romina31 | 20.08.2013 16:13 | Code:
# AdwCleaner v3.000 - Report created 20/08/2013 at 16:34:18
# Updated 20/08/2013 by Xplode
# Operating System : Windows 8 (64 bits)
# Username : romina - ROMINA
# Running from : C:\Users\romina\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\Users\romina\AppData\Local\Google\Chrome\User Data\Default\Extensions\abfmigjiaapipflmopkaaooigcjjdojh
File Deleted : C:\Windows\System32\roboot64.exe
File Deleted : C:\Users\romina\AppData\Roaming\Mozilla\Firefox\Profiles\8knzxwmr.default\searchplugins\Babylon.xml
File Deleted : C:\Users\romina\AppData\Roaming\Mozilla\Firefox\Profiles\8knzxwmr.default\searchplugins\holasearch.xml
File Deleted : C:\Users\romina\AppData\Roaming\Mozilla\Firefox\Profiles\8knzxwmr.default\user.js
File Deleted : C:\Windows\System32\Tasks\BrowserDefendert
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\Iminent
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v23.0 (de)
[ File : C:\Users\romina\AppData\Roaming\Mozilla\Firefox\Profiles\8knzxwmr.default\prefs.js ]
Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=6E486817293A4A5E&affID=121963&tsp=4980");
Line Deleted : user_pref("extensions.holasearch.admin", false);
Line Deleted : user_pref("extensions.holasearch.aflt", "babsst");
Line Deleted : user_pref("extensions.holasearch.appId", "{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}");
Line Deleted : user_pref("extensions.holasearch.autoRvrt", "false");
Line Deleted : user_pref("extensions.holasearch.dfltLng", "de");
Line Deleted : user_pref("extensions.holasearch.excTlbr", false);
Line Deleted : user_pref("extensions.holasearch.ffxUnstlRst", false);
Line Deleted : user_pref("extensions.holasearch.id", "6e4896eb0000000000006817293a4a5e");
Line Deleted : user_pref("extensions.holasearch.instlDay", "15937");
Line Deleted : user_pref("extensions.holasearch.instlRef", "sst");
Line Deleted : user_pref("extensions.holasearch.newTab", false);
Line Deleted : user_pref("extensions.holasearch.prdct", "holasearch");
Line Deleted : user_pref("extensions.holasearch.prtnrId", "holasearch");
Line Deleted : user_pref("extensions.holasearch.rvrt", "false");
Line Deleted : user_pref("extensions.holasearch.smplGrp", "none");
Line Deleted : user_pref("extensions.holasearch.tlbrId", "base");
Line Deleted : user_pref("extensions.holasearch.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.holasearch.vrsn", "1.8.16.16");
Line Deleted : user_pref("extensions.holasearch.vrsnTs", "1.8.16.1614:46:14");
Line Deleted : user_pref("extensions.holasearch.vrsni", "1.8.16.16");
-\\ Google Chrome v
[ File : C:\Users\romina\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [8040 octets] - [20/08/2013 16:30:48]
AdwCleaner[R1].txt - [8100 octets] - [20/08/2013 16:33:49]
AdwCleaner[S0].txt - [7823 octets] - [20/08/2013 16:34:18]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7883 octets] ########## wenn ich firefox jetzt öffne, kommt hola Search nicht mehr. Vielen Dank dafür schonmal :)
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-08-2013 03
Ran by romina (administrator) on 20-08-2013 17:09:51
Running from C:\Users\romina\Desktop
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\ATouch64.exe
() C:\Program Files (x86)\PHotkey\POSD.exe
() C:\Program Files (x86)\PHotkey\GPMTray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Microsoft Corporation) C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16613_none_6273bd8950d6cae2\TiWorker.exe
(Microsoft Corp.) C:\Windows\system32\defrag.exe
(Microsoft Corporation) C:\Windows\system32\aitagent.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\NGenTask.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\NGenTask.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\NGenTask.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-30] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-17] (Realtek Semiconductor)
HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [11733888 2012-12-03] (Motorola Solutions, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2930488 2012-09-21] (Synaptics Incorporated)
MountPoints2: {3aa30c49-e952-11e2-be88-806e6f6e6963} - "E:\SETUP.EXE"
HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe [24504 2012-10-04] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [110144 2013-03-05] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [492248 2012-12-26] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-11] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Service] - C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [263128 2013-03-05] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {96F8AAAB-17C8-4B0E-AFAB-E61BF17A488C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\romina\AppData\Roaming\Mozilla\Firefox\Profiles\8knzxwmr.default
FF SelectedSearchEngine: Hola Search
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Extension: No Name - C:\Users\romina\AppData\Roaming\Mozilla\Firefox\Profiles\8knzxwmr.default\Extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Docs) - C:\Users\romina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Kaspersky URL Advisor) - C:\Users\romina\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0
CHR Extension: (Safe Money) - C:\Users\romina\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.1.4190_0
CHR Extension: (Content Blocker) - C:\Users\romina\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0
CHR Extension: (Virtual Keyboard) - C:\Users\romina\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4292_0
CHR Extension: (Anti-Banner) - C:\Users\romina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx
==================== Services (Whitelisted) =================
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2013-08-02] (Kaspersky Lab ZAO)
R2 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [74712 2013-03-11] (CyberLink)
R2 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [316376 2013-03-11] (CyberLink)
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [160256 2013-01-19] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S2 mfevtp; C:\Windows\system32\mfevtps.exe [182312 2012-12-26] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-09-24] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2010-08-19] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [1153840 2012-09-24] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [131968 2012-10-30] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1342848 2012-12-03] (Motorola Solutions, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458584 2012-06-19] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [619616 2013-08-02] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [28504 2012-08-02] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29016 2013-08-02] (Kaspersky Lab)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29528 2012-10-04] (Kaspersky Lab)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-08-02] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-08-02] (Kaspersky Lab ZAO)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4309032 2012-10-10] (Intel Corporation)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-09-21] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [44344 2012-09-21] (Synaptics Incorporated)
S3 intaud_WaveExtensible; \SystemRoot\system32\drivers\intelaud.sys [x]
S3 iwdbus; \SystemRoot\System32\drivers\iwdbus.sys [x]
S3 mfeapfk; \SystemRoot\system32\drivers\mfeapfk.sys [x]
S0 mfehidk; system32\drivers\mfehidk.sys [x]
S3 TDEIO; \??\G:\BIOS\tdeio64.sys [x]
S3 usb3Hub; \SystemRoot\System32\drivers\usb3Hub.sys [x]
S3 XHCIPort; \SystemRoot\System32\drivers\XHCIPort.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-20 16:48 - 2013-08-20 16:48 - 00000000 ____D C:\output
2013-08-20 16:47 - 2013-08-20 16:47 - 00018432 ___SH C:\Users\romina\Downloads\Thumbs.db
2013-08-20 16:32 - 2013-08-20 16:32 - 00975858 _____ C:\Users\romina\Desktop\adwcleaner.exe
2013-08-20 16:30 - 2013-08-20 16:34 - 00000000 ____D C:\AdwCleaner
2013-08-20 16:21 - 2013-08-20 16:21 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\romina\Desktop\mbam-setup-1.75.0.1300(3).exe
2013-08-20 16:11 - 2013-08-20 16:11 - 00025548 _____ C:\Users\romina\Desktop\Addition.txt
2013-08-20 16:10 - 2013-08-20 16:10 - 01576196 _____ (Farbar) C:\Users\romina\Desktop\FRST64.exe
2013-08-20 16:10 - 2013-08-20 16:10 - 00000000 ____D C:\FRST
2013-08-20 16:08 - 2013-08-20 16:08 - 01070241 _____ (Farbar) C:\Users\romina\Desktop\FRST.exe
2013-08-20 15:43 - 2013-08-20 16:22 - 00001117 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-20 15:43 - 2013-08-20 16:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-20 15:42 - 2013-08-20 15:42 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\romina\Downloads\mbam-setup-1.75.0.1300(2).exe
2013-08-20 15:27 - 2013-08-20 15:27 - 00000085 _____ C:\Windows\wininit.ini
2013-08-20 15:26 - 2013-08-20 15:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\romina\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-08-20 15:22 - 2013-08-20 15:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\romina\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-20 15:07 - 2013-08-20 15:10 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-08-20 15:07 - 2013-08-20 15:07 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-08-20 15:06 - 2013-08-20 15:35 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-08-20 14:49 - 2013-08-20 14:49 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\romina\Downloads\spybotsd-2.1.21-SR2.exe
2013-08-20 14:46 - 2013-08-20 15:09 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-20 14:43 - 2013-05-24 01:02 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-20 14:43 - 2013-05-24 00:25 - 00694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-20 14:42 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-20 14:42 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-20 14:42 - 2013-07-26 07:13 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-08-20 14:42 - 2013-07-26 07:13 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2013-08-20 14:42 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-20 14:42 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-20 14:42 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-20 14:42 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-20 14:42 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-20 14:42 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-20 14:42 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-20 14:42 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-20 14:42 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-20 14:42 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-20 14:42 - 2013-07-26 05:13 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-08-20 14:42 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-20 14:42 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-20 14:42 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-20 14:42 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-20 14:42 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-20 14:42 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-20 14:42 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-20 14:42 - 2013-07-26 02:54 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2013-08-20 14:42 - 2013-07-09 08:07 - 02233168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-20 14:41 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-20 14:41 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-20 14:41 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-20 14:41 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-20 14:41 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-20 14:41 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-20 14:41 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-20 14:41 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-20 14:41 - 2013-07-13 08:18 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-20 14:41 - 2013-07-13 08:16 - 01889280 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-20 14:41 - 2013-07-13 08:16 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-20 14:41 - 2013-07-13 08:15 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll
2013-08-20 14:41 - 2013-07-13 08:15 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll
2013-08-20 14:41 - 2013-07-13 06:24 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-20 14:41 - 2013-07-13 06:23 - 01568256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-20 14:41 - 2013-07-13 06:23 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll
2013-08-20 14:41 - 2013-07-13 06:23 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll
2013-08-07 12:24 - 2013-08-07 12:24 - 00000000 ____D C:\ProgramData\Adobe
2013-08-07 12:23 - 2013-08-07 12:23 - 00000000 ____D C:\Users\romina\AppData\Local\Adobe
2013-08-07 12:23 - 2013-08-07 12:23 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-08-07 12:23 - 2013-08-07 12:23 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-08-07 12:23 - 2013-08-07 12:23 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-08-05 15:28 - 2013-08-05 15:28 - 00346640 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-05 15:23 - 2013-08-05 15:23 - 00000000 ____D C:\Intel
2013-08-05 15:20 - 2013-08-05 15:20 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-08-05 15:13 - 2013-08-20 16:56 - 00000000 ____D C:\Windows\system32\MRT
2013-08-05 13:20 - 2013-08-05 13:20 - 00000000 ____D C:\Users\romina\Downloads\DebugView
2013-08-05 13:04 - 2013-08-05 13:04 - 00293495 _____ C:\Users\romina\Downloads\DebugView.zip
2013-08-05 12:58 - 2013-08-05 12:58 - 00000000 ____D C:\Users\romina\AppData\Local\Secunia PSI
2013-08-05 12:58 - 2013-08-05 12:58 - 00000000 ____D C:\Users\romina\AppData\Local\Macromedia
2013-08-05 12:57 - 2013-08-20 17:04 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-05 12:57 - 2013-08-05 12:57 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-05 12:57 - 2013-08-05 12:57 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-08-05 12:56 - 2013-08-05 12:56 - 03272136 _____ (Secunia) C:\Users\romina\Downloads\PSISetup711.exe
2013-08-05 12:56 - 2013-08-05 12:56 - 03272136 _____ (Secunia) C:\Users\romina\Desktop\PSISetup711.exe
2013-08-05 12:56 - 2013-08-05 12:54 - 17991520 _____ (Adobe Systems Inc.) C:\Users\romina\Desktop\AdobeAIRInstaller.exe
2013-08-05 12:53 - 2013-08-05 12:54 - 17991520 _____ (Adobe Systems Inc.) C:\Users\romina\Downloads\AdobeAIRInstaller.exe
2013-08-05 08:58 - 2013-08-08 20:41 - 00001155 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-08-05 08:58 - 2013-08-05 08:58 - 00000000 ____D C:\Users\romina\AppData\Roaming\Mozilla
2013-08-05 08:58 - 2013-08-05 08:58 - 00000000 ____D C:\Users\romina\AppData\Local\Mozilla
2013-08-05 08:58 - 2013-08-05 08:58 - 00000000 ____D C:\ProgramData\Mozilla
2013-08-05 08:57 - 2013-08-20 15:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-05 08:56 - 2013-08-05 08:56 - 00280368 _____ (Mozilla) C:\Users\romina\Downloads\Firefox Setup Stub 22.0.exe
2013-08-05 02:28 - 2013-08-05 02:29 - 00005647 _____ C:\WirelessDiagLog.csv
2013-08-05 02:24 - 2013-08-05 02:25 - 00003548 _____ C:\Windows\System32\Tasks\CreateChoiceProcessTask
2013-08-05 02:17 - 2013-08-05 02:24 - 00000000 ___RD C:\Windows\BrowserChoice
2013-08-04 17:42 - 2013-04-12 00:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-08-04 17:42 - 2013-04-12 00:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-08-04 17:41 - 2013-06-01 11:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-08-04 17:41 - 2013-06-01 11:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-08-04 17:41 - 2013-05-31 01:14 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-08-04 17:41 - 2013-04-24 01:13 - 01013248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-08-04 17:41 - 2013-04-24 01:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-04 17:41 - 2013-04-24 00:56 - 01255936 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-08-04 17:41 - 2013-04-24 00:55 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-04 17:37 - 2013-05-04 08:59 - 13644288 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2013-08-04 17:37 - 2013-05-04 06:57 - 10788864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-08-04 17:36 - 2013-05-31 01:24 - 01257472 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-08-04 17:36 - 2013-05-31 01:08 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-08-04 17:36 - 2013-05-15 04:25 - 00888320 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2013-08-04 17:36 - 2013-05-15 04:25 - 00542208 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2013-08-04 17:36 - 2013-05-15 04:24 - 00793088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2013-08-04 17:36 - 2013-05-15 04:24 - 00482816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2013-08-04 17:36 - 2013-05-04 09:58 - 00120736 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe
2013-08-04 17:36 - 2013-05-04 09:34 - 00446720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2013-08-04 17:36 - 2013-05-04 09:34 - 00284416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2013-08-04 17:36 - 2013-05-04 09:30 - 00058312 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2013-08-04 17:36 - 2013-05-04 08:59 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2013-08-04 17:36 - 2013-05-04 08:59 - 01619968 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2013-08-04 17:36 - 2013-05-04 08:59 - 01483776 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2013-08-04 17:36 - 2013-05-04 08:59 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe
2013-08-04 17:36 - 2013-05-04 08:59 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2013-08-04 17:36 - 2013-05-04 08:59 - 00251904 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2013-08-04 17:36 - 2013-05-04 08:59 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2013-08-04 17:36 - 2013-05-04 08:59 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2013-08-04 17:36 - 2013-05-04 08:59 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2013-08-04 17:36 - 2013-05-04 08:58 - 10116096 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2013-08-04 17:36 - 2013-05-04 08:58 - 01332736 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2013-08-04 17:36 - 2013-05-04 08:58 - 00470528 _____ (Microsoft Corporation) C:\Windows\system32\netprofmsvc.dll
2013-08-04 17:36 - 2013-05-04 08:58 - 00330240 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2013-08-04 17:36 - 2013-05-04 08:58 - 00328192 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2013-08-04 17:36 - 2013-05-04 08:58 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2013-08-04 17:36 - 2013-05-04 08:58 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll
2013-08-04 17:36 - 2013-05-04 08:58 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\netprofm.dll
2013-08-04 17:36 - 2013-05-04 08:58 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2013-08-04 17:36 - 2013-05-04 08:57 - 02305024 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-08-04 17:36 - 2013-05-04 08:57 - 01131520 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2013-08-04 17:36 - 2013-05-04 08:57 - 00708096 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2013-08-04 17:36 - 2013-05-04 08:57 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2013-08-04 17:36 - 2013-05-04 08:57 - 00501760 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll
2013-08-04 17:36 - 2013-05-04 08:57 - 00389120 _____ (Microsoft Corporation) C:\Windows\system32\BCP47Langs.dll
2013-08-04 17:36 - 2013-05-04 08:57 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2013-08-04 17:36 - 2013-05-04 08:57 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\biwinrt.dll
2013-08-04 17:36 - 2013-05-04 08:57 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\muifontsetup.dll
2013-08-04 17:36 - 2013-05-04 08:56 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl
2013-08-04 17:36 - 2013-05-04 06:58 - 00758784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Magnify.exe
2013-08-04 17:36 - 2013-05-04 06:58 - 00621056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-08-04 17:36 - 2013-05-04 06:58 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-08-04 17:36 - 2013-05-04 06:58 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-08-04 17:36 - 2013-05-04 06:58 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-08-04 17:36 - 2013-05-04 06:57 - 08857088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-08-04 17:36 - 2013-05-04 06:57 - 00303616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll
2013-08-04 17:36 - 2013-05-04 06:57 - 00247296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2013-08-04 17:36 - 2013-05-04 06:57 - 00151040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netplwiz.dll
2013-08-04 17:36 - 2013-05-04 06:57 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netprofm.dll
2013-08-04 17:36 - 2013-05-04 06:57 - 00018432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\npmproxy.dll
2013-08-04 17:36 - 2013-05-04 06:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\muifontsetup.dll
2013-08-04 17:36 - 2013-05-04 06:56 - 02035712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-08-04 17:36 - 2013-05-04 06:56 - 00449536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairing.dll
2013-08-04 17:36 - 2013-05-04 06:56 - 00411136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2013-08-04 17:36 - 2013-05-04 06:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BCP47Langs.dll
2013-08-04 17:36 - 2013-05-04 06:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\biwinrt.dll
2013-08-04 17:36 - 2013-05-04 06:55 - 00389632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-08-04 17:36 - 2013-05-04 06:51 - 00014848 _____ (Microsoft) C:\Windows\system32\rars.rs
2013-08-04 17:36 - 2013-05-04 06:47 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2013-08-04 17:36 - 2013-05-04 06:10 - 00014848 _____ (Microsoft) C:\Windows\SysWOW64\rars.rs
2013-08-04 17:35 - 2013-05-24 01:01 - 01300992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-08-04 17:35 - 2013-05-24 00:27 - 01022464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-08-04 17:29 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2013-08-04 17:29 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2013-08-04 17:29 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2013-08-04 17:29 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2013-08-04 17:29 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS
2013-08-04 17:29 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-04 17:29 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2013-08-04 17:29 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2013-08-04 17:29 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-08-04 17:29 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2013-08-04 17:29 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2013-08-04 17:29 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2013-08-04 17:29 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2013-08-04 17:29 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2013-08-04 17:29 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2013-08-04 17:29 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-08-04 17:29 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-08-04 17:29 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2013-08-04 17:29 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe
2013-08-04 17:29 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2013-08-04 17:29 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2013-08-04 17:29 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2013-08-04 17:29 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2013-08-04 17:29 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2013-08-04 17:29 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2013-08-04 17:29 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2013-08-04 17:29 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll
2013-08-04 17:29 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys
2013-08-04 17:29 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2013-08-04 17:29 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2013-08-04 17:29 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2013-08-04 17:29 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2013-08-04 17:29 - 2013-05-20 02:08 - 00386642 _____ C:\Windows\system32\ApnDatabase.xml
2013-08-04 17:28 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2013-08-04 16:57 - 2013-08-04 16:57 - 00000000 ____D C:\ProgramData\SUPERSetup
2013-08-04 16:38 - 2013-08-04 16:38 - 00000000 ____D C:\Users\romina\AppData\Roaming\Malwarebytes
2013-08-04 16:38 - 2013-08-04 16:38 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-04 16:38 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-04 16:05 - 2013-04-27 07:20 - 00733184 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-08-04 15:54 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-04 15:54 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-04 15:45 - 2013-08-04 15:45 - 00000000 ____D C:\Windows\ERUNT
2013-08-04 14:37 - 2013-08-04 14:37 - 00000000 _____ C:\autoexec.bat
2013-08-04 14:36 - 2013-08-04 14:36 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-04 12:54 - 2013-08-04 16:46 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-04 12:54 - 2013-08-04 12:59 - 00000000 ____D C:\Users\romina\AppData\Local\Google
2013-08-04 12:54 - 2013-08-04 12:54 - 00000000 ____D C:\Users\romina\AppData\Roaming\SUPERAntiSpyware.com
2013-08-04 12:20 - 2013-08-04 23:11 - 00003838 _____ C:\Windows\SysWOW64\bufferpool.txt
2013-08-04 12:11 - 2013-08-04 12:11 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-08-04 12:11 - 2013-08-04 12:11 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-08-04 11:40 - 2013-06-06 22:41 - 00489392 _____ (Ask Partner Network) C:\Users\romina\Documents\APNSetup.exe
2013-08-04 11:29 - 2013-08-04 11:29 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.6480.dll
2013-08-04 11:24 - 2013-08-08 20:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-04 11:23 - 2013-08-04 11:23 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-08-04 11:23 - 2013-08-04 11:23 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-08-04 11:17 - 2012-12-26 09:50 - 00771096 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfehidk.sys.4671.deleteme
2013-08-04 11:17 - 2012-12-26 09:48 - 00178840 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfeapfk.sys.2fac.deleteme
2013-08-04 11:11 - 2012-12-26 09:52 - 00182312 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe.ddf6.deleteme
2013-08-04 11:11 - 2012-12-26 09:52 - 00182312 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe
2013-08-04 11:07 - 2013-08-04 11:11 - 00000000 ____D C:\ProgramData\McAfee
2013-08-04 11:07 - 2013-08-04 11:07 - 00000000 ____D C:\Program Files\Common Files\McAfee
2013-08-04 11:07 - 2012-11-09 06:37 - 00177680 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe.426c.deleteme
2013-08-02 15:01 - 2013-08-02 15:01 - 00001348 _____ C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2013.lnk
2013-08-02 13:07 - 2013-08-07 13:14 - 00000000 ____D C:\Users\romina\AppData\Roaming\Apple Computer
2013-08-02 13:07 - 2013-08-02 13:07 - 00001787 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-08-02 13:07 - 2013-08-02 13:07 - 00000000 ____D C:\Users\romina\AppData\Local\Apple Computer
2013-08-02 13:07 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2013-08-02 13:06 - 2013-08-02 13:07 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-08-02 13:06 - 2013-08-02 13:07 - 00000000 ____D C:\Program Files\iTunes
2013-08-02 13:06 - 2013-08-02 13:07 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\Users\romina\AppData\Local\Apple
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\ProgramData\Apple Computer
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\Program Files\iPod
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-08-02 13:05 - 2013-08-02 13:06 - 00000000 ____D C:\ProgramData\Apple
2013-08-02 13:05 - 2013-08-02 13:05 - 00000000 ____D C:\Program Files\Bonjour
2013-08-02 13:05 - 2013-08-02 13:05 - 00000000 ____D C:\Program Files (x86)\Bonjour
2013-08-02 12:59 - 2013-08-02 13:01 - 90917712 _____ (Apple Inc.) C:\Users\romina\Desktop\iTunes64Setup.exe
2013-08-02 12:57 - 2013-08-20 16:48 - 00000000 ____D C:\Users\romina\AppData\Roaming\PhotoScape
2013-08-02 12:57 - 2013-08-02 12:57 - 00001039 _____ C:\Users\romina\Desktop\PhotoScape.lnk
2013-08-02 12:56 - 2013-08-02 12:57 - 00000000 ____D C:\Program Files (x86)\PhotoScape
2013-08-02 12:41 - 2013-08-05 13:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Works
2013-08-02 12:38 - 2013-08-02 12:38 - 00000000 ____D C:\Program Files\Microsoft Office
2013-08-02 12:37 - 2013-08-20 14:58 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-02 12:37 - 2013-08-02 12:37 - 00000000 ____D C:\Users\romina\AppData\Local\Microsoft Help
2013-08-02 12:36 - 2013-08-02 12:36 - 00000000 __RHD C:\MSOCache
2013-08-02 12:30 - 2013-04-03 01:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-08-02 12:30 - 2013-04-03 01:12 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-08-02 12:25 - 2013-05-16 00:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2013-08-02 12:14 - 2013-08-02 12:14 - 00000000 ____D C:\Users\romina\AppData\Roaming\Macromedia
2013-08-02 12:13 - 2013-08-20 15:47 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3923335138-1269518189-1293654365-1001
2013-08-02 12:08 - 2013-08-20 16:36 - 00000000 ____D C:\Users\romina\Documents\Youcam
2013-08-02 12:08 - 2013-08-05 12:52 - 00000000 ____D C:\Users\romina\AppData\Local\CyberLink
2013-08-02 12:06 - 2013-08-02 12:06 - 00002348 _____ C:\Users\romina\Desktop\Sicherer Zahlungsverkehr.lnk
2013-08-02 12:06 - 2013-08-02 12:06 - 00000000 ____D C:\Users\romina\AppData\Local\Power2Go8
2013-08-02 12:05 - 2013-08-07 12:23 - 00000000 ____D C:\Users\romina\AppData\Roaming\Adobe
2013-08-02 12:05 - 2013-08-04 11:50 - 00000000 ___RD C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-02 12:05 - 2013-08-02 12:05 - 00001446 _____ C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-08-02 12:05 - 2013-08-02 12:05 - 00000000 ___RD C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-08-02 12:05 - 2013-08-02 12:05 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-08-02 12:05 - 2012-08-11 06:25 - 00001193 _____ C:\Users\romina\Desktop\ALDI Foto.lnk
2013-08-02 12:05 - 2012-08-11 06:25 - 00001193 _____ C:\Users\Default\Desktop\ALDI Foto.lnk
2013-08-02 12:05 - 2012-08-11 06:25 - 00001193 _____ C:\Users\Default User\Desktop\ALDI Foto.lnk
2013-08-02 12:05 - 2012-08-11 06:20 - 00001251 _____ C:\Users\romina\Desktop\Medion Services.lnk
2013-08-02 12:05 - 2012-08-11 06:20 - 00001251 _____ C:\Users\Default\Desktop\Medion Services.lnk
2013-08-02 12:05 - 2012-08-11 06:20 - 00001251 _____ C:\Users\Default User\Desktop\Medion Services.lnk
2013-08-02 12:05 - 2012-08-05 14:08 - 00001809 _____ C:\Users\romina\Desktop\ALDI Talk.lnk
2013-08-02 12:05 - 2012-08-05 14:08 - 00001809 _____ C:\Users\Default\Desktop\ALDI Talk.lnk
2013-08-02 12:05 - 2012-08-05 14:08 - 00001809 _____ C:\Users\Default User\Desktop\ALDI Talk.lnk
2013-08-02 12:05 - 2012-08-05 14:08 - 00001093 _____ C:\Users\romina\Desktop\ALDI Nord Reisen.lnk
2013-08-02 12:05 - 2012-08-05 14:08 - 00001093 _____ C:\Users\Default\Desktop\ALDI Nord Reisen.lnk
2013-08-02 12:05 - 2012-08-05 14:08 - 00001093 _____ C:\Users\Default User\Desktop\ALDI Nord Reisen.lnk
2013-08-02 12:05 - 2012-08-05 14:08 - 00001037 _____ C:\Users\romina\Desktop\ALDI Nord Startseite.lnk
2013-08-02 12:05 - 2012-08-05 14:08 - 00001037 _____ C:\Users\Default\Desktop\ALDI Nord Startseite.lnk
2013-08-02 12:05 - 2012-08-05 14:08 - 00001037 _____ C:\Users\Default User\Desktop\ALDI Nord Startseite.lnk
2013-08-02 12:05 - 2012-08-05 13:39 - 00001893 _____ C:\Users\romina\Desktop\ALDI Nord Blumen Service.lnk
2013-08-02 12:05 - 2012-08-05 13:39 - 00001893 _____ C:\Users\Default\Desktop\ALDI Nord Blumen Service.lnk
2013-08-02 12:05 - 2012-08-05 13:39 - 00001893 _____ C:\Users\Default User\Desktop\ALDI Nord Blumen Service.lnk
2013-08-02 12:04 - 2013-08-05 02:24 - 00000000 ____D C:\Users\romina\AppData\Local\Packages
2013-08-02 12:04 - 2013-08-02 12:04 - 00000000 ____D C:\Users\romina\AppData\Roaming\Intel
2013-08-02 12:04 - 2013-08-02 12:04 - 00000000 ____D C:\Users\romina\AppData\Local\VirtualStore
2013-08-02 12:03 - 2013-08-20 16:57 - 02059062 _____ C:\Windows\WindowsUpdate.log
2013-08-02 12:03 - 2013-08-04 12:03 - 00000000 ____D C:\Windows\softwaredistribution.bak
2013-08-02 12:03 - 2013-08-02 12:05 - 00000000 ____D C:\Users\romina
2013-08-02 12:03 - 2013-08-02 12:03 - 00000020 ___SH C:\Users\romina\ntuser.ini
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Vorlagen
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Startmenü
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Netzwerkumgebung
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Lokale Einstellungen
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Eigene Dateien
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Druckumgebung
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Documents\Eigene Musik
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Documents\Eigene Bilder
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\AppData\Local\Verlauf
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\AppData\Local\Anwendungsdaten
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Anwendungsdaten
2013-08-02 12:03 - 2013-06-04 18:02 - 00000000 ___RD C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-08-02 12:03 - 2012-07-26 10:13 - 00000000 ___RD C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-08-02 12:03 - 2012-07-26 10:13 - 00000000 ___RD C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-08-02 12:03 - 2012-07-26 10:13 - 00000000 ____D C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
==================== One Month Modified Files and Folders =======
2013-08-20 17:05 - 2013-08-05 15:13 - 00000000 ____D C:\Windows\system32\MRT
2013-08-20 17:04 - 2013-08-05 12:57 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-20 17:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru
2013-08-20 16:57 - 2013-08-02 12:03 - 02059062 _____ C:\Windows\WindowsUpdate.log
2013-08-20 16:56 - 2013-06-04 14:30 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-20 16:53 - 2013-06-06 12:47 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-08-20 16:48 - 2013-08-20 16:48 - 00000000 ____D C:\output
2013-08-20 16:48 - 2013-08-02 12:57 - 00000000 ____D C:\Users\romina\AppData\Roaming\PhotoScape
2013-08-20 16:47 - 2013-08-20 16:47 - 00018432 ___SH C:\Users\romina\Downloads\Thumbs.db
2013-08-20 16:36 - 2013-08-02 12:08 - 00000000 ____D C:\Users\romina\Documents\Youcam
2013-08-20 16:35 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-20 16:34 - 2013-08-20 16:30 - 00000000 ____D C:\AdwCleaner
2013-08-20 16:34 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2013-08-20 16:32 - 2013-08-20 16:32 - 00975858 _____ C:\Users\romina\Desktop\adwcleaner.exe
2013-08-20 16:22 - 2013-08-20 15:43 - 00001117 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-20 16:22 - 2013-08-20 15:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-20 16:21 - 2013-08-20 16:21 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\romina\Desktop\mbam-setup-1.75.0.1300(3).exe
2013-08-20 16:11 - 2013-08-20 16:11 - 00025548 _____ C:\Users\romina\Desktop\Addition.txt
2013-08-20 16:10 - 2013-08-20 16:10 - 01576196 _____ (Farbar) C:\Users\romina\Desktop\FRST64.exe
2013-08-20 16:10 - 2013-08-20 16:10 - 00000000 ____D C:\FRST
2013-08-20 16:08 - 2013-08-20 16:08 - 01070241 _____ (Farbar) C:\Users\romina\Desktop\FRST.exe
2013-08-20 15:58 - 2013-06-04 14:10 - 00450634 _____ C:\Windows\PFRO.log
2013-08-20 15:47 - 2013-08-02 12:13 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3923335138-1269518189-1293654365-1001
2013-08-20 15:42 - 2013-08-20 15:42 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\romina\Downloads\mbam-setup-1.75.0.1300(2).exe
2013-08-20 15:35 - 2013-08-20 15:06 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-08-20 15:35 - 2013-08-05 08:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-20 15:33 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\SysWOW64\en-GB
2013-08-20 15:33 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\en-GB
2013-08-20 15:27 - 2013-08-20 15:27 - 00000085 _____ C:\Windows\wininit.ini
2013-08-20 15:27 - 2013-08-20 15:26 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\romina\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-08-20 15:24 - 2013-08-20 15:22 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\romina\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-20 15:10 - 2013-08-20 15:07 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-08-20 15:09 - 2013-08-20 14:46 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-20 15:07 - 2013-08-20 15:07 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-08-20 14:58 - 2013-08-02 12:37 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-20 14:49 - 2013-08-20 14:49 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\romina\Downloads\spybotsd-2.1.21-SR2.exe
2013-08-20 14:35 - 2013-06-10 06:48 - 00786588 _____ C:\Windows\system32\perfh013.dat
2013-08-20 14:35 - 2013-06-10 06:48 - 00159122 _____ C:\Windows\system32\perfc013.dat
2013-08-20 14:35 - 2013-06-10 06:30 - 00788984 _____ C:\Windows\system32\perfh00A.dat
2013-08-20 14:35 - 2013-06-10 06:30 - 00162890 _____ C:\Windows\system32\perfc00A.dat
2013-08-20 14:35 - 2013-06-10 06:24 - 00456714 _____ C:\Windows\system32\perfh006.dat
2013-08-20 14:35 - 2013-06-10 06:24 - 00079958 _____ C:\Windows\system32\perfc006.dat
2013-08-20 14:35 - 2013-06-04 18:50 - 00791060 _____ C:\Windows\system32\perfh00C.dat
2013-08-20 14:35 - 2013-06-04 18:50 - 00155620 _____ C:\Windows\system32\perfc00C.dat
2013-08-20 14:35 - 2013-06-04 18:41 - 00754172 _____ C:\Windows\system32\perfh007.dat
2013-08-20 14:35 - 2013-06-04 18:41 - 00156362 _____ C:\Windows\system32\perfc007.dat
2013-08-20 14:35 - 2012-07-26 09:28 - 05126538 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-20 14:33 - 2012-07-26 09:21 - 00029524 _____ C:\Windows\setupact.log
2013-08-08 20:41 - 2013-08-05 08:58 - 00001155 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-08-08 20:41 - 2013-08-04 11:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-07 13:14 - 2013-08-02 13:07 - 00000000 ____D C:\Users\romina\AppData\Roaming\Apple Computer
2013-08-07 12:34 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-08-07 12:24 - 2013-08-07 12:24 - 00000000 ____D C:\ProgramData\Adobe
2013-08-07 12:23 - 2013-08-07 12:23 - 00000000 ____D C:\Users\romina\AppData\Local\Adobe
2013-08-07 12:23 - 2013-08-07 12:23 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-08-07 12:23 - 2013-08-07 12:23 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-08-07 12:23 - 2013-08-07 12:23 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-08-07 12:23 - 2013-08-02 12:05 - 00000000 ____D C:\Users\romina\AppData\Roaming\Adobe
2013-08-05 15:32 - 2013-06-10 07:11 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-08-05 15:28 - 2013-08-05 15:28 - 00346640 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-05 15:23 - 2013-08-05 15:23 - 00000000 ____D C:\Intel
2013-08-05 15:20 - 2013-08-05 15:20 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-08-05 13:20 - 2013-08-05 13:20 - 00000000 ____D C:\Users\romina\Downloads\DebugView
2013-08-05 13:17 - 2013-08-02 12:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Works
2013-08-05 13:04 - 2013-08-05 13:04 - 00293495 _____ C:\Users\romina\Downloads\DebugView.zip
2013-08-05 12:58 - 2013-08-05 12:58 - 00000000 ____D C:\Users\romina\AppData\Local\Secunia PSI
2013-08-05 12:58 - 2013-08-05 12:58 - 00000000 ____D C:\Users\romina\AppData\Local\Macromedia
2013-08-05 12:57 - 2013-08-05 12:57 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-05 12:57 - 2013-08-05 12:57 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-08-05 12:56 - 2013-08-05 12:56 - 03272136 _____ (Secunia) C:\Users\romina\Downloads\PSISetup711.exe
2013-08-05 12:56 - 2013-08-05 12:56 - 03272136 _____ (Secunia) C:\Users\romina\Desktop\PSISetup711.exe
2013-08-05 12:54 - 2013-08-05 12:56 - 17991520 _____ (Adobe Systems Inc.) C:\Users\romina\Desktop\AdobeAIRInstaller.exe
2013-08-05 12:54 - 2013-08-05 12:53 - 17991520 _____ (Adobe Systems Inc.) C:\Users\romina\Downloads\AdobeAIRInstaller.exe
2013-08-05 12:53 - 2013-06-06 13:10 - 00000000 ____D C:\ProgramData\CyberLink
2013-08-05 12:52 - 2013-08-02 12:08 - 00000000 ____D C:\Users\romina\AppData\Local\CyberLink
2013-08-05 12:21 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF
2013-08-05 08:58 - 2013-08-05 08:58 - 00000000 ____D C:\Users\romina\AppData\Roaming\Mozilla
2013-08-05 08:58 - 2013-08-05 08:58 - 00000000 ____D C:\Users\romina\AppData\Local\Mozilla
2013-08-05 08:58 - 2013-08-05 08:58 - 00000000 ____D C:\ProgramData\Mozilla
2013-08-05 08:56 - 2013-08-05 08:56 - 00280368 _____ (Mozilla) C:\Users\romina\Downloads\Firefox Setup Stub 22.0.exe
2013-08-05 02:29 - 2013-08-05 02:28 - 00005647 _____ C:\WirelessDiagLog.csv
2013-08-05 02:25 - 2013-08-05 02:24 - 00003548 _____ C:\Windows\System32\Tasks\CreateChoiceProcessTask
2013-08-05 02:24 - 2013-08-05 02:17 - 00000000 ___RD C:\Windows\BrowserChoice
2013-08-05 02:24 - 2013-08-02 12:04 - 00000000 ____D C:\Users\romina\AppData\Local\Packages
2013-08-05 02:24 - 2013-06-04 14:17 - 00000000 ____D C:\ProgramData\PRICache
2013-08-05 02:18 - 2012-07-26 11:45 - 00000000 ____D C:\Program Files\Windows Journal
2013-08-05 02:13 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe
2013-08-05 02:10 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData
2013-08-05 02:10 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore
2013-08-05 02:10 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-08-05 02:10 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-08-05 02:10 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\SysWOW64\Dism
2013-08-05 02:10 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\Dism
2013-08-04 23:11 - 2013-08-04 12:20 - 00003838 _____ C:\Windows\SysWOW64\bufferpool.txt
2013-08-04 16:57 - 2013-08-04 16:57 - 00000000 ____D C:\ProgramData\SUPERSetup
2013-08-04 16:46 - 2013-08-04 12:54 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-04 16:38 - 2013-08-04 16:38 - 00000000 ____D C:\Users\romina\AppData\Roaming\Malwarebytes
2013-08-04 16:38 - 2013-08-04 16:38 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-04 15:45 - 2013-08-04 15:45 - 00000000 ____D C:\Windows\ERUNT
2013-08-04 14:37 - 2013-08-04 14:37 - 00000000 _____ C:\autoexec.bat
2013-08-04 14:36 - 2013-08-04 14:36 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-08-04 12:59 - 2013-08-04 12:54 - 00000000 ____D C:\Users\romina\AppData\Local\Google
2013-08-04 12:54 - 2013-08-04 12:54 - 00000000 ____D C:\Users\romina\AppData\Roaming\SUPERAntiSpyware.com
2013-08-04 12:41 - 2013-06-04 15:10 - 00000000 ____D C:\Windows\Panther
2013-08-04 12:24 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing
2013-08-04 12:11 - 2013-08-04 12:11 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-08-04 12:11 - 2013-08-04 12:11 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-08-04 12:04 - 2013-06-04 14:31 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-08-04 12:04 - 2013-06-04 14:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-08-04 12:03 - 2013-08-02 12:03 - 00000000 ____D C:\Windows\softwaredistribution.bak
2013-08-04 11:50 - 2013-08-02 12:05 - 00000000 ___RD C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-04 11:29 - 2013-08-04 11:29 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.6480.dll
2013-08-04 11:23 - 2013-08-04 11:23 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-08-04 11:23 - 2013-08-04 11:23 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-08-04 11:11 - 2013-08-04 11:07 - 00000000 ____D C:\ProgramData\McAfee
2013-08-04 11:07 - 2013-08-04 11:07 - 00000000 ____D C:\Program Files\Common Files\McAfee
2013-08-02 15:01 - 2013-08-02 15:01 - 00001348 _____ C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2013.lnk
2013-08-02 13:07 - 2013-08-02 13:07 - 00001787 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-08-02 13:07 - 2013-08-02 13:07 - 00000000 ____D C:\Users\romina\AppData\Local\Apple Computer
2013-08-02 13:07 - 2013-08-02 13:06 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-08-02 13:07 - 2013-08-02 13:06 - 00000000 ____D C:\Program Files\iTunes
2013-08-02 13:07 - 2013-08-02 13:06 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\Users\romina\AppData\Local\Apple
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\ProgramData\Apple Computer
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\Program Files\iPod
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-08-02 13:06 - 2013-08-02 13:06 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-08-02 13:06 - 2013-08-02 13:05 - 00000000 ____D C:\ProgramData\Apple
2013-08-02 13:05 - 2013-08-02 13:05 - 00000000 ____D C:\Program Files\Bonjour
2013-08-02 13:05 - 2013-08-02 13:05 - 00000000 ____D C:\Program Files (x86)\Bonjour
2013-08-02 13:01 - 2013-08-02 12:59 - 90917712 _____ (Apple Inc.) C:\Users\romina\Desktop\iTunes64Setup.exe
2013-08-02 12:57 - 2013-08-02 12:57 - 00001039 _____ C:\Users\romina\Desktop\PhotoScape.lnk
2013-08-02 12:57 - 2013-08-02 12:56 - 00000000 ____D C:\Program Files (x86)\PhotoScape
2013-08-02 12:40 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-08-02 12:38 - 2013-08-02 12:38 - 00000000 ____D C:\Program Files\Microsoft Office
2013-08-02 12:37 - 2013-08-02 12:37 - 00000000 ____D C:\Users\romina\AppData\Local\Microsoft Help
2013-08-02 12:37 - 2012-07-26 11:45 - 00000000 ____D C:\Windows\ShellNew
2013-08-02 12:36 - 2013-08-02 12:36 - 00000000 __RHD C:\MSOCache
2013-08-02 12:35 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\restore
2013-08-02 12:31 - 2013-06-06 12:47 - 00619616 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2013-08-02 12:31 - 2013-06-06 12:47 - 00090208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2013-08-02 12:31 - 2012-10-04 17:25 - 00029016 _____ (Kaspersky Lab) C:\Windows\system32\Drivers\klkbdflt.sys
2013-08-02 12:31 - 2012-08-13 17:49 - 00178448 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2013-08-02 12:31 - 2012-08-03 16:55 - 00050448 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klwfp.sys
2013-08-02 12:14 - 2013-08-02 12:14 - 00000000 ____D C:\Users\romina\AppData\Roaming\Macromedia
2013-08-02 12:06 - 2013-08-02 12:06 - 00002348 _____ C:\Users\romina\Desktop\Sicherer Zahlungsverkehr.lnk
2013-08-02 12:06 - 2013-08-02 12:06 - 00000000 ____D C:\Users\romina\AppData\Local\Power2Go8
2013-08-02 12:05 - 2013-08-02 12:05 - 00001446 _____ C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-08-02 12:05 - 2013-08-02 12:05 - 00000000 ___RD C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-08-02 12:05 - 2013-08-02 12:05 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-08-02 12:05 - 2013-08-02 12:03 - 00000000 ____D C:\Users\romina
2013-08-02 12:05 - 2012-07-26 09:20 - 00000000 ____D C:\Windows\Setup
2013-08-02 12:04 - 2013-08-02 12:04 - 00000000 ____D C:\Users\romina\AppData\Roaming\Intel
2013-08-02 12:04 - 2013-08-02 12:04 - 00000000 ____D C:\Users\romina\AppData\Local\VirtualStore
2013-08-02 12:04 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2013-08-02 12:03 - 2013-08-02 12:03 - 00000020 ___SH C:\Users\romina\ntuser.ini
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Vorlagen
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Startmenü
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Netzwerkumgebung
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Lokale Einstellungen
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Eigene Dateien
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Druckumgebung
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Documents\Eigene Musik
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Documents\Eigene Bilder
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\AppData\Local\Verlauf
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\AppData\Local\Anwendungsdaten
2013-08-02 12:03 - 2013-08-02 12:03 - 00000000 _SHDL C:\Users\romina\Anwendungsdaten
2013-08-02 11:57 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\Recovery
2013-08-02 11:54 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache
2013-07-26 07:13 - 2013-08-20 14:42 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-26 07:13 - 2013-08-20 14:42 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-26 07:13 - 2013-08-20 14:42 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-07-26 07:13 - 2013-08-20 14:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2013-07-26 07:13 - 2013-08-20 14:42 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-26 07:12 - 2013-08-20 14:42 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-26 07:12 - 2013-08-20 14:42 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-26 07:12 - 2013-08-20 14:42 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-26 07:12 - 2013-08-20 14:42 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-26 07:12 - 2013-08-20 14:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-26 07:12 - 2013-08-20 14:42 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-26 07:12 - 2013-08-20 14:41 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-26 07:12 - 2013-08-20 14:41 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-26 07:12 - 2013-08-20 14:41 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-26 07:12 - 2013-08-20 14:41 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-26 05:35 - 2013-08-20 14:42 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-26 05:13 - 2013-08-20 14:42 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-26 05:13 - 2013-08-20 14:42 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-26 05:13 - 2013-08-20 14:42 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-07-26 05:12 - 2013-08-20 14:42 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-26 05:12 - 2013-08-20 14:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-26 05:12 - 2013-08-20 14:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-26 05:12 - 2013-08-20 14:42 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-26 05:12 - 2013-08-20 14:41 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-26 05:12 - 2013-08-20 14:41 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-26 05:12 - 2013-08-20 14:41 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-26 05:12 - 2013-08-20 14:41 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-26 05:11 - 2013-08-20 14:42 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-26 05:11 - 2013-08-20 14:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-26 04:49 - 2013-08-20 14:42 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-26 02:54 - 2013-08-20 14:42 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-20 17:00
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
war es das was ich alles machen musste? |