-08-30 04:19 116224 ----a-w- c:\windows\system32\ff_liba52.dll 2013-08-30 04:19 . 2013-08-30 04:19 190464 ----a-w- c:\windows\system32\libmpeg2_ff.dll 2013-08-30 03:54 . 2012-03-22 16:46 4417024 ----a-w- c:\windows\SysWow64\ffmpeg.dll 2013-08-30 03:53 . 2012-02-26 14:47 79360 ----a-w- c:\windows\SysWow64\ff_vfw.dll 2013-08-30 03:53 . 2012-03-22 16:46 3471360 ----a-w- c:\windows\SysWow64\ffdshow.ax 2013-08-30 03:51 . 2012-02-26 14:46 99840 ----a-w- c:\windows\SysWow64\ff_wmv9.dll 2013-08-30 03:51 . 2012-02-26 14:46 158720 ----a-w- c:\windows\SysWow64\ff_unrar.dll 2013-08-30 03:51 . 2012-02-26 14:45 146944 ----a-w- c:\windows\SysWow64\ff_libmad.dll 2013-08-30 03:51 . 2012-02-26 14:45 1525248 ----a-w- c:\windows\SysWow64\ff_samplerate.dll 2013-08-30 03:51 . 2012-02-26 14:45 212480 ----a-w- c:\windows\SysWow64\ff_libdts.dll 2013-08-30 03:51 . 2012-02-26 14:45 115200 ----a-w- c:\windows\SysWow64\ff_liba52.dll 2013-08-30 03:51 . 2012-02-26 14:46 260608 ----a-w- c:\windows\SysWow64\TomsMoComp_ff.dll 2013-08-30 03:51 . 2012-02-26 14:45 137728 ----a-w- c:\windows\SysWow64\libmpeg2_ff.dll 2013-08-28 14:33 . 2013-08-28 14:33 15678464 ----a-w- c:\program files (x86)\Common Files\lpuninstall.exe 2013-08-28 07:49 . 2013-08-28 07:52 -------- d-----w- c:\users\PvB\AppData\Roaming\ObviousIdea 2013-08-28 07:47 . 2013-08-28 07:47 -------- d-----w- C:\User Data 2013-08-28 06:25 . 2013-09-03 02:46 -------- d-----w- c:\users\PvB\AppData\Local\DeSTRoi 2013-08-28 05:50 . 2013-08-28 05:50 -------- d---a-w- C:\.Trash-999 2013-08-28 02:32 . 2013-08-28 02:32 -------- d-----w- c:\users\PvB\AppData\Roaming\Standard . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-09-13 05:54 . 2012-06-27 15:01 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-09-13 05:54 . 2012-06-27 15:01 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-09-12 21:23 . 2012-07-08 16:18 79143768 ----a-w- c:\windows\system32\MRT.exe 2013-09-12 04:24 . 2012-06-29 19:14 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys 2013-09-02 18:14 . 2012-06-27 14:54 972712 ----a-w- c:\windows\system32\deployJava1.dll 2013-09-02 18:14 . 2012-06-27 14:54 1093032 ----a-w- c:\windows\system32\npDeployJava1.dll 2013-08-07 02:22 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe 2013-08-05 09:50 . 2012-06-27 14:36 53248 ----a-w- c:\windows\SysWow64\CSVer.dll 2013-08-02 01:48 . 2013-09-12 15:35 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-07-26 13:24 . 2013-07-26 13:24 412336 ----a-w- c:\windows\system32\swscale-lav-2.dll 2013-07-26 13:24 . 2013-07-26 13:24 225456 ----a-w- c:\windows\system32\libbluray.dll 2013-07-26 13:24 . 2013-07-26 13:24 1527984 ----a-w- c:\windows\system32\LAVVideo.ax 2013-07-26 13:24 . 2013-07-26 13:24 6485168 ----a-w- c:\windows\system32\avcodec-lav-55.dll 2013-07-26 13:24 . 2013-07-26 13:24 524976 ----a-w- c:\windows\system32\LAVSplitter.ax 2013-07-26 13:24 . 2013-07-26 13:24 374960 ----a-w- c:\windows\system32\IntelQuickSyncDecoder.dll 2013-07-26 13:24 . 2013-07-26 13:24 296624 ----a-w- c:\windows\system32\avutil-lav-52.dll 2013-07-26 13:24 . 2013-07-26 13:24 280240 ----a-w- c:\windows\system32\LAVAudio.ax 2013-07-26 13:24 . 2013-07-26 13:24 245936 ----a-w- c:\windows\system32\avfilter-lav-3.dll 2013-07-26 13:24 . 2013-07-26 13:24 160944 ----a-w- c:\windows\system32\avresample-lav-1.dll 2013-07-26 13:24 . 2013-07-26 13:24 1205424 ----a-w- c:\windows\system32\avformat-lav-55.dll 2013-07-26 13:24 . 2013-07-26 13:24 6275760 ----a-w- c:\windows\SysWow64\avcodec-lav-55.dll 2013-07-26 13:24 . 2013-07-26 13:24 431792 ----a-w- c:\windows\SysWow64\LAVSplitter.ax 2013-07-26 13:24 . 2013-07-26 13:24 394416 ----a-w- c:\windows\SysWow64\swscale-lav-2.dll 2013-07-26 13:24 . 2013-07-26 13:24 296112 ----a-w- c:\windows\SysWow64\IntelQuickSyncDecoder.dll 2013-07-26 13:24 . 2013-07-26 13:24 288944 ----a-w- c:\windows\SysWow64\avutil-lav-52.dll 2013-07-26 13:24 . 2013-07-26 13:24 245936 ----a-w- c:\windows\SysWow64\LAVAudio.ax 2013-07-26 13:24 . 2013-07-26 13:24 235184 ----a-w- c:\windows\SysWow64\avfilter-lav-3.dll 2013-07-26 13:24 . 2013-07-26 13:24 190640 ----a-w- c:\windows\SysWow64\libbluray.dll 2013-07-26 13:24 . 2013-07-26 13:24 150192 ----a-w- c:\windows\SysWow64\avresample-lav-1.dll 2013-07-26 13:24 . 2013-07-26 13:24 1239216 ----a-w- c:\windows\SysWow64\avformat-lav-55.dll 2013-07-26 13:24 . 2013-07-26 13:24 1190064 ----a-w- c:\windows\SysWow64\LAVVideo.ax 2013-07-17 12:23 . 2013-03-19 03:42 94208 ----a-w- c:\windows\system32\drivers\EtronXHCI.sys 2013-06-18 19:50 . 2013-06-18 19:50 247216 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2013-06-18 19:50 . 2013-06-18 19:50 139616 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2013-06-18 14:22 . 2012-06-27 14:38 108760 ----a-w- c:\windows\system32\RTNUninst64.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ CodecPackUpdateChecker.lnk - c:\windows\SysWOW64\C2MP\UpdateChecker.exe [2013-6-12 48248] Install LastPass FF RunOnce.lnk - c:\program files (x86)\Common Files\lpuninstall.exe -q -name=LastPass -ffuuid support@lastpass.com [2013-8-28 15678464] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\prwntdrv] @="" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW "Driver Genius"= "DivXMediaServer"=c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun . R2 CLKMSVC10_9EC60124;CyberLink Product - 2012/06/27 17:32;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 prwntdrv;prwntdrv;c:\windows\system32\prwntdrv.sys;c:\windows\SYSNATIVE\prwntdrv.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x] S1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\DRIVERS\CLBStor.sys;c:\windows\SYSNATIVE\DRIVERS\CLBStor.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 CLBUDF;CyberLink InstantBurn UDF Filesystem; [x] S2 HerculesDJControlMP3;Hercules DJ Control MP3;c:\program files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE;c:\program files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 Bulk;HDJBulk;c:\windows\system32\Drivers\HDJBulk.sys;c:\windows\SYSNATIVE\Drivers\HDJBulk.sys [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x] S3 HDJAsioK;HDJAsioK;c:\windows\system32\Drivers\HDJAsioK.sys;c:\windows\SYSNATIVE\Drivers\HDJAsioK.sys [x] S3 HDJMidi;Hercules DJ Console Mk4 MIDI;c:\windows\system32\DRIVERS\HDJMidi.sys;c:\windows\SYSNATIVE\DRIVERS\HDJMidi.sys [x] S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *Deregistered* - CLKMDRV10_9EC60124 . Inhalt des "geplante Tasks" Ordners . 2013-09-13 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-27 05:54] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-07-18 1356240] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-03-22 172016] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-03-22 399856] "Persistence"="c:\windows\system32\igfxpers.exe" [2013-03-22 442352] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-11-19 13260944] "RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2012-11-19 1253520] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-07-31 3091224] "Hercules DJ Series TrayAgent"="c:\program files\Guillemot\HDJTray\HDJSeries2TrayBar.exe" [2013-05-10 3572048] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SYSTEM32\blank.htm IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\PvB\AppData\Roaming\Mozilla\Firefox\Profiles\tg7dw9os.default-1378141527687\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ FF - ExtSQL: 2013-08-31 09:31; {23fcfd51-4958-4f00-80a3-ae97e717ed8b}; c:\program files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF - ExtSQL: 2013-09-02 19:49; support@lastpass.com; c:\users\PvB\AppData\Roaming\Mozilla\Firefox\Profiles\tg7dw9os.default-1378141527687\extensions\support@lastpass.com FF - ExtSQL: 2013-09-02 20:22; {E6C1199F-E687-42da-8C24-E7770CC3AE66}; c:\users\PvB\AppData\Roaming\Mozilla\Firefox\Profiles\tg7dw9os.default-1378141527687\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi FF - ExtSQL: 2013-09-12 03:31; {F58A62EB-38DC-43C4-A539-DC52E135208D}; c:\users\PvB\AppData\Roaming\Mozilla\Firefox\Profiles\tg7dw9os.default-1378141527687\extensions\{F58A62EB-38DC-43C4-A539-DC52E135208D} . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-xp-AntiSpy - c:\program files (x86)\xp-AntiSpy\Uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_174_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_174_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_174_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_174_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_174.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_174.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_174.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_174.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-09-13 17:38:54 ComboFix-quarantined-files.txt 2013-09-13 15:38 . Vor Suchlauf: 13 Verzeichnis(se), 46.861.946.880 Bytes frei Nach Suchlauf: 17 Verzeichnis(se), 46.670.024.704 Bytes frei . - - End Of File - - E0A3418E22AA582A3F665CF75FF7CB86 A36C5E4F47E84449FF07ED3517B43A31 |
14.09.2013, 13:37 | #6 |
/// the machine /// TB-Ausbilder | Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich |
14.09.2013, 20:50 | #7 |
| Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich Malwarebytes Anti-Malware (PRO) 1.75.0.1300 Malwarebytes : Free Anti-Malware download Datenbank Version: v2013.09.14.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16686 PvB :: PVB-PC [Administrator] Schutz: Aktiviert 14.09.2013 20:48:17 MBAM-log-2013-09-14 (21-29-26).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 435084 Laufzeit: 26 Minute(n), 23 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 1 HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo (PUP.Optional.Elex.A) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\USER DATA\Default\EXTENSIONS\newtab.crx (PUP.Optional.Elex.A) -> Keine Aktion durchgeführt. (Ende) 2013/09/14 20:25:49 +0200 PVB-PC (null) MESSAGE Starting protection 2013/09/14 20:25:49 +0200 PVB-PC (null) MESSAGE Protection started successfully 2013/09/14 20:25:49 +0200 PVB-PC (null) MESSAGE Starting IP protection 2013/09/14 20:25:50 +0200 PVB-PC (null) MESSAGE IP Protection started successfully 2013/09/14 20:40:11 +0200 PVB-PC PvB MESSAGE Executing scheduled update: Daily 2013/09/14 20:40:20 +0200 PVB-PC PvB MESSAGE Scheduled update executed successfully: database updated from version v2013.09.13.03 to version v2013.09.14.08 2013/09/14 20:40:20 +0200 PVB-PC PvB MESSAGE Starting database refresh 2013/09/14 20:40:21 +0200 PVB-PC PvB MESSAGE Stopping IP protection 2013/09/14 20:40:21 +0200 PVB-PC PvB MESSAGE IP Protection stopped successfully 2013/09/14 20:40:23 +0200 PVB-PC PvB MESSAGE Database refreshed successfully 2013/09/14 20:40:23 +0200 PVB-PC PvB MESSAGE Starting IP protection 2013/09/14 20:40:24 +0200 PVB-PC PvB MESSAGE IP Protection started successfully 2013/09/14 20:44:46 +0200 PVB-PC (null) MESSAGE Starting protection 2013/09/14 20:44:46 +0200 PVB-PC (null) MESSAGE Protection started successfully 2013/09/14 20:44:46 +0200 PVB-PC (null) MESSAGE Starting IP protection 2013/09/14 20:44:47 +0200 PVB-PC (null) MESSAGE IP Protection started successfully 2013/09/14 21:37:10 +0200 PVB-PC (null) MESSAGE Starting protection 2013/09/14 21:37:10 +0200 PVB-PC (null) MESSAGE Protection started successfully 2013/09/14 21:37:10 +0200 PVB-PC (null) MESSAGE Starting IP protection 2013/09/14 21:37:12 +0200 PVB-PC (null) MESSAGE IP Protection started successfullyAdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.003 - Bericht erstellt am 14/09/2013 um 21:36:20 # Updated 07/09/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : PvB - PVB-PC # Gestartet von : D:\Software\Internet Tools\3003-adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16686 -\\ Mozilla Firefox v23.0.1 (de) [ Datei : C:\Users\PvB\AppData\Roaming\Mozilla\Firefox\Profiles\tg7dw9os.default-1378141527687\prefs.js ] ************************* AdwCleaner[R0].txt - [9910 octets] - [12/09/2013 12:24:26] AdwCleaner[R1].txt - [1044 octets] - [12/09/2013 12:32:22] AdwCleaner[R2].txt - [1109 octets] - [12/09/2013 17:44:51] AdwCleaner[R3].txt - [1229 octets] - [12/09/2013 17:48:45] AdwCleaner[R4].txt - [1238 octets] - [14/09/2013 21:31:06] AdwCleaner[S0].txt - [8401 octets] - [12/09/2013 12:25:46] AdwCleaner[S1].txt - [1171 octets] - [12/09/2013 17:46:31] AdwCleaner[S2].txt - [1291 octets] - [12/09/2013 17:49:42] AdwCleaner[S3].txt - [1160 octets] - [14/09/2013 21:36:20] ########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1220 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.0 (09.12.2013:1) OS: Windows 7 Home Premium x64 Ran by PvB on 14.09.2013 at 21:45:22,21 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-866691505-2663605119-3151094225-1000\Software\SweetIM Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskToolbarNRO_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskToolbarNRO_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskToolbarNRO_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskToolbarNRO_RASMANCS ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted: [File] C:\user.js Emptied folder: C:\Users\PvB\AppData\Roaming\mozilla\firefox\profiles\tg7dw9os.default-1378141527687\minidumps [5 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 14.09.2013 at 21:48:36,22 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
15.09.2013, 10:20 | #8 |
/// the machine /// TB-Ausbilder | Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglichESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.09.2013, 17:23 | #9 |
| Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=525c21a15d9a084faf9dfab47dc49c8b # engine=15138 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-09-15 04:08:27 # local_time=2013-09-15 06:08:27 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 1110317 130891157 0 0 # scanned=270683 # found=6 # cleaned=0 # scan_time=13855 sh=77F8AA2F6F39020290E2D185AF257C74C6A57BA7 ft=0 fh=0000000000000000 vn="Win32/Adware.AddLyrics.F application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XingHaoLyrics\chrome.crx.vir" sh=DE2FAA0946042D3C207253C033CDA8210E4CD995 ft=0 fh=0000000000000000 vn="Win32/Adware.AddLyrics.F application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\XingHaoLyrics\FF\chrome\content\main.js.vir" sh=B69E778069F3E25B65F081B4D079EC7A285C0130 ft=0 fh=0000000000000000 vn="Win32/Adware.AddLyrics.F application" ac=I fn="C:\Users\PvB\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmiopbgcekanlhpjkonogoljpfmhpkhf\1.111\contentscript.js" sh=C5FC732E58A84B3F2FA24354408406D6DF1998F9 ft=0 fh=0000000000000000 vn="Win32/Adware.AddLyrics.F application" ac=I fn="I:\PVB-PC\Backup Set 2013-06-23 190001\Backup Files 2013-06-23 190001\Backup files 11.zip" sh=639CC217D4C14EA1531E9D9B7623E1D06B668ACB ft=0 fh=0000000000000000 vn="Win32/Adware.AddLyrics.F application" ac=I fn="I:\PVB-PC\Backup Set 2013-07-14 190000\Backup Files 2013-07-14 190000\Backup files 16.zip" sh=EE7F8064B50B5ACF41AC07B851032104449DFA17 ft=0 fh=0000000000000000 vn="Win32/Adware.AddLyrics.F application" ac=I fn="I:\PVB-PC\Backup Set 2013-07-14 190000\Backup Files 2013-09-05 015935\Backup files 8.zip" Results of screen317's Security Check version 0.99.73 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 25 Adobe Flash Player 11.8.800.168 Adobe Reader XI Mozilla Firefox (23.0.1) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-09-2013 05 Ran by PvB (administrator) on PVB-PC on 15-09-2013 18:17:52 Running from C:\Users\PvB\Desktop\Trojaner.de Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Rocket Division Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Hercules®) C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe () C:\Windows\SysWOW64\C2MP\UpdateChecker.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe (Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\cpl2\HDJSeries2CPL.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1356240 2013-07-18] (Microsoft Corporation) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13260944 2012-11-20] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1253520 2012-11-19] (Realtek Semiconductor) HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-07-31] (Logitech, Inc.) HKLM\...\Run: [Hercules DJ Series TrayAgent] - C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe [3572048 2013-05-10] (Hercules®) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = PortalDoSites HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {63EE8684-4E15-469b-823D-D703A41BADC3} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH SearchScopes: HKCU - {68BDEDD4-9936-4744-8927-4F8AEFD89207} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\PvB\AppData\Roaming\Mozilla\Firefox\Profiles\tg7dw9os.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass64.dll (LastPass) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@holasearch.com FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: () - C:\Users\PvB\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\0.0.4.1 CHR Extension: (LyricsPal) - C:\Users\PvB\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmiopbgcekanlhpjkonogoljpfmhpkhf\1.111 CHR Extension: (Plus-HD-3.8) - C:\Users\PvB\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjgnhihlklpobkaloamkankaaoclfjh\1.23.19_0 CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - \User Data\Default\Extensions\newtab.crx CHR HKLM-x32\...\Chrome\Extension: [mmiopbgcekanlhpjkonogoljpfmhpkhf] - C:\Program Files (x86)\XingHaoLyrics\Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () S2 CLKMSVC10_9EC60124; C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [240112 2010-11-18] (CyberLink) R2 HerculesDJControlMP3; C:\Program Files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE [47104 2013-05-21] (Hercules®) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165664 2012-08-23] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2013-07-18] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-07-18] (Microsoft Corporation) R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [275968 2007-05-28] (Rocket Division Software) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () R3 Bulk; C:\Windows\System32\Drivers\HDJBulk.sys [258352 2013-05-21] (© Guillemot R&D, 2013. All rights reserved.) R1 CLBStor; C:\Windows\System32\DRIVERS\CLBStor.sys [24560 2009-10-07] (Cyberlink Co.,Ltd.) R2 CLBUDF; C:\Windows\System32\Drivers\CLBUDF.sys [376304 2009-10-07] (CyberLink Corporation.) R3 HDJAsioK; C:\Windows\System32\Drivers\HDJAsioK.sys [320816 2013-05-21] (© Guillemot R&D, 2013. All rights reserved.) R3 HDJMidi; C:\Windows\System32\DRIVERS\HDJMidi.sys [274736 2013-05-21] (© Guillemot R&D, 2013. All rights reserved.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation) S3 prwntdrv; C:\Windows\system32\prwntdrv.sys [16776 2010-08-25] () S3 prwntdrv; C:\Windows\system32\prwntdrv.sys [16776 2010-08-25] () R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [868848 2012-06-27] () U3 aipd8wg2; C:\Windows\System32\Drivers\aipd8wg2.sys [0 ] (Microsoft Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 gdrv; \??\C:\Windows\gdrv.sys [x] S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [x] S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-15 11:00 - 2013-09-15 11:00 - 00000000 ____D C:\Users\PvB\Downloads\Extrawelt - Kopie 2013-09-15 11:00 - 2013-09-15 11:00 - 00000000 ____D C:\Users\PvB\Downloads\D-unity - Kopie 2013-09-15 10:51 - 2013-09-15 11:00 - 00000000 ____D C:\Users\PvB\Downloads\Oliver Schories 2013-09-14 21:51 - 2013-09-15 18:17 - 00000000 ____D C:\Users\PvB\Desktop\Trojaner.de 2013-09-14 21:45 - 2013-09-14 21:45 - 00000000 ____D C:\Windows\ERUNT 2013-09-13 17:38 - 2013-09-13 17:38 - 00029671 _____ C:\ComboFix.txt 2013-09-13 17:34 - 2013-09-13 17:38 - 00000000 ____D C:\Windows\erdnt 2013-09-13 17:34 - 2013-09-13 17:38 - 00000000 ____D C:\Qoobox 2013-09-13 17:34 - 2013-09-13 17:38 - 00000000 ____D C:\ComboFix 2013-09-13 17:34 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-13 17:34 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-13 17:34 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-13 17:34 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-13 17:34 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-13 17:34 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-13 17:34 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-13 17:34 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-13 09:28 - 2013-09-13 09:28 - 00000000 ____D C:\Windows\Microsoft Antimalware 2013-09-12 23:24 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 23:24 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 23:24 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-12 23:24 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 23:24 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 23:24 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 23:24 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 23:24 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 23:24 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 23:24 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 23:24 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-12 23:24 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-12 23:24 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-12 23:24 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-12 23:24 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-12 23:24 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-12 23:24 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-12 23:24 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-12 23:24 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-12 23:24 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-12 23:24 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-12 23:24 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-12 23:24 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-12 23:24 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-12 23:24 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-12 23:24 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-12 23:24 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-12 23:24 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 23:24 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-12 23:24 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-12 23:24 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-12 17:35 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-12 17:35 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-12 17:35 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-12 17:35 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-12 17:35 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-12 17:35 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-12 17:35 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-12 17:35 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-12 17:35 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-12 17:35 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-12 17:35 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-12 17:35 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-12 17:35 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-12 17:35 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-12 17:35 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-12 17:35 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-12 17:35 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-12 17:35 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-12 17:35 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-12 17:35 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-12 17:35 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-12 17:35 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-12 17:35 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-12 17:35 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-12 17:35 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-12 17:35 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-12 17:35 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-12 15:41 - 2013-09-15 17:34 - 01165487 ____N C:\Windows\WindowsUpdate.log 2013-09-12 14:48 - 2013-09-12 14:48 - 00000000 ____D C:\FRST 2013-09-12 12:22 - 2013-09-14 21:36 - 00000000 ____D C:\AdwCleaner 2013-09-12 11:24 - 2013-09-12 11:24 - 00000108 _____ C:\index.ini 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Malwarebytes 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-12 10:03 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-12 06:35 - 2013-05-14 16:50 - 00248832 _____ ( Hercules) C:\Windows\system32\HDJusbaudioapi_x64.dll 2013-09-12 06:32 - 2013-05-21 15:44 - 00320816 _____ (© Guillemot R&D, 2013. All rights reserved.) C:\Windows\system32\Drivers\HDJAsioK.sys 2013-09-12 06:32 - 2013-05-21 15:44 - 00274736 _____ (© Guillemot R&D, 2013. All rights reserved.) C:\Windows\system32\Drivers\HDJMidi.sys 2013-09-12 06:32 - 2013-05-21 15:44 - 00258352 _____ (© Guillemot R&D, 2013. All rights reserved.) C:\Windows\system32\Drivers\HDJBulk.sys 2013-09-12 06:32 - 2013-05-21 15:44 - 00038704 _____ (© Guillemot R&D, 2012. All rights reserved.) C:\Windows\system32\Drivers\HDJCtrl.sys 2013-09-12 06:32 - 2013-05-21 15:35 - 00091648 _____ (Hercules®) C:\Windows\system32\HDJAsiou.dll 2013-09-12 06:32 - 2013-05-21 15:35 - 00078336 _____ (Hercules®) C:\Windows\SysWOW64\HDJAsiou.dll 2013-09-12 06:32 - 2013-03-05 15:30 - 00079872 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\HerculesDJUSBAudioDevices_x64.dll 2013-09-12 06:32 - 2013-02-04 16:56 - 00000365 ____R C:\Windows\SysWOW64\HDJcustom.ini 2013-09-12 06:32 - 2013-02-04 16:56 - 00000365 ____R C:\Windows\system32\HDJcustom.ini 2013-09-12 06:27 - 2013-07-17 14:23 - 00065408 _____ (Etron Technology Inc) C:\Windows\system32\Drivers\EtronHub3.sys 2013-09-12 06:25 - 2013-06-18 16:22 - 00872152 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2013-09-12 06:25 - 2013-06-18 16:22 - 00074456 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll 2013-09-12 06:24 - 2013-09-12 06:24 - 00000000 ____D C:\Program Files\Logitech 2013-09-12 06:22 - 2013-09-12 06:22 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-09-12 06:22 - 2012-11-28 04:52 - 04222096 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2013-09-12 06:22 - 2012-11-28 02:30 - 00381365 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2013-09-12 06:22 - 2012-11-27 22:25 - 10612736 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat 2013-09-12 06:22 - 2012-11-21 00:32 - 00118928 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2013-09-12 06:22 - 2012-11-20 01:18 - 02714720 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2013-09-12 06:22 - 2012-11-16 21:30 - 03673232 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2013-09-12 06:22 - 2012-10-23 23:03 - 09546616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll 2013-09-12 06:22 - 2012-10-23 23:03 - 02080120 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll 2013-09-12 06:22 - 2012-10-23 02:48 - 01269904 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2013-09-12 06:22 - 2012-10-04 00:56 - 00772224 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll 2013-09-12 06:22 - 2012-10-02 21:41 - 00501192 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll 2013-09-12 06:22 - 2012-10-02 21:41 - 00487368 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll 2013-09-12 06:22 - 2012-10-02 21:41 - 00415688 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll 2013-09-12 06:22 - 2012-09-21 05:44 - 01460600 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek264.dll 2013-09-12 06:22 - 2012-09-20 07:59 - 00869752 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll 2013-09-12 06:22 - 2012-09-12 16:51 - 02743440 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2013-09-12 06:22 - 2012-09-09 21:34 - 02028920 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll 2013-09-12 06:22 - 2012-09-01 02:18 - 07164176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll 2013-09-12 06:22 - 2012-09-01 02:17 - 00434960 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll 2013-09-12 06:22 - 2012-09-01 02:17 - 00141584 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll 2013-09-12 06:22 - 2012-09-01 02:17 - 00124176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll 2013-09-12 06:22 - 2012-09-01 02:17 - 00075024 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll 2013-09-12 06:22 - 2012-08-21 21:51 - 00881808 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2013-09-12 06:22 - 2012-08-14 01:06 - 01561744 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2013-09-12 06:22 - 2012-07-16 04:13 - 00394616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll 2013-09-12 06:22 - 2012-07-16 04:13 - 00394616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll 2013-09-12 06:22 - 2012-06-21 00:26 - 00110592 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2013-09-12 06:22 - 2012-03-08 18:47 - 00202336 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2013-09-12 06:22 - 2012-03-08 18:47 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2013-09-12 06:22 - 2012-01-30 18:43 - 00836544 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll 2013-09-12 06:22 - 2012-01-10 17:20 - 00065944 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll 2013-09-12 06:22 - 2011-12-20 22:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2013-09-12 06:22 - 2011-11-22 23:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll 2013-09-12 06:22 - 2011-09-02 21:21 - 00221024 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll 2013-09-12 06:22 - 2011-09-02 21:21 - 00081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll 2013-09-12 06:22 - 2011-09-02 21:21 - 00078688 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll 2013-09-12 06:22 - 2011-08-24 00:00 - 00603984 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00712296 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll 2013-09-12 06:22 - 2011-05-31 16:42 - 00241768 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll 2013-09-12 06:22 - 2011-03-17 19:17 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll 2013-09-12 06:22 - 2011-03-08 00:11 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2013-09-12 06:22 - 2010-11-08 14:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2013-09-12 06:22 - 2010-11-04 01:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2013-09-12 06:22 - 2010-09-27 16:34 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2013-09-12 06:22 - 2010-07-22 23:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll 2013-09-12 06:22 - 2009-11-24 16:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2013-09-12 06:22 - 2009-11-24 16:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll 2013-09-12 06:22 - 2009-11-24 16:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll 2013-09-12 06:22 - 2009-11-24 16:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2013-09-12 06:12 - 2012-06-05 13:45 - 00237968 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtHDMIVX.sys 2013-09-12 06:12 - 2012-05-17 11:29 - 07163744 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64H.dll 2013-09-12 06:12 - 2012-05-17 11:29 - 00433504 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64H.dll 2013-09-12 06:12 - 2012-05-17 11:29 - 00141152 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64H.dll 2013-09-12 06:12 - 2012-05-17 11:29 - 00123744 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64H.dll 2013-09-12 06:12 - 2012-05-17 11:29 - 00074592 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64H.dll 2013-09-12 06:12 - 2011-12-02 14:20 - 03746408 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkHDM64.dll 2013-09-12 06:12 - 2011-09-27 14:04 - 02526824 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RHDMEx64.dll 2013-09-12 06:12 - 2011-07-06 13:27 - 00092264 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RHCoInst64.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00372056 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64H.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RH3DHT64.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RH3DAA64.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64H.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00097624 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64H.dll 2013-09-12 06:12 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64H.dll 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\ProgramData\ATI 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-09-12 05:24 - 2012-11-16 23:11 - 06253224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2013-09-12 05:24 - 2012-11-16 23:08 - 11922944 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-09-12 05:24 - 2012-11-16 22:52 - 00245944 _____ C:\Windows\SysWOW64\atiapfxx.blb 2013-09-12 05:24 - 2012-11-16 22:52 - 00245944 _____ C:\Windows\system32\atiapfxx.blb 2013-09-12 05:24 - 2012-11-16 22:51 - 00159744 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-09-12 05:24 - 2012-11-16 22:50 - 00918528 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-09-12 05:24 - 2012-11-16 22:45 - 00514048 _____ (AMD) C:\Windows\system32\atieclxx.exe 2013-09-12 05:24 - 2012-11-16 22:44 - 00238080 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2013-09-12 05:24 - 2012-11-16 22:43 - 00120320 _____ (AMD) C:\Windows\system32\atitmm64.dll 2013-09-12 05:24 - 2012-11-16 22:43 - 00059392 _____ (ATI Technologies, Inc.) C:\Windows\system32\atiedu64.dll 2013-09-12 05:24 - 2012-11-16 22:43 - 00043520 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll 2013-09-12 05:24 - 2012-11-16 22:43 - 00021504 _____ (AMD) C:\Windows\system32\atimuixx.dll 2013-09-12 05:24 - 2012-11-16 22:42 - 06811648 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-09-12 05:24 - 2012-11-16 22:34 - 26017280 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-09-12 05:24 - 2012-11-16 22:29 - 00069632 _____ (AMD) C:\Windows\system32\coinst_8.97.100.7.dll 2013-09-12 05:24 - 2012-11-16 22:17 - 19584512 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-09-12 05:24 - 2012-11-16 22:03 - 01960960 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdmv.dll 2013-09-12 05:24 - 2012-11-16 22:03 - 01053696 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6v.dll 2013-09-12 05:24 - 2012-11-16 21:59 - 00051200 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-09-12 05:24 - 2012-11-16 21:59 - 00046080 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-09-12 05:24 - 2012-11-16 21:59 - 00044544 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-09-12 05:24 - 2012-11-16 21:59 - 00044544 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-09-12 05:24 - 2012-11-16 21:58 - 15827456 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-09-12 05:24 - 2012-11-16 21:54 - 13402112 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-09-12 05:24 - 2012-11-16 21:54 - 04749312 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00364544 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00359936 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-09-12 05:24 - 2012-11-16 21:39 - 00041984 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00033280 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00017920 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00014848 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-09-12 05:24 - 2012-11-16 21:39 - 00014848 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2013-09-12 05:24 - 2012-11-16 21:38 - 00042496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-09-12 05:24 - 2012-11-16 21:37 - 00053248 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2013-09-12 05:24 - 2012-11-16 21:37 - 00032768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-09-12 05:24 - 2012-11-16 21:35 - 00056832 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-09-12 05:24 - 2012-11-16 21:35 - 00056832 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-09-12 05:24 - 2012-11-16 21:35 - 00056320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2013-09-12 05:24 - 2012-11-16 21:35 - 00056320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2013-09-12 04:54 - 2013-09-12 04:54 - 00002279 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12 Compact Mode.lnk 2013-09-12 04:54 - 2013-09-12 04:54 - 00001323 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12.lnk 2013-09-12 04:54 - 2013-09-12 04:54 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ashampoo 2013-09-12 03:37 - 2013-09-12 04:45 - 00000000 ____D C:\ProgramData\FreeDriverScout 2013-09-12 03:37 - 2013-09-12 03:37 - 00000000 ____D C:\Users\PvB\Documents\Freemium Driver Utilities 2013-09-12 03:30 - 2013-09-12 04:45 - 00000000 ____D C:\Program Files (x86)\Plus-HD-3.8 2013-09-12 03:29 - 2013-09-12 03:29 - 00000000 ____D C:\Program Files\Covus Freemium 2013-09-12 03:28 - 2013-09-12 04:45 - 00000000 ____D C:\ProgramData\Package Cache 2013-09-12 03:28 - 2013-09-12 04:45 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-09-12 03:01 - 2013-09-12 03:01 - 00000000 ____D C:\Users\PvB\Documents\Ashampoo Burning Studio 12 2013-09-05 09:26 - 2013-09-12 04:45 - 00000000 ____D C:\Windows\SysWOW64\languages 2013-09-05 09:26 - 2013-09-12 04:45 - 00000000 ____D C:\Windows\SysWOW64\custom matrices 2013-09-05 09:26 - 2013-09-12 04:45 - 00000000 ____D C:\Program Files (x86)\DirectVobSub 2013-09-05 09:26 - 2013-09-05 09:26 - 01180013 _____ C:\Windows\SysWOW64\unins000.exe 2013-09-05 09:26 - 2013-09-05 09:26 - 00715038 _____ C:\Windows\unins000.exe 2013-09-05 09:26 - 2013-09-05 09:26 - 00052895 _____ C:\Windows\SysWOW64\unins000.dat 2013-09-05 09:26 - 2013-09-05 09:26 - 00001890 _____ C:\Windows\unins000.dat 2013-09-05 09:26 - 2013-09-05 09:26 - 00000000 ____D C:\Program Files (x86)\Xvid 2013-09-05 09:26 - 2012-02-26 16:45 - 00328704 _____ C:\Windows\SysWOW64\ff_libfaad2.dll 2013-09-05 09:26 - 2012-02-26 16:40 - 00251392 _____ C:\Windows\SysWOW64\ff_kernelDeint.dll 2013-09-05 09:26 - 2011-12-17 14:59 - 00001695 _____ C:\Windows\SysWOW64\openIE.js 2013-09-05 09:26 - 2011-05-30 15:42 - 00255488 _____ C:\Windows\system32\xvidvfw.dll 2013-09-05 09:26 - 2011-05-30 15:42 - 00240640 _____ C:\Windows\SysWOW64\xvidvfw.dll 2013-09-05 09:26 - 2011-05-23 11:52 - 00153088 _____ C:\Windows\SysWOW64\xvid.ax 2013-09-05 09:26 - 2011-05-23 09:49 - 00173568 _____ C:\Windows\system32\xvid.ax 2013-09-05 09:26 - 2011-05-23 09:45 - 00696832 _____ C:\Windows\system32\xvidcore.dll 2013-09-05 09:26 - 2010-12-12 02:16 - 00017903 _____ C:\Windows\SysWOW64\gnu_license.txt 2013-09-05 09:26 - 2010-12-12 02:16 - 00001563 _____ C:\Windows\SysWOW64\Boost_Software_License_1.0.txt 2013-09-05 09:23 - 2010-11-21 05:24 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll 2013-09-05 08:30 - 2013-09-05 08:30 - 00000110 ___RH C:\Users\PvB\Downloads\Stinger.opt 2013-09-05 08:24 - 2013-09-05 08:30 - 00000000 ____D C:\Program Files\stinger 2013-09-05 07:46 - 2013-09-05 07:46 - 00000000 ____D C:\Program Files\Realtek 2013-09-05 06:41 - 2013-09-05 08:09 - 00000000 ___DC C:\Users\PvB\AppData\Local\MigWiz 2013-09-05 03:19 - 2013-09-12 09:51 - 00000000 ____D C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP 2013-09-05 03:06 - 2013-09-05 03:06 - 00003242 _____ C:\Windows\System32\Tasks\{65FACB05-279E-462F-BE27-B5B7E41F5E11} 2013-09-05 02:29 - 2013-09-05 02:37 - 00000000 ____D C:\Windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP 2013-09-05 02:29 - 2013-09-05 02:29 - 00000000 _____ C:\autoexec.bat 2013-09-05 02:12 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2013-09-05 02:12 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2013-09-05 02:12 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2013-09-05 02:12 - 2012-08-23 16:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2013-09-05 02:12 - 2012-08-23 15:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-09-05 02:12 - 2012-08-23 15:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-09-05 02:12 - 2012-08-23 15:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-09-05 02:12 - 2012-08-23 15:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-09-05 02:12 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2013-09-05 02:12 - 2012-08-23 15:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2013-09-05 02:12 - 2012-08-23 15:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-09-05 02:12 - 2012-08-23 15:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2013-09-05 02:12 - 2012-08-23 15:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2013-09-05 02:12 - 2012-08-23 14:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-09-05 02:12 - 2012-08-23 13:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2013-09-05 02:12 - 2012-08-23 13:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-09-05 02:12 - 2012-08-23 13:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2013-09-05 02:12 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2013-09-05 02:12 - 2012-08-23 12:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-09-05 02:12 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2013-09-05 02:12 - 2012-08-23 12:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-09-05 02:12 - 2012-08-23 12:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-09-05 02:12 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-09-05 02:12 - 2012-08-23 10:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-09-05 02:12 - 2012-08-23 10:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-09-05 02:07 - 2012-08-24 20:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-09-05 02:07 - 2012-08-24 20:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-09-05 02:07 - 2012-08-24 20:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-09-05 02:07 - 2012-08-24 20:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-09-05 02:07 - 2012-08-24 18:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-09-05 02:07 - 2012-08-24 18:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-09-05 02:07 - 2012-08-24 18:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-09-05 02:07 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-09-05 02:07 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-09-03 21:19 - 2013-09-03 21:19 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-09-03 21:19 - 2013-09-03 21:19 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-09-03 03:52 - 2013-09-12 04:45 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-09-02 21:46 - 2013-09-02 21:46 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-09-02 21:46 - 2013-09-02 21:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-09-02 20:16 - 2013-09-02 20:16 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00000000 ____D C:\ProgramData\Sun 2013-09-02 20:16 - 2013-09-02 20:16 - 00000000 ____D C:\Program Files (x86)\Java 2013-09-02 20:14 - 2013-09-03 04:13 - 00000000 ____D C:\Program Files\Java 2013-09-02 20:14 - 2013-09-02 20:14 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-09-02 19:48 - 2013-09-02 19:48 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-02 19:48 - 2013-09-02 19:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-02 19:20 - 2013-09-05 07:37 - 00003232 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-09-02 19:20 - 2013-09-02 19:20 - 00000000 ____D C:\Users\PvB\AppData\Roaming\AVG2013 2013-09-02 19:19 - 2013-09-02 21:42 - 00000000 ____D C:\ProgramData\AVG2013 2013-09-02 19:19 - 2013-09-02 21:42 - 00000000 ____D C:\$AVG 2013-09-02 19:18 - 2013-09-02 21:43 - 00000000 ____D C:\ProgramData\MFAData 2013-09-02 19:18 - 2013-09-02 19:21 - 00000000 ____D C:\Users\PvB\AppData\Local\Avg2013 2013-09-02 19:18 - 2013-09-02 19:18 - 00000000 ____D C:\Users\PvB\AppData\Local\MFAData 2013-09-02 18:55 - 2013-09-02 18:55 - 00000000 ____D C:\Program Files (x86)\Emsisoft HiJackFree 2013-09-02 18:43 - 2013-09-02 18:43 - 00003118 _____ C:\Windows\System32\Tasks\{E79E7AF6-22C4-4BFE-B386-A9F49AFCB6E0} 2013-09-02 18:39 - 2013-09-02 18:39 - 00003126 _____ C:\Windows\System32\Tasks\{1901E6CA-FC54-4E2F-86D2-C3156922418E} 2013-09-01 20:38 - 2013-09-01 20:38 - 00000055 _____ C:\Users\PvB\AppData\Roaming\WB.CFG 2013-09-01 20:38 - 2013-09-01 20:38 - 00000005 _____ C:\Users\PvB\AppData\Roaming\WBPU-TTL.DAT 2013-09-01 19:44 - 2013-09-02 19:32 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Ipobc 2013-09-01 19:44 - 2013-09-02 19:03 - 00000000 ____D C:\Users\PvB\AppData\Roaming\tor 2013-09-01 19:44 - 2013-09-02 18:36 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Hetu 2013-09-01 19:38 - 2013-09-01 19:38 - 00000000 ____D C:\Users\PvB\AppData\Roaming\0D0S1L2Z1P1B 2013-09-01 19:29 - 2013-09-01 19:29 - 00003372 _____ C:\Windows\System32\Tasks\{A4667A53-6E83-40FC-AD5C-A4185730D018} 2013-08-31 11:08 - 2013-08-31 11:18 - 00000000 ____D C:\Users\PvB\AppData\Roaming\vlc 2013-08-31 11:01 - 2013-08-31 11:01 - 00000000 ____D C:\Users\PvB\AppData\Roaming\SeeSimilar 2013-08-31 11:00 - 2013-08-31 11:00 - 00000000 ____D C:\Users\PvB\AppData\Roaming\4Free 2013-08-31 10:45 - 2013-08-31 10:45 - 00000000 ____D C:\Users\PvB\Documents\Tipard Studio 2013-08-31 10:45 - 2013-08-31 10:45 - 00000000 ____D C:\Users\PvB\AppData\Local\Tipard Studio 2013-08-31 10:09 - 2013-08-31 10:20 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Xilisoft 2013-08-31 09:55 - 2013-08-31 09:56 - 00000000 ____D C:\Users\PvB\AppData\Roaming\FreeVideoConverter 2013-08-31 09:47 - 2013-08-31 10:20 - 00000000 ____D C:\Program Files (x86)\AnvSoft 2013-08-31 09:47 - 2013-08-31 09:47 - 00000000 ____D C:\Users\PvB\Documents\Any Video Converter Professional 2013-08-31 09:47 - 2013-08-31 09:47 - 00000000 ____D C:\Users\PvB\Documents\Any Video Converter 2013-08-31 09:40 - 2013-08-31 09:40 - 00000000 ____D C:\Users\PvB\Documents\My Received Files 2013-08-31 09:40 - 2013-08-31 09:40 - 00000000 ____D C:\Users\PvB\AppData\Roaming\MusicNet 2013-08-31 09:30 - 2013-09-05 09:26 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2013-08-31 09:30 - 2013-09-05 09:26 - 00000000 ____D C:\Program Files (x86)\DSP-worx 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\LavFilters 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\CDXReader 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Program Files (x86)\OpenSource Flash Video Splitter 2013-08-31 09:21 - 2013-08-31 11:25 - 00000000 ____D C:\Users\PvB\AppData\Local\VMware 2013-08-31 09:20 - 2013-09-12 05:49 - 00000000 ____D C:\Users\PvB\AppData\Roaming\VMware 2013-08-31 09:01 - 2013-09-12 05:49 - 00000000 ____D C:\ProgramData\VMware 2013-08-30 06:21 - 2013-08-30 06:21 - 04012544 _____ C:\Windows\system32\ffmpeg.dll 2013-08-30 06:20 - 2013-08-30 06:20 - 04374016 _____ C:\Windows\system32\ffdshow.ax 2013-08-30 06:20 - 2013-08-30 06:20 - 00631296 _____ C:\Windows\system32\TomsMoComp_ff.dll 2013-08-30 06:20 - 2013-08-30 06:20 - 00474624 _____ C:\Windows\system32\ff_kernelDeint.dll 2013-08-30 06:20 - 2012-12-13 22:59 - 00127488 _____ C:\Windows\system32\ff_vfw.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 01532928 _____ C:\Windows\system32\ff_samplerate.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00222720 _____ C:\Windows\system32\ff_libdts.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00190464 _____ C:\Windows\system32\libmpeg2_ff.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00183296 _____ C:\Windows\system32\ff_unrar.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00156672 _____ C:\Windows\system32\ff_libmad.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00116224 _____ C:\Windows\system32\ff_liba52.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00114688 _____ C:\Windows\system32\ff_wmv9.dll 2013-08-30 05:54 - 2012-03-22 18:46 - 04417024 _____ C:\Windows\SysWOW64\ffmpeg.dll 2013-08-30 05:53 - 2012-03-22 18:46 - 03471360 _____ C:\Windows\SysWOW64\ffdshow.ax 2013-08-30 05:53 - 2012-02-26 16:47 - 00079360 _____ C:\Windows\SysWOW64\ff_vfw.dll 2013-08-30 05:51 - 2012-02-26 16:46 - 00260608 _____ C:\Windows\SysWOW64\TomsMoComp_ff.dll 2013-08-30 05:51 - 2012-02-26 16:46 - 00158720 _____ C:\Windows\SysWOW64\ff_unrar.dll 2013-08-30 05:51 - 2012-02-26 16:46 - 00099840 _____ C:\Windows\SysWOW64\ff_wmv9.dll 2013-08-30 05:51 - 2012-02-26 16:45 - 01525248 _____ C:\Windows\SysWOW64\ff_samplerate.dll 2013-08-30 05:51 - 2012-02-26 16:45 - 00212480 _____ C:\Windows\SysWOW64\ff_libdts.dll 2013-08-30 05:51 - 2012-02-26 16:45 - 00146944 _____ C:\Windows\SysWOW64\ff_libmad.dll 2013-08-30 05:51 - 2012-02-26 16:45 - 00137728 _____ C:\Windows\SysWOW64\libmpeg2_ff.dll 2013-08-30 05:51 - 2012-02-26 16:45 - 00115200 _____ C:\Windows\SysWOW64\ff_liba52.dll 2013-08-28 09:49 - 2013-08-28 09:52 - 00000000 ____D C:\Users\PvB\AppData\Roaming\ObviousIdea 2013-08-28 09:47 - 2013-08-28 09:47 - 00000000 ____D C:\User Data 2013-08-28 08:25 - 2013-09-03 04:46 - 00000000 ____D C:\Users\PvB\AppData\Local\DeSTRoi 2013-08-28 07:50 - 2013-08-28 07:50 - 00000000 ____D C:\.Trash-999 2013-08-28 04:32 - 2013-08-28 04:32 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Standard 2013-08-28 04:32 - 2013-08-28 04:32 - 00000000 ____D C:\Program Files (x86)\Shark007 2013-08-28 04:31 - 2013-08-28 04:32 - 00000000 ____D C:\ProgramData\Standard 2013-08-28 04:27 - 2013-08-28 04:27 - 00000000 ____D C:\Program Files\K-Lite Codec Pack x64 2013-08-28 04:23 - 2013-09-05 09:23 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Shark007 2013-08-28 04:23 - 2013-09-05 09:23 - 00000000 ____D C:\ProgramData\Shark007 2013-08-28 04:23 - 2007-02-05 17:05 - 00000038 _____ C:\Windows\AviSplitter.INI 2013-08-28 04:22 - 2013-09-05 09:22 - 00000000 ____D C:\Program Files\Shark007 2013-08-28 04:22 - 2013-04-05 21:27 - 02231296 _____ C:\Windows\system32\ac3filter.acm.new 2013-08-28 04:22 - 2013-01-11 09:16 - 04294656 _____ C:\Windows\system32\x264vfw.dll 2013-08-28 04:22 - 2012-07-21 11:55 - 00180736 _____ (fccHandler) C:\Windows\system32\ac3acm.acm 2013-08-28 04:22 - 2012-07-21 11:54 - 00361472 _____ (fccHandler) C:\Windows\system32\aacacm.acm 2013-08-28 04:22 - 2012-07-17 14:21 - 00206336 _____ C:\Windows\system32\unrar64.dll 2013-08-28 04:22 - 2011-12-07 19:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll 2013-08-28 04:22 - 2009-08-11 18:22 - 00580096 _____ C:\Windows\system32\ac3filter.acm.old 2013-08-28 04:22 - 2009-08-11 17:22 - 00580096 _____ C:\Windows\system32\ac3filter.acm 2013-08-28 04:22 - 2009-01-22 21:51 - 00124909 _____ (Open Source Software community project) C:\Windows\system32\pthreadGC2.dll 2013-08-28 04:20 - 2013-08-28 04:20 - 00003584 _____ C:\Users\PvB\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-08-28 04:12 - 2013-08-28 04:12 - 00000000 ____D C:\Windows\SysWOW64\C2MP 2013-08-27 17:24 - 2013-09-05 09:49 - 00002934 _____ C:\Windows\System32\Tasks\{720DB07B-6571-4601-80F7-B3BED7BC3D88} 2013-08-27 17:24 - 2013-09-05 09:49 - 00002934 _____ C:\Windows\System32\Tasks\{12258E8A-F421-41D3-8B14-723E36D317BF} 2013-08-27 00:35 - 2013-08-27 00:35 - 00000000 ____D C:\Users\PvB\Neo 2013-08-26 01:24 - 2013-09-12 05:11 - 00000000 ____D C:\Users\PvB\AppData\Roaming\LumacDaemon 2013-08-26 01:24 - 2013-08-26 01:24 - 00000000 ____D C:\Users\PvB\AppData\Local\Firstload 2013-08-20 11:09 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2013-08-20 11:09 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2013-08-20 11:09 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2013-08-20 11:09 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2013-08-20 11:09 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2013-08-20 11:09 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2013-08-20 10:37 - 2013-08-20 10:37 - 00000219 _____ C:\Users\PvB\Desktop\Counter-Strike Global Offensive.url 2013-08-20 10:37 - 2013-08-20 10:37 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-08-20 10:26 - 2013-08-31 00:07 - 00000000 ____D C:\Program Files (x86)\Steam 2013-08-20 10:26 - 2013-08-20 10:26 - 00000917 _____ C:\Users\Public\Desktop\Steam.lnk ==================== One Month Modified Files and Folders ======= 2013-09-15 18:17 - 2013-09-14 21:51 - 00000000 ____D C:\Users\PvB\Desktop\Trojaner.de 2013-09-15 17:54 - 2012-06-27 17:01 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-15 17:34 - 2013-09-12 15:41 - 01165487 ____N C:\Windows\WindowsUpdate.log 2013-09-15 14:19 - 2011-04-12 09:43 - 00699432 _____ C:\Windows\system32\perfh007.dat 2013-09-15 14:19 - 2011-04-12 09:43 - 00149572 _____ C:\Windows\system32\perfc007.dat 2013-09-15 14:19 - 2009-07-14 07:13 - 01620684 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-15 11:00 - 2013-09-15 11:00 - 00000000 ____D C:\Users\PvB\Downloads\Extrawelt - Kopie 2013-09-15 11:00 - 2013-09-15 11:00 - 00000000 ____D C:\Users\PvB\Downloads\D-unity - Kopie 2013-09-15 11:00 - 2013-09-15 10:51 - 00000000 ____D C:\Users\PvB\Downloads\Oliver Schories 2013-09-15 10:53 - 2009-07-14 06:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-15 10:53 - 2009-07-14 06:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-15 10:46 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-14 21:45 - 2013-09-14 21:45 - 00000000 ____D C:\Windows\ERUNT 2013-09-14 21:36 - 2013-09-12 12:22 - 00000000 ____D C:\AdwCleaner 2013-09-13 19:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-13 17:38 - 2013-09-13 17:38 - 00029671 _____ C:\ComboFix.txt 2013-09-13 17:38 - 2013-09-13 17:34 - 00000000 ____D C:\Windows\erdnt 2013-09-13 17:38 - 2013-09-13 17:34 - 00000000 ____D C:\Qoobox 2013-09-13 17:38 - 2013-09-13 17:34 - 00000000 ____D C:\ComboFix 2013-09-13 17:37 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-09-13 09:28 - 2013-09-13 09:28 - 00000000 ____D C:\Windows\Microsoft Antimalware 2013-09-13 07:54 - 2012-06-27 17:01 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-13 07:54 - 2012-06-27 17:01 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-13 07:54 - 2012-06-27 17:01 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-13 07:07 - 2012-06-27 17:26 - 00000000 ____D C:\Windows\Panther 2013-09-13 07:07 - 2012-06-27 17:08 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Winamp 2013-09-13 01:31 - 2012-06-27 16:33 - 00000000 ___RD C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-13 01:31 - 2012-06-27 16:33 - 00000000 ___RD C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-13 01:30 - 2013-05-23 06:02 - 00378536 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 23:24 - 2013-08-15 00:05 - 00000000 ____D C:\Windows\system32\MRT 2013-09-12 23:24 - 2009-07-14 04:34 - 00000499 _____ C:\Windows\win.ini 2013-09-12 23:23 - 2012-07-08 18:18 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-12 14:48 - 2013-09-12 14:48 - 00000000 ____D C:\FRST 2013-09-12 12:50 - 2012-06-27 16:54 - 00000000 ____D C:\Program Files\CCleaner 2013-09-12 12:25 - 2012-06-27 16:33 - 00000991 _____ C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-12 11:36 - 2013-02-28 12:31 - 00000000 ____D C:\Program Files (x86)\7-Zip 2013-09-12 11:24 - 2013-09-12 11:24 - 00000108 _____ C:\index.ini 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Malwarebytes 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-12 10:03 - 2013-09-12 10:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-12 09:51 - 2013-09-05 03:19 - 00000000 ____D C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP 2013-09-12 09:38 - 2012-06-27 16:37 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-09-12 06:36 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-12 06:32 - 2012-06-27 17:32 - 00000000 ____D C:\Program Files\Guillemot 2013-09-12 06:25 - 2012-06-27 16:37 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-09-12 06:24 - 2013-09-12 06:24 - 00000000 ____D C:\Program Files\Logitech 2013-09-12 06:24 - 2012-12-14 21:20 - 00000000 ____D C:\ProgramData\Logitech 2013-09-12 06:24 - 2012-06-29 21:14 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2013-09-12 06:24 - 2012-06-29 21:14 - 00000000 ____D C:\ProgramData\Logishrd 2013-09-12 06:24 - 2012-06-29 21:13 - 00000000 ____D C:\Program Files\Common Files\LogiShrd 2013-09-12 06:22 - 2013-09-12 06:22 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-09-12 05:49 - 2013-08-31 09:20 - 00000000 ____D C:\Users\PvB\AppData\Roaming\VMware 2013-09-12 05:49 - 2013-08-31 09:01 - 00000000 ____D C:\ProgramData\VMware 2013-09-12 05:29 - 2012-06-29 21:18 - 00018682 _____ C:\Windows\system32\results.xml 2013-09-12 05:27 - 2012-06-27 16:36 - 00000000 ____D C:\Program Files (x86)\Intel 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\ProgramData\ATI 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-09-12 05:25 - 2013-09-12 05:25 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-09-12 05:25 - 2012-06-27 16:52 - 00000000 ____D C:\ProgramData\AMD 2013-09-12 05:25 - 2012-06-27 16:51 - 00000000 ____D C:\Program Files\ATI Technologies 2013-09-12 05:19 - 2012-12-14 21:06 - 00000000 ____D C:\ProgramData\DriverGenius 2013-09-12 05:11 - 2013-08-26 01:24 - 00000000 ____D C:\Users\PvB\AppData\Roaming\LumacDaemon 2013-09-12 04:54 - 2013-09-12 04:54 - 00002279 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12 Compact Mode.lnk 2013-09-12 04:54 - 2013-09-12 04:54 - 00001323 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12.lnk 2013-09-12 04:54 - 2013-09-12 04:54 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ashampoo 2013-09-12 04:54 - 2012-06-27 17:04 - 00000000 ____D C:\ProgramData\ashampoo 2013-09-12 04:45 - 2013-09-12 03:37 - 00000000 ____D C:\ProgramData\FreeDriverScout 2013-09-12 04:45 - 2013-09-12 03:30 - 00000000 ____D C:\Program Files (x86)\Plus-HD-3.8 2013-09-12 04:45 - 2013-09-12 03:28 - 00000000 ____D C:\ProgramData\Package Cache 2013-09-12 04:45 - 2013-09-12 03:28 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-09-12 04:45 - 2013-09-05 09:26 - 00000000 ____D C:\Windows\SysWOW64\languages 2013-09-12 04:45 - 2013-09-05 09:26 - 00000000 ____D C:\Windows\SysWOW64\custom matrices 2013-09-12 04:45 - 2013-09-05 09:26 - 00000000 ____D C:\Program Files (x86)\DirectVobSub 2013-09-12 04:45 - 2013-09-03 03:52 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-09-12 04:45 - 2012-06-27 17:04 - 00000000 ____D C:\Program Files (x86)\Ashampoo 2013-09-12 04:45 - 2012-06-27 17:01 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2013-09-12 04:45 - 2012-06-27 17:01 - 00000000 ____D C:\Windows\system32\Macromed 2013-09-12 04:45 - 2012-06-27 16:33 - 00000000 ____D C:\Users\PvB 2013-09-12 04:45 - 2011-04-12 09:54 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-09-12 04:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-09-12 04:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\security 2013-09-12 04:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2013-09-12 04:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat 2013-09-12 03:37 - 2013-09-12 03:37 - 00000000 ____D C:\Users\PvB\Documents\Freemium Driver Utilities 2013-09-12 03:29 - 2013-09-12 03:29 - 00000000 ____D C:\Program Files\Covus Freemium 2013-09-12 03:11 - 2012-06-27 17:17 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Ashampoo 2013-09-12 03:01 - 2013-09-12 03:01 - 00000000 ____D C:\Users\PvB\Documents\Ashampoo Burning Studio 12 2013-09-11 21:04 - 2012-06-27 17:04 - 00000000 ____D C:\Users\PvB\AppData\Local\ashampoo 2013-09-05 22:02 - 2012-06-27 16:50 - 01602306 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-09-05 09:52 - 2012-06-27 16:50 - 00002198 _____ C:\Windows\epplauncher.mif 2013-09-05 09:49 - 2013-08-27 17:24 - 00002934 _____ C:\Windows\System32\Tasks\{720DB07B-6571-4601-80F7-B3BED7BC3D88} 2013-09-05 09:49 - 2013-08-27 17:24 - 00002934 _____ C:\Windows\System32\Tasks\{12258E8A-F421-41D3-8B14-723E36D317BF} 2013-09-05 09:26 - 2013-09-05 09:26 - 01180013 _____ C:\Windows\SysWOW64\unins000.exe 2013-09-05 09:26 - 2013-09-05 09:26 - 00715038 _____ C:\Windows\unins000.exe 2013-09-05 09:26 - 2013-09-05 09:26 - 00052895 _____ C:\Windows\SysWOW64\unins000.dat 2013-09-05 09:26 - 2013-09-05 09:26 - 00001890 _____ C:\Windows\unins000.dat 2013-09-05 09:26 - 2013-09-05 09:26 - 00000000 ____D C:\Program Files (x86)\Xvid 2013-09-05 09:26 - 2013-08-31 09:30 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2013-09-05 09:26 - 2013-08-31 09:30 - 00000000 ____D C:\Program Files (x86)\DSP-worx 2013-09-05 09:26 - 2012-07-09 03:58 - 00000000 ____D C:\Program Files (x86)\DivX 2013-09-05 09:26 - 2012-07-09 03:57 - 00000000 ____D C:\ProgramData\DivX 2013-09-05 09:23 - 2013-08-28 04:23 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Shark007 2013-09-05 09:23 - 2013-08-28 04:23 - 00000000 ____D C:\ProgramData\Shark007 2013-09-05 09:22 - 2013-08-28 04:22 - 00000000 ____D C:\Program Files\Shark007 2013-09-05 08:45 - 2013-04-10 13:07 - 00007597 _____ C:\Users\PvB\AppData\Local\resmon.resmoncfg 2013-09-05 08:30 - 2013-09-05 08:30 - 00000110 ___RH C:\Users\PvB\Downloads\Stinger.opt 2013-09-05 08:30 - 2013-09-05 08:24 - 00000000 ____D C:\Program Files\stinger 2013-09-05 08:09 - 2013-09-05 06:41 - 00000000 ___DC C:\Users\PvB\AppData\Local\MigWiz 2013-09-05 07:46 - 2013-09-05 07:46 - 00000000 ____D C:\Program Files\Realtek 2013-09-05 07:37 - 2013-09-02 19:20 - 00003232 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-09-05 07:31 - 2012-06-27 17:08 - 00000000 ____D C:\Program Files\WinRAR 2013-09-05 07:07 - 2013-03-18 19:12 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-09-05 03:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-09-05 03:06 - 2013-09-05 03:06 - 00003242 _____ C:\Windows\System32\Tasks\{65FACB05-279E-462F-BE27-B5B7E41F5E11} 2013-09-05 02:37 - 2013-09-05 02:29 - 00000000 ____D C:\Windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP 2013-09-05 02:29 - 2013-09-05 02:29 - 00000000 _____ C:\autoexec.bat 2013-09-03 21:19 - 2013-09-03 21:19 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-09-03 21:19 - 2013-09-03 21:19 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-09-03 05:55 - 2012-07-09 03:58 - 00000000 ____D C:\Program Files\DivX 2013-09-03 05:54 - 2012-07-09 03:59 - 00000000 ____D C:\Users\PvB\AppData\Roaming\DivX 2013-09-03 04:46 - 2013-08-28 08:25 - 00000000 ____D C:\Users\PvB\AppData\Local\DeSTRoi 2013-09-03 04:13 - 2013-09-02 20:14 - 00000000 ____D C:\Program Files\Java 2013-09-03 03:50 - 2012-07-01 16:57 - 00000000 ____D C:\Users\PvB\AppData\Local\Adobe 2013-09-02 21:46 - 2013-09-02 21:46 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-09-02 21:46 - 2013-09-02 21:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-09-02 21:43 - 2013-09-02 19:18 - 00000000 ____D C:\ProgramData\MFAData 2013-09-02 21:42 - 2013-09-02 19:19 - 00000000 ____D C:\ProgramData\AVG2013 2013-09-02 21:42 - 2013-09-02 19:19 - 00000000 ____D C:\$AVG 2013-09-02 20:16 - 2013-09-02 20:16 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-09-02 20:16 - 2013-09-02 20:16 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-09-02 20:16 - 2013-09-02 20:16 - 00000000 ____D C:\ProgramData\Sun 2013-09-02 20:16 - 2013-09-02 20:16 - 00000000 ____D C:\Program Files (x86)\Java 2013-09-02 20:14 - 2013-09-02 20:14 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-02 20:14 - 2013-09-02 20:14 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-09-02 20:14 - 2012-06-27 16:54 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-09-02 20:14 - 2012-06-27 16:54 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-09-02 19:48 - 2013-09-02 19:48 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-02 19:48 - 2013-09-02 19:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-02 19:48 - 2013-01-11 15:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-02 19:32 - 2013-09-01 19:44 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Ipobc 2013-09-02 19:21 - 2013-09-02 19:18 - 00000000 ____D C:\Users\PvB\AppData\Local\Avg2013 2013-09-02 19:20 - 2013-09-02 19:20 - 00000000 ____D C:\Users\PvB\AppData\Roaming\AVG2013 2013-09-02 19:18 - 2013-09-02 19:18 - 00000000 ____D C:\Users\PvB\AppData\Local\MFAData 2013-09-02 19:12 - 2012-06-27 17:09 - 00000000 ____D C:\Users\PvB\Desktop\Progs 2013-09-02 19:03 - 2013-09-01 19:44 - 00000000 ____D C:\Users\PvB\AppData\Roaming\tor 2013-09-02 18:55 - 2013-09-02 18:55 - 00000000 ____D C:\Program Files (x86)\Emsisoft HiJackFree 2013-09-02 18:43 - 2013-09-02 18:43 - 00003118 _____ C:\Windows\System32\Tasks\{E79E7AF6-22C4-4BFE-B386-A9F49AFCB6E0} 2013-09-02 18:39 - 2013-09-02 18:39 - 00003126 _____ C:\Windows\System32\Tasks\{1901E6CA-FC54-4E2F-86D2-C3156922418E} 2013-09-02 18:36 - 2013-09-01 19:44 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Hetu 2013-09-02 17:37 - 2012-06-27 16:43 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Mozilla 2013-09-01 23:18 - 2012-06-27 16:43 - 00000000 ____D C:\Users\PvB\AppData\Local\Mozilla 2013-09-01 20:38 - 2013-09-01 20:38 - 00000055 _____ C:\Users\PvB\AppData\Roaming\WB.CFG 2013-09-01 20:38 - 2013-09-01 20:38 - 00000005 _____ C:\Users\PvB\AppData\Roaming\WBPU-TTL.DAT 2013-09-01 19:38 - 2013-09-01 19:38 - 00000000 ____D C:\Users\PvB\AppData\Roaming\0D0S1L2Z1P1B 2013-09-01 19:29 - 2013-09-01 19:29 - 00003372 _____ C:\Windows\System32\Tasks\{A4667A53-6E83-40FC-AD5C-A4185730D018} 2013-08-31 11:25 - 2013-08-31 09:21 - 00000000 ____D C:\Users\PvB\AppData\Local\VMware 2013-08-31 11:18 - 2013-08-31 11:08 - 00000000 ____D C:\Users\PvB\AppData\Roaming\vlc 2013-08-31 11:01 - 2013-08-31 11:01 - 00000000 ____D C:\Users\PvB\AppData\Roaming\SeeSimilar 2013-08-31 11:00 - 2013-08-31 11:00 - 00000000 ____D C:\Users\PvB\AppData\Roaming\4Free 2013-08-31 10:45 - 2013-08-31 10:45 - 00000000 ____D C:\Users\PvB\Documents\Tipard Studio 2013-08-31 10:45 - 2013-08-31 10:45 - 00000000 ____D C:\Users\PvB\AppData\Local\Tipard Studio 2013-08-31 10:20 - 2013-08-31 10:09 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Xilisoft 2013-08-31 10:20 - 2013-08-31 09:47 - 00000000 ____D C:\Program Files (x86)\AnvSoft 2013-08-31 10:12 - 2012-08-16 01:43 - 00000000 ____D C:\Users\PvB\AppData\Roaming\AnvSoft 2013-08-31 09:56 - 2013-08-31 09:55 - 00000000 ____D C:\Users\PvB\AppData\Roaming\FreeVideoConverter 2013-08-31 09:47 - 2013-08-31 09:47 - 00000000 ____D C:\Users\PvB\Documents\Any Video Converter Professional 2013-08-31 09:47 - 2013-08-31 09:47 - 00000000 ____D C:\Users\PvB\Documents\Any Video Converter 2013-08-31 09:40 - 2013-08-31 09:40 - 00000000 ____D C:\Users\PvB\Documents\My Received Files 2013-08-31 09:40 - 2013-08-31 09:40 - 00000000 ____D C:\Users\PvB\AppData\Roaming\MusicNet 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\LavFilters 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Users\PvB\AppData\Roaming\CDXReader 2013-08-31 09:30 - 2013-08-31 09:30 - 00000000 ____D C:\Program Files (x86)\OpenSource Flash Video Splitter 2013-08-31 00:07 - 2013-08-20 10:26 - 00000000 ____D C:\Program Files (x86)\Steam 2013-08-30 06:21 - 2013-08-30 06:21 - 04012544 _____ C:\Windows\system32\ffmpeg.dll 2013-08-30 06:20 - 2013-08-30 06:20 - 04374016 _____ C:\Windows\system32\ffdshow.ax 2013-08-30 06:20 - 2013-08-30 06:20 - 00631296 _____ C:\Windows\system32\TomsMoComp_ff.dll 2013-08-30 06:20 - 2013-08-30 06:20 - 00474624 _____ C:\Windows\system32\ff_kernelDeint.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 01532928 _____ C:\Windows\system32\ff_samplerate.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00222720 _____ C:\Windows\system32\ff_libdts.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00190464 _____ C:\Windows\system32\libmpeg2_ff.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00183296 _____ C:\Windows\system32\ff_unrar.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00156672 _____ C:\Windows\system32\ff_libmad.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00116224 _____ C:\Windows\system32\ff_liba52.dll 2013-08-30 06:19 - 2013-08-30 06:19 - 00114688 _____ C:\Windows\system32\ff_wmv9.dll 2013-08-28 18:43 - 2012-08-13 03:36 - 00000000 ____D C:\Program Files\VideoLAN 2013-08-28 16:33 - 2012-06-27 16:56 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-08-28 16:33 - 2012-06-27 16:56 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-08-28 09:52 - 2013-08-28 09:49 - 00000000 ____D C:\Users\PvB\AppData\Roaming\ObviousIdea 2013-08-28 09:49 - 2013-05-23 06:02 - 00092944 _____ C:\Users\PvB\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-28 09:47 - 2013-08-28 09:47 - 00000000 ____D C:\User Data 2013-08-28 07:50 - 2013-08-28 07:50 - 00000000 ____D C:\.Trash-999 2013-08-28 04:32 - 2013-08-28 04:32 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Standard 2013-08-28 04:32 - 2013-08-28 04:32 - 00000000 ____D C:\Program Files (x86)\Shark007 2013-08-28 04:32 - 2013-08-28 04:31 - 00000000 ____D C:\ProgramData\Standard 2013-08-28 04:27 - 2013-08-28 04:27 - 00000000 ____D C:\Program Files\K-Lite Codec Pack x64 2013-08-28 04:20 - 2013-08-28 04:20 - 00003584 _____ C:\Users\PvB\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-08-28 04:12 - 2013-08-28 04:12 - 00000000 ____D C:\Windows\SysWOW64\C2MP 2013-08-27 22:19 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-08-27 00:36 - 2013-07-15 13:16 - 00000000 ____D C:\Users\PvB\Documents\Calibre Bibliothek 2013-08-27 00:35 - 2013-08-27 00:35 - 00000000 ____D C:\Users\PvB\Neo 2013-08-26 01:24 - 2013-08-26 01:24 - 00000000 ____D C:\Users\PvB\AppData\Local\Firstload 2013-08-20 10:37 - 2013-08-20 10:37 - 00000219 _____ C:\Users\PvB\Desktop\Counter-Strike Global Offensive.url 2013-08-20 10:37 - 2013-08-20 10:37 - 00000000 ____D C:\Users\PvB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-08-20 10:26 - 2013-08-20 10:26 - 00000917 _____ C:\Users\Public\Desktop\Steam.lnk 2013-08-19 00:15 - 2013-08-07 21:14 - 00000000 ____D C:\Users\PvB\Downloads\sft-loader_2009_final Some content of TEMP: ==================== C:\Users\PvB\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-11 02:53 ==================== End Of Log ============================ --- --- --- --- --- --- Beim Hochfehren des Pcs besteht immer noch das selbe Problem nach dem Bios kommt Bildschirm, wo ich ausSpyHunter, Betriebsystem Xp oder Windows 7 aussuchen muss. Gruss PvB |
15.09.2013, 22:25 | #10 |
/// the machine /// TB-Ausbilder | Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich poste mal bitte noch ein FRST log com XP System.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.09.2013, 16:11 | #11 |
| Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich Danke für Deine Hilfe, doch ich habe heute mein Betriebsystem neu aufgespielt,was auch reltiv fix und problemos war(SDD).Nächstes mal wird erst gegoogelt und dann ein AV aufgespielt. Trotzem vielen Dank für die mühe. Gruss PvB |
16.09.2013, 19:49 | #12 |
/// the machine /// TB-Ausbilder | Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich ok.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7 , 64 bit: Restlose Deinstallation von SpyHunter4 nicht möglich |
administrator, anti-malware, appdatalow, autostart, booten, entfernen, firefox, gelöscht, google, iexplore.exe, internet, launch, malware, microsoft, neu, nicht möglich, preferences, pup.optional.elex.a, registrierungsdatenbank, registry, scan, spyhunter, spyhunter entfernen, system32, tarma, win32/adware.addlyrics.f, windows, windows xp |