Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   PC Optimizer Pro (https://www.trojaner-board.de/147270-pc-optimizer-pro.html)

boti 03.01.2014 21:28

PC Optimizer Pro
 
Hallo
Ich habe mir leider auch den PC Optimizer Pro "eingefangen".
Habe danach gegoogelt und auch hier im Forum einen Thread bzgl. des Problems gefunden.
Das Forum Mitglied : cosinus , hat einem anderen Betroffenen bei der Beseitigung geholfen.
Ich benutze einen Toshiba Satellite Pro mit Windows 8.
Ich habe den ersten Schritt der Anleitung gemacht und habe das JRT - Junkware Removal Tool
installiert und einen scan damit gemacht.
Den Logfile habe ich auf meinem Desktop.

Kann mir Bitte jemand Weiterhelfen...das wäre echt Spitze.
Schon mal ein dickes : Danke Schön im voraus.

LG boti

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.9 (01.01.2014:1)
OS: Windows 8 x64
Ran by dagobert on 03.01.2014 at 21:09:37,13
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services

Successfully stopped: [Service] addonshelper
Failed to delete: [Service] addonshelper
Successfully stopped: [Service] cltmngsvc
Failed to delete: [Service] cltmngsvc



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113}
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3541415397-2149579106-852229368-1001\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\searchURL\\Default



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{562B9316-C08A-444A-9482-62080DD851AE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{D34F391D-4CB7-467F-A543-F583857C63B0}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\bonanzadealslive.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{118E1BF6-6279-432F-A285-373A77B90C7A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{14CEEA2F-3D21-46ED-A7D2-89056C520E5E}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1CC8D970-F626-4F19-815F-890032BB6606}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{33BAF587-9647-4281-A34F-F4830CDC1B9F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{5B5E5D0E-7C83-4A32-ADD2-E5F488DD6783}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{6802463D-636F-41FE-9924-4CAD56906590}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{806785D0-375F-4C2C-92E3-B8EE65D28E83}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{944661E7-67B9-4DF7-BFF2-05388C166D34}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A7CF66EF-4F0D-46B1-AF71-A500378D6C34}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B71934E5-6B93-448D-9D32-CBAA5150C5D8}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{C4BEF720-313C-420A-ACF6-77DD95D8F553}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{D34F391D-4CB7-467F-A543-F583857C63B0}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E970727E-0508-4BEB-8B72-BBA9D0D047C7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{EBF1F869-D2F0-4D31-A877-386C853A9C3D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F3CF4912-CF0A-451B-AF3B-C4F216C715E4}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\bonanzadeals
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\bonanzadealslive
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\iminent
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installcore
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\somoto
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3541415397-2149579106-852229368-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\bonanzadeals
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\bonanzadealslive
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\iminent
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\installcore
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealslive.oneclickctrl.9
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealslive.oneclickprocesslaunchermachine
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealslive.oneclickprocesslaunchermachine.1.0
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealslive.update3webcontrol.3
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.cocreateasync
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.cocreateasync.1.0
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.coreclass
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.coreclass.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.coremachineclass
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.coremachineclass.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.credentialdialogmachine
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.credentialdialogmachine.1.0
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.ondemandcomclassmachine
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.ondemandcomclassmachine.1.0
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.ondemandcomclassmachinefallback
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.ondemandcomclassmachinefallback.1.0
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.ondemandcomclasssvc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.ondemandcomclasssvc.1.0
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.processlauncher
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.processlauncher.1.0
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.update3comclassservice
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.update3comclassservice.1.0
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.update3webmachine
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.update3webmachine.1.0
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.update3webmachinefallback
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.update3webmachinefallback.1.0
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.update3websvc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bonanzadealsliveupdate.update3websvc.1.0
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4BEF720-313C-420A-ACF6-77DD95D8F553}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iminent_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iminent_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\snapdo_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\snapdo_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\bonanza deals
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\filesfrog update checker
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchthewebarp
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{d85ffe92-bf14-4e9b-bccd-e5c16069e65f}_is1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0041856.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0041856.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0041856.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0041856.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110411181156}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220422182256}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550455185556}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660466186656}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440444184456}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110411181156}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220422182256}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550455185556}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660466186656}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440444184456}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0041856.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0041856.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0041856.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0041856.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550455185556}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660466186656}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440444184456}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411181156}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411181156}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550455185556}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660466186656}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440444184456}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411181156}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}



~~~ Files

Successfully deleted: [File] C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job
Successfully deleted: [File] C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\bonanzadealslive"
Successfully deleted: [Folder] "C:\ProgramData\dsearchlink"
Successfully deleted: [Folder] "C:\Users\dagobert\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\dagobert\appdata\local\bonanzadealslive"
Successfully deleted: [Folder] "C:\Users\dagobert\appdata\local\filesfrog update checker"
Successfully deleted: [Folder] "C:\Users\dagobert\appdata\local\searchprotect"
Successfully deleted: [Folder] "C:\Program Files (x86)\bonanzadeals"
Successfully deleted: [Folder] "C:\Program Files (x86)\bonanzadealslive"
Successfully deleted: [Folder] "C:\Program Files (x86)\optimizer pro"
Successfully deleted: [Folder] "C:\Program Files (x86)\searchprotect"
Successfully deleted: [Folder] "C:\Users\dagobert\AppData\Roaming\microsoft\windows\start menu\programs\bonanzadeals"
Successfully deleted: [Folder] "C:\Users\dagobert\AppData\Roaming\microsoft\windows\start menu\programs\filesfrog update checker"
Successfully deleted: [Folder] "C:\Users\dagobert\documents\optimizer pro"



~~~ FireFox

Successfully deleted: [File] C:\Users\dagobert\AppData\Roaming\mozilla\firefox\profiles\ufdk0uqw.default\invalidprefs.js
Successfully deleted: [Folder] C:\Users\dagobert\AppData\Roaming\mozilla\firefox\profiles\ufdk0uqw.default\extensions\{5ebdca98-43b3-45bb-87e0-716029fb42ab}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.bdupdater.com/bonanzadealslive update;version=3
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.bdupdater.com/bonanzadealslive update;version=9
Successfully deleted the following from C:\Users\dagobert\AppData\Roaming\mozilla\firefox\profiles\ufdk0uqw.default\prefs.js

user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3317740&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SPC2563704-DD91-45AB-9F47-63B60B469F
user_pref("browser.search.defaultenginename", "Conduit Search");
user_pref("browser.search.selectedEngine", "Conduit Search");
user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3317740&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPC2563704-DD91-45AB-9F47-63B60B469F7A&SSP
user_pref("extensions.helperbar.SmartbarDisabled", false);
user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
user_pref("extensions.helperbar.downloadprovider", "somoto");
user_pref("extensions.helperbar.publisher", "somoto");
user_pref("iminent.LayoutId", "1");
user_pref("iminent.ShowThankyouPixel", "0");
user_pref("iminent.registerToolbarEvent101", "1383250273510");
user_pref("iminent.registerToolbarEvent140", "1383260583806");
user_pref("iminent.version", "7.43.4.1");
user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.43.4.1\",\"InstallEventCTime\":1383091714481,\"InstallEvent\":\"True\"}");
Emptied folder: C:\Users\dagobert\AppData\Roaming\mozilla\firefox\profiles\ufdk0uqw.default\minidumps [8 files]



~~~ Chrome

Successfully deleted: [Folder] C:\Users\dagobert\appdata\local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.01.2014 at 21:17:12,30
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


aharonov 04.01.2014 01:41

Hallo,

mach bitte einen FRST-Scan:


Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


boti 04.01.2014 12:58

Hi

...Super !
Danke für die schnelle Hilfe.
Hier die Beiden Scan Files :

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2014
Ran by dagobert (administrator) on PC on 04-01-2014 12:54:21
Running from C:\Users\dagobert\Desktop
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe
(ArtistScope Pty Ltd) C:\Program Files\Common Files\ArtistScope\CSHelper64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Users\dagobert\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
() C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
() C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe
() C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
() C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoResident.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe
() C:\Program Files (x86)\HiSuite\HiSuite.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
() C:\Users\dagobert\AppData\Local\HiSuite\userdata\hwtools\hwtransport.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
(Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
(Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
(Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
() C:\Program Files (x86)\The Geek\AGT Pro - Betfair\AGT Pro.exe
(Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
(Binteko Software) C:\Program Files (x86)\FairBot\FairBot.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [] - [x]
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13196432 2012-09-25] (Realtek Semiconductor)
HKLM\...\Run: [TCrdMain] - C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2611112 2012-09-04] ()
HKLM\...\Run: [TODDMain] - C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe [213136 2012-08-05] ()
HKLM\...\Run: [TecoResident] - C:\Program Files\TOSHIBA\Teco\TecoResident.exe [169896 2012-08-14] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] - C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [356776 2012-07-11] (TOSHIBA Corporation)
HKLM\...\Run: [SRS Premium Sound HD] - C:\Program Files\SRS Labs\SRS Control Panel\SRS_Premium_Sound_HD.zip [223242 2012-08-20] ()
HKLM\...\Run: [Ocs_SM] - C:\Users\dagobert\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [106496 2013-10-30] (OCS)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-08-01] (Intel Corporation)
HKLM-x32\...\Run: [TPUReg] - C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe [7148032 2012-10-31] (Pegatron Corporation)
HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-12-08] (AVAST Software)
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Mobile Partner] - C:\Program Files (x86)\HiSuite\HiSuite.exe [583488 2013-07-11] ()
MountPoints2: {7a08f65c-248b-11e3-be78-2cd05a211b8c} - "E:\SETUP.EXE"
MountPoints2: {b0225b53-6424-11e3-be8c-2cd05a211b8c} - "F:\autorun.exe"
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [ ] ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com/search?q={searchTerms}
SearchScopes: HKLM - DefaultScope {92A50442-8429-4206-B4B5-D839300467D8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MATMJS
SearchScopes: HKLM - {92A50442-8429-4206-B4B5-D839300467D8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MATMJS
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://www.bing.com/search?q={searchTerms}
BHO: LyriXeeker-1 - {11111111-1111-1111-1111-110411181156} - C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-bho64.dll (Lyrics)
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: DNS Error Helper - {9B6B03F1-16CF-4491-BBBB-E872802DD717} - C:\ProgramData\DNSErrorHelper\bho.dll ()
BHO-x32: BatBrowse - {b67b3dbb-c1c9-49d2-b016-2748b0b5017e} - C:\Program Files (x86)\BatBrowse\BatBrowseBHO.dll (BatBrowse)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
BHO-x32: BonanzaDeals - {fe063412-bea4-4d76-8ed3-183be6220d17} - C:\Program Files (x86)\BonanzaDeals\BonanzaDealsIE.dll No File
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default
FF Keyword.URL: hxxp://www.google.com/search?rls=org.mozilla:en-US:official&client=firefox-a&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @artistscope.com/DRMPlugin - C:\Program Files (x86)\CopySafe PDF Reader\npArtistScopeDRM.dll ()
FF Plugin-x32: @artistscope.com/PDFReaderWeb - C:\Program Files (x86)\CopySafe PDF Reader\npPDFReaderWeb.dll (ArtistScope Pty Ltd)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @artistscope.com/PDFReaderWeb - C:\Program Files (x86)\CopySafe PDF Reader\npPDFReaderWeb.dll (ArtistScope Pty Ltd)
FF SearchPlugin: C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: FireJump - C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default\Extensions\firejump@firejump.net
FF Extension: ProxTube - Unblock YouTube - C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default\Extensions\ich@maltegoetz.de
FF Extension: BatBrowse - C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default\Extensions\firefox@batbrowse.com.xpi
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [dnshelp@dnshelp.com] - C:\Users\dagobert\AppData\Roaming\Helper
FF Extension: Helper - C:\Users\dagobert\AppData\Roaming\Helper
FF HKCU\...\Firefox\Extensions: [firejump@firejump.net] - C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default\extensions\firejump@firejump.net
FF Extension: FireJump - C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default\extensions\firejump@firejump.net

Chrome:
=======
CHR HomePage: http:\/\/search.conduit.com\/?ctid=CT3317740&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPC2563704-DD91-45AB-9F47-63B60B469F7A&SSPV=
CHR RestoreOnStartup: "http:\/\/search.conduit.com\/?ctid=CT3317740&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPC2563704-DD91-45AB-9F47-63B60B469F7A&SSPV="
CHR DefaultSearchURL: http:\/\/search.conduit.com\/Results.aspx?ctid=CT3317740&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPC2563704-DD91-45AB-9F47-63B60B469F7A&q={searchTerms}&SSPV=
CHR Extension: (ProxTube) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.1.0_0
CHR Extension: (Google Docs) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (BatBrowse) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccncljhbalbbkkfgopogabimepmfkmff\1.0.0_0
CHR Extension: (Google Search) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (LyriXeeker-1) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgmpcnmaamenhngcinchjeifhhnlaig\1.24.10_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [aakchaleigkohafkfjfjbblobjifikek] - C:\Users\dagobert\AppData\LocalLow\proxtube\CHROME\proxtube.crx
CHR HKLM-x32\...\Chrome\Extension: [ccncljhbalbbkkfgopogabimepmfkmff] - C:\Program Files (x86)\BatBrowse\ccncljhbalbbkkfgopogabimepmfkmff.crx

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-08] (AVAST Software)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-06-29] (IvoSoft)
R2 CSHelper; C:\Program Files\Common Files\ArtistScope\CSHelper64.exe [361552 2013-12-12] (ArtistScope Pty Ltd)
R2 GFNEXSrv; C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe [156672 2011-10-13] ()
R2 HiSuiteOuc64.exe; C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe [137024 2013-07-11] ()
R2 HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [197632 2013-05-02] ()
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201360 2012-08-31] (Realtek Semiconductor)
R2 SearchAnonymizer; C:\Users\dagobert\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [40960 2013-10-30] ()
R3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [116088 2013-07-18] (Toshiba Europe GmbH)
R2 Update BatBrowse; C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe [66336 2013-11-07] ()
R2 Util BatBrowse; C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe [66336 2013-11-07] ()
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
S2 bonanzadealslive; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe /svc [x]
S3 bonanzadealslivem; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe /medsvc [x]

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [38984 2013-12-08] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [84328 2013-12-08] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2013-12-08] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-08] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1032416 2013-12-08] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [409832 2013-12-08] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-12-08] ()
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 CSDriver; C:\Program Files\Common Files\ArtistScope\CSDriver64.sys [61424 2013-12-12] ()
R2 PEGAGFN; C:\Program Files (x86)\TOSHIBA\Password Utility\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [24208 2012-07-11] (Realtek Microelectronics)
S3 RTL8192Ce; C:\Windows\system32\DRIVERS\rtwlane.sys [1498256 2012-08-29] (Realtek Semiconductor Corporation                          )
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1498256 2012-08-29] (Realtek Semiconductor Corporation                          )
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-16] (Synaptics Incorporated)
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [28632 2012-07-31] (Windows (R) Win 7 DDK provider)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2011-10-24] (Huawei Technologies Co., Ltd.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-04 12:53 - 2014-01-04 12:54 - 00029416 _____ C:\Users\dagobert\Desktop\Addition.txt
2014-01-04 12:51 - 2014-01-04 12:54 - 00020415 _____ C:\Users\dagobert\Desktop\FRST.txt
2014-01-04 12:51 - 2014-01-04 12:51 - 00000000 ____D C:\FRST
2014-01-04 12:50 - 2014-01-04 12:50 - 01931368 _____ (Farbar) C:\Users\dagobert\Desktop\FRST64.exe
2014-01-03 21:39 - 2014-01-03 21:39 - 01233962 _____ C:\Users\dagobert\Desktop\adwcleaner.exe
2014-01-03 21:17 - 2014-01-03 21:17 - 00017071 _____ C:\Users\dagobert\Desktop\JRT.txt
2014-01-03 21:08 - 2014-01-03 21:08 - 00000000 ____D C:\windows\ERUNT
2014-01-03 21:02 - 2014-01-03 21:02 - 01036305 _____ (Thisisu) C:\Users\dagobert\Desktop\JRT.exe
2014-01-03 20:54 - 2014-01-03 21:29 - 106000000 _____ C:\Users\dagobert\Downloads\BRRTB_DENUADH_PG.part1.rar
2014-01-02 21:22 - 2014-01-02 21:38 - 48281764 _____ C:\Users\dagobert\Downloads\RTB_M_PG.rar
2014-01-02 17:46 - 2014-01-02 17:46 - 05629632 _____ (IvoSoft) C:\Users\dagobert\Downloads\ClassicShellSetup_4_0_2.exe
2014-01-02 12:01 - 2014-01-02 12:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-02 11:18 - 2014-01-02 11:18 - 00000000 ____D C:\Users\dagobert\Desktop\MyPhoneExplorer portable
2014-01-02 11:15 - 2014-01-02 11:15 - 07080248 _____ C:\Users\dagobert\Downloads\MyPhoneExplorer_1.8.5.exe
2014-01-02 10:51 - 2014-01-02 10:51 - 00001173 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-01-02 10:51 - 2014-01-02 10:51 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2014-01-01 22:29 - 2014-01-03 21:07 - 00000000 ____D C:\Users\dagobert\Desktop\Loreena McKennitt - Troubadours On The Rhine (2012)
2014-01-01 22:26 - 2014-01-01 22:26 - 00001732 _____ C:\Users\dagobert\Desktop\dee8bf01883ccfcc31d20370e4879aac.dlc
2014-01-01 21:55 - 2014-01-01 21:55 - 102703242 _____ C:\Users\dagobert\Desktop\Rhein.rar
2013-12-30 18:56 - 2013-12-30 18:56 - 00001171 _____ C:\Users\dagobert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-12-30 12:54 - 2013-12-30 12:54 - 00189714 _____ C:\Users\dagobert\Desktop\1by1_181.exe
2013-12-30 12:52 - 2013-12-30 13:07 - 00000000 ____D C:\Users\dagobert\AppData\Local\Mobogenie
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 ____D C:\Users\dagobert\Documents\Mobogenie
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 ____D C:\Users\dagobert\AppData\Local\cache
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 _____ C:\Users\dagobert\daemonprocess.txt
2013-12-30 12:51 - 2013-12-30 18:54 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2013-12-30 12:51 - 2013-12-30 12:51 - 00003248 _____ C:\windows\System32\Tasks\SomotoUpdateCheckerAutoStart
2013-12-30 12:43 - 2013-12-30 12:43 - 00000000 ____D C:\Users\dagobert\Desktop\Loreena McKenitt
2013-12-29 21:05 - 2013-12-29 21:05 - 00001873 _____ C:\Users\Public\Desktop\FLAC Frontend.lnk
2013-12-29 21:05 - 2013-12-29 21:05 - 00000000 ____D C:\Program Files (x86)\FLAC
2013-12-27 20:51 - 2013-12-27 20:51 - 02744087 _____ C:\Users\dagobert\Desktop\flac-1.2.1b.exe
2013-12-27 20:47 - 2013-07-13 19:55 - 47718685 ____R C:\Users\dagobert\Downloads\07. Loreena McKennitt - God Rest Ye Merry, Gentlemen (Abdelli Version).flac
2013-12-27 20:47 - 2013-07-13 19:55 - 24117606 ____R C:\Users\dagobert\Downloads\05. Loreena McKennitt - Good King Wenceslas.flac
2013-12-27 20:47 - 2013-07-13 19:55 - 12544244 ____R C:\Users\dagobert\Downloads\06. Loreena McKennitt - Coventry Carol.flac
2013-12-27 20:47 - 2013-07-13 19:54 - 35967651 ____R C:\Users\dagobert\Downloads\04. Loreena McKennitt - Noël Nouvelet !.flac
2013-12-27 20:47 - 2013-07-13 19:54 - 32452407 ____R C:\Users\dagobert\Downloads\08. Loreena McKennitt - Snow.flac
2013-12-27 20:47 - 2013-07-13 19:54 - 30110016 ____R C:\Users\dagobert\Downloads\10. Loreena McKennitt - Seeds Of Love.flac
2013-12-27 20:47 - 2013-07-13 19:54 - 25602457 ____R C:\Users\dagobert\Downloads\12. Loreena McKennitt - Emmanuel.flac
2013-12-27 20:47 - 2013-07-13 19:53 - 16734714 ____R C:\Users\dagobert\Downloads\11. Loreena McKennitt - Gloucestershire Wassail.flac
2013-12-27 20:47 - 2013-07-13 19:52 - 29194831 ____R C:\Users\dagobert\Downloads\03. Loreena McKennitt - The Seven Rejoices Of Mary.flac
2013-12-27 20:47 - 2013-07-13 19:52 - 18437355 ____R C:\Users\dagobert\Downloads\09. Loreena McKennitt - Breton Carol.flac
2013-12-27 20:47 - 2013-07-13 19:51 - 25009882 ____R C:\Users\dagobert\Downloads\01. Loreena McKennitt - The Holly And The Ivy.flac
2013-12-27 20:47 - 2013-07-13 19:49 - 20316857 ____R C:\Users\dagobert\Downloads\02. Loreena McKennitt - Un Flambeau, Jeannette, Isabelle.flac
2013-12-27 20:47 - 2013-07-13 19:49 - 14078965 ____R C:\Users\dagobert\Downloads\13. Loreena McKennitt - In The Bleak Midwinter.flac
2013-12-27 20:47 - 2013-07-13 19:43 - 00006095 ____R C:\Users\dagobert\Downloads\Loreena McKennitt - A Midwinter Night's Dream.log
2013-12-27 20:47 - 2013-07-13 19:43 - 00002707 ____R C:\Users\dagobert\Downloads\A Midwinter Night's Dream.cue
2013-12-27 20:47 - 2013-07-13 19:43 - 00001364 ____R C:\Users\dagobert\Downloads\Loreena McKennitt - A Midwinter Night's Dream.m3u
2013-12-27 20:47 - 2013-07-13 19:43 - 00000000 ____D C:\Users\dagobert\Downloads\Scans
2013-12-27 20:45 - 2013-12-27 20:45 - 00000000 ____D C:\Program Files\7-Zip
2013-12-27 18:15 - 2014-01-02 21:21 - 338124282 _____ C:\Users\dagobert\Downloads\497834093840394.7z
2013-12-27 18:07 - 2013-12-27 18:15 - 23551482 _____ C:\Users\dagobert\Downloads\497834093840394.7z.004
2013-12-26 17:27 - 2013-12-26 18:01 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.003
2013-12-25 21:00 - 2013-12-25 21:34 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.002
2013-12-25 17:03 - 2013-12-25 17:38 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.001
2013-12-25 16:44 - 2014-01-02 22:40 - 00000000 ____D C:\Users\dagobert\Desktop\CD
2013-12-23 16:02 - 2013-12-23 16:02 - 00002786 _____ C:\Users\dagobert\AppData\Local\recently-used.xbel
2013-12-23 16:02 - 2013-12-23 16:02 - 00000000 ____D C:\Users\dagobert\AppData\Local\gtk-2.0
2013-12-23 09:19 - 2013-12-23 09:19 - 00000000 ____D C:\Users\dagobert\.android
2013-12-23 09:18 - 2014-01-02 11:13 - 00000000 ____D C:\Users\dagobert\Documents\HiSuite
2013-12-23 09:18 - 2013-12-23 09:19 - 00000000 ____D C:\Users\dagobert\AppData\Local\HiSuite
2013-12-23 09:18 - 2013-12-23 09:18 - 00001002 _____ C:\Users\Public\Desktop\HiSuite.lnk
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\ProgramData\HiSuiteOuc
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\ProgramData\HandSetService
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\Program Files (x86)\HiSuite
2013-12-23 09:18 - 2012-02-08 10:07 - 00281088 _____ (Huawei Technologies Co., Ltd.) C:\windows\system32\Drivers\hw_quusbnet.sys
2013-12-23 09:18 - 2011-10-24 05:04 - 00223232 _____ (Huawei Technologies Co., Ltd.) C:\windows\system32\Drivers\hw_quusbmdm.sys
2013-12-23 09:18 - 2011-10-24 04:51 - 00116864 _____ (Huawei Technologies Co., Ltd.) C:\windows\system32\Drivers\hw_usbdev.sys
2013-12-23 09:18 - 2010-02-19 00:00 - 01533512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFUpdate_01007.dll
2013-12-23 09:18 - 2010-02-19 00:00 - 01490656 _____ (Microsoft Corporation) C:\windows\system32\WdfCoInstaller01007.dll
2013-12-23 09:18 - 2010-02-19 00:00 - 01490656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfCoInstaller01007.dll
2013-12-23 09:18 - 2010-02-19 00:00 - 00708168 _____ (Microsoft Corporation) C:\windows\system32\WinUSBCoInstaller.dll
2013-12-23 09:18 - 2010-02-19 00:00 - 00708168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WinUSBCoInstaller.dll
2013-12-23 09:15 - 2013-12-23 09:15 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-12-19 13:51 - 2012-04-05 14:44 - 00000000 ____D C:\Users\dagobert\Downloads\Secret Garden
2013-12-19 12:36 - 2013-12-19 13:51 - 451675335 _____ C:\Users\dagobert\Downloads\Secret Garden.part3.rar
2013-12-19 06:21 - 2013-12-19 07:57 - 576716800 _____ C:\Users\dagobert\Downloads\Secret Garden.part2.rar
2013-12-19 00:22 - 2013-12-19 00:22 - 00000026 _____ C:\Users\dagobert\AppData\Roaming\WB.CFG
2013-12-18 21:12 - 2013-12-19 00:25 - 576716800 _____ C:\Users\dagobert\Downloads\Secret Garden.part1.rar
2013-12-15 11:36 - 2013-12-15 11:36 - 110600192 _____ C:\Users\dagobert\Desktop\ebook 2.camrec
2013-12-15 11:09 - 2013-12-15 11:09 - 47251456 _____ C:\Users\dagobert\Desktop\insidertips ebook.camrec
2013-12-15 11:04 - 2013-12-15 11:04 - 167469056 _____ C:\Users\dagobert\Desktop\insidertips.at.camrec
2013-12-13 19:31 - 2013-12-13 19:31 - 555133442 _____ C:\windows\MEMORY.DMP
2013-12-13 19:31 - 2013-12-13 19:31 - 00424616 _____ C:\windows\system32\FNTCACHE.DAT
2013-12-13 19:31 - 2013-12-13 19:31 - 00285928 _____ C:\windows\Minidump\121313-38265-01.dmp
2013-12-13 19:31 - 2013-12-13 19:31 - 00000000 ____D C:\windows\Minidump
2013-12-13 16:26 - 2013-12-13 16:26 - 08065024 _____ C:\Users\dagobert\Desktop\capture-1.camrec
2013-12-13 14:40 - 2013-12-13 14:40 - 07613196 _____ C:\Users\dagobert\Desktop\104751_Mach_dich_zum_Gewinner_2.enc
2013-12-13 12:54 - 2013-12-13 12:54 - 00000000 ____D C:\Users\dagobert\AppData\Roaming\AVAST Software
2013-12-12 22:03 - 2013-12-12 22:03 - 00008942 _____ C:\Users\dagobert\Desktop\InsidertippsEachWay(1).zip
2013-12-12 22:00 - 2013-12-12 22:00 - 00008942 _____ C:\Users\dagobert\Desktop\InsidertippsEachWay.zip
2013-12-12 21:28 - 2013-12-12 21:28 - 00002022 _____ C:\Users\Public\Desktop\CopySafe PDF Reader.lnk
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\windows\CopySafe PDF Reader
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\Program Files\Common Files\ArtistScope
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\Program Files (x86)\CopySafe PDF Reader
2013-12-12 21:26 - 2013-12-12 21:26 - 06280128 _____ (ArtistScope) C:\Users\dagobert\Desktop\CopysafePDFreader.exe
2013-12-11 18:34 - 2013-12-11 18:34 - 00000000 ____D C:\Users\dagobert\.thumbnails
2013-12-11 18:30 - 2013-12-23 16:02 - 00000000 ____D C:\Users\dagobert\.gimp-2.8
2013-12-11 18:30 - 2013-12-11 18:30 - 00000000 ____D C:\Users\dagobert\AppData\Local\gegl-0.2
2013-12-11 18:27 - 2013-12-11 18:28 - 00000000 ____D C:\Program Files\GIMP 2
2013-12-11 16:24 - 2013-10-25 07:19 - 02241536 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-12-11 16:24 - 2013-10-25 07:19 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-12-11 16:24 - 2013-10-25 07:19 - 00915968 _____ (Microsoft Corporation) C:\windows\system32\uxtheme.dll
2013-12-11 16:24 - 2013-10-25 07:19 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-12-11 16:24 - 2013-10-25 07:18 - 19271168 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-12-11 16:24 - 2013-10-25 07:18 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-12-11 16:24 - 2013-10-25 07:17 - 15404032 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-12-11 16:24 - 2013-10-25 07:17 - 03959808 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-12-11 16:24 - 2013-10-25 07:17 - 02648576 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-12-11 16:24 - 2013-10-25 07:17 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-12-11 16:24 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-12-11 16:24 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-12-11 16:24 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-12-11 16:24 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-12-11 16:24 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-12-11 16:24 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-12-11 16:24 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-12-11 16:24 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-12-11 16:24 - 2013-10-19 06:45 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2013-12-11 16:24 - 2013-10-19 05:04 - 00059392 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2013-12-11 16:24 - 2013-10-09 02:33 - 00059416 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2013-12-11 16:24 - 2013-10-08 23:30 - 00628736 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2013-12-11 16:24 - 2013-10-08 23:30 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2013-12-11 16:24 - 2013-10-08 23:30 - 00084992 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2013-12-11 16:24 - 2013-10-08 23:30 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2013-12-11 16:24 - 2013-10-08 23:28 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2013-12-11 16:24 - 2013-10-08 23:27 - 03279872 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 01622016 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 00773120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 00252928 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\storewuauth.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 00142848 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 00099328 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2013-12-11 16:24 - 2013-10-05 07:10 - 00285016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\spaceport.sys
2013-12-11 16:24 - 2013-10-03 23:09 - 00385528 _____ C:\windows\system32\ApnDatabase.xml
2013-12-11 16:24 - 2013-10-02 03:50 - 00447320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
2013-12-11 16:24 - 2013-09-28 06:48 - 00778752 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2013-12-11 16:24 - 2013-09-28 04:58 - 00551424 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2013-12-11 16:24 - 2013-09-19 08:32 - 01455448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2013-12-11 16:24 - 2013-08-30 06:19 - 00626688 _____ (Microsoft Corporation) C:\windows\system32\resutils.dll
2013-12-11 16:24 - 2013-08-30 06:18 - 00374784 _____ (Microsoft Corporation) C:\windows\system32\clusapi.dll
2013-12-11 16:24 - 2013-08-30 00:48 - 00488960 _____ (Microsoft Corporation) C:\windows\SysWOW64\resutils.dll
2013-12-11 16:24 - 2013-08-30 00:47 - 00302080 _____ (Microsoft Corporation) C:\windows\SysWOW64\clusapi.dll
2013-12-11 16:23 - 2013-11-23 07:43 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2013-12-11 16:23 - 2013-11-23 06:05 - 00368640 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2013-12-11 16:23 - 2013-11-07 00:18 - 04036608 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-12-11 16:23 - 2013-11-01 06:38 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2013-12-11 16:23 - 2013-11-01 04:49 - 00273408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2013-12-11 16:23 - 2013-10-10 10:32 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe
2013-12-11 16:23 - 2013-10-10 10:30 - 00162304 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrobj.dll
2013-12-11 16:23 - 2013-10-10 10:30 - 00156160 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2013-12-11 16:23 - 2013-10-10 10:24 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2013-12-11 16:23 - 2013-10-10 10:23 - 00146944 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2013-12-11 16:23 - 2013-10-10 10:22 - 00222720 _____ (Microsoft Corporation) C:\windows\system32\scrobj.dll
2013-12-11 16:23 - 2013-10-10 10:22 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2013-12-11 16:23 - 2013-09-28 04:35 - 00288768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-01-04 12:54 - 2014-01-04 12:53 - 00029416 _____ C:\Users\dagobert\Desktop\Addition.txt
2014-01-04 12:54 - 2014-01-04 12:51 - 00020415 _____ C:\Users\dagobert\Desktop\FRST.txt
2014-01-04 12:51 - 2014-01-04 12:51 - 00000000 ____D C:\FRST
2014-01-04 12:50 - 2014-01-04 12:50 - 01931368 _____ (Farbar) C:\Users\dagobert\Desktop\FRST64.exe
2014-01-04 12:45 - 2013-11-17 22:04 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2014-01-04 12:45 - 2013-09-21 03:41 - 01570532 _____ C:\windows\WindowsUpdate.log
2014-01-04 12:37 - 2012-07-26 09:12 - 00000000 ____D C:\windows\system32\sru
2014-01-04 12:35 - 2013-09-22 21:22 - 00001308 _____ C:\windows\Tasks\LyriXeeker-1-updater.job
2014-01-04 12:35 - 2013-09-22 21:21 - 00001922 _____ C:\windows\Tasks\LyriXeeker-1-chromeinstaller.job
2014-01-04 12:35 - 2013-09-22 20:17 - 00001116 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-03 21:56 - 2013-09-22 20:43 - 00000000 ____D C:\Users\dagobert\AppData\Roaming\Skype
2014-01-03 21:39 - 2014-01-03 21:39 - 01233962 _____ C:\Users\dagobert\Desktop\adwcleaner.exe
2014-01-03 21:34 - 2013-09-22 20:17 - 00001120 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-03 21:29 - 2014-01-03 20:54 - 106000000 _____ C:\Users\dagobert\Downloads\BRRTB_DENUADH_PG.part1.rar
2014-01-03 21:22 - 2013-10-29 23:22 - 00000306 _____ C:\windows\Tasks\FoxTab.job
2014-01-03 21:17 - 2014-01-03 21:17 - 00017071 _____ C:\Users\dagobert\Desktop\JRT.txt
2014-01-03 21:08 - 2014-01-03 21:08 - 00000000 ____D C:\windows\ERUNT
2014-01-03 21:07 - 2014-01-01 22:29 - 00000000 ____D C:\Users\dagobert\Desktop\Loreena McKennitt - Troubadours On The Rhine (2012)
2014-01-03 21:02 - 2014-01-03 21:02 - 01036305 _____ (Thisisu) C:\Users\dagobert\Desktop\JRT.exe
2014-01-03 20:06 - 2013-10-05 21:58 - 00000000 ____D C:\Users\dagobert\AppData\Local\PokerStars.EU
2014-01-03 16:50 - 2013-10-09 22:35 - 00000000 ____D C:\Users\dagobert\AppData\Local\CrashDumps
2014-01-03 16:37 - 2012-07-26 09:12 - 00000000 ____D C:\windows\AUInstallAgent
2014-01-03 14:43 - 2012-07-26 09:12 - 00000000 ____D C:\windows\system32\FxsTmp
2014-01-02 22:40 - 2013-12-25 16:44 - 00000000 ____D C:\Users\dagobert\Desktop\CD
2014-01-02 21:38 - 2014-01-02 21:22 - 48281764 _____ C:\Users\dagobert\Downloads\RTB_M_PG.rar
2014-01-02 21:21 - 2013-12-27 18:15 - 338124282 _____ C:\Users\dagobert\Downloads\497834093840394.7z
2014-01-02 17:46 - 2014-01-02 17:46 - 05629632 _____ (IvoSoft) C:\Users\dagobert\Downloads\ClassicShellSetup_4_0_2.exe
2014-01-02 17:46 - 2013-09-23 14:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-02 12:01 - 2014-01-02 12:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-02 11:18 - 2014-01-02 11:18 - 00000000 ____D C:\Users\dagobert\Desktop\MyPhoneExplorer portable
2014-01-02 11:15 - 2014-01-02 11:15 - 07080248 _____ C:\Users\dagobert\Downloads\MyPhoneExplorer_1.8.5.exe
2014-01-02 11:13 - 2013-12-23 09:18 - 00000000 ____D C:\Users\dagobert\Documents\HiSuite
2014-01-02 11:12 - 2012-08-01 17:55 - 00780976 _____ C:\windows\system32\perfh010.dat
2014-01-02 11:12 - 2012-08-01 17:55 - 00152608 _____ C:\windows\system32\perfc010.dat
2014-01-02 11:12 - 2012-08-01 17:38 - 00753134 _____ C:\windows\system32\perfh007.dat
2014-01-02 11:12 - 2012-08-01 17:38 - 00155826 _____ C:\windows\system32\perfc007.dat
2014-01-02 11:12 - 2012-07-26 08:28 - 02679026 _____ C:\windows\system32\PerfStringBackup.INI
2014-01-02 11:02 - 2013-10-21 11:21 - 00000000 ____D C:\Users\dagobert\AppData\Roaming\TeamViewer
2014-01-02 11:00 - 2012-07-26 08:21 - 00030044 _____ C:\windows\setupact.log
2014-01-02 10:51 - 2014-01-02 10:51 - 00001173 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-01-02 10:51 - 2014-01-02 10:51 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2014-01-01 22:26 - 2014-01-01 22:26 - 00001732 _____ C:\Users\dagobert\Desktop\dee8bf01883ccfcc31d20370e4879aac.dlc
2014-01-01 21:55 - 2014-01-01 21:55 - 102703242 _____ C:\Users\dagobert\Desktop\Rhein.rar
2013-12-30 18:56 - 2013-12-30 18:56 - 00001171 _____ C:\Users\dagobert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-12-30 18:54 - 2013-12-30 12:51 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2013-12-30 13:07 - 2013-12-30 12:52 - 00000000 ____D C:\Users\dagobert\AppData\Local\Mobogenie
2013-12-30 12:54 - 2013-12-30 12:54 - 00189714 _____ C:\Users\dagobert\Desktop\1by1_181.exe
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 ____D C:\Users\dagobert\Documents\Mobogenie
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 ____D C:\Users\dagobert\AppData\Local\cache
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 _____ C:\Users\dagobert\daemonprocess.txt
2013-12-30 12:52 - 2013-09-21 03:43 - 00000000 ____D C:\Users\dagobert
2013-12-30 12:51 - 2013-12-30 12:51 - 00003248 _____ C:\windows\System32\Tasks\SomotoUpdateCheckerAutoStart
2013-12-30 12:43 - 2013-12-30 12:43 - 00000000 ____D C:\Users\dagobert\Desktop\Loreena McKenitt
2013-12-29 21:05 - 2013-12-29 21:05 - 00001873 _____ C:\Users\Public\Desktop\FLAC Frontend.lnk
2013-12-29 21:05 - 2013-12-29 21:05 - 00000000 ____D C:\Program Files (x86)\FLAC
2013-12-27 20:51 - 2013-12-27 20:51 - 02744087 _____ C:\Users\dagobert\Desktop\flac-1.2.1b.exe
2013-12-27 20:45 - 2013-12-27 20:45 - 00000000 ____D C:\Program Files\7-Zip
2013-12-27 20:41 - 2013-10-29 23:23 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-12-27 18:15 - 2013-12-27 18:07 - 23551482 _____ C:\Users\dagobert\Downloads\497834093840394.7z.004
2013-12-26 21:14 - 2013-10-08 18:13 - 00000000 ____D C:\Users\dagobert\Desktop\Neuer Ordner
2013-12-26 18:01 - 2013-12-26 17:27 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.003
2013-12-25 21:34 - 2013-12-25 21:00 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.002
2013-12-25 17:38 - 2013-12-25 17:03 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.001
2013-12-25 16:46 - 2013-10-04 10:28 - 00000000 ____D C:\Users\dagobert\Desktop\Facebook Bilder
2013-12-25 16:45 - 2013-10-09 10:07 - 00000000 ____D C:\Users\dagobert\Desktop\Arturas
2013-12-23 17:00 - 2013-10-19 19:59 - 00001002 _____ C:\Users\dagobert\Desktop\FairBot.lnk
2013-12-23 17:00 - 2013-10-19 19:59 - 00000000 ____D C:\Program Files (x86)\FairBot
2013-12-23 16:02 - 2013-12-23 16:02 - 00002786 _____ C:\Users\dagobert\AppData\Local\recently-used.xbel
2013-12-23 16:02 - 2013-12-23 16:02 - 00000000 ____D C:\Users\dagobert\AppData\Local\gtk-2.0
2013-12-23 16:02 - 2013-12-11 18:30 - 00000000 ____D C:\Users\dagobert\.gimp-2.8
2013-12-23 09:19 - 2013-12-23 09:19 - 00000000 ____D C:\Users\dagobert\.android
2013-12-23 09:19 - 2013-12-23 09:18 - 00000000 ____D C:\Users\dagobert\AppData\Local\HiSuite
2013-12-23 09:18 - 2013-12-23 09:18 - 00001002 _____ C:\Users\Public\Desktop\HiSuite.lnk
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\ProgramData\HiSuiteOuc
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\ProgramData\HandSetService
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\Program Files (x86)\HiSuite
2013-12-23 09:15 - 2013-12-23 09:15 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-12-22 21:46 - 2013-11-06 21:46 - 00000000 ____D C:\Users\dagobert\Desktop\Fussi Trades
2013-12-22 21:46 - 2013-10-01 13:03 - 00000000 ____D C:\Users\dagobert\Desktop\tex
2013-12-19 13:51 - 2013-12-19 12:36 - 451675335 _____ C:\Users\dagobert\Downloads\Secret Garden.part3.rar
2013-12-19 12:41 - 2013-09-22 20:43 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-12-19 12:41 - 2013-09-22 20:42 - 00000000 ____D C:\ProgramData\Skype
2013-12-19 07:57 - 2013-12-19 06:21 - 576716800 _____ C:\Users\dagobert\Downloads\Secret Garden.part2.rar
2013-12-19 00:25 - 2013-12-18 21:12 - 576716800 _____ C:\Users\dagobert\Downloads\Secret Garden.part1.rar
2013-12-19 00:22 - 2013-12-19 00:22 - 00000026 _____ C:\Users\dagobert\AppData\Roaming\WB.CFG
2013-12-15 18:29 - 2013-10-05 21:58 - 00000000 ____D C:\Program Files (x86)\PokerStars.EU
2013-12-15 11:36 - 2013-12-15 11:36 - 110600192 _____ C:\Users\dagobert\Desktop\ebook 2.camrec
2013-12-15 11:35 - 2013-10-09 15:12 - 00004096 _____ C:\Users\dagobert\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-15 11:09 - 2013-12-15 11:09 - 47251456 _____ C:\Users\dagobert\Desktop\insidertips ebook.camrec
2013-12-15 11:04 - 2013-12-15 11:04 - 167469056 _____ C:\Users\dagobert\Desktop\insidertips.at.camrec
2013-12-14 22:11 - 2012-07-26 09:12 - 00000000 ____D C:\windows\rescache
2013-12-14 22:00 - 2013-09-22 22:09 - 00000000 ____D C:\windows\system32\MRT
2013-12-14 21:58 - 2013-09-22 22:09 - 90708896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-12-14 21:23 - 2013-09-23 17:36 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2013-12-13 19:31 - 2013-12-13 19:31 - 555133442 _____ C:\windows\MEMORY.DMP
2013-12-13 19:31 - 2013-12-13 19:31 - 00424616 _____ C:\windows\system32\FNTCACHE.DAT
2013-12-13 19:31 - 2013-12-13 19:31 - 00285928 _____ C:\windows\Minidump\121313-38265-01.dmp
2013-12-13 19:31 - 2013-12-13 19:31 - 00000000 ____D C:\windows\Minidump
2013-12-13 19:31 - 2012-07-26 08:22 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-12-13 16:26 - 2013-12-13 16:26 - 08065024 _____ C:\Users\dagobert\Desktop\capture-1.camrec
2013-12-13 14:40 - 2013-12-13 14:40 - 07613196 _____ C:\Users\dagobert\Desktop\104751_Mach_dich_zum_Gewinner_2.enc
2013-12-13 12:54 - 2013-12-13 12:54 - 00000000 ____D C:\Users\dagobert\AppData\Roaming\AVAST Software
2013-12-13 12:51 - 2012-11-14 03:05 - 00060180 _____ C:\windows\PFRO.log
2013-12-12 23:16 - 2012-07-26 06:26 - 00262144 ___SH C:\windows\system32\config\BBI
2013-12-12 23:14 - 2012-07-26 09:12 - 00000000 ____D C:\windows\system32\SecureBootUpdates
2013-12-12 22:03 - 2013-12-12 22:03 - 00008942 _____ C:\Users\dagobert\Desktop\InsidertippsEachWay(1).zip
2013-12-12 22:00 - 2013-12-12 22:00 - 00008942 _____ C:\Users\dagobert\Desktop\InsidertippsEachWay.zip
2013-12-12 21:28 - 2013-12-12 21:28 - 00002022 _____ C:\Users\Public\Desktop\CopySafe PDF Reader.lnk
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\windows\CopySafe PDF Reader
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\Program Files\Common Files\ArtistScope
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\Program Files (x86)\CopySafe PDF Reader
2013-12-12 21:26 - 2013-12-12 21:26 - 06280128 _____ (ArtistScope) C:\Users\dagobert\Desktop\CopysafePDFreader.exe
2013-12-11 18:34 - 2013-12-11 18:34 - 00000000 ____D C:\Users\dagobert\.thumbnails
2013-12-11 18:30 - 2013-12-11 18:30 - 00000000 ____D C:\Users\dagobert\AppData\Local\gegl-0.2
2013-12-11 18:28 - 2013-12-11 18:27 - 00000000 ____D C:\Program Files\GIMP 2
2013-12-11 16:29 - 2013-09-23 21:14 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 16:27 - 2012-07-26 06:38 - 00000000 ____D C:\windows\system32\oobe
2013-12-10 19:45 - 2013-11-17 22:04 - 00003772 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-12-09 10:46 - 2013-09-21 03:50 - 00003598 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3541415397-2149579106-852229368-1001
2013-12-08 19:54 - 2013-09-23 17:36 - 01032416 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00409832 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00334648 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2013-12-08 19:54 - 2013-09-23 17:36 - 00205320 _____ C:\windows\system32\Drivers\aswVmm.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00092544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00084328 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00065776 _____ C:\windows\system32\Drivers\aswRvrt.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00038984 _____ (AVAST Software) C:\windows\system32\Drivers\aswFsBlk.sys
2013-12-08 19:54 - 2013-09-23 17:34 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2013-12-08 19:52 - 2013-09-23 17:34 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-08 19:51 - 2013-09-23 17:36 - 00000000 _____ C:\windows\SysWOW64\config.nt
2013-12-06 09:16 - 2013-09-24 14:49 - 00000000 ____D C:\Users\dagobert\Desktop\MAG
2013-12-06 07:40 - 2013-09-23 21:14 - 00000000 ____D C:\Users\dagobert\AppData\Local\Microsoft Help
2013-12-06 06:36 - 2013-09-22 20:17 - 00002186 _____ C:\Users\Public\Desktop\Google Chrome.lnk

Some content of TEMP:
====================
C:\Users\ADMINI~1\AppData\Local\Temp\PresentationCore.dll
C:\Users\ADMINI~1\AppData\Local\Temp\PresentationFramework.dll
C:\Users\ADMINI~1\AppData\Local\Temp\ReachFramework.dll
C:\Users\ADMINI~1\AppData\Local\Temp\UIAutomationProvider.dll
C:\Users\ADMINI~1\AppData\Local\Temp\UIAutomationTypes.dll
C:\Users\ADMINI~1\AppData\Local\Temp\WindowsBase.dll
C:\Users\ADMINI~1\AppData\Local\Temp\WindowsFormsIntegration.dll
C:\Users\dagobert\AppData\Local\Temp\biclient.exe
C:\Users\dagobert\AppData\Local\Temp\fairbot.exe
C:\Users\dagobert\AppData\Local\Temp\flac-1.2.1b.exe
C:\Users\dagobert\AppData\Local\Temp\ICReinstall_ImageEditorSetup.exe
C:\Users\dagobert\AppData\Local\Temp\ICReinstall_ZipExtractorSetup.exe
C:\Users\dagobert\AppData\Local\Temp\Installer_new.exe
C:\Users\dagobert\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\dagobert\AppData\Local\Temp\Mobogenie_Setup_2.1.23_515.exe
C:\Users\dagobert\AppData\Local\Temp\nsfB739.exe
C:\Users\dagobert\AppData\Local\Temp\nslB9DA.exe
C:\Users\dagobert\AppData\Local\Temp\nsoB295.exe
C:\Users\dagobert\AppData\Local\Temp\nsr7B07.exe
C:\Users\dagobert\AppData\Local\Temp\nsx7DE6.exe
C:\Users\dagobert\AppData\Local\Temp\nsz822D.exe
C:\Users\dagobert\AppData\Local\Temp\OptimizerPro.exe
C:\Users\dagobert\AppData\Local\Temp\ose00000.exe
C:\Users\dagobert\AppData\Local\Temp\PokerStarsInstallEU.exe
C:\Users\dagobert\AppData\Local\Temp\SearchProtectINT.exe
C:\Users\dagobert\AppData\Local\Temp\SplashLite_downloader.exe
C:\Users\dagobert\AppData\Local\Temp\splash_lite_setup.exe
C:\Users\dagobert\AppData\Local\Temp\TeamViewer_Setup_de_9.0.24951.exe
C:\Users\dagobert\AppData\Local\Temp\uninst1.exe
C:\Users\dagobert\AppData\Local\Temp\UpdateCheckerSetup.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-28 17:28

==================== End Of Log ============================

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-01-2014
Ran by dagobert at 2014-01-04 12:55:02
Running from C:\Users\dagobert\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05 - Adobe Systems Incorporated)
AGT Pro - Betfair (x32 Version: 1.2.14 - The Geek)
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
avast! Free Antivirus (x32 Version: 9.0.2008 - Avast Software)
BatBrowse 1.0.0 (Version: 1.0.0 - BatBrowse) <==== ATTENTION
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Betsender (x32 Version:  - Betsender Ltd.)
Bf Bot Manager v2 (x32 Version: 2.0.0 - bfbotmanager.com)
Camtasia Studio 8 (x32 Version: 8.1.2.1327 - TechSmith Corporation)
Canon My Printer (x32 Version: 3.1.0 - Canon Inc.)
CD-LabelPrint (x32 Version:  - )
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Classic Shell (Version: 3.6.8 - IvoSoft)
CopySafe PDF Reader (x32 Version: 3.0.5.3 - ArtistScope)
Desktop Icon für Amazon (Version: 1.0.1 (de) - )
Empress of the Deep - The Darkest Secret (x32 Version: 2.2.0.98 - WildTangent) Hidden
FairBot (x32 Version: 3.4 - Binteko Software)
FLAC 1.2.1b (remove only) (x32 Version: 1.2.1b - Xiph.org)
FlvPlayer (x32 Version: ${VERSION} - )
Foxtab (x32 Version:  - FoxTab) <==== ATTENTION
GIMP 2.8.10 (Version: 2.8.10 - The GIMP Team)
Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.)
Google Earth (x32 Version: 7.1.2.2019 - Google)
Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
HiSuite (x32 Version: 32.610.20.00.06 - Huawei Technologies Co.,Ltd)
Intel AppUp(SM) center (x32 Version: 3.6.1.33268.15 - Intel)
Intel(R) Management Engine Components (x32 Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (x32 Version: 9.17.10.3040 - Intel Corporation)
Intel(R) Rapid Storage Technology (x32 Version: 11.5.2.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
Island Tribe (x32 Version: 2.2.0.98 - WildTangent) Hidden
Java 7 Update 45 (x32 Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
JDownloader 0.9 (x32 Version: 0.9 - AppWork GmbH)
Jewel Quest Solitaire 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
LyriXeeker-1 (x32 Version: 1.28.153.3 - Lyrics) <==== ATTENTION
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Maxthon Cloud Browser (x32 Version: 4.1.2.4000 - Maxthon International Limited)
McAfee Security Scan Plus (Version: 3.8.130.10 - McAfee, Inc.)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla)
Nero 12 Essentials Toshiba (x32 Version: 12.0.00600 - Nero AG)
Nero BackItUp (x32 Version: 12.0.3000 - Nero AG) Hidden
Nero BackItUp Help (CHM) (x32 Version: 12.0.3000 - Nero AG) Hidden
Nero Blu-ray Player (x32 Version: 12.0.17500 - Nero AG) Hidden
Nero Blu-ray Player Help (CHM) (x32 Version: 12.0.4000 - Nero AG) Hidden
Nero BurnRights (x32 Version: 12.0.5000 - Nero AG) Hidden
Nero BurnRights Help (CHM) (x32 Version: 12.0.5000 - Nero AG) Hidden
Nero ControlCenter (x32 Version: 11.0.15300 - Nero AG) Hidden
Nero ControlCenter Help (CHM) (x32 Version: 12.0.5000 - Nero AG) Hidden
Nero Core Components (x32 Version: 11.0.18200 - Nero AG) Hidden
Nero Express (x32 Version: 12.0.20000 - Nero AG) Hidden
Nero Express Help (CHM) (x32 Version: 12.0.5000 - Nero AG) Hidden
Nero Kwik Media (x32 Version: 1.18.18900 - Nero AG) Hidden
Nero Kwik Media Help (CHM) (x32 Version: 12.0.4000 - Nero AG) Hidden
Nero Kwik Themes Basic (x32 Version: 12.0.11500 - Nero AG) Hidden
Nero Launcher (x32 Version: 12.2.6000 - Nero AG) Hidden
Nero RescueAgent (x32 Version: 12.0.9000 - Nero AG) Hidden
Nero RescueAgent Help (CHM) (x32 Version: 12.0.3000 - Nero AG) Hidden
Nero SharedVideoCodecs (x32 Version: 1.0.12100.2.0 - Nero AG) Hidden
Nero Update (x32 Version: 11.0.11800.31.0 - Nero AG) Hidden
PDF24 Creator 5.7.0 (x32 Version:  - PDF24.org)
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
PICkit 2 v2.61 (x32 Version: 2.61.00 - Microchip)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
PokerStars.eu (x32 Version:  - PokerStars.eu)
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Premium Sound HD (Version: 1.12.5000 - SRS Labs, Inc.)
Prerequisite installer (x32 Version: 12.0.0002 - Nero AG) Hidden
Realtek Bluetooth Filter Driver Package (x32 Version: 12.24.2012.0802 - REALTEK Semiconductor Corp)
Realtek Bluetooth Filter Driver Package (x32 Version: 12.24.2012.0802 - REALTEK Semiconductor Corp) Hidden
Realtek Ethernet Controller Driver (x32 Version: 8.3.730.2012 - Realtek)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6738 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.8400.30136 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (x32 Version: 2.00.0020 - REALTEK Semiconductor Corp.)
SearchAnonymizer (Version: 1.0.1 (de) - )
Secure Eraser (x32 Version: 4.2.0.1 - ASCOMP Software GmbH)
Shared C Run-time for x64 (Version: 10.0.0 - McAfee)
Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.)
SopCast 3.8.3 (x32 Version: 3.8.3 - www.sopcast.com)
Synaptics Pointing Device Driver (Version: 16.2.10.5 - Synaptics Incorporated)
TeamViewer 9 (x32 Version: 9.0.24951 - TeamViewer)
TOSHIBA Desktop Assist (Version: 1.00.08.6402 - Toshiba Corporation)
TOSHIBA eco Utility (Version: 2.0.0.6415 - Toshiba Corporation)
TOSHIBA Function Key (Version: 1.00.6626.6406 - Toshiba Corporation)
TOSHIBA Manuals (x32 Version: 10.10 - TOSHIBA)
Toshiba Password Utility (x32 Version: 2.00.972 - Toshiba Corporation)
Toshiba Password Utility (x32 Version: 2.00.972 - Toshiba Corporation) Hidden
TOSHIBA PC Health Monitor (Version: 1.8.17.640104 - Toshiba Corporation)
TOSHIBA Recovery Media Creator (x32 Version: 2.2.1.54043006 - Toshiba Corporation)
TOSHIBA Resolution+ Plug-in for Windows Media Player (x32 Version: 1.2.2.00 - TOSHIBA Corporation)
TOSHIBA Service Station (Version: 2.4.4 - TOSHIBA)
TOSHIBA System Driver (x32 Version: 1.00.0015 - Toshiba Corporation)
TOSHIBA System Settings (x32 Version: 1.00.0002.32002 - Toshiba Corporation)
Toshiba TEMPRO (x32 Version: 4.5.0 - Toshiba Europe GmbH)
TOSHIBA VIDEO PLAYER (Version: 5.1.0.12-A - Toshiba Corporation)
TrueCrypt (x32 Version: 7.1a - TrueCrypt Foundation)
Update for 2007 Microsoft Office System (KB967642) (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office Access 2007 Help (KB963663) (x32 Version:  - Microsoft)
Update for Microsoft Office Excel 2007 Help (KB963678) (x32 Version:  - Microsoft)
Update for Microsoft Office Infopath 2007 Help (KB963662) (x32 Version:  - Microsoft)
Update for Microsoft Office OneNote 2007 Help (KB963670) (x32 Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Help (KB963677) (x32 Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version:  - Microsoft)
Update for Microsoft Office Publisher 2007 Help (KB963667) (x32 Version:  - Microsoft)
Update for Microsoft Office Script Editor Help (KB963671) (x32 Version:  - Microsoft)
Update for Microsoft Office Word 2007 Help (KB963665) (x32 Version:  - Microsoft)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden
VirtualCloneDrive (x32 Version:  - Elaborate Bytes)
Welcome App (Start-up experience) (x32 Version: 12.0.14000 - Nero AG) Hidden
WildTangent Games (x32 Version: 1.0.3.0 - WildTangent)
WildTangent Games App (Toshiba Games) (x32 Version: 4.0.9.7 - WildTangent) Hidden
Windows Driver Package - Realtek Semiconductor Corp. RtkBtFilter Bluetooth  (07/11/2012 2.3.13.3) (Version: 07/11/2012 2.3.13.3 - Realtek Semiconductor Corp.)
WinRAR 5.00 (64-Bit) (Version: 5.00.0 - win.rar GmbH)

==================== Restore Points  =========================

15-12-2013 18:00:07 Windows-Sicherung
24-12-2013 08:17:46 Geplanter Prüfpunkt
27-12-2013 19:44:14 Installed 7-Zip 9.20 (x64 edition)

==================== Hosts content: ==========================

2012-07-26 06:26 - 2013-10-08 22:26 - 00000917 ____A C:\windows\system32\Drivers\etc\hosts
127.0.0.1          oscount.techsmith.com
127.0.0.1          activation.cloud.techsmith.com


==================== Scheduled Tasks (whitelisted) =============

Task: {03522D2F-BE96-4AB4-897D-387A752D6899} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {04BA285E-61D8-4346-B84B-B42336F63FE5} - System32\Tasks\FoxTab => C:\Users\dagobert\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {0DF7A06C-B0F2-43AC-AA38-2DD225212285} - System32\Tasks\{57BAE7B9-E2AB-4B8B-A0BE-8DDCA21E9AE9} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.7.0.102/de/abandoninstall?page=tsProgressBar
Task: {14B45408-6182-4665-9D9F-EAAB05CB20AE} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [2012-07-27] (TOSHIBA Corporation)
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {291F9454-E408-4132-952D-FEED6647EAAE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-22] (Google Inc.)
Task: {2DDADEF9-69BA-4D50-96C9-8DA5F885FD0D} - System32\Tasks\LyriXeeker-1-updater => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-updater.exe [2013-09-22] (Lyrics)
Task: {3D73AD2D-83BE-49D1-9973-8D3EEF53349B} - System32\Tasks\SomotoUpdateCheckerAutoStart => C:\Users\dagobert\AppData\Local\FilesFrog Update Checker\update_checker.exe <==== ATTENTION
Task: {46E26CCC-05F8-4763-A8B9-56EE51AAC852} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-16] (Synaptics Incorporated)
Task: {476553E5-CB3D-458F-94C3-7D518D8F79D5} - System32\Tasks\Toshiba\CommonNotifier => C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [2013-07-18] (Toshiba Europe GmbH)
Task: {4F621189-DCEB-43E2-8E7D-9DFE6D4FE739} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated)
Task: {59987F29-E682-49AA-A8C1-60F0E07D6FCD} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\MxUp.exe [2013-10-09] (Maxthon International ltd.)
Task: {5ABCC407-5950-46C5-8D25-7CF502B3EEA5} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-12-08] (AVAST Software)
Task: {7D9D22FC-8FDC-4581-AA20-50712F35A489} - System32\Tasks\Microsoft\Windows\Setup\Windows Upgrade Notification Task => C:\Windows\System32\NotificationUI.exe [2013-08-16] (Microsoft Corporation)
Task: {842E735E-7839-435A-892C-27DB673BFF02} - System32\Tasks\BonanzaDealsUpdate => C:\Program <==== ATTENTION
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {AE95DF8B-F1E5-4FC2-BCD6-7BBD0546C99B} - System32\Tasks\LyriXeeker-1-chromeinstaller => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-chromeinstaller.exe [2013-09-22] (Lyrics)
Task: {B182B692-DDD6-429E-B324-FC887608E144} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\System32\NotificationUI.exe [2013-08-16] (Microsoft Corporation)
Task: {BF33B041-E4CB-4F76-9FB8-42C4679D738B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-22] (Google Inc.)
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\FoxTab.job => C:\Users\dagobert\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\LyriXeeker-1-chromeinstaller.job => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-chromeinstaller.exe
Task: C:\windows\Tasks\LyriXeeker-1-updater.job => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-updater.exe

==================== Loaded Modules (whitelisted) =============

2013-09-29 23:55 - 2012-09-07 15:57 - 00559424 _____ () C:\Program Files (x86)\ASCOMP Software\Secure Eraser\SecEraser64.dll
2012-07-19 03:38 - 2012-07-19 03:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll
2012-07-19 03:38 - 2012-07-19 03:38 - 00049064 _____ () C:\Program Files\TOSHIBA\Hotkey\Hotkey\FnZ.dll
2012-08-14 04:13 - 2012-08-14 04:13 - 00018344 _____ () C:\Program Files\TOSHIBA\Teco\TecoMUI.dll
2012-08-06 06:36 - 2012-08-06 06:36 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-01-03 21:18 - 2014-01-03 19:28 - 02152960 _____ () C:\Program Files\AVAST Software\Avast\defs\14010300\algo.dll
2013-10-30 23:56 - 2013-10-30 23:56 - 00337920 _____ () C:\Program Files (x86)\BatBrowse\bin\sqlite3.DLL
2013-02-02 00:40 - 2012-06-25 19:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00634176 _____ () C:\Program Files (x86)\HiSuite\core.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00302912 _____ () C:\Program Files (x86)\HiSuite\sdk.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00017832 _____ () C:\Program Files (x86)\HiSuite\mingwm10.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00049472 _____ () C:\Program Files (x86)\HiSuite\libgcc_s_dw2-1.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 02421568 _____ () C:\Program Files (x86)\HiSuite\QtCore4.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 07723328 _____ () C:\Program Files (x86)\HiSuite\QtGui4.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 12326208 _____ () C:\Program Files (x86)\HiSuite\QtWebKit4.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00911168 _____ () C:\Program Files (x86)\HiSuite\QtNetwork4.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00262464 _____ () C:\Program Files (x86)\HiSuite\phonon4.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00855872 _____ () C:\Program Files (x86)\HiSuite\Proxy.DLL
2013-07-11 15:47 - 2013-07-11 15:47 - 00764224 _____ () C:\Program Files (x86)\HiSuite\Common.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00535360 _____ () C:\Program Files (x86)\HiSuite\Trace.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00596288 _____ () C:\Program Files (x86)\HiSuite\PluginContainer.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 01475392 _____ () C:\Program Files (x86)\HiSuite\AtComm.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00759616 _____ () C:\Program Files (x86)\HiSuite\AddrBookSrvPlugin.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00586560 _____ () C:\Program Files (x86)\HiSuite\CalendarPlugin.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00105792 _____ () C:\Program Files (x86)\HiSuite\CryptPlugin.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00751424 _____ () C:\Program Files (x86)\HiSuite\vCardvCalPlugin.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00558400 _____ () C:\Program Files (x86)\HiSuite\XCodec.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00953664 _____ () C:\Program Files (x86)\HiSuite\DeviceAppPlugin.dll
2013-07-11 15:46 - 2013-07-11 15:46 - 00635200 _____ () C:\Program Files (x86)\HiSuite\ADB.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00504640 _____ () C:\Program Files (x86)\HiSuite\OSPowerMgr.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00768832 _____ () C:\Program Files (x86)\HiSuite\XObex.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00070976 _____ () C:\Program Files (x86)\HiSuite\obex.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00613184 _____ () C:\Program Files (x86)\HiSuite\ADBAdapt.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00637760 _____ () C:\Program Files (x86)\HiSuite\OSAdapt.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00108864 _____ () C:\Program Files (x86)\HiSuite\SmsSrvPlugin.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00687936 _____ () C:\Program Files (x86)\HiSuite\SmsAppPlugin.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00844608 _____ () C:\Program Files (x86)\HiSuite\SyncPlugin.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00540480 _____ () C:\Program Files (x86)\HiSuite\APKManagerPlugin.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00572736 _____ () C:\Program Files (x86)\HiSuite\MusicPlaySrvPlugin.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00551744 _____ () C:\Program Files (x86)\HiSuite\ImageMgrSrvPlugin.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00089408 _____ () C:\Program Files (x86)\HiSuite\plugins\imageformats\qgif4.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00088384 _____ () C:\Program Files (x86)\HiSuite\plugins\imageformats\qico4.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00198464 _____ () C:\Program Files (x86)\HiSuite\plugins\imageformats\qjpeg4.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00357184 _____ () C:\Program Files (x86)\HiSuite\plugins\imageformats\qmng4.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00078656 _____ () C:\Program Files (x86)\HiSuite\plugins\imageformats\qsvg4.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00305984 _____ () C:\Program Files (x86)\HiSuite\QtSvg4.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00376640 _____ () C:\Program Files (x86)\HiSuite\plugins\imageformats\qtiff4.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00253248 _____ () C:\Program Files (x86)\HiSuite\XFramePlugin.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00332096 _____ () C:\Program Files (x86)\HiSuite\QtXml4.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00222016 _____ () C:\Program Files (x86)\HiSuite\QtSql4.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00147264 _____ () C:\Program Files (x86)\HiSuite\StatusBarMgrPlugin.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 01233216 _____ () C:\Program Files (x86)\HiSuite\AddrBookUIPlugin.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00208704 _____ () C:\Program Files (x86)\HiSuite\SettingUIPlugin.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00170304 _____ () C:\Program Files (x86)\HiSuite\RelationPlugin.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 01483072 _____ () C:\Program Files (x86)\HiSuite\SMSUIPlugin.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00598336 _____ () C:\Program Files (x86)\HiSuite\CalendarUIPlugin.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00273216 _____ () C:\Program Files (x86)\HiSuite\TaskUIPlugin.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00222528 _____ () C:\Program Files (x86)\HiSuite\DownLoadPlugin.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00106816 _____ () C:\Program Files (x86)\HiSuite\NotifyServicePlugin.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 01455936 _____ () C:\Program Files (x86)\HiSuite\ImExportUIPlugin.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00159040 _____ () C:\Program Files (x86)\HiSuite\GmailOperation.DLL
2013-07-11 15:48 - 2013-07-11 15:48 - 00993600 _____ () C:\Program Files (x86)\HiSuite\libxml2.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00084288 _____ () C:\Program Files (x86)\HiSuite\zlib1.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00211264 _____ () C:\Program Files (x86)\HiSuite\Outlook.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00137536 _____ () C:\Program Files (x86)\HiSuite\OutlookExpress.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00119616 _____ () C:\Program Files (x86)\HiSuite\LayoutPlugin.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00227136 _____ () C:\Program Files (x86)\HiSuite\ModuleTreePlugin.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00274752 _____ () C:\Program Files (x86)\HiSuite\HomeUIPlugin.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00897344 _____ () C:\Program Files (x86)\HiSuite\AppManagerUIPlugin.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 01560896 _____ () C:\Program Files (x86)\HiSuite\QtScript4.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 01182528 _____ () C:\Program Files (x86)\HiSuite\MusicMgrUIPlugin.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00713024 _____ () C:\Program Files (x86)\HiSuite\ImageMgrUIPlugin.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00239424 _____ () C:\Program Files (x86)\HiSuite\ScreenShotUIPlugin.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 02308928 _____ () C:\Program Files (x86)\HiSuite\UpdateUIPlugin.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00087360 _____ () C:\Program Files (x86)\HiSuite\HWEMUIEditToolsUIPlugin.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00083264 _____ () C:\Program Files (x86)\HiSuite\LogoPlugin.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 00916288 _____ () C:\Program Files (x86)\HiSuite\DeviceMgrUIPlugin.dll
2013-07-11 15:49 - 2013-07-11 15:49 - 00552768 _____ () C:\Program Files (x86)\HiSuite\SyncUIPlugin.dll
2013-07-11 15:47 - 2013-07-11 15:47 - 02282304 _____ () C:\Program Files (x86)\HiSuite\BackUpUIPlugin.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00203584 _____ () C:\Program Files (x86)\HiSuite\MenuMgrPlugin.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00364864 _____ () C:\Program Files (x86)\HiSuite\WebKitUIPlugin.dll
2013-07-11 15:48 - 2013-07-11 15:48 - 00171328 _____ () C:\Program Files (x86)\HiSuite\KuwoWebUIPlugin.dll
2013-07-11 15:50 - 2013-07-11 15:50 - 00832320 _____ () C:\Program Files (x86)\HiSuite\UpdateSrvPlugin.dll
2013-12-08 19:54 - 2013-12-08 19:54 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2013-09-23 16:30 - 2013-07-12 01:30 - 00258944 _____ () C:\Program Files (x86)\Maxthon\bin\Maxzlib.dll
2013-09-23 16:30 - 2013-07-12 01:30 - 00258944 _____ () C:\Program Files (x86)\Maxthon\Bin\maxzlib.dll
2013-09-23 16:30 - 2013-08-01 10:18 - 00232760 _____ () C:\Program Files (x86)\Maxthon\Addons\Mobile\MxMobile.dll
2013-09-23 16:30 - 2013-08-09 01:36 - 00755000 _____ () C:\Program Files (x86)\Maxthon\Core\Webkit\libglesv2.dll
2013-09-23 16:30 - 2013-08-09 01:36 - 00149304 _____ () C:\Program Files (x86)\Maxthon\Core\Webkit\libegl.dll
2013-09-23 16:30 - 2013-08-13 10:15 - 14586736 _____ () C:\Program Files (x86)\Maxthon\Core\Webkit\Npplugins\NPSWF32.dll
2013-09-21 12:00 - 2013-09-21 12:00 - 00295424 _____ () C:\Program Files (x86)\The Geek\AGT Pro - Betfair\Charts.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============

Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2013-12-15 21:12:20.153
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Common Files\ArtistScope\CSInstru64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-15 20:57:59.545
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Common Files\ArtistScope\CSInstru64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 79%
Total physical RAM: 3979.21 MB
Available physical RAM: 806.57 MB
Total Pagefile: 8075.21 MB
Available Pagefile: 3737.12 MB
Total Virtual: 8192 MB
Available Virtual: 8191.76 MB

==================== Drives ================================

Drive c: (TI31018700A) (Fixed) (Total:287.24 GB) (Free:216.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 298 GB) (Disk ID: 00000000)

Partition: GPT Partition Type
==================== End Of Log ============================


aharonov 04.01.2014 14:25

Ok.


Schritt 1
  • Gehe in die Systemsteuerung und öffne Programme und Funktionen.
  • Suche und deinstalliere dort der Reihe nach folgende Einträge:
    BatBrowse 1.0.0
    Foxtab
    LyriXeeker-1
    SearchAnonymizer
  • Schliesse das Fenster wieder und führe einen Neustart durch, wenn das gefordert wurde.



Schritt 2

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).



Schritt 3

Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, werden ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.



Bitte poste in deiner nächsten Antwort:
  • Log von AdwCleaner
  • Log von FRST

boti 04.01.2014 19:10

Hallo Leo

ich habe soweit deine Anleitung befolgt, habe alles Deinstalliert ausser : LyriXeeker-1
Das lässt sich nicht Deinstallieren?

Danke Dir für deine Hilfe.

LG boti


FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2014
Ran by dagobert (administrator) on PC on 04-01-2014 18:23:37
Running from C:\Users\dagobert\Desktop
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
() C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ArtistScope Pty Ltd) C:\Program Files\Common Files\ArtistScope\CSHelper64.exe
() C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe
() C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoResident.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe
() C:\Program Files (x86)\HiSuite\HiSuite.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
() C:\Users\dagobert\AppData\Local\HiSuite\userdata\hwtools\hwtransport.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16683_none_62280e15510f8e79\TiWorker.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [] - [x]
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13196432 2012-09-25] (Realtek Semiconductor)
HKLM\...\Run: [TCrdMain] - C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2611112 2012-09-04] ()
HKLM\...\Run: [TODDMain] - C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe [213136 2012-08-05] ()
HKLM\...\Run: [TecoResident] - C:\Program Files\TOSHIBA\Teco\TecoResident.exe [169896 2012-08-14] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] - C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [356776 2012-07-11] (TOSHIBA Corporation)
HKLM\...\Run: [SRS Premium Sound HD] - C:\Program Files\SRS Labs\SRS Control Panel\SRS_Premium_Sound_HD.zip [223242 2012-08-20] ()
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-08-01] (Intel Corporation)
HKLM-x32\...\Run: [TPUReg] - C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe [7148032 2012-10-31] (Pegatron Corporation)
HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-12-08] (AVAST Software)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Mobile Partner] - C:\Program Files (x86)\HiSuite\HiSuite.exe [583488 2013-07-11] ()
MountPoints2: {7a08f65c-248b-11e3-be78-2cd05a211b8c} - "E:\SETUP.EXE"
MountPoints2: {b0225b53-6424-11e3-be8c-2cd05a211b8c} - "F:\autorun.exe"
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [ ] ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com/search?q={searchTerms}
SearchScopes: HKLM - DefaultScope {92A50442-8429-4206-B4B5-D839300467D8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MATMJS
SearchScopes: HKLM - {92A50442-8429-4206-B4B5-D839300467D8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MATMJS
BHO: LyriXeeker-1 - {11111111-1111-1111-1111-110411181156} - C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-bho64.dll No File
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: DNS Error Helper - {9B6B03F1-16CF-4491-BBBB-E872802DD717} - C:\ProgramData\DNSErrorHelper\bho.dll No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @artistscope.com/DRMPlugin - C:\Program Files (x86)\CopySafe PDF Reader\npArtistScopeDRM.dll ()
FF Plugin-x32: @artistscope.com/PDFReaderWeb - C:\Program Files (x86)\CopySafe PDF Reader\npPDFReaderWeb.dll (ArtistScope Pty Ltd)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @artistscope.com/PDFReaderWeb - C:\Program Files (x86)\CopySafe PDF Reader\npPDFReaderWeb.dll (ArtistScope Pty Ltd)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default\Extensions\ich@maltegoetz.de
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF

Chrome:
=======
CHR Extension: (ProxTube) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.1.0_0
CHR Extension: (Google Docs) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [aakchaleigkohafkfjfjbblobjifikek] - C:\Users\dagobert\AppData\LocalLow\proxtube\CHROME\proxtube.crx

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-08] (AVAST Software)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-06-29] (IvoSoft)
R2 CSHelper; C:\Program Files\Common Files\ArtistScope\CSHelper64.exe [361552 2013-12-12] (ArtistScope Pty Ltd)
R2 GFNEXSrv; C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe [156672 2011-10-13] ()
R2 HiSuiteOuc64.exe; C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe [137024 2013-07-11] ()
R2 HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [197632 2013-05-02] ()
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201360 2012-08-31] (Realtek Semiconductor)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [116088 2013-07-18] (Toshiba Europe GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [38984 2013-12-08] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [84328 2013-12-08] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2013-12-08] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-08] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1032416 2013-12-08] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [409832 2013-12-08] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-12-08] ()
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 CSDriver; C:\Program Files\Common Files\ArtistScope\CSDriver64.sys [61424 2013-12-12] ()
R2 PEGAGFN; C:\Program Files (x86)\TOSHIBA\Password Utility\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [24208 2012-07-11] (Realtek Microelectronics)
S3 RTL8192Ce; C:\Windows\system32\DRIVERS\rtwlane.sys [1498256 2012-08-29] (Realtek Semiconductor Corporation                          )
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1498256 2012-08-29] (Realtek Semiconductor Corporation                          )
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-16] (Synaptics Incorporated)
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [28632 2012-07-31] (Windows (R) Win 7 DDK provider)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2011-10-24] (Huawei Technologies Co., Ltd.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-04 18:23 - 2014-01-04 18:23 - 00015848 _____ C:\Users\dagobert\Desktop\FRST.txt
2014-01-04 18:11 - 2014-01-04 18:18 - 00000000 ____D C:\AdwCleaner
2014-01-04 16:50 - 2014-01-04 16:50 - 00000000 ____D C:\windows\system32\IO
2014-01-04 16:49 - 2014-01-04 16:49 - 00003136 _____ C:\windows\System32\Tasks\{F8D0D227-1CE3-4729-880C-88C727E51CB3}
2014-01-04 16:43 - 2014-01-04 16:43 - 01233962 _____ C:\Users\dagobert\Desktop\adwcleaner(1).exe
2014-01-04 12:51 - 2014-01-04 12:51 - 00000000 ____D C:\FRST
2014-01-04 12:50 - 2014-01-04 12:50 - 01931368 _____ (Farbar) C:\Users\dagobert\Desktop\FRST64.exe
2014-01-03 21:39 - 2014-01-03 21:39 - 01233962 _____ C:\Users\dagobert\Desktop\adwcleaner.exe
2014-01-03 21:17 - 2014-01-03 21:17 - 00017071 _____ C:\Users\dagobert\Desktop\JRT.txt
2014-01-03 21:08 - 2014-01-03 21:08 - 00000000 ____D C:\windows\ERUNT
2014-01-03 21:02 - 2014-01-03 21:02 - 01036305 _____ (Thisisu) C:\Users\dagobert\Desktop\JRT.exe
2014-01-03 20:54 - 2014-01-03 21:29 - 106000000 _____ C:\Users\dagobert\Downloads\BRRTB_DENUADH_PG.part1.rar
2014-01-02 21:22 - 2014-01-02 21:38 - 48281764 _____ C:\Users\dagobert\Downloads\RTB_M_PG.rar
2014-01-02 17:46 - 2014-01-02 17:46 - 05629632 _____ (IvoSoft) C:\Users\dagobert\Downloads\ClassicShellSetup_4_0_2.exe
2014-01-02 12:01 - 2014-01-02 12:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-02 11:18 - 2014-01-02 11:18 - 00000000 ____D C:\Users\dagobert\Desktop\MyPhoneExplorer portable
2014-01-02 11:15 - 2014-01-02 11:15 - 07080248 _____ C:\Users\dagobert\Downloads\MyPhoneExplorer_1.8.5.exe
2014-01-02 10:51 - 2014-01-02 10:51 - 00001173 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-01-02 10:51 - 2014-01-02 10:51 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2014-01-01 22:29 - 2014-01-03 21:07 - 00000000 ____D C:\Users\dagobert\Desktop\Loreena McKennitt - Troubadours On The Rhine (2012)
2014-01-01 22:26 - 2014-01-01 22:26 - 00001732 _____ C:\Users\dagobert\Desktop\dee8bf01883ccfcc31d20370e4879aac.dlc
2014-01-01 21:55 - 2014-01-01 21:55 - 102703242 _____ C:\Users\dagobert\Desktop\Rhein.rar
2013-12-30 18:56 - 2013-12-30 18:56 - 00001171 _____ C:\Users\dagobert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-12-30 12:54 - 2013-12-30 12:54 - 00189714 _____ C:\Users\dagobert\Desktop\1by1_181.exe
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 ____D C:\Users\dagobert\AppData\Local\cache
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 _____ C:\Users\dagobert\daemonprocess.txt
2013-12-30 12:51 - 2013-12-30 12:51 - 00003248 _____ C:\windows\System32\Tasks\SomotoUpdateCheckerAutoStart
2013-12-30 12:43 - 2013-12-30 12:43 - 00000000 ____D C:\Users\dagobert\Desktop\Loreena McKenitt
2013-12-29 21:05 - 2013-12-29 21:05 - 00001873 _____ C:\Users\Public\Desktop\FLAC Frontend.lnk
2013-12-29 21:05 - 2013-12-29 21:05 - 00000000 ____D C:\Program Files (x86)\FLAC
2013-12-27 20:51 - 2013-12-27 20:51 - 02744087 _____ C:\Users\dagobert\Desktop\flac-1.2.1b.exe
2013-12-27 20:47 - 2013-07-13 19:55 - 47718685 ____R C:\Users\dagobert\Downloads\07. Loreena McKennitt - God Rest Ye Merry, Gentlemen (Abdelli Version).flac
2013-12-27 20:47 - 2013-07-13 19:55 - 24117606 ____R C:\Users\dagobert\Downloads\05. Loreena McKennitt - Good King Wenceslas.flac
2013-12-27 20:47 - 2013-07-13 19:55 - 12544244 ____R C:\Users\dagobert\Downloads\06. Loreena McKennitt - Coventry Carol.flac
2013-12-27 20:47 - 2013-07-13 19:54 - 35967651 ____R C:\Users\dagobert\Downloads\04. Loreena McKennitt - Noël Nouvelet !.flac
2013-12-27 20:47 - 2013-07-13 19:54 - 32452407 ____R C:\Users\dagobert\Downloads\08. Loreena McKennitt - Snow.flac
2013-12-27 20:47 - 2013-07-13 19:54 - 30110016 ____R C:\Users\dagobert\Downloads\10. Loreena McKennitt - Seeds Of Love.flac
2013-12-27 20:47 - 2013-07-13 19:54 - 25602457 ____R C:\Users\dagobert\Downloads\12. Loreena McKennitt - Emmanuel.flac
2013-12-27 20:47 - 2013-07-13 19:53 - 16734714 ____R C:\Users\dagobert\Downloads\11. Loreena McKennitt - Gloucestershire Wassail.flac
2013-12-27 20:47 - 2013-07-13 19:52 - 29194831 ____R C:\Users\dagobert\Downloads\03. Loreena McKennitt - The Seven Rejoices Of Mary.flac
2013-12-27 20:47 - 2013-07-13 19:52 - 18437355 ____R C:\Users\dagobert\Downloads\09. Loreena McKennitt - Breton Carol.flac
2013-12-27 20:47 - 2013-07-13 19:51 - 25009882 ____R C:\Users\dagobert\Downloads\01. Loreena McKennitt - The Holly And The Ivy.flac
2013-12-27 20:47 - 2013-07-13 19:49 - 20316857 ____R C:\Users\dagobert\Downloads\02. Loreena McKennitt - Un Flambeau, Jeannette, Isabelle.flac
2013-12-27 20:47 - 2013-07-13 19:49 - 14078965 ____R C:\Users\dagobert\Downloads\13. Loreena McKennitt - In The Bleak Midwinter.flac
2013-12-27 20:47 - 2013-07-13 19:43 - 00006095 ____R C:\Users\dagobert\Downloads\Loreena McKennitt - A Midwinter Night's Dream.log
2013-12-27 20:47 - 2013-07-13 19:43 - 00002707 ____R C:\Users\dagobert\Downloads\A Midwinter Night's Dream.cue
2013-12-27 20:47 - 2013-07-13 19:43 - 00001364 ____R C:\Users\dagobert\Downloads\Loreena McKennitt - A Midwinter Night's Dream.m3u
2013-12-27 20:47 - 2013-07-13 19:43 - 00000000 ____D C:\Users\dagobert\Downloads\Scans
2013-12-27 20:45 - 2013-12-27 20:45 - 00000000 ____D C:\Program Files\7-Zip
2013-12-27 18:15 - 2014-01-02 21:21 - 338124282 _____ C:\Users\dagobert\Downloads\497834093840394.7z
2013-12-27 18:07 - 2013-12-27 18:15 - 23551482 _____ C:\Users\dagobert\Downloads\497834093840394.7z.004
2013-12-26 17:27 - 2013-12-26 18:01 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.003
2013-12-25 21:00 - 2013-12-25 21:34 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.002
2013-12-25 17:03 - 2013-12-25 17:38 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.001
2013-12-25 16:44 - 2014-01-02 22:40 - 00000000 ____D C:\Users\dagobert\Desktop\CD
2013-12-23 16:02 - 2013-12-23 16:02 - 00002786 _____ C:\Users\dagobert\AppData\Local\recently-used.xbel
2013-12-23 16:02 - 2013-12-23 16:02 - 00000000 ____D C:\Users\dagobert\AppData\Local\gtk-2.0
2013-12-23 09:19 - 2013-12-23 09:19 - 00000000 ____D C:\Users\dagobert\.android
2013-12-23 09:18 - 2014-01-02 11:13 - 00000000 ____D C:\Users\dagobert\Documents\HiSuite
2013-12-23 09:18 - 2013-12-23 09:19 - 00000000 ____D C:\Users\dagobert\AppData\Local\HiSuite
2013-12-23 09:18 - 2013-12-23 09:18 - 00001002 _____ C:\Users\Public\Desktop\HiSuite.lnk
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\ProgramData\HiSuiteOuc
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\ProgramData\HandSetService
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\Program Files (x86)\HiSuite
2013-12-23 09:18 - 2012-02-08 10:07 - 00281088 _____ (Huawei Technologies Co., Ltd.) C:\windows\system32\Drivers\hw_quusbnet.sys
2013-12-23 09:18 - 2011-10-24 05:04 - 00223232 _____ (Huawei Technologies Co., Ltd.) C:\windows\system32\Drivers\hw_quusbmdm.sys
2013-12-23 09:18 - 2011-10-24 04:51 - 00116864 _____ (Huawei Technologies Co., Ltd.) C:\windows\system32\Drivers\hw_usbdev.sys
2013-12-23 09:18 - 2010-02-19 00:00 - 01533512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFUpdate_01007.dll
2013-12-23 09:18 - 2010-02-19 00:00 - 01490656 _____ (Microsoft Corporation) C:\windows\system32\WdfCoInstaller01007.dll
2013-12-23 09:18 - 2010-02-19 00:00 - 01490656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfCoInstaller01007.dll
2013-12-23 09:18 - 2010-02-19 00:00 - 00708168 _____ (Microsoft Corporation) C:\windows\system32\WinUSBCoInstaller.dll
2013-12-23 09:18 - 2010-02-19 00:00 - 00708168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WinUSBCoInstaller.dll
2013-12-23 09:15 - 2013-12-23 09:15 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-12-19 13:51 - 2012-04-05 14:44 - 00000000 ____D C:\Users\dagobert\Downloads\Secret Garden
2013-12-19 12:36 - 2013-12-19 13:51 - 451675335 _____ C:\Users\dagobert\Downloads\Secret Garden.part3.rar
2013-12-19 06:21 - 2013-12-19 07:57 - 576716800 _____ C:\Users\dagobert\Downloads\Secret Garden.part2.rar
2013-12-19 00:22 - 2014-01-04 13:22 - 00000072 _____ C:\Users\dagobert\AppData\Roaming\WB.CFG
2013-12-18 21:12 - 2013-12-19 00:25 - 576716800 _____ C:\Users\dagobert\Downloads\Secret Garden.part1.rar
2013-12-15 11:36 - 2013-12-15 11:36 - 110600192 _____ C:\Users\dagobert\Desktop\ebook 2.camrec
2013-12-15 11:09 - 2013-12-15 11:09 - 47251456 _____ C:\Users\dagobert\Desktop\insidertips ebook.camrec
2013-12-15 11:04 - 2013-12-15 11:04 - 167469056 _____ C:\Users\dagobert\Desktop\insidertips.at.camrec
2013-12-13 19:31 - 2014-01-04 18:20 - 00424640 _____ C:\windows\system32\FNTCACHE.DAT
2013-12-13 19:31 - 2013-12-13 19:31 - 555133442 _____ C:\windows\MEMORY.DMP
2013-12-13 19:31 - 2013-12-13 19:31 - 00285928 _____ C:\windows\Minidump\121313-38265-01.dmp
2013-12-13 19:31 - 2013-12-13 19:31 - 00000000 ____D C:\windows\Minidump
2013-12-13 16:26 - 2013-12-13 16:26 - 08065024 _____ C:\Users\dagobert\Desktop\capture-1.camrec
2013-12-13 14:40 - 2013-12-13 14:40 - 07613196 _____ C:\Users\dagobert\Desktop\104751_Mach_dich_zum_Gewinner_2.enc
2013-12-13 12:54 - 2013-12-13 12:54 - 00000000 ____D C:\Users\dagobert\AppData\Roaming\AVAST Software
2013-12-12 22:03 - 2013-12-12 22:03 - 00008942 _____ C:\Users\dagobert\Desktop\InsidertippsEachWay(1).zip
2013-12-12 22:00 - 2013-12-12 22:00 - 00008942 _____ C:\Users\dagobert\Desktop\InsidertippsEachWay.zip
2013-12-12 21:28 - 2013-12-12 21:28 - 00002022 _____ C:\Users\Public\Desktop\CopySafe PDF Reader.lnk
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\windows\CopySafe PDF Reader
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\Program Files\Common Files\ArtistScope
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\Program Files (x86)\CopySafe PDF Reader
2013-12-12 21:26 - 2013-12-12 21:26 - 06280128 _____ (ArtistScope) C:\Users\dagobert\Desktop\CopysafePDFreader.exe
2013-12-11 18:34 - 2013-12-11 18:34 - 00000000 ____D C:\Users\dagobert\.thumbnails
2013-12-11 18:30 - 2013-12-23 16:02 - 00000000 ____D C:\Users\dagobert\.gimp-2.8
2013-12-11 18:30 - 2013-12-11 18:30 - 00000000 ____D C:\Users\dagobert\AppData\Local\gegl-0.2
2013-12-11 18:27 - 2013-12-11 18:28 - 00000000 ____D C:\Program Files\GIMP 2
2013-12-11 16:24 - 2013-10-25 07:19 - 02241536 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-12-11 16:24 - 2013-10-25 07:19 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-12-11 16:24 - 2013-10-25 07:19 - 00915968 _____ (Microsoft Corporation) C:\windows\system32\uxtheme.dll
2013-12-11 16:24 - 2013-10-25 07:19 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-12-11 16:24 - 2013-10-25 07:18 - 19271168 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-12-11 16:24 - 2013-10-25 07:18 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-12-11 16:24 - 2013-10-25 07:17 - 15404032 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-12-11 16:24 - 2013-10-25 07:17 - 03959808 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-12-11 16:24 - 2013-10-25 07:17 - 02648576 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-12-11 16:24 - 2013-10-25 07:17 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-12-11 16:24 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-12-11 16:24 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-12-11 16:24 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-12-11 16:24 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-12-11 16:24 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-12-11 16:24 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-12-11 16:24 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-12-11 16:24 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-12-11 16:24 - 2013-10-19 06:45 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2013-12-11 16:24 - 2013-10-19 05:04 - 00059392 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2013-12-11 16:24 - 2013-10-09 02:33 - 00059416 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2013-12-11 16:24 - 2013-10-08 23:30 - 00628736 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2013-12-11 16:24 - 2013-10-08 23:30 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2013-12-11 16:24 - 2013-10-08 23:30 - 00084992 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2013-12-11 16:24 - 2013-10-08 23:30 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2013-12-11 16:24 - 2013-10-08 23:28 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2013-12-11 16:24 - 2013-10-08 23:27 - 03279872 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 01622016 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 00773120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 00252928 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\storewuauth.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 00142848 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2013-12-11 16:24 - 2013-10-08 23:27 - 00099328 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2013-12-11 16:24 - 2013-10-05 07:10 - 00285016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\spaceport.sys
2013-12-11 16:24 - 2013-10-03 23:09 - 00385528 _____ C:\windows\system32\ApnDatabase.xml
2013-12-11 16:24 - 2013-10-02 03:50 - 00447320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
2013-12-11 16:24 - 2013-09-28 06:48 - 00778752 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2013-12-11 16:24 - 2013-09-28 04:58 - 00551424 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2013-12-11 16:24 - 2013-09-19 08:32 - 01455448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2013-12-11 16:24 - 2013-08-30 06:19 - 00626688 _____ (Microsoft Corporation) C:\windows\system32\resutils.dll
2013-12-11 16:24 - 2013-08-30 06:18 - 00374784 _____ (Microsoft Corporation) C:\windows\system32\clusapi.dll
2013-12-11 16:24 - 2013-08-30 00:48 - 00488960 _____ (Microsoft Corporation) C:\windows\SysWOW64\resutils.dll
2013-12-11 16:24 - 2013-08-30 00:47 - 00302080 _____ (Microsoft Corporation) C:\windows\SysWOW64\clusapi.dll
2013-12-11 16:23 - 2013-11-23 07:43 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2013-12-11 16:23 - 2013-11-23 06:05 - 00368640 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2013-12-11 16:23 - 2013-11-07 00:18 - 04036608 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-12-11 16:23 - 2013-11-01 06:38 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2013-12-11 16:23 - 2013-11-01 04:49 - 00273408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2013-12-11 16:23 - 2013-10-10 10:32 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe
2013-12-11 16:23 - 2013-10-10 10:30 - 00162304 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrobj.dll
2013-12-11 16:23 - 2013-10-10 10:30 - 00156160 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2013-12-11 16:23 - 2013-10-10 10:24 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2013-12-11 16:23 - 2013-10-10 10:23 - 00146944 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2013-12-11 16:23 - 2013-10-10 10:22 - 00222720 _____ (Microsoft Corporation) C:\windows\system32\scrobj.dll
2013-12-11 16:23 - 2013-10-10 10:22 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2013-12-11 16:23 - 2013-09-28 04:35 - 00288768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-01-04 18:23 - 2014-01-04 18:23 - 00015848 _____ C:\Users\dagobert\Desktop\FRST.txt
2014-01-04 18:22 - 2013-09-22 20:17 - 00001116 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-04 18:21 - 2012-07-26 08:22 - 00000006 ____H C:\windows\Tasks\SA.DAT
2014-01-04 18:20 - 2013-12-13 19:31 - 00424640 _____ C:\windows\system32\FNTCACHE.DAT
2014-01-04 18:19 - 2013-09-23 14:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-04 18:19 - 2012-11-14 03:05 - 00060762 _____ C:\windows\PFRO.log
2014-01-04 18:19 - 2012-07-26 06:26 - 00262144 ___SH C:\windows\system32\config\BBI
2014-01-04 18:18 - 2014-01-04 18:11 - 00000000 ____D C:\AdwCleaner
2014-01-04 18:02 - 2013-09-22 20:43 - 00000000 ____D C:\Users\dagobert\AppData\Roaming\Skype
2014-01-04 18:00 - 2012-07-26 09:12 - 00000000 ____D C:\windows\system32\sru
2014-01-04 17:45 - 2013-11-17 22:04 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2014-01-04 17:34 - 2013-09-22 20:17 - 00001120 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-04 17:32 - 2013-09-21 03:41 - 01594781 _____ C:\windows\WindowsUpdate.log
2014-01-04 16:50 - 2014-01-04 16:50 - 00000000 ____D C:\windows\system32\IO
2014-01-04 16:49 - 2014-01-04 16:49 - 00003136 _____ C:\windows\System32\Tasks\{F8D0D227-1CE3-4729-880C-88C727E51CB3}
2014-01-04 16:43 - 2014-01-04 16:43 - 01233962 _____ C:\Users\dagobert\Desktop\adwcleaner(1).exe
2014-01-04 13:22 - 2013-12-19 00:22 - 00000072 _____ C:\Users\dagobert\AppData\Roaming\WB.CFG
2014-01-04 12:51 - 2014-01-04 12:51 - 00000000 ____D C:\FRST
2014-01-04 12:50 - 2014-01-04 12:50 - 01931368 _____ (Farbar) C:\Users\dagobert\Desktop\FRST64.exe
2014-01-03 21:39 - 2014-01-03 21:39 - 01233962 _____ C:\Users\dagobert\Desktop\adwcleaner.exe
2014-01-03 21:29 - 2014-01-03 20:54 - 106000000 _____ C:\Users\dagobert\Downloads\BRRTB_DENUADH_PG.part1.rar
2014-01-03 21:17 - 2014-01-03 21:17 - 00017071 _____ C:\Users\dagobert\Desktop\JRT.txt
2014-01-03 21:08 - 2014-01-03 21:08 - 00000000 ____D C:\windows\ERUNT
2014-01-03 21:07 - 2014-01-01 22:29 - 00000000 ____D C:\Users\dagobert\Desktop\Loreena McKennitt - Troubadours On The Rhine (2012)
2014-01-03 21:02 - 2014-01-03 21:02 - 01036305 _____ (Thisisu) C:\Users\dagobert\Desktop\JRT.exe
2014-01-03 20:06 - 2013-10-05 21:58 - 00000000 ____D C:\Users\dagobert\AppData\Local\PokerStars.EU
2014-01-03 16:50 - 2013-10-09 22:35 - 00000000 ____D C:\Users\dagobert\AppData\Local\CrashDumps
2014-01-03 16:37 - 2012-07-26 09:12 - 00000000 ____D C:\windows\AUInstallAgent
2014-01-03 14:43 - 2012-07-26 09:12 - 00000000 ____D C:\windows\system32\FxsTmp
2014-01-02 22:40 - 2013-12-25 16:44 - 00000000 ____D C:\Users\dagobert\Desktop\CD
2014-01-02 21:38 - 2014-01-02 21:22 - 48281764 _____ C:\Users\dagobert\Downloads\RTB_M_PG.rar
2014-01-02 21:21 - 2013-12-27 18:15 - 338124282 _____ C:\Users\dagobert\Downloads\497834093840394.7z
2014-01-02 17:46 - 2014-01-02 17:46 - 05629632 _____ (IvoSoft) C:\Users\dagobert\Downloads\ClassicShellSetup_4_0_2.exe
2014-01-02 12:01 - 2014-01-02 12:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-02 11:18 - 2014-01-02 11:18 - 00000000 ____D C:\Users\dagobert\Desktop\MyPhoneExplorer portable
2014-01-02 11:15 - 2014-01-02 11:15 - 07080248 _____ C:\Users\dagobert\Downloads\MyPhoneExplorer_1.8.5.exe
2014-01-02 11:13 - 2013-12-23 09:18 - 00000000 ____D C:\Users\dagobert\Documents\HiSuite
2014-01-02 11:12 - 2012-08-01 17:55 - 00780976 _____ C:\windows\system32\perfh010.dat
2014-01-02 11:12 - 2012-08-01 17:55 - 00152608 _____ C:\windows\system32\perfc010.dat
2014-01-02 11:12 - 2012-08-01 17:38 - 00753134 _____ C:\windows\system32\perfh007.dat
2014-01-02 11:12 - 2012-08-01 17:38 - 00155826 _____ C:\windows\system32\perfc007.dat
2014-01-02 11:12 - 2012-07-26 08:28 - 02679026 _____ C:\windows\system32\PerfStringBackup.INI
2014-01-02 11:02 - 2013-10-21 11:21 - 00000000 ____D C:\Users\dagobert\AppData\Roaming\TeamViewer
2014-01-02 11:00 - 2012-07-26 08:21 - 00030044 _____ C:\windows\setupact.log
2014-01-02 10:51 - 2014-01-02 10:51 - 00001173 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-01-02 10:51 - 2014-01-02 10:51 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2014-01-01 22:26 - 2014-01-01 22:26 - 00001732 _____ C:\Users\dagobert\Desktop\dee8bf01883ccfcc31d20370e4879aac.dlc
2014-01-01 21:55 - 2014-01-01 21:55 - 102703242 _____ C:\Users\dagobert\Desktop\Rhein.rar
2013-12-30 18:56 - 2013-12-30 18:56 - 00001171 _____ C:\Users\dagobert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-12-30 12:54 - 2013-12-30 12:54 - 00189714 _____ C:\Users\dagobert\Desktop\1by1_181.exe
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 ____D C:\Users\dagobert\AppData\Local\cache
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 _____ C:\Users\dagobert\daemonprocess.txt
2013-12-30 12:52 - 2013-09-21 03:43 - 00000000 ____D C:\Users\dagobert
2013-12-30 12:51 - 2013-12-30 12:51 - 00003248 _____ C:\windows\System32\Tasks\SomotoUpdateCheckerAutoStart
2013-12-30 12:43 - 2013-12-30 12:43 - 00000000 ____D C:\Users\dagobert\Desktop\Loreena McKenitt
2013-12-29 21:05 - 2013-12-29 21:05 - 00001873 _____ C:\Users\Public\Desktop\FLAC Frontend.lnk
2013-12-29 21:05 - 2013-12-29 21:05 - 00000000 ____D C:\Program Files (x86)\FLAC
2013-12-27 20:51 - 2013-12-27 20:51 - 02744087 _____ C:\Users\dagobert\Desktop\flac-1.2.1b.exe
2013-12-27 20:45 - 2013-12-27 20:45 - 00000000 ____D C:\Program Files\7-Zip
2013-12-27 20:41 - 2013-10-29 23:23 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-12-27 18:15 - 2013-12-27 18:07 - 23551482 _____ C:\Users\dagobert\Downloads\497834093840394.7z.004
2013-12-26 21:14 - 2013-10-08 18:13 - 00000000 ____D C:\Users\dagobert\Desktop\Neuer Ordner
2013-12-26 18:01 - 2013-12-26 17:27 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.003
2013-12-25 21:34 - 2013-12-25 21:00 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.002
2013-12-25 17:38 - 2013-12-25 17:03 - 104857600 _____ C:\Users\dagobert\Downloads\497834093840394.7z.001
2013-12-25 16:46 - 2013-10-04 10:28 - 00000000 ____D C:\Users\dagobert\Desktop\Facebook Bilder
2013-12-25 16:45 - 2013-10-09 10:07 - 00000000 ____D C:\Users\dagobert\Desktop\Arturas
2013-12-23 17:00 - 2013-10-19 19:59 - 00001002 _____ C:\Users\dagobert\Desktop\FairBot.lnk
2013-12-23 17:00 - 2013-10-19 19:59 - 00000000 ____D C:\Program Files (x86)\FairBot
2013-12-23 16:02 - 2013-12-23 16:02 - 00002786 _____ C:\Users\dagobert\AppData\Local\recently-used.xbel
2013-12-23 16:02 - 2013-12-23 16:02 - 00000000 ____D C:\Users\dagobert\AppData\Local\gtk-2.0
2013-12-23 16:02 - 2013-12-11 18:30 - 00000000 ____D C:\Users\dagobert\.gimp-2.8
2013-12-23 09:19 - 2013-12-23 09:19 - 00000000 ____D C:\Users\dagobert\.android
2013-12-23 09:19 - 2013-12-23 09:18 - 00000000 ____D C:\Users\dagobert\AppData\Local\HiSuite
2013-12-23 09:18 - 2013-12-23 09:18 - 00001002 _____ C:\Users\Public\Desktop\HiSuite.lnk
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\ProgramData\HiSuiteOuc
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\ProgramData\HandSetService
2013-12-23 09:18 - 2013-12-23 09:18 - 00000000 ____D C:\Program Files (x86)\HiSuite
2013-12-23 09:15 - 2013-12-23 09:15 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-12-22 21:46 - 2013-11-06 21:46 - 00000000 ____D C:\Users\dagobert\Desktop\Fussi Trades
2013-12-22 21:46 - 2013-10-01 13:03 - 00000000 ____D C:\Users\dagobert\Desktop\tex
2013-12-19 13:51 - 2013-12-19 12:36 - 451675335 _____ C:\Users\dagobert\Downloads\Secret Garden.part3.rar
2013-12-19 12:41 - 2013-09-22 20:43 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-12-19 12:41 - 2013-09-22 20:42 - 00000000 ____D C:\ProgramData\Skype
2013-12-19 07:57 - 2013-12-19 06:21 - 576716800 _____ C:\Users\dagobert\Downloads\Secret Garden.part2.rar
2013-12-19 00:25 - 2013-12-18 21:12 - 576716800 _____ C:\Users\dagobert\Downloads\Secret Garden.part1.rar
2013-12-15 18:29 - 2013-10-05 21:58 - 00000000 ____D C:\Program Files (x86)\PokerStars.EU
2013-12-15 11:36 - 2013-12-15 11:36 - 110600192 _____ C:\Users\dagobert\Desktop\ebook 2.camrec
2013-12-15 11:35 - 2013-10-09 15:12 - 00004096 _____ C:\Users\dagobert\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-15 11:09 - 2013-12-15 11:09 - 47251456 _____ C:\Users\dagobert\Desktop\insidertips ebook.camrec
2013-12-15 11:04 - 2013-12-15 11:04 - 167469056 _____ C:\Users\dagobert\Desktop\insidertips.at.camrec
2013-12-14 22:11 - 2012-07-26 09:12 - 00000000 ____D C:\windows\rescache
2013-12-14 22:00 - 2013-09-22 22:09 - 00000000 ____D C:\windows\system32\MRT
2013-12-14 21:58 - 2013-09-22 22:09 - 90708896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-12-14 21:23 - 2013-09-23 17:36 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2013-12-13 19:31 - 2013-12-13 19:31 - 555133442 _____ C:\windows\MEMORY.DMP
2013-12-13 19:31 - 2013-12-13 19:31 - 00285928 _____ C:\windows\Minidump\121313-38265-01.dmp
2013-12-13 19:31 - 2013-12-13 19:31 - 00000000 ____D C:\windows\Minidump
2013-12-13 16:26 - 2013-12-13 16:26 - 08065024 _____ C:\Users\dagobert\Desktop\capture-1.camrec
2013-12-13 14:40 - 2013-12-13 14:40 - 07613196 _____ C:\Users\dagobert\Desktop\104751_Mach_dich_zum_Gewinner_2.enc
2013-12-13 12:54 - 2013-12-13 12:54 - 00000000 ____D C:\Users\dagobert\AppData\Roaming\AVAST Software
2013-12-12 23:14 - 2012-07-26 09:12 - 00000000 ____D C:\windows\system32\SecureBootUpdates
2013-12-12 22:03 - 2013-12-12 22:03 - 00008942 _____ C:\Users\dagobert\Desktop\InsidertippsEachWay(1).zip
2013-12-12 22:00 - 2013-12-12 22:00 - 00008942 _____ C:\Users\dagobert\Desktop\InsidertippsEachWay.zip
2013-12-12 21:28 - 2013-12-12 21:28 - 00002022 _____ C:\Users\Public\Desktop\CopySafe PDF Reader.lnk
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\windows\CopySafe PDF Reader
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\Program Files\Common Files\ArtistScope
2013-12-12 21:28 - 2013-12-12 21:28 - 00000000 ____D C:\Program Files (x86)\CopySafe PDF Reader
2013-12-12 21:26 - 2013-12-12 21:26 - 06280128 _____ (ArtistScope) C:\Users\dagobert\Desktop\CopysafePDFreader.exe
2013-12-11 18:34 - 2013-12-11 18:34 - 00000000 ____D C:\Users\dagobert\.thumbnails
2013-12-11 18:30 - 2013-12-11 18:30 - 00000000 ____D C:\Users\dagobert\AppData\Local\gegl-0.2
2013-12-11 18:28 - 2013-12-11 18:27 - 00000000 ____D C:\Program Files\GIMP 2
2013-12-11 16:29 - 2013-09-23 21:14 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 16:27 - 2012-07-26 06:38 - 00000000 ____D C:\windows\system32\oobe
2013-12-10 19:45 - 2013-11-17 22:04 - 00003772 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-12-09 10:46 - 2013-09-21 03:50 - 00003598 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3541415397-2149579106-852229368-1001
2013-12-08 19:54 - 2013-09-23 17:36 - 01032416 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00409832 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00334648 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2013-12-08 19:54 - 2013-09-23 17:36 - 00205320 _____ C:\windows\system32\Drivers\aswVmm.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00092544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00084328 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00065776 _____ C:\windows\system32\Drivers\aswRvrt.sys
2013-12-08 19:54 - 2013-09-23 17:36 - 00038984 _____ (AVAST Software) C:\windows\system32\Drivers\aswFsBlk.sys
2013-12-08 19:54 - 2013-09-23 17:34 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2013-12-08 19:52 - 2013-09-23 17:34 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-08 19:51 - 2013-09-23 17:36 - 00000000 _____ C:\windows\SysWOW64\config.nt
2013-12-06 09:16 - 2013-09-24 14:49 - 00000000 ____D C:\Users\dagobert\Desktop\MAG
2013-12-06 07:40 - 2013-09-23 21:14 - 00000000 ____D C:\Users\dagobert\AppData\Local\Microsoft Help
2013-12-06 06:36 - 2013-09-22 20:17 - 00002186 _____ C:\Users\Public\Desktop\Google Chrome.lnk

Some content of TEMP:
====================
C:\Users\ADMINI~1\AppData\Local\Temp\PresentationCore.dll
C:\Users\ADMINI~1\AppData\Local\Temp\PresentationFramework.dll
C:\Users\ADMINI~1\AppData\Local\Temp\ReachFramework.dll
C:\Users\ADMINI~1\AppData\Local\Temp\UIAutomationProvider.dll
C:\Users\ADMINI~1\AppData\Local\Temp\UIAutomationTypes.dll
C:\Users\ADMINI~1\AppData\Local\Temp\WindowsBase.dll
C:\Users\ADMINI~1\AppData\Local\Temp\WindowsFormsIntegration.dll
C:\Users\dagobert\AppData\Local\Temp\84892uninstall.exe
C:\Users\dagobert\AppData\Local\Temp\fairbot.exe
C:\Users\dagobert\AppData\Local\Temp\flac-1.2.1b.exe
C:\Users\dagobert\AppData\Local\Temp\ICReinstall_ImageEditorSetup.exe
C:\Users\dagobert\AppData\Local\Temp\ICReinstall_ZipExtractorSetup.exe
C:\Users\dagobert\AppData\Local\Temp\Installer_new.exe
C:\Users\dagobert\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\dagobert\AppData\Local\Temp\Mobogenie_Setup_2.1.23_515.exe
C:\Users\dagobert\AppData\Local\Temp\nsfB739.exe
C:\Users\dagobert\AppData\Local\Temp\nslB9DA.exe
C:\Users\dagobert\AppData\Local\Temp\nsoB295.exe
C:\Users\dagobert\AppData\Local\Temp\nsr7B07.exe
C:\Users\dagobert\AppData\Local\Temp\nsx7DE6.exe
C:\Users\dagobert\AppData\Local\Temp\nsz822D.exe
C:\Users\dagobert\AppData\Local\Temp\OptimizerPro.exe
C:\Users\dagobert\AppData\Local\Temp\ose00000.exe
C:\Users\dagobert\AppData\Local\Temp\PokerStarsInstallEU.exe
C:\Users\dagobert\AppData\Local\Temp\Quarantine.exe
C:\Users\dagobert\AppData\Local\Temp\SearchProtectINT.exe
C:\Users\dagobert\AppData\Local\Temp\SplashLite_downloader.exe
C:\Users\dagobert\AppData\Local\Temp\splash_lite_setup.exe
C:\Users\dagobert\AppData\Local\Temp\Sqlite3.dll
C:\Users\dagobert\AppData\Local\Temp\TeamViewer_Setup_de_9.0.24951.exe
C:\Users\dagobert\AppData\Local\Temp\uninst1.exe
C:\Users\dagobert\AppData\Local\Temp\UpdateCheckerSetup.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-28 17:28

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

Ops...sorry ..dachte hätte den LogFile von AdwCleaner gelöscht...

Aber habe den Logfile doch noch :crazy:

Hier :
Code:

# AdwCleaner v3.016 - Bericht erstellt am 04/01/2014 um 18:18:01
# Aktualisiert 23/12/2013 von Xplode
# Betriebssystem : Windows 8  (64 bits)
# Benutzername : dagobert - PC
# Gestartet von : C:\Users\dagobert\Desktop\adwcleaner(1).exe
# Option : Löschen

***** [ Dienste ] *****

[#] Dienst Gelöscht : bonanzadealslive
[#] Dienst Gelöscht : bonanzadealslivem

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\DNSErrorHelper
Ordner Gelöscht : C:\Program Files (x86)\Mobogenie
Ordner Gelöscht : C:\Program Files (x86)\LyriXeeker-1
Ordner Gelöscht : C:\Users\dagobert\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\dagobert\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\dagobert\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\dagobert\AppData\Roaming\FoxTab
Ordner Gelöscht : C:\Users\dagobert\AppData\Roaming\HELPER
Ordner Gelöscht : C:\Users\dagobert\AppData\Roaming\OCS
Ordner Gelöscht : C:\Users\dagobert\Documents\Mobogenie
Ordner Gelöscht : C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default\Extensions\firejump@firejump.net
Ordner Gelöscht : C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccncljhbalbbkkfgopogabimepmfkmff
Ordner Gelöscht : C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgmpcnmaamenhngcinchjeifhhnlaig
Datei Gelöscht : C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default\searchplugins\conduit-search.xml
Datei Gelöscht : C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default\user.js
Datei Gelöscht : C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
Datei Gelöscht : C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www2.delta-search.com_0.localstorage
Datei Gelöscht : C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www2.delta-search.com_0.localstorage-journal
Datei Gelöscht : C:\windows\System32\Tasks\BonanzaDealsUpdate
Datei Gelöscht : C:\windows\Tasks\FoxTab.job
Datei Gelöscht : C:\windows\System32\Tasks\FoxTab
Datei Gelöscht : C:\windows\Tasks\LyriXeeker-1-chromeinstaller.job
Datei Gelöscht : C:\windows\System32\Tasks\LyriXeeker-1-chromeinstaller
Datei Gelöscht : C:\windows\Tasks\LyriXeeker-1-updater.job
Datei Gelöscht : C:\windows\System32\Tasks\LyriXeeker-1-updater

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [dnshelp@dnshelp.com]
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [firejump@firejump.net]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateBatBrowse_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateBatBrowse_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exe
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
Schlüssel Gelöscht : HKLM\SOFTWARE\5328ad9b36abe47
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F904AC50-215C-42AB-A532-77E9FDBA9B19}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FE063412-BEA4-4D76-8ED3-183BE6220D17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063412-BEA4-4D76-8ED3-183BE6220D17}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B67B3DBB-C1C9-49D2-B016-2748B0B5017E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063412-BEA4-4D76-8ED3-183BE6220D17}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B67B3DBB-C1C9-49D2-B016-2748B0B5017E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063412-BEA4-4D76-8ED3-183BE6220D17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4BEF720-313C-420A-ACF6-77DD95D8F553}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{33BAF587-9647-4281-A34F-F4830CDC1B9F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{090bb045-13a7-447c-b78e-30b1ddb41389}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2fa47400-045a-4ff8-81a2-377f157a4e5a}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{37237a65-5777-43f2-ba9b-339de5a29d22}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4b7fb8aa-25e0-4a1d-ba79-f77e674dd6a2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90b3c11d-5652-4b5a-886b-9e20a42dbadc}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\InstalledThirdPartyPrograms
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\SearchProtectINT
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\LyriXeeker-1
Schlüssel Gelöscht : HKLM\Software\LyriXeeker-1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LyriXeeker-1
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledThirdPartyPrograms
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DesktopIconAmazon

***** [ Browser ] *****

-\\ Internet Explorer v10.0.9200.16537


-\\ Mozilla Firefox v26.0 (de)

[ Datei : C:\Users\dagobert\AppData\Roaming\Mozilla\Firefox\Profiles\ufdk0uqw.default\prefs.js ]

Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
Zeile gelöscht : user_pref("extensions.helperbar.Visibility", true);
Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "de");
Zeile gelöscht : user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[]\"}");
Zeile gelöscht : user_pref("extensions.helperbar.installationid", "63d1f931-4e1a-85ca-e2d6-ee2f74858a54");
Zeile gelöscht : user_pref("extensions.helperbar.installdate", "30/12/2013");
Zeile gelöscht : user_pref("extensions.helperbar.lastExternalJsUpdate", "1388405626266");
Zeile gelöscht : user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.43.4.1\",\"InstallEventCTime\":1383091714481,\"InstallEvent\":\"True\"}");

-\\ Google Chrome v31.0.1650.63

[ Datei : C:\Users\dagobert\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht : homepage
Gelöscht : icon_url

*************************

AdwCleaner[R0].txt - [17010 octets] - [04/01/2014 18:11:49]
AdwCleaner[R1].txt - [17071 octets] - [04/01/2014 18:17:23]
AdwCleaner[S0].txt - [15868 octets] - [04/01/2014 18:18:01]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15929 octets] ##########


aharonov 04.01.2014 19:38

Wie läuft der Rechner nach folgenden Schritten? Noch Probleme vorhangen?


Schritt 1

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [ ] ()
BHO: LyriXeeker-1 - {11111111-1111-1111-1111-110411181156} - C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-bho64.dll No File
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 ____D C:\Users\dagobert\AppData\Local\cache
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 _____ C:\Users\dagobert\daemonprocess.txt
C:\Users\dagobert\AppData\Local\Temp\*.exe


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.




Schritt 2

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




Schritt 3


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


boti 05.01.2014 17:57

Hi

...so habe die ersten Schritte wie von Dir beschrieben gemacht.
Ich poste jetzt die beiden Log Files und danach lasse ich ESET das System Scannen

Code:

Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2014.01.04.05

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16750
dagobert :: PC [Administrator]

Schutz: Aktiviert

04.01.2014 21:27:45
mbam-log-2014-01-04 (21-27-45).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 221712
Laufzeit: 4 Minute(n), 19 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\dagobert\Downloads\Java.exe (PUP.Optional.DomaIQ) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\dagobert\Downloads\Java7.exe (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Code:

Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2014.01.04.05

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16750
dagobert :: PC [Administrator]

Schutz: Aktiviert

04.01.2014 21:27:45
mbam-log-2014-01-04 (21-27-45).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 221712
Laufzeit: 4 Minute(n), 19 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\dagobert\Downloads\Java.exe (PUP.Optional.DomaIQ) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\dagobert\Downloads\Java7.exe (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-01-2014
Ran by dagobert at 2014-01-04 21:24:35 Run:1
Running from C:\Users\dagobert\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [ ] ()
BHO: LyriXeeker-1 - {11111111-1111-1111-1111-110411181156} - C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-bho64.dll No File
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 ____D C:\Users\dagobert\AppData\Local\cache
2013-12-30 12:52 - 2013-12-30 12:52 - 00000000 _____ C:\Users\dagobert\daemonprocess.txt
C:\Users\dagobert\AppData\Local\Temp\*.exe
*****************

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411181156} => Key deleted successfully.
HKCR\CLSID\{11111111-1111-1111-1111-110411181156} => Key not found.
C:\Users\dagobert\AppData\Local\cache => Moved successfully.
C:\Users\dagobert\daemonprocess.txt => Moved successfully.
C:\Users\dagobert\AppData\Local\Temp\*.exe => Moved successfully.

==== End of Fixlog ====


aharonov 05.01.2014 18:12

Ok soweit. Der ESET-Scan könnte etwas länger dauern, das ist normal.
(Sind die Probleme mittlerweile verschwunden?)

boti 05.01.2014 22:38

Danke Dir....
ESET hat noch einiges gefunden und in Quarantäne gesteckt...
Aber der Rechner läuft jetzt wieder Richtig Flott!

Danke für deine Hilfe

LG boti

aharonov 05.01.2014 22:42

Hast du das ESET-Log noch?


Alle Zeitangaben in WEZ +1. Es ist jetzt 05:41 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19