frst.txt aus dem Anhang
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2014
Ran by ***** (administrator) on HORSTWALL-HP on 12-01-2014 15:48:15
Running from C:\Users\*****\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Safe Mode (with Networking)
==================== Processes (Whitelisted) =================
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [hpsysdrv] - c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] - c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
HKLM-x32\...\Run: [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-09-27] (EasyBits Software AS)
HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-08-12] (PDF Complete Inc)
HKLM-x32\...\Run: [SSBkgdUpdate] - C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] - C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe [29984 2008-07-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [IndexSearch] - C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe [46368 2008-07-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort11reminder] - C:\Program Files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe [328992 2007-08-31] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [BrMfcWnd] - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1648264 2013-04-30] (Ask)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2486296 2014-01-08] ()
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [761536 2013-12-26] ()
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKCU\...\Run: [RssReader] - C:\Users\*****\AppData\Roaming\Qlikworld\RSSReader\RSSReader.exe [3067904 2008-10-24] (QlikWorld BV)
HKCU\...\Run: [lollipop] - c:\users\*****\appdata\local\lollipop\lollipop.exe [3507200 2014-01-08] ()
HKCU\...\Run: [NextLive] - C:\Users\*****\AppData\Roaming\newnext.me\nengine.dll [1283584 2013-11-14] (NewNextDotMe)
HKCU\...\Run: [Optimizer Pro] - C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [134648 2013-10-28] ()
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKCU\...\Policies\system: [DisableChangePassword] 0
AppInit_DLLs: C:\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll [2603312 2014-01-08] ()
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll c:\progra~2\optimi~1\optpro~1.dll [2869720 2013-10-29] ()
Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3318154&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPB089E9FC-DD2D-47EF-BB48-7D1F4D56DA6E&SSPV=
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC&q={searchTerms}
URLSearchHook: HKLM-x32 - FileConverter 1.3 Toolbar - {78e516ef-11de-47a1-8364-a99b917ec5ee} - C:\Program Files (x86)\FileConverter_1.3\prxtbFile.dll (Conduit Ltd.)
URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
URLSearchHook: HKCU - FileConverter 1.3 Toolbar - {78e516ef-11de-47a1-8364-a99b917ec5ee} - C:\Program Files (x86)\FileConverter_1.3\prxtbFile.dll (Conduit Ltd.)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC&q={searchTerms}
SearchScopes: HKLM - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CPDTDF
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC&q={searchTerms}
SearchScopes: HKLM - {6CCC8849-9F79-4CBB-BD60-27F6D8FB7297} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF
SearchScopes: HKLM - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC&q={searchTerms}
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CPDTDF
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC&q={searchTerms}
SearchScopes: HKLM-x32 - {6CCC8849-9F79-4CBB-BD60-27F6D8FB7297} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF
SearchScopes: HKLM-x32 - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms}
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3318154&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPB089E9FC-DD2D-47EF-BB48-7D1F4D56DA6E&q={searchTerms}&SSPV=
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3318154&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPB089E9FC-DD2D-47EF-BB48-7D1F4D56DA6E&q={searchTerms}&SSPV=
SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CPDTDF
SearchScopes: HKCU - {2FA9F27F-A6D9-4B39-9D5D-D4EC1A79D44B} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=a634d4be-3dbe-4d5d-994e-07990bc90856&apn_sauid=7ED585B6-5C3C-4CAC-930C-6A20AE98726E
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC&q={searchTerms}
SearchScopes: HKCU - {6CCC8849-9F79-4CBB-BD60-27F6D8FB7297} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://mysearch.avg.com/search?cid={08F01C49-9DED-43DF-A65E-46B270F52671}&mid=bd1760d3a97547d29b8031820818fa8e-3fe217883cc5fff0878381876b074be8961d0c03&lang=de&ds=ub011&coid=avgtbdisub&cmpid=&pr=sa&d=2014-01-07 08:37:25&v=17.2.0.38&pid=safeguard&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF
SearchScopes: HKCU - {C37717FE-A85A-47D0-A6FE-AF531D7D9483} URL = hxxp://www.google.com/search?q={searchTerms}&rlz=
SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms}
SearchScopes: HKCU - {F68A1EDC-DF98-4D26-A9FE-2B5C233D4737} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3241949
BHO: Plus-HD-4.9 - {11111111-1111-1111-1111-110411591118} - C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-bho64.dll (Plus HD)
BHO: Feven 2.2 - {11111111-1111-1111-1111-110411901112} - C:\Program Files (x86)\Feven 2.2\Feven 2.2-bho64.dll (Feven)
BHO: Speed Test 127 - {11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} - C:\Program Files (x86)\Speed Test 127\ScriptHost64.dll (BestOffers)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost64.dll (BestOffers)
BHO-x32: Re-markit - {07fb9bf1-e9db-4f0b-a2d2-1269ee4af48b} - C:\Program Files (x86)\Re-markit\150.dll ()
BHO-x32: Plus-HD-4.9 - {11111111-1111-1111-1111-110411591118} - C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-bho.dll (Plus HD)
BHO-x32: Feven 2.2 - {11111111-1111-1111-1111-110411901112} - C:\Program Files (x86)\Feven 2.2\Feven 2.2-bho.dll (Feven)
BHO-x32: Speed Test 127 - {11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} - C:\Program Files (x86)\Speed Test 127\ScriptHost.dll (BestOffers)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: FileConverter 1.3 Toolbar - {78e516ef-11de-47a1-8364-a99b917ec5ee} - C:\Program Files (x86)\FileConverter_1.3\prxtbFile.dll (Conduit Ltd.)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.0.49\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost.dll (BestOffers)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - FileConverter 1.3 Toolbar - {78e516ef-11de-47a1-8364-a99b917ec5ee} - C:\Program Files (x86)\FileConverter_1.3\prxtbFile.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.3.0.49\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - No Name - {78E516EF-11DE-47A1-8364-A99B917EC5EE} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.3.0\ViProtocol.dll (AVG Secure Search)
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2012-03-07] (EasyBits Software Corp.)
Tcpip\Parameters: [DhcpNameServer] 83.169.184.161 83.169.184.225
FireFox:
========
FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ucmy31d4.default
FF user.js: detected! => C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ucmy31d4.default\user.js
FF DefaultSearchEngine: AVG Secure Search
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: AVG Secure Search
FF Homepage: hxxp://mysearch.avg.com?cid={08F01C49-9DED-43DF-A65E-46B270F52671}&mid=bd1760d3a97547d29b8031820818fa8e-3fe217883cc5fff0878381876b074be8961d0c03&lang=de&ds=ub011&coid=avgtbdisub&cmpid=&pr=sa&d=&v=17.2.0.38&pid=safeguard&sg=&sap=hp
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.3.0\\npsitesafety.dll (AVG Technologies)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\*****\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ucmy31d4.default\searchplugins\askcom.xml
FF Extension: Widget context - C:\Users\*****\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi [2014-01-12]
FF Extension: Feven 2.2 - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ucmy31d4.default\Extensions\15d84a30-fc9d-4fca-80a7-e5797da621a2@b2cb2d04-e262-4863-aee7-9d0e4333b550.com [2014-01-08]
FF Extension: Plus-HD-4.9 - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ucmy31d4.default\Extensions\d019febe-eb2b-4057-a3f2-7def88f2c9cd@1cced8ec-0ffe-43ea-b4b2-fbce5de8e9a4.com [2013-12-26]
FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ucmy31d4.default\Extensions\toolbar@ask.com [2013-03-07]
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49
FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49 [2014-01-08]
FF HKCU\...\Firefox\Extensions: [{6e795b09-eec7-4ea1-885c-37d2b496bf1b}] - C:\Program Files (x86)\Re-markit\150.xpi
FF Extension: Re-markit - C:\Program Files (x86)\Re-markit\150.xpi [2014-01-08]
Chrome:
=======
CHR HomePage: hxxp://search.conduit.com/?ctid=CT3318154&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPB089E9FC-DD2D-47EF-BB48-7D1F4D56DA6E&SSPV=
CHR RestoreOnStartup: "hxxp://search.conduit.com/?ctid=CT3318154&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPB089E9FC-DD2D-47EF-BB48-7D1F4D56DA6E&SSPV="
CHR DefaultSearchKeyword: conduit.search
CHR DefaultSearchProvider: Widget context
CHR DefaultSearchURL: hxxp://search.conduit.com/Results.aspx?ctid=CT3318154&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPB089E9FC-DD2D-47EF-BB48-7D1F4D56DA6E&q={searchTerms}&SSPV=
CHR Extension: (Avira Toolbar) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaabfjnbeinlpljodiajipidiompfl\7.15.18.0_0 [2013-06-07]
CHR Extension: (Feven 2.2) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdhbagplpkkoeifmpmpdaieomnggppmo\1.26.15_0 [2014-01-08]
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 [2013-09-01]
CHR Extension: (Extended Protection) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0 [2014-01-08]
CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 [2013-09-01]
CHR Extension: (Plus-HD-4.9) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjflmfkjppbmejlfbhlpgjnomdoefkfa\1.26.36_0 [2013-12-26]
CHR Extension: () - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0 [2014-01-08]
CHR Extension: () - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf\3.0.0.0 [2014-01-08]
CHR Extension: (AVG SafeGuard) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.2.0.38_0 [2014-01-07]
CHR Extension: (Chrome In-App Payments service) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 [2013-09-01]
CHR Extension: (Widget context) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombmmloebnfnpehgjnmkcgoegfachobp\3.0_0 [2014-01-12]
CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 [2012-11-28]
CHR HKLM-x32\...\Chrome\Extension: [aaaaabfjnbeinlpljodiajipidiompfl] - C:\Users\*****\AppData\Local\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.18.0.crx [2013-03-07]
CHR HKLM-x32\...\Chrome\Extension: [dcpfhaghaadpjpgocojgnlhjcieeooel] - C:\Program Files (x86)\Re-markit\150.crx [2014-01-08]
CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx [2014-01-08]
CHR HKLM-x32\...\Chrome\Extension: [jljheddigenhleadfofeccneimcmlefp] - C:\Users\*****\AppData\Roaming\speedtest4354\speedtest4354.crx [2013-12-19]
CHR HKLM-x32\...\Chrome\Extension: [lbgfiglojokgabdbhegbpjgojgppppgf] - C:\Users\*****\AppData\Roaming\freegames111\freegames111.crx [2013-12-19]
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\17.3.0.49\avg.crx [2014-01-08]
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1389166574&from=tugs&uid=ST3500413AS_Z2AN7LGC
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
S2 70e6ca8c; C:\Program Files (x86)\Optimizer Pro\OptProCrash.exe [143488 2014-01-08] ()
S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-12] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-12] (Avira Operations GmbH & Co. KG)
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [38440 2013-09-19] (Just Develop It)
S2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2251552 2013-12-16] (Conduit)
S2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE [102400 2006-04-18] (SEIKO EPSON CORPORATION)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
S2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-08-12] (PDF Complete Inc)
S2 vToolbarUpdater17.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe [1771544 2014-01-08] (AVG Secure Search)
S2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2014-01-08] (Cherished Technololgy LIMITED)
S2 HP Support Assistant Service; "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" [x]
S3 hpqwmiex; "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe" [x]
==================== Drivers (Whitelisted) ====================
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2014-01-07] (AVG Technologies)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-12] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-12 15:48 - 2014-01-12 15:48 - 00025492 _____ C:\Users\*****\Desktop\FRST.txt
2014-01-12 15:48 - 2014-01-12 15:48 - 00000000 ____D C:\Users\*****\Desktop\FRST-OlderVersion
2014-01-12 15:47 - 2014-01-12 15:48 - 02075136 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe
2014-01-12 15:47 - 2014-01-12 15:48 - 00000000 ____D C:\FRST
2014-01-12 15:33 - 2014-01-12 15:33 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-12 15:33 - 2014-01-12 15:33 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes
2014-01-12 15:33 - 2014-01-12 15:33 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-12 15:33 - 2014-01-12 15:33 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-12 15:33 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-10 12:57 - 2014-01-10 12:57 - 00000000 ____D C:\Users\*****\AppData\Local\{78554A9F-A7D9-4D7D-BB23-E32D99EE6176}
2014-01-08 09:01 - 2014-01-12 15:02 - 00000286 _____ C:\Windows\Tasks\PC Performer_DEFAULT.job
2014-01-08 09:01 - 2014-01-12 15:01 - 00003118 _____ C:\Windows\System32\Tasks\PC Performer
2014-01-08 09:01 - 2014-01-08 10:20 - 00000294 _____ C:\Windows\Tasks\PC Performer_UPDATES.job
2014-01-08 09:01 - 2014-01-08 09:01 - 00003054 _____ C:\Windows\System32\Tasks\PC Performer_UPDATES
2014-01-08 09:01 - 2014-01-08 09:01 - 00002898 _____ C:\Windows\System32\Tasks\PC Performer_DEFAULT
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\speedtest4354
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\PerformerSoft
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Video Performer
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\freegames111
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Users\*****\AppData\Local\SearchProtect
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Program Files (x86)\Video Performer
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Program Files (x86)\Speed Test 127
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Program Files (x86)\SearchProtect
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Program Files (x86)\PC Performer
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Program Files (x86)\Free Games 111
2014-01-08 08:50 - 2014-01-08 08:50 - 00470536 _____ C:\Users\*****\Downloads\Setup (3).exe
2014-01-08 08:43 - 2014-01-08 08:43 - 00469888 _____ C:\Users\*****\Downloads\Setup (2).exe
2014-01-08 08:37 - 2014-01-12 14:37 - 00001326 _____ C:\Windows\Tasks\Feven 2.2-updater.job
2014-01-08 08:37 - 2014-01-12 14:37 - 00001278 _____ C:\Windows\Tasks\Feven 2.2-codedownloader.job
2014-01-08 08:37 - 2014-01-12 14:37 - 00001150 _____ C:\Windows\Tasks\Feven 2.2-enabler.job
2014-01-08 08:37 - 2014-01-08 08:37 - 00004356 _____ C:\Windows\System32\Tasks\Feven 2.2-updater
2014-01-08 08:37 - 2014-01-08 08:37 - 00004308 _____ C:\Windows\System32\Tasks\Feven 2.2-codedownloader
2014-01-08 08:37 - 2014-01-08 08:37 - 00004180 _____ C:\Windows\System32\Tasks\Feven 2.2-enabler
2014-01-08 08:37 - 2014-01-08 08:37 - 00000000 ____D C:\Users\*****\AppData\Roaming\Optimizer Pro
2014-01-08 08:37 - 2014-01-08 08:37 - 00000000 ____D C:\Program Files (x86)\VideoPlayer
2014-01-08 08:37 - 2014-01-08 08:37 - 00000000 ____D C:\Program Files (x86)\Optimizer Pro
2014-01-08 08:36 - 2014-01-12 15:37 - 00003392 _____ C:\Users\*****\daemonprocess.txt
2014-01-08 08:36 - 2014-01-12 15:37 - 00001999 _____ C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lollipop.lnk
2014-01-08 08:36 - 2014-01-12 15:31 - 00000000 ____D C:\Users\*****\AppData\Local\Lollipop
2014-01-08 08:36 - 2014-01-12 14:36 - 00002110 _____ C:\Windows\Tasks\Feven 2.2-chromeinstaller.job
2014-01-08 08:36 - 2014-01-12 14:36 - 00002032 _____ C:\Windows\Tasks\Feven 2.2-firefoxinstaller.job
2014-01-08 08:36 - 2014-01-12 13:37 - 00000000 ____D C:\Users\*****\AppData\Roaming\newnext.me
2014-01-08 08:36 - 2014-01-12 08:26 - 00000394 _____ C:\Windows\Tasks\Re-markit Update.job
2014-01-08 08:36 - 2014-01-08 08:51 - 00000000 ____D C:\Users\*****\AppData\Local\Mobogenie
2014-01-08 08:36 - 2014-01-08 08:37 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2014-01-08 08:36 - 2014-01-08 08:37 - 00000000 ____D C:\Program Files (x86)\Feven 2.2
2014-01-08 08:36 - 2014-01-08 08:36 - 00003052 _____ C:\Windows\System32\Tasks\Re-markit Update
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\Users\*****\AppData\Local\genienext
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\Users\*****\AppData\Local\cache
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\Users\*****\.android
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\ProgramData\WPM
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\Program Files (x86)\Re-markit
2014-01-07 08:59 - 2014-01-07 08:59 - 00004044 _____ C:\Windows\System32\Tasks\LaunchApp
2014-01-07 08:59 - 2014-01-07 08:59 - 00000000 ____D C:\Users\*****\SyncFolder
2014-01-07 08:37 - 2014-01-08 08:51 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2014-01-07 08:37 - 2014-01-07 08:37 - 00000000 ____D C:\Users\*****\AppData\Local\AVG SafeGuard toolbar
2014-01-07 08:37 - 2014-01-07 08:37 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2014-01-07 08:37 - 2014-01-07 08:36 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-01-07 08:30 - 2014-01-07 08:30 - 00469504 _____ C:\Users\*****\Downloads\Setup (1).exe
2014-01-07 08:25 - 2014-01-12 15:37 - 00000282 _____ C:\Windows\Tasks\SpeedUpMyPC Startup.job
2014-01-07 08:25 - 2014-01-12 15:00 - 00000288 _____ C:\Windows\Tasks\SpeedUpMyPC Maintenance.job
2014-01-07 08:25 - 2014-01-07 08:25 - 00003244 _____ C:\Windows\System32\Tasks\SpeedUpMyPC Maintenance
2014-01-07 08:25 - 2014-01-07 08:25 - 00002532 _____ C:\Windows\System32\Tasks\SpeedUpMyPC Startup
2014-01-07 08:24 - 2014-01-07 08:37 - 00000000 ____D C:\Users\*****\AppData\Roaming\Uniblue
2014-01-07 08:24 - 2014-01-07 08:24 - 00000000 ____D C:\Program Files (x86)\Uniblue
2014-01-07 08:11 - 2014-01-12 07:38 - 00003120 _____ C:\Windows\System32\Tasks\Advanced System Protector_startup
2014-01-07 08:10 - 2014-01-12 07:41 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
2014-01-07 08:10 - 2014-01-07 08:59 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2014-01-07 08:10 - 2014-01-07 08:10 - 00000000 ____D C:\Users\*****\AppData\Roaming\systweak
2014-01-07 08:10 - 2014-01-07 08:10 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2014-01-07 08:10 - 2014-01-07 08:10 - 00000000 ____D C:\ProgramData\Systweak
2014-01-07 08:10 - 2014-01-07 08:10 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
2014-01-07 08:10 - 2014-01-07 08:10 - 00000000 ____D C:\Program Files (x86)\Advanced System Protector
2014-01-07 08:10 - 2013-06-19 14:58 - 00019456 _____ (PerformerSoft LLC) C:\Windows\system32\roboot64.exe
2014-01-07 08:10 - 2012-07-25 12:03 - 00016896 _____ C:\Windows\system32\sasnative64.exe
2014-01-07 08:09 - 2014-01-07 08:09 - 00469472 _____ C:\Users\*****\Downloads\Setup.exe
2013-12-26 15:46 - 2013-12-26 15:46 - 00000000 ____D C:\output
2013-12-26 15:36 - 2014-01-12 15:36 - 00002114 _____ C:\Windows\Tasks\Plus-HD-4.9-firefoxinstaller.job
2013-12-26 15:36 - 2014-01-12 15:36 - 00001338 _____ C:\Windows\Tasks\Plus-HD-4.9-updater.job
2013-12-26 15:36 - 2014-01-12 15:36 - 00001240 _____ C:\Windows\Tasks\Plus-HD-4.9-codedownloader.job
2013-12-26 15:36 - 2014-01-12 15:36 - 00001140 _____ C:\Windows\Tasks\Plus-HD-4.9-enabler.job
2013-12-26 15:36 - 2013-12-26 15:36 - 00004368 _____ C:\Windows\System32\Tasks\Plus-HD-4.9-updater
2013-12-26 15:36 - 2013-12-26 15:36 - 00004270 _____ C:\Windows\System32\Tasks\Plus-HD-4.9-codedownloader
2013-12-26 15:36 - 2013-12-26 15:36 - 00004170 _____ C:\Windows\System32\Tasks\Plus-HD-4.9-enabler
2013-12-26 15:36 - 2013-12-26 15:36 - 00000000 ____D C:\Users\*****\AppData\Roaming\SpeedTestAnalysis
2013-12-26 15:36 - 2013-12-26 15:36 - 00000000 ____D C:\Program Files\Google
2013-12-26 15:35 - 2014-01-12 15:36 - 00001984 _____ C:\Windows\Tasks\Plus-HD-4.9-chromeinstaller.job
2013-12-26 15:35 - 2013-12-26 15:41 - 00000000 ____D C:\Users\*****\AppData\Roaming\PhotoScape
2013-12-26 15:35 - 2013-12-26 15:36 - 00000000 ____D C:\ProgramData\Google
2013-12-26 15:35 - 2013-12-26 15:36 - 00000000 ____D C:\Program Files (x86)\Plus-HD-4.9
2013-12-26 15:35 - 2013-12-26 15:35 - 00000000 ____D C:\Program Files (x86)\PhotoScape
2013-12-17 19:32 - 2013-12-17 19:32 - 00002214 _____ C:\Users\Public\Desktop\Google Earth.lnk
==================== One Month Modified Files and Folders =======
2014-01-12 15:48 - 2014-01-12 15:48 - 00025492 _____ C:\Users\*****\Desktop\FRST.txt
2014-01-12 15:48 - 2014-01-12 15:48 - 00000000 ____D C:\Users\*****\Desktop\FRST-OlderVersion
2014-01-12 15:48 - 2014-01-12 15:47 - 02075136 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe
2014-01-12 15:48 - 2014-01-12 15:47 - 00000000 ____D C:\FRST
2014-01-12 15:37 - 2014-01-08 08:36 - 00003392 _____ C:\Users\*****\daemonprocess.txt
2014-01-12 15:37 - 2014-01-08 08:36 - 00001999 _____ C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lollipop.lnk
2014-01-12 15:37 - 2014-01-07 08:25 - 00000282 _____ C:\Windows\Tasks\SpeedUpMyPC Startup.job
2014-01-12 15:37 - 2012-06-30 10:14 - 01488250 _____ C:\Windows\WindowsUpdate.log
2014-01-12 15:36 - 2013-12-26 15:36 - 00002114 _____ C:\Windows\Tasks\Plus-HD-4.9-firefoxinstaller.job
2014-01-12 15:36 - 2013-12-26 15:36 - 00001338 _____ C:\Windows\Tasks\Plus-HD-4.9-updater.job
2014-01-12 15:36 - 2013-12-26 15:36 - 00001240 _____ C:\Windows\Tasks\Plus-HD-4.9-codedownloader.job
2014-01-12 15:36 - 2013-12-26 15:36 - 00001140 _____ C:\Windows\Tasks\Plus-HD-4.9-enabler.job
2014-01-12 15:36 - 2013-12-26 15:35 - 00001984 _____ C:\Windows\Tasks\Plus-HD-4.9-chromeinstaller.job
2014-01-12 15:36 - 2012-03-07 16:30 - 00697072 _____ C:\Windows\system32\perfh007.dat
2014-01-12 15:36 - 2012-03-07 16:30 - 00148110 _____ C:\Windows\system32\perfc007.dat
2014-01-12 15:36 - 2009-07-14 06:13 - 01614100 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-12 15:33 - 2014-01-12 15:33 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-12 15:33 - 2014-01-12 15:33 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes
2014-01-12 15:33 - 2014-01-12 15:33 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-12 15:33 - 2014-01-12 15:33 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-12 15:32 - 2009-07-14 05:51 - 00239109 _____ C:\Windows\setupact.log
2014-01-12 15:31 - 2014-01-08 08:36 - 00000000 ____D C:\Users\*****\AppData\Local\Lollipop
2014-01-12 15:31 - 2012-09-28 16:54 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-12 15:18 - 2013-12-02 14:07 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-12 15:02 - 2014-01-08 09:01 - 00000286 _____ C:\Windows\Tasks\PC Performer_DEFAULT.job
2014-01-12 15:01 - 2014-01-08 09:01 - 00003118 _____ C:\Windows\System32\Tasks\PC Performer
2014-01-12 15:00 - 2014-01-07 08:25 - 00000288 _____ C:\Windows\Tasks\SpeedUpMyPC Maintenance.job
2014-01-12 14:37 - 2014-01-08 08:37 - 00001326 _____ C:\Windows\Tasks\Feven 2.2-updater.job
2014-01-12 14:37 - 2014-01-08 08:37 - 00001278 _____ C:\Windows\Tasks\Feven 2.2-codedownloader.job
2014-01-12 14:37 - 2014-01-08 08:37 - 00001150 _____ C:\Windows\Tasks\Feven 2.2-enabler.job
2014-01-12 14:36 - 2014-01-08 08:36 - 00002110 _____ C:\Windows\Tasks\Feven 2.2-chromeinstaller.job
2014-01-12 14:36 - 2014-01-08 08:36 - 00002032 _____ C:\Windows\Tasks\Feven 2.2-firefoxinstaller.job
2014-01-12 13:37 - 2014-01-08 08:36 - 00000000 ____D C:\Users\*****\AppData\Roaming\newnext.me
2014-01-12 13:31 - 2012-09-28 16:54 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-12 12:45 - 2012-08-16 16:15 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2014-01-12 08:26 - 2014-01-08 08:36 - 00000394 _____ C:\Windows\Tasks\Re-markit Update.job
2014-01-12 07:46 - 2009-07-14 05:45 - 00024400 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-12 07:46 - 2009-07-14 05:45 - 00024400 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-12 07:45 - 2013-03-07 10:49 - 00000000 ____D C:\Users\*****\AppData\Local\DoNotTrackPlus
2014-01-12 07:41 - 2014-01-07 08:10 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
2014-01-12 07:38 - 2014-01-07 08:11 - 00003120 _____ C:\Windows\System32\Tasks\Advanced System Protector_startup
2014-01-12 07:38 - 2012-03-07 17:12 - 00000000 ____D C:\ProgramData\PDFC
2014-01-12 07:36 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-11 20:09 - 2013-07-02 08:54 - 00003966 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{2B6FD10E-38FD-448D-AB63-87797203405E}
2014-01-10 19:24 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2014-01-10 12:57 - 2014-01-10 12:57 - 00000000 ____D C:\Users\*****\AppData\Local\{78554A9F-A7D9-4D7D-BB23-E32D99EE6176}
2014-01-09 20:48 - 2012-06-30 10:34 - 00000000 ____D C:\Users\*****\AppData\Roaming\SoftGrid Client
2014-01-09 09:39 - 2012-06-30 10:32 - 00000000 ____D C:\Users\*****\Documents\Privat
2014-01-08 10:20 - 2014-01-08 09:01 - 00000294 _____ C:\Windows\Tasks\PC Performer_UPDATES.job
2014-01-08 09:01 - 2014-01-08 09:01 - 00003054 _____ C:\Windows\System32\Tasks\PC Performer_UPDATES
2014-01-08 09:01 - 2014-01-08 09:01 - 00002898 _____ C:\Windows\System32\Tasks\PC Performer_DEFAULT
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\speedtest4354
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\PerformerSoft
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Video Performer
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\freegames111
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Users\*****\AppData\Local\SearchProtect
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Program Files (x86)\Video Performer
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Program Files (x86)\Speed Test 127
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Program Files (x86)\SearchProtect
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Program Files (x86)\PC Performer
2014-01-08 09:01 - 2014-01-08 09:01 - 00000000 ____D C:\Program Files (x86)\Free Games 111
2014-01-08 08:51 - 2014-01-08 08:36 - 00000000 ____D C:\Users\*****\AppData\Local\Mobogenie
2014-01-08 08:51 - 2014-01-07 08:37 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2014-01-08 08:50 - 2014-01-08 08:50 - 00470536 _____ C:\Users\*****\Downloads\Setup (3).exe
2014-01-08 08:43 - 2014-01-08 08:43 - 00469888 _____ C:\Users\*****\Downloads\Setup (2).exe
2014-01-08 08:37 - 2014-01-08 08:37 - 00004356 _____ C:\Windows\System32\Tasks\Feven 2.2-updater
2014-01-08 08:37 - 2014-01-08 08:37 - 00004308 _____ C:\Windows\System32\Tasks\Feven 2.2-codedownloader
2014-01-08 08:37 - 2014-01-08 08:37 - 00004180 _____ C:\Windows\System32\Tasks\Feven 2.2-enabler
2014-01-08 08:37 - 2014-01-08 08:37 - 00000000 ____D C:\Users\*****\AppData\Roaming\Optimizer Pro
2014-01-08 08:37 - 2014-01-08 08:37 - 00000000 ____D C:\Program Files (x86)\VideoPlayer
2014-01-08 08:37 - 2014-01-08 08:37 - 00000000 ____D C:\Program Files (x86)\Optimizer Pro
2014-01-08 08:37 - 2014-01-08 08:36 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2014-01-08 08:37 - 2014-01-08 08:36 - 00000000 ____D C:\Program Files (x86)\Feven 2.2
2014-01-08 08:36 - 2014-01-08 08:36 - 00003052 _____ C:\Windows\System32\Tasks\Re-markit Update
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\Users\*****\AppData\Local\genienext
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\Users\*****\AppData\Local\cache
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\Users\*****\.android
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\ProgramData\WPM
2014-01-08 08:36 - 2014-01-08 08:36 - 00000000 ____D C:\Program Files (x86)\Re-markit
2014-01-08 08:36 - 2012-09-28 16:57 - 00002345 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-08 08:36 - 2012-06-30 10:21 - 00001607 _____ C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-08 08:36 - 2012-06-30 10:15 - 00000000 ____D C:\Users\*****
2014-01-07 08:59 - 2014-01-07 08:59 - 00004044 _____ C:\Windows\System32\Tasks\LaunchApp
2014-01-07 08:59 - 2014-01-07 08:59 - 00000000 ____D C:\Users\*****\SyncFolder
2014-01-07 08:59 - 2014-01-07 08:10 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2014-01-07 08:37 - 2014-01-07 08:37 - 00000000 ____D C:\Users\*****\AppData\Local\AVG SafeGuard toolbar
2014-01-07 08:37 - 2014-01-07 08:37 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2014-01-07 08:37 - 2014-01-07 08:24 - 00000000 ____D C:\Users\*****\AppData\Roaming\Uniblue
2014-01-07 08:36 - 2014-01-07 08:37 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-01-07 08:30 - 2014-01-07 08:30 - 00469504 _____ C:\Users\*****\Downloads\Setup (1).exe
2014-01-07 08:25 - 2014-01-07 08:25 - 00003244 _____ C:\Windows\System32\Tasks\SpeedUpMyPC Maintenance
2014-01-07 08:25 - 2014-01-07 08:25 - 00002532 _____ C:\Windows\System32\Tasks\SpeedUpMyPC Startup
2014-01-07 08:24 - 2014-01-07 08:24 - 00000000 ____D C:\Program Files (x86)\Uniblue
2014-01-07 08:10 - 2014-01-07 08:10 - 00000000 ____D C:\Users\*****\AppData\Roaming\systweak
2014-01-07 08:10 - 2014-01-07 08:10 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2014-01-07 08:10 - 2014-01-07 08:10 - 00000000 ____D C:\ProgramData\Systweak
2014-01-07 08:10 - 2014-01-07 08:10 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
2014-01-07 08:10 - 2014-01-07 08:10 - 00000000 ____D C:\Program Files (x86)\Advanced System Protector
2014-01-07 08:10 - 2012-06-30 10:21 - 00000000 ___RD C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-07 08:09 - 2014-01-07 08:09 - 00469472 _____ C:\Users\*****\Downloads\Setup.exe
2013-12-31 09:15 - 2012-06-30 10:32 - 00000000 ____D C:\Users\*****\Documents\Sonstiges
2013-12-26 16:00 - 2010-11-21 04:47 - 00571098 _____ C:\Windows\PFRO.log
2013-12-26 16:00 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-26 15:46 - 2013-12-26 15:46 - 00000000 ____D C:\output
2013-12-26 15:41 - 2013-12-26 15:35 - 00000000 ____D C:\Users\*****\AppData\Roaming\PhotoScape
2013-12-26 15:36 - 2013-12-26 15:36 - 00004368 _____ C:\Windows\System32\Tasks\Plus-HD-4.9-updater
2013-12-26 15:36 - 2013-12-26 15:36 - 00004270 _____ C:\Windows\System32\Tasks\Plus-HD-4.9-codedownloader
2013-12-26 15:36 - 2013-12-26 15:36 - 00004170 _____ C:\Windows\System32\Tasks\Plus-HD-4.9-enabler
2013-12-26 15:36 - 2013-12-26 15:36 - 00000000 ____D C:\Users\*****\AppData\Roaming\SpeedTestAnalysis
2013-12-26 15:36 - 2013-12-26 15:36 - 00000000 ____D C:\Program Files\Google
2013-12-26 15:36 - 2013-12-26 15:35 - 00000000 ____D C:\ProgramData\Google
2013-12-26 15:36 - 2013-12-26 15:35 - 00000000 ____D C:\Program Files (x86)\Plus-HD-4.9
2013-12-26 15:36 - 2012-09-28 16:54 - 00000000 ____D C:\Program Files (x86)\Google
2013-12-26 15:35 - 2013-12-26 15:35 - 00000000 ____D C:\Program Files (x86)\PhotoScape
2013-12-20 15:02 - 2012-06-30 10:31 - 00000000 ____D C:\Users\*****\Documents\Auslandsreisen
2013-12-17 19:32 - 2013-12-17 19:32 - 00002214 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-12-16 19:04 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-15 13:48 - 2013-07-14 08:37 - 00000000 ____D C:\Windows\system32\MRT
2013-12-15 13:47 - 2012-07-23 11:54 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\*****\AppData\Local\Temp\adgwsukbgauoppf.exe
C:\Users\*****\AppData\Local\Temp\avgnt.exe
C:\Users\*****\AppData\Local\Temp\BackupSetup.exe
C:\Users\*****\AppData\Local\Temp\dlLogic.exe
C:\Users\*****\AppData\Local\Temp\GCVerifier.dll
C:\Users\*****\AppData\Local\Temp\install_helper.exe
C:\Users\*****\AppData\Local\Temp\nsi8FD8.exe
C:\Users\*****\AppData\Local\Temp\nss6EDF.exe
C:\Users\*****\AppData\Local\Temp\nst92D6.exe
C:\Users\*****\AppData\Local\Temp\nsy6BF2.exe
C:\Users\*****\AppData\Local\Temp\oi_{DF5731D3-8D44-4962-8308-6F61768DCD3A}.exe
C:\Users\*****\AppData\Local\Temp\plus-hd-4-91.exe
C:\Users\*****\AppData\Local\Temp\setup.exe
C:\Users\*****\AppData\Local\Temp\SpeedAnalysisSetup.exe
C:\Users\*****\AppData\Local\Temp\tbedrs.dll
C:\Users\*****\AppData\Local\Temp\vcredist_x86.exe
C:\Users\*****\AppData\Local\Temp\verifier.exe
C:\Users\*****\AppData\Local\Temp\worker.exe
C:\Users\*****\AppData\Local\Temp\_isB07.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-30 08:34
==================== End Of Log ============================ --- --- ---
Addition.txt aus Anhang Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-01-2014
Ran by ***** at 2014-01-12 15:49:04
Running from C:\Users\*****\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe AIR (x32 Version: 2.6.0.19120 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 2.6.0.19120 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader X (10.1.6) - Deutsch (x32 Version: 10.1.6 - Adobe Systems Incorporated)
Advanced System Protector (x32 Version: 2.1.1000.12580 - Systweak Software) <==== ATTENTION
Ask Toolbar (x32 Version: 1.15.26.0 - Ask.com) <==== ATTENTION
AVG SafeGuard toolbar (x32 Version: 17.3.0.49 - AVG Technologies)
Avira Free Antivirus (x32 Version: 14.0.2.286 - Avira)
Avira SearchFree Toolbar plus Web Protection Updater (HKCU Version: 1.2.6.45268 - Ask.com)
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bing Bar (x32 Version: 7.0.826.0 - Microsoft Corporation)
Brother MFL-Pro Suite DCP-195C (x32 Version: 1.0.1.0 - Brother Industries, Ltd.)
Cake Mania (x32 Version: 2.2.0.98 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Compaq Setup Manager (x32 Version: 1.2.15145.3905 - Hewlett-Packard Company)
Cradle of Rome 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
DMUninstaller (x32 Version: - )
EPSON-Drucker-Software (Version: - SEIKO EPSON Corporation)
Facebook (x32 Version: 1.1.0004 - Hewlett-Packard)
Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Farmscapes (x32 Version: 2.2.0.98 - WildTangent) Hidden
FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
FC Bayern München - NewsBox (x32 Version: 1.00.0000 - FC Bayern München - NewsBox)
Feven 2.2 (x32 Version: 1.33.153.1 - Feven) <==== ATTENTION
FileConverter 1.3 Toolbar (x32 Version: 6.9.0.16 - FileConverter 1.3)
Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden
Fishdom (TM) 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Free Games 111 (x32 Version: 3.0.0.0 - BestOffers) <==== ATTENTION
Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.)
Google Earth (x32 Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (x32 Version: 7.5.4805.320 - Google Inc.)
Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.1.2.0 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
HP Auto (Version: 1.0.12935.3667 - Hewlett-Packard Company) Hidden
HP Client Services (Version: 1.1.12938.3539 - Hewlett-Packard) Hidden
HP Clock (x32 Version: 5.1.4244.16367 - Hewlett-Packard)
HP Customer Experience Enhancements (x32 Version: 6.0.1.8 - Hewlett-Packard) Hidden
HP Games (x32 Version: 1.0.2.5 - WildTangent)
HP Magic Canvas Tutorials (x32 Version: 5.0.0.3 - Hewlett-Packard)
HP Notes (x32 Version: 5.1.4274.30382 - Hewlett-Packard)
HP Odometer (x32 Version: 2.10.0000 - Hewlett-Packard)
HP RSS (x32 Version: 5.1.4301.21494 - Hewlett-Packard)
HP Support Information (x32 Version: 11.00.0001 - Hewlett-Packard)
HP TouchSmart RecipeBox (x32 Version: 3.0.3830.27730 - Hewlett-Packard)
HP Update (x32 Version: 5.003.001.001 - Hewlett-Packard)
HP Vision Hardware Diagnostics (Version: 2.12.1.0 - Hewlett-Packard)
Insaniquarium Deluxe (x32 Version: 2.2.0.97 - WildTangent) Hidden
Intel(R) Control Center (x32 Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2372 - Intel Corporation)
Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Jewel Quest II (x32 Version: 2.2.0.97 - WildTangent) Hidden
Jewel Quest Solitaire 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (x32 Version: 2.5.4507 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.4507 - CyberLink Corp.) Hidden
Lollipop (HKCU Version: - Lollipop Network, S.L.) <==== ATTENTION
Magic Desktop (x32 Version: 3.0 - EasyBits Software AS)
Mahjongg Artifacts (x32 Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Mathematics (x32 Version: 4.0 - Microsoft Corporation)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.5139.5005 - Microsoft Corporation)
Microsoft PowerPoint Viewer (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Mobogenie (x32 Version: - Mobogenie.com) <==== ATTENTION
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation)
MyPC Backup (Version: - MyPC Backup) <==== ATTENTION
Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
Norton Online Backup (x32 Version: 2.1.17869 - Symantec Corporation)
opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
Optimizer Pro v3.2 (x32 Version: - PC Utilities Software Limited) <==== ATTENTION
PaperPort Image Printer 64-bit (Version: 1.00.0000 - Nuance Communications, Inc.)
PC Performer (x32 Version: 11.10 - PerformerSoft LLC) <==== ATTENTION
PDF Complete Special Edition (x32 Version: 4.0.65 - PDF Complete, Inc)
PhotoScape (x32 Version: - )
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
PlayReady PC Runtime amd64 (Version: 1.3.0 - Microsoft Corporation)
Plus-HD-4.9 (x32 Version: 1.32.153.0 - Plus HD) <==== ATTENTION
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Power2Go (x32 Version: 6.1.5705 - CyberLink Corp.)
Power2Go (x32 Version: 6.1.5705 - CyberLink Corp.) Hidden
Ranch Rush 2 - Premium Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6387 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 5.5.0.4424 - CyberLink Corp.) Hidden
RegClean Pro (x32 Version: 6.21 - Systweak Inc) <==== ATTENTION
Re-markit (x32 Version: - Re-markit Software)
ScanSoft PaperPort 11 (x32 Version: 11.2.0000 - Nuance Communications, Inc.)
Search Protect (x32 Version: 2.9.8.2 - Conduit) <==== ATTENTION
Skype™ 5.10 (x32 Version: 5.10.116 - Skype Technologies S.A.)
Speed Test 127 (x32 Version: 3.0.0.0 - BestOffers) <==== ATTENTION
SpeedUpMyPC (x32 Version: 6.0.0.0 - Uniblue Systems Limited)
Torchlight (x32 Version: 2.2.0.98 - WildTangent) Hidden
TSHostedAppLauncher (x32 Version: 5.1.15.0 - Hewlett-Packard) Hidden
Unity Web Player (HKCU Version: - Unity Technologies ApS)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Video Performer (x32 Version: - PerformerSoft LLC)
VideoPlayer v2.0.6 (x32 Version: v2.0.6 - TUGUU SL)
Virtual Families (x32 Version: 2.2.0.98 - WildTangent) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden
Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden
WildTangent Games App (HP Games) (x32 Version: 4.0.5.32 - WildTangent) Hidden
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
WPM17.8.0.3297 (x32 Version: 17.8.0.3297 - Cherished Technololgy LIMITED) <==== ATTENTION
Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC)
Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden
Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden
==================== Restore Points =========================
31-12-2013 09:58:25 Geplanter Prüfpunkt
07-01-2014 07:13:18 RegClean Pro Di, Jan 07, 14 08:13
07-01-2014 07:24:30 Uniblue SpeedUpMyPC installation
==================== Hosts content: ==========================
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {00587290-286E-4BC0-9146-8897DE618E1C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater\HPSFUpdater.exe [2011-12-15] (Hewlett-Packard)
Task: {03D5F763-2864-486B-B696-6DB0AD500F25} - System32\Tasks\Plus-HD-4.9-codedownloader => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-codedownloader.exe [2013-12-26] (Plus HD) <==== ATTENTION
Task: {05F13E7E-B9DF-4B99-AC5A-4A7BDB0A0166} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2013-12-27] (Systweak Inc) <==== ATTENTION
Task: {06552032-D4FF-4E20-8FD0-0805C6A0B727} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe
Task: {0CDD04F2-8CBA-4AE0-9D91-8868BC1318F4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe
Task: {0E77A369-4FF0-499E-9234-F743E33F9827} - System32\Tasks\Plus-HD-4.9-firefoxinstaller => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-firefoxinstaller.exe [2013-12-26] (Plus HD) <==== ATTENTION
Task: {1F8A572D-FBC1-43B1-AB6F-95BDFBF9D81F} - System32\Tasks\Feven 2.2-codedownloader => C:\Program Files (x86)\Feven 2.2\Feven 2.2-codedownloader.exe [2014-01-08] (Feven) <==== ATTENTION
Task: {41248ECE-1BD6-4611-8DDE-FB8059478C37} - System32\Tasks\Plus-HD-4.9-enabler => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-enabler.exe [2013-12-26] (Plus HD) <==== ATTENTION
Task: {4958CED8-264D-4083-BF95-CC058D865656} - System32\Tasks\SpeedUpMyPC Maintenance => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe [2013-12-12] (Uniblue Systems Limited)
Task: {5CA3C8A3-687F-40BA-A8DA-1031756C6A1E} - System32\Tasks\Feven 2.2-chromeinstaller => C:\Program Files (x86)\Feven 2.2\Feven 2.2-chromeinstaller.exe [2014-01-08] (Feven) <==== ATTENTION
Task: {614D0E71-75B3-48A5-AA32-5DEFD713F175} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {6DAA64F3-3EB4-463B-B32B-FF455620D6BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated)
Task: {701CCF15-0122-4751-B8BB-F72BE807167B} - System32\Tasks\SpeedUpMyPC Startup => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe [2013-12-12] (Uniblue Systems Limited)
Task: {8660873F-3DB1-45D1-AB35-7EF205C8030A} - System32\Tasks\PC Performer_UPDATES => C:\Program Files (x86)\PC Performer\PCPerformer.exe [2013-06-19] (PerformerSoft LLC) <==== ATTENTION
Task: {9307A8DA-626A-45AA-8E32-6EECE05141D5} - System32\Tasks\PC Performer => C:\Program Files (x86)\PC Performer\PCPerformer.exe [2013-06-19] (PerformerSoft LLC) <==== ATTENTION
Task: {A7C357E8-CAEC-4C8E-8BBF-4AD4ECA41796} - System32\Tasks\Re-markit Update => C:\Program Files (x86)\Re-markit\ReMarkit_up.exe [2014-01-08] () <==== ATTENTION
Task: {A95E97BA-271D-4F42-BCEF-0F81C8666BDF} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe [2013-09-19] (MyPCBackup.com)
Task: {AC9C69AB-4F18-4309-BB33-6E53F68E4C9C} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2013-04-30] ()
Task: {B4656BC4-4034-41BE-8D2E-2C36CD63C3F2} - System32\Tasks\Plus-HD-4.9-chromeinstaller => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-chromeinstaller.exe [2013-12-26] (Plus HD) <==== ATTENTION
Task: {BF6C6666-83A2-4751-B24A-4073D5B49A5F} - System32\Tasks\Feven 2.2-firefoxinstaller => C:\Program Files (x86)\Feven 2.2\Feven 2.2-firefoxinstaller.exe [2014-01-08] (Feven) <==== ATTENTION
Task: {C22F5EE5-9D1B-4AA7-99F0-4253347E895F} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\Dependencies\RemEngine.exe
Task: {C3E872DF-A1F5-4836-84FE-AD545722A5ED} - System32\Tasks\Feven 2.2-updater => C:\Program Files (x86)\Feven 2.2\Feven 2.2-updater.exe [2014-01-08] (Feven) <==== ATTENTION
Task: {CAEB264B-6315-4719-98E9-0FE2BB6EA36E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-28] (Google Inc.)
Task: {D8EB31C1-821E-4E52-A26B-258DAAD06765} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {DCA5B87C-8B46-4883-BF02-B3DBD6600130} - System32\Tasks\Feven 2.2-enabler => C:\Program Files (x86)\Feven 2.2\Feven 2.2-enabler.exe [2014-01-08] (Feven) <==== ATTENTION
Task: {EDA37AFA-475B-4C71-89B5-1FFDA76F16AF} - System32\Tasks\Plus-HD-4.9-updater => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-updater.exe [2013-12-26] (Plus HD) <==== ATTENTION
Task: {F26D7924-3309-497E-A92A-05C0116CB640} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe [2013-12-23] (Systweak) <==== ATTENTION
Task: {F74CF655-42F9-4739-B449-768EF9F063E9} - System32\Tasks\PC Performer_DEFAULT => C:\Program Files (x86)\PC Performer\PCPerformer.exe [2013-06-19] (PerformerSoft LLC) <==== ATTENTION
Task: {F85D5A33-EFA2-4C3E-8B04-62A2BBF67672} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-28] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Feven 2.2-chromeinstaller.job => C:\Program Files (x86)\Feven 2.2\Feven 2.2-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 2.2-codedownloader.job => C:\Program Files (x86)\Feven 2.2\Feven 2.2-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 2.2-enabler.job => C:\Program Files (x86)\Feven 2.2\Feven 2.2-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 2.2-firefoxinstaller.job => C:\Program Files (x86)\Feven 2.2\Feven 2.2-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 2.2-updater.job => C:\Program Files (x86)\Feven 2.2\Feven 2.2-updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\PC Performer_DEFAULT.job => C:\Program Files (x86)\PC Performer\PCPerformer.exe <==== ATTENTION
Task: C:\Windows\Tasks\PC Performer_UPDATES.job => C:\Program Files (x86)\PC Performer\PCPerformer.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-4.9-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-4.9-codedownloader.job => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-4.9-enabler.job => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-4.9-firefoxinstaller.job => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-4.9-updater.job => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\Re-markit Update.job => C:\Program Files (x86)\Re-markit\ReMarkit_up.exe <==== ATTENTION
Task: C:\Windows\Tasks\SpeedUpMyPC Maintenance.job => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe
Task: C:\Windows\Tasks\SpeedUpMyPC Startup.job => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe
==================== Loaded Modules (whitelisted) =============
2013-09-19 23:37 - 2013-09-19 23:37 - 03889152 _____ () C:\Program Files (x86)\MyPC Backup\MPCBIconOverlays.dll
2013-09-19 23:32 - 2013-09-19 23:32 - 01102336 _____ () C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll
2013-09-19 23:37 - 2013-09-19 23:37 - 00012288 _____ () C:\Program Files (x86)\MyPC Backup\GetText.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\Temp:373E1720
AlternateDataStreams: C:\Users\*****\Downloads\Fwd_Lena.eml:OECustomProperty
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
==================== Faulty Device Manager Devices =============
Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (01/12/2014 03:47:17 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (01/12/2014 03:33:09 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (01/12/2014 00:45:40 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: Plus-HD-4.9-bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x52a4a373
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0b608f18
ID des fehlerhaften Prozesses: 0x1ef8
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (01/12/2014 00:42:44 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: Plus-HD-4.9-bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x52a4a373
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0ad08f18
ID des fehlerhaften Prozesses: 0x2684
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (01/12/2014 00:34:39 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: Plus-HD-4.9-bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x52a4a373
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0a958f18
ID des fehlerhaften Prozesses: 0x2588
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (01/12/2014 00:17:59 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: Plus-HD-4.9-bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x52a4a373
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0a318f18
ID des fehlerhaften Prozesses: 0x1ff8
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (01/12/2014 10:41:07 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: Plus-HD-4.9-bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x52a4a373
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0b838f18
ID des fehlerhaften Prozesses: 0x1d94
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (01/12/2014 10:41:07 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: Plus-HD-4.9-bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x52a4a373
Ausnahmecode: 0xc0000005
Fehleroffset: 0x02ac8f18
ID des fehlerhaften Prozesses: 0x720
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (01/12/2014 10:34:49 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x77a51234
ID des fehlerhaften Prozesses: 0x1eac
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (01/12/2014 10:34:49 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: Plus-HD-4.9-bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x52a4a373
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0af28f18
ID des fehlerhaften Prozesses: 0x1ff4
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
System errors:
=============
Error: (01/12/2014 03:48:25 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (01/12/2014 03:48:25 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (01/12/2014 03:48:25 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (01/12/2014 03:47:43 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (01/12/2014 03:47:43 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (01/12/2014 03:47:43 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (01/12/2014 03:47:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (01/12/2014 03:47:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (01/12/2014 03:47:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (01/12/2014 03:46:17 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Microsoft Office Sessions:
=========================
Error: (01/12/2014 03:47:17 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestH:\Wall\esetsmartinstaller_enu.exe
Error: (01/12/2014 03:33:09 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestH:\Wall\esetsmartinstaller_enu.exe
Error: (01/12/2014 00:45:40 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cPlus-HD-4.9-bho.dll_unloaded0.0.0.052a4a373c00000050b608f181ef801cf0f8b98096045C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEPlus-HD-4.9-bho.dll0f27b8ed-7b7f-11e3-b857-e0cb4efc137d
Error: (01/12/2014 00:42:44 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cPlus-HD-4.9-bho.dll_unloaded0.0.0.052a4a373c00000050ad08f18268401cf0f8a78fd6359C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEPlus-HD-4.9-bho.dlla6467879-7b7e-11e3-b857-e0cb4efc137d
Error: (01/12/2014 00:34:39 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cPlus-HD-4.9-bho.dll_unloaded0.0.0.052a4a373c00000050a958f18258801cf0f88d0fb3a58C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEPlus-HD-4.9-bho.dll853ddd5f-7b7d-11e3-b857-e0cb4efc137d
Error: (01/12/2014 00:17:59 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cPlus-HD-4.9-bho.dll_unloaded0.0.0.052a4a373c00000050a318f181ff801cf0f87c34493b7C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEPlus-HD-4.9-bho.dll312576b6-7b7b-11e3-b857-e0cb4efc137d
Error: (01/12/2014 10:41:07 AM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cPlus-HD-4.9-bho.dll_unloaded0.0.0.052a4a373c00000050b838f181d9401cf0f79a205257fC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEPlus-HD-4.9-bho.dlla8eb1cb4-7b6d-11e3-b857-e0cb4efc137d
Error: (01/12/2014 10:41:07 AM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cPlus-HD-4.9-bho.dll_unloaded0.0.0.052a4a373c000000502ac8f1872001cf0f7a1458d30dC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEPlus-HD-4.9-bho.dlla8eaf5a4-7b6d-11e3-b857-e0cb4efc137d
Error: (01/12/2014 10:34:49 AM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cunknown0.0.0.000000000c000000577a512341eac01cf0f7810af4c52C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEunknownc79cab69-7b6c-11e3-b857-e0cb4efc137d
Error: (01/12/2014 10:34:49 AM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cPlus-HD-4.9-bho.dll_unloaded0.0.0.052a4a373c00000050af28f181ff401cf0f77f35dfde1C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEPlus-HD-4.9-bho.dllc79c8459-7b6c-11e3-b857-e0cb4efc137d
==================== Memory info ===========================
Percentage of memory in use: 18%
Total physical RAM: 4002.52 MB
Available physical RAM: 3244.96 MB
Total Pagefile: 8003.21 MB
Available Pagefile: 7286.59 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:448.56 GB) (Free:382.2 GB) NTFS
Drive d: (HP_RECOVERY) (Fixed) (Total:17.1 GB) (Free:2.14 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive h: (CORSAIR) (Removable) (Total:14.9 GB) (Free:1.66 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 62040D50)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=449 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=17 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 15 GB) (Disk ID: 00000000)
Partition 1: (Active) - (Size=15 GB) - (Type=0C)
==================== End Of Log ============================ gmer.txt aus Anhang Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2014-01-12 15:55:08
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST350041 rev.HP64 465,76GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\HORSTW~1\AppData\Local\Temp\fwliauod.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80001ff4000 86 bytes [70, 27, 6D, 06, 80, FA, FF, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 616 fffff80001ff4058 64 bytes [40, 80, E2, 07, 80, FA, FF, ...]
---- EOF - GMER 2.1 ---- |